Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 33 fixes is now available.

LinuxSecurity.com: A vulnerability was discovered in uw-imap, the University of Washington IMAP Toolkit, that might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a

Latest container exploit (runc) can be blocked by SELinux
A year in review: 2018 Product Security Risk Report

LinuxSecurity.com: Garming Sam reported an out-of-bounds read in the ldb_wildcard_compare() function of ldb, a LDAP-like embedded database, resulting in denial of service.

LinuxSecurity.com: Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform various Cross-Side Scripting (XSS) and PHP injections attacks, delete files, leak potentially sensitive data, create posts of unauthorized types, or

security update

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Several security issues were fixed in GD.

LinuxSecurity.com: ultiple vulnerabilities have been discovered in SoX (Sound eXchange), a sound processing program: CVE-2017-15370

LinuxSecurity.com: An update for java-11-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Several vulnerabilities were found in QEMU, a fast processor emulator: CVE-2018-12617

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update that solves two vulnerabilities and has four fixes is now available.

LinuxSecurity.com: An information leak issue was discovered in phpMyAdmin. An attacker can read any file on the server that the web server’s user can access. This is related to the mysql.allow_local_infile PHP

LinuxSecurity.com: A regression was introduced in the previous chromium security update. The browser would always crash when launched in headless mode. This update fixes this problem.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 7 fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 7 fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 to fix a security issue.

LinuxSecurity.com: Security fix for CVE-2018-16741,CVE-2018-16744,CVE-2018-16745

LinuxSecurity.com: The package logstash before version 6.6.1-1 is vulnerable to information disclosure.

LinuxSecurity.com: The package elasticsearch before version 6.6.1-1 is vulnerable to privilege escalation.

LinuxSecurity.com: An update for polkit is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: GNOME Keyring could be made to expose sensitive information.

LinuxSecurity.com: USN-3866-2 introduced a regression in Ghostscript.

LinuxSecurity.com: LDB could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: ultiple vulnerabilities have been discovered in liblivemedia, the LIVE555 RTSP server library: CVE-2019-6256

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 7 vulnerabilities is now available.

LinuxSecurity.com: The package kibana before version 6.6.1-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several security issues were fixed in Bind.

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A newer version of waagent is needed for several features of the Azure platform. For Debian 8 “Jessie”, this problem has been fixed in version

LinuxSecurity.com: The package msmtp before version 1.8.3-1 is vulnerable to certificate verification bypass.

LinuxSecurity.com: The package python-mysql-connector before version 8.0.15-1 is vulnerable to authentication bypass.

Setting up a Django application on RHEL 8 Beta

security update

security update

security update

security update

Consistent security by crypto policies in Red Hat Enterprise Linux 8
It starts with Linux: How Red Hat is helping to counter Linux container security flaws
Understanding the Red Hat Enterprise Linux random number generator interface
Hardening ELF binaries using Relocation Read-Only (RELRO)
What data privacy means and how to guard it in 2019
Preparing for Identity Management in Red Hat Enterprise Linux 8
Red Hat Global Customer Tech Outlook 2019: Automation, cloud, & security lead funding priorities
The Kubernetes privilege escalation flaw: Innovation still needs IT security expertise
Understanding the critical Kubernetes privilege escalation flaw in OpenShift 3
Security embargoes at Red Hat

security update

security update

security update

The package python2-django before version 1.11.19-1 is vulnerable to denial of service.

The package python-django before version 2.1.6-1 is vulnerable to denial of service.

The package lib32-curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-compat before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package lib32-libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package libcurl-gnutls before version 7.64.0-1 is vulnerable to arbitrary code execution.

The package curl before version 7.64.0-1 is vulnerable to arbitrary code execution.

security update

The package aubio before version 0.4.9-1 is vulnerable to denial of service.

The package libu2f-host before version 1.1.7-1 is vulnerable to arbitrary code execution.

The package spice before version 0.14.0-3 is vulnerable to arbitrary code execution.

The package chromium before version 72.0.3626.81-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing and insufficient validation.

security update

The package firefox before version 65.0-1 is vulnerable to multiple issues including arbitrary code execution, privilege escalation and access restriction bypass.

The package dovecot before version 2.3.4.1-1 is vulnerable to authentication bypass.

security update

EU Parliament Clears a Path to Give Snowden Asylum
Still fuming over HTTPS mishap, Google makes Symantec an offer it can
Teen Who Hacked CIA Director
Vint Cerf and 260 experts give FCC a plan to secure Wi-Fi routers
Journalist convicted of helping Anonymous hack the LA Times
Security awareness is our shared responsibility
10 cutting-edge security threats
CSOs could see 7% raise next year
Arrest of 14-Year-Old Student for Making a Clock: the Fruits of Sustained Fearmongering and Anti-Mus

security update

security update

security update

security update

security update

security update

security update