Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Congress Passes Bill to Create New Federal Cybersecurity Agency
New HealthEquity Data Breach Exposes PII/PHI of Almost 21,000 Customers
Instagram bug inadvertently exposed some user’s passwords

LinuxSecurity.com: An out-of-bounds bounds memory access issue was discovered in chromium’s v8 javascript library by cloudfuzzer. This update also fixes two problems introduced by the previous security

security update

LinuxSecurity.com: Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message (CVE-2018-17141).

LinuxSecurity.com: Due to incorrect input handling, Squid is vulnerable to a Cross-Site Scripting vulnerability when generating HTTPS response messages about TLS errors (CVE-2018-19131). Due to a memory leak in SNMP query rejection code, Squid is vulnerable

LinuxSecurity.com: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption (CVE-2018-16843). nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the

LinuxSecurity.com: The ProcessGpsInfo function may have allowed a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling (CVE-2018-16554).

LinuxSecurity.com: This update fixes various security vulnerabilities affecting the SDL2_image library, listed below. The fixes are provided in SDL2_image 2.0.4, which depends on SDL2 2.0.8 or later. As such, the SDL2 and SDL2_mixer libraries are also updated to their current stable releases, providing various bug fixes and features.

LinuxSecurity.com: Hanno B?ck discovered that libmspack incorrectly handled certain CHM files. An attacker could possibly use this issue to cause a denial of service (CVE-2018-14679, CVE-2018-14680). Jakub Wilk discovered that libmspack incorrectly handled certain KWAJ

LinuxSecurity.com: The package patch before version 2.7.6-7 is vulnerable to multiple issues including arbitrary command execution and denial of service.

Mylobot Botnet Now Exfiltrates Data Using Second Stage Khalesi Trojan
Malicious code hidden in advert images cost ad networks $1.13bn this year

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 7 fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 8 fixes is now available.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in Python.

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: It was discovered that Mutt incorrectly handled certain requests. An attacker could possibly use this to execute arbitrary code (CVE-2018-14350, CVE-2018-14352, CVE-2018-14354, CVE-2018-14359, CVE-2018-14358, CVE-2018-14353 ,CVE-2018-14357).

LinuxSecurity.com: A NULL pointer dereference flaw was found in the way patch processed patch files. An attacker could potentially use this flaw to crash patch by tricking it into processing crafted patches (CVE-2018-6951). A double-free flaw was found in the way the patch utility processed

LinuxSecurity.com: A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use this flaw to execute code with the permissions of superuser in the database (CVE-2018-1058).

LinuxSecurity.com: It was discovered that incorrect connection setup in the server for Teeworlds, an online multi-player platform 2D shooter, could result in denial of service via forged connection packets (rendering all game server slots occupied) (CVE-2018-18541). This update fixes it.

LinuxSecurity.com: Updated php-pear-CAS packages fix security vulnerabilities: An XSS vulnerabilities has been fixed for proxy mode. References: – https://bugs.mageia.org/show_bug.cgi?id=23833

LinuxSecurity.com: An important vulnerability in Adobe Flash Player 31.0.0.122 and earlier versions. Successful exploitation could lead to information disclosure. (CVE-2018-15978) References:

LinuxSecurity.com: There is a possible XSS vulnerability in Rack. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`.Applications that expect the scheme to be limited to “http” or “https” and do not escape the return value could be vulnerable to an XSS attack (CVE-2018-16471).

LinuxSecurity.com: A flaw was found in gdal up to version 2.3.0. A Heap-buffer-overflow in GTiffOddBitsBand::IReadBlock. A flaw was found in gdal. A Heap-buffer-overflow in NITFRasterBand::Unpack.

Dutch Film Boss Sacked After 19m BEC Loss
2018 on Track to Be One of the Worst Ever for Data Breaches
Cyber criminals abuse US Postal Service Informed Delivery for ID theft

LinuxSecurity.com: Several security issues were mitigated in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

security update

LinuxSecurity.com: PostgreSQL could be made to run SQL statements as the administrator.

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were fixed in Python.

LinuxSecurity.com: The package powerdns-recursor before version 4.1.5-1 is vulnerable to denial of service.

LinuxSecurity.com: The package powerdns before version 4.1.5-1 is vulnerable to denial of service.

LinuxSecurity.com: An update for python-cryptography is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple vulnerabilities were discovered in Ceph, a distributed storage and file system: The cephx authentication protocol was suspectible to replay attacks and calculated signatures incorrectly, “ceph mon” did not validate capabilities for pool operations (resulting in potential

LinuxSecurity.com: Multiple vulnerabilities were found in Spamassassin, which could lead to Remote Code Execution and Denial of Service attacks under certain circumstances.

LinuxSecurity.com: A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: New Red Hat Single Sign-On 7.2.5 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: New Red Hat Single Sign-On 7.2.5 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several security issues were fixed in systemd.

LinuxSecurity.com: gettext could be made to execute arbitrary code if it received a specially crafted message.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

LinuxSecurity.com: Several security issues were fixed in ClamAV.

Post-WannaCry: Only 3% of companies are prepared for new types of cyberattacks
IoT security and Linux: Why IncludeOS thinks it has the edge

LinuxSecurity.com: A security update is now available for Red Hat JBoss BRMS 5.3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for httpd24-httpd, httpd24-nghttp2, and httpd24-curl is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several vulnerabilities have been discovered in the firmware for Broadcom BCM43xx wifi chips that may lead to a privilege escalation or loss of confidentiality.

LinuxSecurity.com: CVE-2018-18025 Fix for heap-based buffer over-read which can result in a denial of service via a crafted file.

security update

LinuxSecurity.com: gettext could be made to execute arbitrary code if it received a specially crafted message.

LinuxSecurity.com: It was discovered that there was a potential SSH passphrase disclosure vulnerability in the ansible configuration management system, The “User” module leaked data that was passed as a parameter to the

LinuxSecurity.com: An update for rh-git29-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple security issues have been found in Thunderbird: Multiple memory safety errors and use-after-frees may lead to the execution of arbitrary code or denial of service.

LinuxSecurity.com: Dulwich, when an SSH subprocess is used, allowed remote attackers to execute arbitrary commands via an ssh URL with an initial dash character in the hostname (CVE-2017-16228). References:

LinuxSecurity.com: A flaw was found in iniparser version prior to 4.1. A stack buffer underflow in the function iniparser_load() in iniparser.c file which can be triggered by parsing a file that containing a zero-byte. This vulnerability may allow an attacker to cause a Denial of Service (DoS).

LinuxSecurity.com: A NULL pointer dereference in modules/ModuleState.cpp:ModuleState::setup() allows for denial of service via crafted file (CVE-2018-13440). A Heap-based buffer overflow was found in Expand3To4Module::run when running sfconvert (CVE-2018-17095).

LinuxSecurity.com: It was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker’s control, allowing to run arbitrary code as a result (CVE-2018-10874). It was found that ansible.cfg is being read from the current working

LinuxSecurity.com: It was discovered that opencc contained an out of bounds pointer in BinaryDict.cpp which could lead to segment fault and a Denial of Service (CVE-2018-16982). References:

LinuxSecurity.com: An out-of-bounds read during parsing of a malformed manifest entry (CVE-2018-17983). References: – https://bugs.mageia.org/show_bug.cgi?id=23763

LinuxSecurity.com: An issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c. (CVE-2018-18661) References:

LinuxSecurity.com: The package systemd before version 239.300-1 is vulnerable to multiple issues including arbitrary code execution and privilege escalation.

security update

LinuxSecurity.com: Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service, disclosure of existence and size of arbitrary files, or the execution of arbitrary code if a malformed Postscript file is processed (despite the

Pakistan Banks Not Breached, but Probably Skimmed
Meaner, more violent Stuxnet variant reportedly hits Iran
Ransomware Still the Top Malware Threat During 2018 According to Europol
Zero-day in popular WordPress plugin exploited in the wild to take over sites
Income, tax and immigration data stolen in Healthcare.gov breach

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.62.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-curl before version 7.62.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.62.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-compat before version 7.62.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-gnutls before version 7.62.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: Multiple security issues have been found in Thunderbird: Multiple memory safety errors may lead to the execution of arbitrary code or denial of service.

LinuxSecurity.com: The package curl before version 7.62.0-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

Oracle’s VirtualBox vulnerability leaked by disgruntled researcher
Dharma Ransomware Hits Altus Baytown Hospital’s Systems

LinuxSecurity.com: Multiple vulnerabilities have been found in libde265, the worst of which allows remote attackers to execute arbitrary code.