Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: The package wesnoth before version 1.14.4-1 is vulnerable to arbitrary code execution.

security update

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to fix security issues.

security update

LinuxSecurity.com: The fix for arbitrary code execution documented in CVE-2017-17458 was incomplete in the previous upload. A more exhaustive change was implemented upstream and completely disables non-Mercurial subrepositories unless users changed the subrepos.allowed setting.

LinuxSecurity.com: USN-3722-1 introduced a regression in ClamAV.

LinuxSecurity.com: A security update is now available for Red Hat JBoss Enterprise Application Platform from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A security update is now available for Red Hat Single Sign-On 7.2 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Virginian Bank Robbed Twice in Eight Months
COSCO Hit by Suspected Ransomware

LinuxSecurity.com: The security update of mailman announced as DLA-1442-1 introduced a regression due to an incomplete fix for CVE-2018-13796 that broke the admin and listinfo overview pages.

LinuxSecurity.com: Security researchers identified two software analysis methods that, if used for malicious purposes, have the potential to improperly gather sensitive data from multiple types of computing devices with different vendors’ processors and operating systems.

LinuxSecurity.com: Busybox, utility programs for small and embedded systems, was affected by several security vulnerabilities. The Common Vulnerabilities and Exposures project identifies the following issues.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-4117

LinuxSecurity.com: CVE-2018-11319 The improper handling of search for configuration files might be exploited for arbitrary code execution via a malicious gcc plugin.

LinuxSecurity.com: An update for ceph is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2241

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2252

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2242

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2240

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

8 types of malware and how to recognize them
DHS Officials: Hundreds of US Utility Victims Infiltrated by Russian Hackers

LinuxSecurity.com: The package jenkins before version 2.133-1 is vulnerable to multiple issues including access restriction bypass, arbitrary filesystem access, cross-site scripting and information disclosure.

security update

security update

LinuxSecurity.com: This update includes the latest upstream release, **httpd 2.4.34**, with multiple bug fixes and enhancements. See http://www.apache.org/dist/httpd/CHANGES_2.4.34 for more information on the changes in this version. A security vulnerability is addressed in this update: * `mod_md`: DoS via Coredumps on specially crafted requests (CVE-2018-8011)

LinuxSecurity.com: New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2251

Security Technologies: ExecShield
Endpoint Concerns Blight IIoT Security
Two-Thirds of Organizations Hit in Supply-Chain Attacks
London Calling with New Strategies to Stop Ransomware

LinuxSecurity.com: A vulnerability has been discovered in Sympa, a modern mailing list manager, that allows write access to files on the server filesystem. This flaw allows to create or modify any file writable by the Sympa user, located on the server filesystem, using the function of Sympa

LinuxSecurity.com: The libarchive-zip-perl package is vulnerable to a directory traversal attack in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use

LinuxSecurity.com: CVE-2018-12584 A flaw in function ConnectionBase::preparseNewBytes of resip/stack/ConnectionBase.cxx has been detected, that

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

security update

LinuxSecurity.com: Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Supplier Error Leaks Decade of Data from Carmakers
Campaign’s Election Data Exposed in Virginia

LinuxSecurity.com: An update for rhev-hypervisor7 is now available for RHEV 3.X Hypervisor and Agents for Red Hat Enterprise Linux 6 and RHEV 3.X Hypervisor and Agents Extended Lifecycle Support for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for rh-ror50-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ror42-rubygem-sprockets is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: OpenJDK: insufficient index validation in PatternSyntaxException getMessage() (Concurrency, 8199547) (CVE-2018-2952) SL6 x86_64 java-1.8.0-openjdk-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8.0-openjdk-debug-1.8.0.181-3.b13.el6_10.x86_64.rpm java-1.8 [More…]

LinuxSecurity.com: Update to 1.2.6 to fix a local authenticated privilege escalation bug (CVE-2018-10900). The issue has been discovered and responsibly disclosed by Denis Andzakovic: https://pulsesecurity.co.nz/advisories/NM-VPNC-Privesc

LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.

LinuxSecurity.com: A regression that caused boot failures was fixed in the Linux kernel.

Has GDPR Impacted Insider Threats?
UK Gov Launches Consultation to Speed-Up Cybersecurity Strategy
Attention Airline Passengers, Your Data Is at Risk

LinuxSecurity.com: Multiple vulnerabilities have been found in Passenger, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: CVE-2018-7033 Fix for issue in accounting_storage/mysql plugin by always escaping strings within the slurmdbd.

LinuxSecurity.com: Early versions of opencv have problems while reading data, which might result in either buffer overflows, out-of bounds errors or integer

US Intel Officials Share Their National Cybersecurity Concerns
Key takeaways from Singapore healthcare data breach

LinuxSecurity.com: The package networkmanager-vpnc before version 1.2.6-1 is vulnerable to privilege escalation.

LinuxSecurity.com: The package apache before version 2.4.34-1 is vulnerable to denial of service.

LinuxSecurity.com: The package znc before version 1.7.1-1 is vulnerable to multiple issues including privilege escalation and directory traversal.

The Fundamental Flaw in Security Awareness Programs
IoT hacker builds Huawei-based botnet, enslaves 18,000 devices in one day

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program.

LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)

LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.

LinuxSecurity.com: An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The dns-root-data update to 2017072601~deb8u2 broke dnsmasq’s init script, making dnsmasq no longer start when dns-root-data was installed.

Millions of Health Records at Risk Following LabCorp Suspected Breach
Gov Slow to Address Urgent CNI Security Needs
White House Cybersecurity Strategy at a Crossroads

LinuxSecurity.com: The linux-base package has been updated to support the package of Linux 4.9 that was recently added to Debian 8. This resolves a dependency that was not satisfiable by the jessie and jessie-security suites.

LinuxSecurity.com: CVE-2015-1239 Fix for denial of service (process crash) via a crafted PDF.

security update

security update

LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)

LinuxSecurity.com: Fix heap memory corruption, CVE-2017-17833

LinuxSecurity.com: – Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) – Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) – Fix two-key 3DES (PR #390) – Fix accelerated CTR mode (PR #359) – Fix Fortuna PRNG (PR #363) – Fix compilation on platforms where cc doesn’t point to gcc (PR #382) […]

LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.

LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.

LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for fluentd is now available for Red Hat OpenStack Platform 13.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

Cloud Security: Lessons Learned from Intrusion Prevention Systems
US Vote-Counting Computers Had Flaw, Allowed Hackers Access
US Orgs Overly Optimistic About Cyber-Readiness

LinuxSecurity.com: unzip and untar target tasks in ant allows the extraction of files outside the target directory. A crafted zip or tar file submitted to an Ant build could create or overwrite arbitrary files with the

LinuxSecurity.com: Jeriko One discovered two vulnerabilities in the ZNC IRC bouncer which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: CVE-2018-11439 Fix for a heap-based buffer over-read via a crafted audio file.

security update

security update

LinuxSecurity.com: New release (1:12.2.6-1) Security fix for CVE-2018-1128 Security fix for CVE-2018-1129 Security fix for CVE-2018-10861