Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

NSA Brings Nation-State Details to DEF CON
#DEFCON L0pht Reunite to Find Security Unimproved

security update

security update

LinuxSecurity.com: – update to 2.56.x

LinuxSecurity.com: – update to 2.56.x

LinuxSecurity.com: rebase to 8.37.0 ———————- – few fixes and enhancements handling journal input – now requires librelp at least 1.2.16, adding support for setting address to bind – various other rsyslog core bugfixes and stability fixes

LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Two vulnerabilities have been found in the PostgreSQL database system: CVE-2018-10915

LinuxSecurity.com: It was discovered that the PatternSyntaxException class in the Concurrency component of OpenJDK, an implementation of the Oracle Java platform could result in denial of service via excessive memory consumption.

LinuxSecurity.com: Various vulnerabilities leading to denial of service or possible unspecified other impacts were discovered in sam2p, an utility to convert raster images to EPS, PDF, and other formats.

LinuxSecurity.com: Several security issues were fixed in the kernel.

Over 20 Flaws Discovered in Popular Healthcare Software
#BHUSA: Politics and Cyber-Defense Are Colliding

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: Java applications could be made to use excessive memory.

LinuxSecurity.com: Java applications could be made to use excessive memory.

security update

How SELinux helps mitigate risk while facilitating compliance

LinuxSecurity.com: The following vulnerability was discovered in wpa_supplicant. CVE-2018-14526: | An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0

IT Leaders Believe AI is a ‘Silver Bullet’ for Threats
Healthcare Firm Exposes Data on 2m+ Mexicans

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: The package linux-hardened before version 4.17.11.a-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux-zen before version 4.17.11-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux before version 4.17.11-1 is vulnerable to denial of service.

LinuxSecurity.com: The package linux-lts before version 4.14.59-1 is vulnerable to denial of service.

LinuxSecurity.com: Henning Westerholt discovered a flaw related to the To header processing in kamailio, a very fast, dynamic and configurable SIP server. Missing input validation in the build_res_buf_from_sip_req function could result in denial of service and potentially the execution of arbitrary code.

LinuxSecurity.com: New upstream version 0.7alpha. Fixes CVE-2018-14679 libmspack: off-by-one error in the CHM PMGI/PMGL chunk number validity checks

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The security update for slurm-llnl introduced a regression in the fix for CVE-2018-10995 which broke accounting. For Debian 8 “Jessie”, this problem has been fixed in version

SingHealth Attack Potentially State-Linked
Linux kernel bug: TCP flaw lets remote attackers stall devices with tiny DoS attack

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Chipmaker TSMC Hit by Virus Outbreak
Privacy International Takes Police Phone ‘Hacking’ Case to IPC

LinuxSecurity.com: It was discovered that there were several vulnerabilities in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious .CAB, .CHM or .KWAJ files

LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.

LinuxSecurity.com: It was discovered that there was a directory traversal vulnerability in cgit, a web frontend for Git repositories. For Debian 8 “Jessie”, this issue has been fixed in cgit version

LinuxSecurity.com: An update for openslp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for rhvm-setup-plugins is now available for Red Hat Virtualization Engine 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The fix for CVE-2018-10886 was incomplete in the previous upload. New changes was implemented upstream which check and resolve symlinks before expanding the archives.

LinuxSecurity.com: It was discovered that the Apache XML Security for C++ library performed insufficient validation of KeyInfo hints, which could result in denial of service via NULL pointer dereferences when processing malformed XML data.

LinuxSecurity.com: Andreas Hug discovered an open redirect in Django, a Python web development framework, which is exploitable if django.middleware.common.CommonMiddleware is used and the APPEND_SLASH setting is enabled.

security update

security update

LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)

LinuxSecurity.com: Update to 3.2.1 (CVE-2017-12627)

LinuxSecurity.com: Backport fix for CVE 2017-11548

security update

LinuxSecurity.com: The package python2-django before version 1.11.15-1 is vulnerable to open redirect.

LinuxSecurity.com: The package cgit before version 1.2.1-1 is vulnerable to directory traversal.

Industrial Sector Targeted in Highly Personalized Spear-Phishing Campaign
GDPR: What’s really changed so far?

LinuxSecurity.com: Jann Horn discovered a directory traversal vulnerability in cgit, a fast web frontend for git repositories written in C. A remote attacker can take advantage of this flaw to retrieve arbitrary files via a specially crafted request, when ‘enable-http-clone=1’ (default) is not turned off.

security update

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]

LinuxSecurity.com: Sync with git (CVE-2017-14160, CVE-2018-10392, CVE-2018-10393, bz#1516379)

LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards

security update

LinuxSecurity.com: Update Python 2 dependency declarations to new packaging standards

LinuxSecurity.com: The 4.17.11 stable update contains a number of important fixes across the tree. Also of note, starting with this release, kernel-headers is built from a different srpm. The contents should be the same, but there were some benefits to breaking it from the kernel build. —- The 4.17.10 stable kernel update contains a number […]

LinuxSecurity.com: Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to open redirects, cross-site request forgery, information disclosure, session fixation or denial of service.

LinuxSecurity.com: Enrico Zini discovered a vulnerability in Syntastic, an addon module for the Vim editor that runs a file through external checkers and displays any resulting errors. Config files were looked up in the current working directory which could result in arbitrary

LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275

LinuxSecurity.com: Update to 2.26, fixes CVE-2018-9275

LinuxSecurity.com: Several security issues were fixed in ClamAV.

LinuxSecurity.com: It was found that the security update of busybox announced as DLA-1445-1 to prevent the exploitation of CVE-2011-5325, a symlinking attack, was too strict in case of cpio archives. This update restores the old behavior.

DHS Launches Cyber-Risk Management Center
Reddit Breached After SMS 2FA Fail

LinuxSecurity.com: Various vulnerabilities were discovered in graphicsmagick, a collection of image processing tools and associated libraries, resulting in denial of service, information disclosure, and a variety of buffer overflows and overreads.

security update

LinuxSecurity.com: New lftp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Several vulnerabilities were discovered in libsmpack, a library used to handle Microsoft compression formats. A remote attacker could craft malicious CAB, CHM or KWAJ files and use these flaws to cause a denial of service via application crash, or potentially execute arbitrary code.

LinuxSecurity.com: openslp: Heap memory corruption in slpd/slpd_process.c allows denial of service or potentially code execution (CVE-2017-17833) SL6 x86_64 openslp-2.0.0-3.el6.i686.rpm openslp-2.0.0-3.el6.x86_64.rpm openslp-debuginfo-2.0.0-3.el6.i686.rpm openslp-debuginfo-2.0.0-3.el6.x86_64.rpm openslp-devel-2.0.0-3.el6.i686.rpm openslp-devel-2.0.0-3.el6.x86_64.rpm openslp-server- [More…]

LinuxSecurity.com: New version 2.6.2. Security fix for CVE-2018-14339, CVE-2018-14340, CVE-2018-14341, CVE-2018-14342, CVE-2018-14343, CVE-2018-14344, CVE-2018-14367, CVE-2018-14368, CVE-2018-14369, CVE-2018-14370.

LinuxSecurity.com: Update to 6.6. —- Version 6.5 – address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 – fix injection of Fedora LDFLAGS