Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in Ghostscript.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: Firefox 60 is now the only supported version of the ESR series and it brings a completely new browser engine, designed to take full advantage of the processing power in modern devices. Firefox also now exclusively supports extensions built using the WebExtension API.

security update

Linux Is Getting New Network Libraries From Veteran systemd/BUS1 Developers
Python is a hit with hackers, report finds

LinuxSecurity.com: This is an update to Mozilla’s CA certificates list version 2.26, which has been published as part of Mozilla NSS 3.39. For additional details, please refer to the NSS 3.39 release notes: https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.39_release_notes

LinuxSecurity.com: Security fix for CVE-2018-17336

LinuxSecurity.com: libxkbcommon 0.8.2, CVE-2018-15853 through to 15864. These fix a number of memory handling issues with xkbcommon. Together with the keymap FD handling in various Wayland compositors (keymaps could be mapped rw and clients could thus replace the content) libxkbcommon’s memory issues could serve as attack vector to gain access to another client. The update […]

LinuxSecurity.com: Fixed some small bugs in the previous package: Initial rules now have the correct version, sought channel config is dropped (since it doesn’t exist anymore) and build / runtime deps adjusted. —- Update to 3.4.2. Fixes CVE-2017-15705, CVE-2018-11780 and CVE-2018-11781 along with many other bugfixes and improvements. See https://www.mail-

LinuxSecurity.com: Security fix for CVE-2018-17336

LinuxSecurity.com: **libbson 1.13.0** **Features:** * New functions to save and restore progress of a bson_iter_t: bson_iter_key_len, bson_iter_offset, and son_iter_init_from_data_at_offset Additional functions bson_iter_overwrite_date_time, bson_iter_overwrite_oid, and bson_iter_overwrite_timestamp. All fixed-length BSON values can now be

security update

LinuxSecurity.com: It was discovered that the emergency logging system in 389-ds-base (the 389 Directory Server) is affected by a race condition caused by the invalidation of the concurrently used log file file descriptor without proper locking. This issue might be triggered by remote attackers to

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2731

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2731

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2766

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2757

Mobile password managers vulnerable to phishing apps
Linux firewalls: What you need to know about iptables and firewalld

LinuxSecurity.com: CVE-2017-7653 As invalid UTF-8 strings are not correctly checked, an attacker could

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and a buffer overflow in PyString_DecodeEscape.

LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).

LinuxSecurity.com: Changes since 10.1.8.16: === v 10.1.9.6 handle legacy external message recipients * [XSS] Updated known HTML5 events * Better IPV6 support * UI support for protocol-only entries v 10.1.9.5

LinuxSecurity.com: Security fix for CVE-2018-10897

LinuxSecurity.com: This release fixes a heap-based buffer over-read when parsing a mallformed BSON document (CVE-2018-16790).

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Majority of Orgs Failing to Make Machine Learning Fair, Safe & Balanced
Critical Linux Kernel Flaw Gives Root Access to Attackers
BLK-MQ To Support Runtime Power Management With Linux 4.20~5.0

LinuxSecurity.com: Several security issues were fixed in Mutt.

LinuxSecurity.com: CVE-2018-14404 Fix of a NULL pointer dereference which might result in a crash and thus in a denial of service.

LinuxSecurity.com: Multiple security issues were discovered in Python: ElementTree failed to initialise Expat’s hash salt, two denial of service issues were found in difflib and poplib and the shutil module was affected by a command injection vulnerability.

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty), Red Hat OpenStack Platform 9.0 (Mitaka), Red Hat OpenStack Platform 10.0 (Newton), Red Hat OpenStack Platform 12.0 (Pike), and Red Hat OpenStack Platform 13.0 (Queens).

Linux Readying Spectre V2 Userspace-Userspace Protection
Mirai Authors Escape Jail Time – But Here Are 7 Other Criminal Hackers Who Didn’t
Malware steals passwords from 6.4 million SHEIN customers

LinuxSecurity.com: Security fix for CVE-2018-16435

LinuxSecurity.com: HylaFAX+ 5.6.1 vulnerabilities (18 Sep 2018)

LinuxSecurity.com: The 4.18.9 stable update contains a number of important fixes across the tree. —- The 4.18.8 update contains a number of important fixes across the tree

LinuxSecurity.com: Fix for CVE-2018-14630

LinuxSecurity.com: Security fix for CVE-2017-5950.

LinuxSecurity.com: Fixed 2.1.0 update, includes security fixes and added performance fix

Security Technologies: FORTIFY_SOURCE
The Sony hacker indictment: 5 lessons for IT security
Vulnerable open source component adoption skyrockets in the enterprise
French cybersecurity agency open sources security hardened CLIP OS

LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.6.173.0.130 is now available with updates to packages that fix one security issue and several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple vulnerabilities were found in the CPython interpreter which can cause denial of service, information gain, and arbitrary code execution.

LinuxSecurity.com: Multiple vulnerabilities were found in the CPython interpreter which can cause denial of service, information gain, and arbitrary code execution.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

security update

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for mod_perl is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package zsh before version 5.6-1 is vulnerable to insufficient validation.

Freelance workers targeted in new malware campaign
Linux or Windows: 25 Things You Must Know While Choosing The Best Platform

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

security update

security update

security update

LinuxSecurity.com: mod_perl: arbitrary Perl code execution in the context of the user account via a user-owned .htaccess (CVE-2011-2767) SL6 x86_64 mod_perl-2.0.4-12.el6_10.x86_64.rpm mod_perl-debuginfo-2.0.4-12.el6_10.x86_64.rpm mod_perl-debuginfo-2.0.4-12.el6_10.i686.rpm mod_perl-devel-2.0.4-12.el6_10.i686.rpm mod_perl-devel-2.0.4-12.el6_10.x86_64.rpm i386 mod_perl-2.0.4-12.el6_10. [More…]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in openafs, an implementation of the distributed filesystem AFS. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

White House Issues National Cyber Strategy
Independence Blue Cross Breach Exposed 17K Records
Data Manipulation: How Security Pros Can Respond to an Emerging Threat

LinuxSecurity.com: Joran Herve discovered that the Okular document viewer was susceptible to directory traversal via malformed .okular files (annotated document archives), which could result in the creation of arbitrary files.