Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: CVE-2018-11439 Fix for a heap-based buffer over-read via a crafted audio file.

security update

security update

LinuxSecurity.com: New release (1:12.2.6-1) Security fix for CVE-2018-1128 Security fix for CVE-2018-1129 Security fix for CVE-2018-10861

LinuxSecurity.com: The package curl before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-curl before version 7.61.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: Several security issues were fixed in PolicyKit.

SPECTRE Variant 1 scanning tool
Time to Yank Cybercrime into the Light
Russian National Vulnerability Database Operation Raises Suspicions

LinuxSecurity.com: A vulnerability was discovered in WordPress, a web blogging tool. It allowed remote attackers with specific roles to execute arbitrary code.

LinuxSecurity.com: A vulnerability in tqdm could allow remote attackers to execute arbitrary code.

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in various parsers of Blender, a 3D modeller/ renderer. Malformed .blend model files and malformed multimedia files (AVI, BMP, HDR, CIN, IRIS, PNG, TIFF) may result in the execution of arbitrary code.

LinuxSecurity.com: New mutt packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

security update

LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL7 x86_64 gnupg2-2.0.22-5.el7_5.x86_64.rpm gnupg2-debuginfo-2.0.22-5.el7_5.x86_64.rpm gnupg2-smime-2.0.22-5.el7_5.x86_64.rpm gnupg2-2.0.22-5.el7_5.src.rpm – Scientific Linux Development Team

LinuxSecurity.com: An update that fixes one vulnerability is now available.

“Red Alert” Warning on US Cyber-Attacks, Now at “Critical Point”
Russia Fends Off 25 Million Cyber-Attacks During World Cup

LinuxSecurity.com: The package thunderbird before version 52.9.1-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery and information disclosure.

LinuxSecurity.com: A timing attack was discovered in the function for CSRF token validation of the “Ruby rack protection” framework. For the stable distribution (stretch), this problem has been fixed in

security update

security update

LinuxSecurity.com: The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo

LinuxSecurity.com: – Security fix for CVE-2017-9258, CVE-2017-9259, CVE-2017-9260

Major International Airport System Access Sold for $10 on Dark Web
Western E-Tailers Set to Lose Nearly $19bn to Fraud
GandCrab Ransomware Continues to Evolve But Can’t Spread Via SMB Shares Yet

LinuxSecurity.com: CVE-2015-1854 A flaw was found while doing authorization of modrdn operations. An unauthenticated attacker able to issue an ldapmodrdn call to

LinuxSecurity.com: It was discovered that there were two issues in znc, a modular IRC bouncer: * There was insufficient validation of lines coming from the network

Australia’s Airport Security Threatened by Hack
FBI: Email Account Compromise Losses Reach $12B
Russian intelligence officers indicted in DNC hacking

LinuxSecurity.com: Update to 4.9.7 security release. https://wordpress.org/news/2018/07/wordpress-4-9-7-security-and-maintenance- release/

LinuxSecurity.com: Security fix for CVE-2018-8009 —- Version update to 2.7.6. Fixes many open CVEs and bugs.

LinuxSecurity.com: Update to Sprockets 3.7.2. Fixes CVE-2018-3760: https://access.redhat.com/security/cve/cve-2018-3760

security update

LinuxSecurity.com: Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System. These issues have been identified with the following CVE ids: CVE-2018-4180

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

Timehop Reveals More Personal Data Was Breached
WordPress Sites Targeted in World Cup-Themed Spam Scam

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

LinuxSecurity.com: gnupg2: Improper sanitization of filenames allows for the display of fake status messages and the bypass of signature verification (CVE-2018-12020) SL6 x86_64 gnupg2-2.0.14-9.el6_10.x86_64.rpm gnupg2-debuginfo-2.0.14-9.el6_10.x86_64.rpm gnupg2-smime-2.0.14-9.el6_10.x86_64.rpm i386 gnupg2-2.0.14-9.el6_10.i686.rpm gnupg2-debuginfo-2.0.14-9.el6_10.i686.rpm gnupg2-smim [More…]

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Red Hat JBoss Core Services Pack Apache Server 2.4.29 packages are now available. Red Hat Product Security has rated this release as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was discovered that there was a symlink attack in the Cinnamon desktop environment. An attacker could overwrite an arbitrary file on the filesystem via

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2112

LinuxSecurity.com: Update to upstream version 9.4.11. Fixes CVE-2017-7656, CVE-2017-7657, CVE-2017-7658, CVE-2018-12538.

Insights Security Hardening Rules

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Not All Hacks Are Created Equal
This Is How Much a ‘Mega Breach’ Really Costs
Hacker Exploits 2-Year Old Router Issue To Steal Sensitive US Military Data
Stolen Taiwanese Certs Used in Malware Campaign
Asian Countries Frequent Targets of APT Attacks
Cost of UK Data Breaches Rises to ?2.7m

LinuxSecurity.com: It was discovered that there was a discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker could take advantage of this flaw to read arbitrary files outside an application’s root directory via “file://” requests.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New bind packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2113

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for gnupg2 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Updated kernel-rt packages that fix two security issues and add one enhancement are now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Xapian-core could be made to execute arbitrary code if it received a specially crafted file.

Creating a Defensible Security Architecture
Ticketmaster breach was part of a larger credit card skimming effort, analysis shows

LinuxSecurity.com: Updates for rh-dotnet20-dotnet, rh-dotnet21-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix bugs and security issues.

security update

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent […]

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent […]

security update

LinuxSecurity.com: libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file.

Red Hat’s disclosure process

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.4. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

The Worst Cybersecurity Breaches of 2018 So Far
Timehop Breach Hits 21 Million Customers

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for rh-git29-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Orange Tsai discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker can take advantage of this flaw to read arbitrary files outside an application’s root directory via specially crafted requests, when the Sprockets server is