Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Updated openssl packages fix security vulnerabilities: During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a

LinuxSecurity.com: Updated java-1.8.0-openjdk packages fixes atleast the following security vulnerability: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (CVE-2018-2952)

LinuxSecurity.com: The updated packages fix security vulnerabilities: gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a

LinuxSecurity.com: Two security issues have been discovered in the Tomcat servlet and JSP engine. CVE-2018-1336

Hearing Date Set in Georgia Election Security Case
How One Company’s Cybersecurity Problem Becomes Another’s Fraud Problem

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Two vulnerabilities have been discovered in php5, a server-side, HTML-embedded scripting language. One (CVE-2018-14851) results in a potential denial of service (out-of-bounds read and application crash)

Lessons From the Black Hat USA NOC

LinuxSecurity.com: A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or,

LinuxSecurity.com: This update provides mercurial version 4.6.2 and fixes the following security issues: Fix the mpatch_apply function in mpatch.c that incorrectly proceeds in cases where the fragment start is past the end of the original data

LinuxSecurity.com: The updated packages fix a security vulnerability: Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial

LinuxSecurity.com: The updated packages fix security vulnerabilities: An out-of-bounds read flaw exists in parse_file_info in archive_read_support_format_iso9660.c in libarchive 3.3.2 when extracting a specially crafted iso9660 iso file, related to

LinuxSecurity.com: This update provides libraw 0.18.13 fixing atleast the following security issues: LibRaw versions prior to 0.18.12 are vulnerable to an integer overflow in the internal/dcraw_common.cpp:parse_qt() function. An attacker could

LinuxSecurity.com: Updated mariadb packages fix security vulnerabilities: Vulnerability in the MariaDB Server component of MariaDB (subcomponent: MyISAM). Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MariaDB Server.

LinuxSecurity.com: Updated quazip packages fix security vulnerability: A vulnerability has been found in the way developers have implemented the archive extraction of files. An arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other

LinuxSecurity.com: This update provides the virtualbox 5.1.18 maintenance release that fixes atleast the following security issues: Fixed an easily exploitable vulnerability that allowed unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox

LinuxSecurity.com: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c (CVE-2018-15473).

LinuxSecurity.com: Updated libxcursor packages fix security vulnerability _XcursorThemeInherits in library.c in libXcursor before 1.1.15 allows remote attackers to cause denial of service or potentially code execution via a one-byte heap overflow. (CVE-2015-9262)

LinuxSecurity.com: Updated squirrelmail packages fix XSS-security vulnerability: It was discovered that some special tags have not been filtered accordingly which can be used for an XSS-attack.

LinuxSecurity.com: It was discovered that there were a number of Cross Site Scripting (XSS) vulnerabilities in the squirrelmail webmail client. For Debian 8 “Jessie”, these issues has been fixed in squirrelmail

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Passport Numbers Exposed in Air Canada Data Breach
‘Celebgate’ Hacker Heading to Prison
What is WannaCry ransomware, how does it infect, and who was responsible?

LinuxSecurity.com: CVE-2018-5740 The “deny-answer-aliases” feature in BIND has a flaw which can cause named to exit with an assertion failure.

LinuxSecurity.com: CVE-2018-10871 By default nsslapd-unhashed-pw-switch was set to ‘on’. So a copy of

LinuxSecurity.com: Several security issues were fixed in libx11.

LinuxSecurity.com: Several security issues were fixed in libx11.

LinuxSecurity.com: An update for OpenDaylight is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: poppler could be made to crash if it received specially crafted PDF file.

A DDoS Knocked Spain’s Central Bank Offline
A False Sense of Security

LinuxSecurity.com: Several issues were discovered in libx11, the client interface to the X Windows System. The functions XGetFontPath, XListExtensions, and XListFonts are vulnerable to an off-by-one override on malicious server responses. A malicious server could also send a reply in which

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2570

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2557

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2571

ICO Breach Complaints Jump 160% in a Year
The Difference Between Sandboxing, Honeypots & Security Deception
Fiserv Flaw Exposed Customer Data at Hundreds of Banks

LinuxSecurity.com: Several issues were discovered in the Tomcat servlet and JSP engine. They could lead to unauthorized access to protected resources, denial-of-service, or information leak.

security update

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate security issues.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read

LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL6 x86_64 bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-debuginfo-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.i686.rpm bind-libs-9.8.2-0.68.rc1.el6_10.1.x86_64.rpm bind-utils-9.8.2-0.68.rc1.el6_10.1 [More…]

LinuxSecurity.com: bind: processing of certain records when “deny-answer-aliases” is in use may trigger an assert leading to a denial of service (CVE-2018-5740) SL7 x86_64 bind-debuginfo-9.9.4-61.el7_5.1.i686.rpm bind-debuginfo-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-9.9.4-61.el7_5.1.i686.rpm bind-libs-9.9.4-61.el7_5.1.x86_64.rpm bind-libs-lite-9.9.4-61.el7_5.1.i686.rpm bind-libs-lite-9. [More…]

LinuxSecurity.com: Several security issues were fixed in GD.

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.4 Advanced Mission Critical (AMC). This notification applies only to those customers subscribed to the Advanced Mission Critical (AMC) channel for Red Hat Enterprise Linux 6.4.

EU may fine political groups misusing personal data to skew elections
How hackers managed to steal $13.5 million in Cosmos bank heist

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 10 fixes is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in Ruby 2.1. CVE-2016-2337

LinuxSecurity.com: The Bootstrap framework was found to have cross-site scripting vulnerabilities in the “collapse” plugin. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: The system could be made to expose sensitive information.

US Election Hack Whistleblower Gets Five Years
Cheddar’s Scratch Kitchen Chain Suffers Data Breach

LinuxSecurity.com: An update for rh-postgresql96-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-postgresql10-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 31 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

99% of Texas Voter Records Exposed
It’s The Season For A Lot Of Interesting Linux / Open-Source Conferences
T-Mobile, AT&T customer account PINs were exposed by website flaws

LinuxSecurity.com: CVE-2018-15501 A potential out-of-bounds read when processing a “ng” smart packet might lead to a Denial of Service.

The GDPR Ripple Effect
T-Mobile Hacked – 2 Million Customers’ Personal Data Stolen

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: Spice could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: postgresql: Certain host connection parameters defeat client-side security defenses (CVE-2018-10915) SL7 x86_64 postgresql-debuginfo-9.2.24-1.el7_5.i686.rpm postgresql-debuginfo-9.2.24-1.el7_5.x86_64.rpm postgresql-libs-9.2.24-1.el7_5.i686.rpm postgresql-libs-9.2.24-1.el7_5.x86_64.rpm postgresql-9.2.24-1.el7_5.i686.rpm postgresql-9.2.24-1.el7_5.x86_64.rpm postgre [More…]

LinuxSecurity.com: An update for postgresql is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Medical records of high school students leaked in ‘appalling’ data breach

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

security update

LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Pango could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: Several security issues were fixed in Spidermonkey.

LinuxSecurity.com: An update that solves two vulnerabilities and has 21 fixes is now available.