Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

LinuxSecurity.com: A remote code execution vulnerability exists in PHP’s built-in phar stream wrapper when performing file operations on an untrusted phar:// URI. Some Drupal code (core, contrib, and custom) may be performing file operations on insufficiently validated user input, thereby being

LinuxSecurity.com: Bug fixes for binutils including one that is preventing Yocot/oe-core from building properly

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1 and 14.2 to fix security issues.

LinuxSecurity.com: Several issues have been discovered in the MariaDB database server. The vulnerabilities are addressed by upgrading MariaDB to the new upstream version 10.0.38. Please see the MariaDB 10.0 Release Notes for further details:

LinuxSecurity.com: The 4.20.5 stable kernel update contains a number of important fixes across the tree.

security update

security update

security update

LinuxSecurity.com: Several security issues were fixed in Avahi.

LinuxSecurity.com: The package ghostscript before version 9.26-2 is vulnerable to sandbox escape.

security update

LinuxSecurity.com: New mozilla-firefox packages are available for 14.2 and -current to fix security issues.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Update to mingw-qt5-*-5.11.3, see http://blog.qt.io/blog/2018/12/04/qt-5-11-3-released-important-security-updates/ for details. Update to mingw-sip-4.19.13, see https://www.riverbankcomputing.com/static/Downloads/sip/ChangeLog for details.

LinuxSecurity.com: Security fix for CVE-2019-6706.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several issues in wireshark, a network traffic analyzer, have been found. Dissectors of – ISAKMP, a Internet Security Association and Key Management Protocol

LinuxSecurity.com: Several issues were discovered in qtbase-opensource-src, a cross-platform C++ application framework, which could lead to denial-of-service via application crash. Additionally, this update fixes a problem affecting vlc, where it would start without a GUI.

LinuxSecurity.com: Multiple vulnerabilities were discovered in coTURN, a TURN and STUN server for VoIP. CVE-2018-4056

security update

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

LinuxSecurity.com: The package nasm before version 2.14.02-1 is vulnerable to denial of service.

LinuxSecurity.com: The package haproxy before version 1.9.0-1 is vulnerable to denial of service.

LinuxSecurity.com: The package matrix-synapse before version 0.34.1.1-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package powerdns-recursor before version 4.1.9-1 is vulnerable to multiple issues including insufficient validation and access restriction bypass.

LinuxSecurity.com: The package apache before version 2.4.38-1 is vulnerable to multiple issues including denial of service and insufficient validation.

LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.

LinuxSecurity.com: The package go before version 2:1.11.5-1 is vulnerable to private key recovery.

LinuxSecurity.com: New version 2.6.6. Security fix for CVE-2019-5716, CVE-2019-5717, CVE-2019-5718, CVE-2019-5719

security update

LinuxSecurity.com: krb5, a MIT Kerberos implementation, had several flaws in LDAP DN checking, which could be used to circumvent a DN containership check by supplying special parameters to some calls.

LinuxSecurity.com: The PostgreSQL project has release a new minor release of the 9.4 branch. For Debian 8 “Jessie”, this has been uploaded as version

LinuxSecurity.com: New Version

LinuxSecurity.com: Ghostscript could be made to crash, access files, or run programs if it opened a specially crafted file.

LinuxSecurity.com: Several security issues were fixed in MySQL.

LinuxSecurity.com: A vulnerability in the HTML_QuickForm package has been found which potentially allows remote code execution. References: – https://bugs.mageia.org/show_bug.cgi?id=24185

LinuxSecurity.com: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service (CVE-2018-20544). It was discovered that libcaca incorrectly handled certain images. An

LinuxSecurity.com: An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806).

Nasty security bug found and fixed in Linux apt
New ransomware strain is locking up Bitcoin mining rigs in China
Sky Go app security failure exposes customers to snooping, data theft

LinuxSecurity.com: Security fix for CVE-2018-20551, CVE-2018-20481, CVE-2018-20650 and CVE-2018-18897.

LinuxSecurity.com: Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.

LinuxSecurity.com: – xattr: strip credentials from any URL that is stored (CVE-2018-20483)

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Multiple vulnerabilities were found in the journald component of systemd which can lead to a crash or code execution. CVE-2018-16864

LinuxSecurity.com: Fix for CVE-2019-5885 Upgrade notes available at https://github.com/matrix- org/synapse/blob/v0.34.0/UPGRADE.rst#upgrading-to-v0340 – Note this continues to use Python 2.

LinuxSecurity.com: Several vulnerabilities have been resolved in libjpeg-turbo, Debian’s default JPEG implemenation. CVE-2016-3616

LinuxSecurity.com: It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the –log option. This might allow local users to obtain sensitive information by reading this file.

security update

Websites can steal browser data via extensions APIs

LinuxSecurity.com: admin: Prevent access if any authentication agent isn’t available

LinuxSecurity.com: Fix for use after free in affile_dw_reap

LinuxSecurity.com: libssh versions 0.6 and above have an authentication bypass vulnerability in the server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate

GDPR Suit Filed Against Amazon, Apple
2018’s Most Common Vulnerabilities Include Issues New and Old
How 2018 became Facebook’s worst year in privacy and security
North Korean Hackers Get Access To Chile’s ATM After Employee Falls For Fake Job Interview Over Skyp

LinuxSecurity.com: Security fix for CVE-2018-20455 CVE-2018-20456 CVE-2018-20457 CVE-2018-20458 CVE-2018-20459 CVE-2018-20460 CVE-2018-20461 through rebase to 3.2.0

LinuxSecurity.com: **PHP version 7.2.14** (10 Jan 2019) **Core:** * Fixed bug php#77369 (memcpy with negative length via crafted DNS response). (Stas) * Fixed bug php#71041 (zend_signal_startup() needs ZEND_API). (Valentin V. Bartenev) * Fixed bug php#76046 (PHP generates “FE_FREE” opcode on the wrong line). (Nikita) **Date:** * Fixed bug php#77097 (DateTime::diff gives wrong diff when the

security update

The 773 Million Record “Collection #1” Data Breach
There’s a simple reason why your new smart TV was so affordable: It’s collecting and selling your da
15+ Password Cracking Techniques Used By Hackers 2019
As the Government Shutdown Drags on, Security Risks Intensify

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

LinuxSecurity.com: Several security issues were fixed in libcaca.

Firms fined $1M for SingHealth data security breach
UK Banks Finally Issue New Cards After Ticketmaster Breach

LinuxSecurity.com: This update fixes CVE-2018-20685 (the first “variant”) and backports several fixes to unbreak ECDSA authentication from PKCS#11, certificate authentication and so on.

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).

LinuxSecurity.com: Patch for CVE-2016-10091

LinuxSecurity.com: It was observed that URL’s which gets downloaded via “–log=” attribute stores sensitive information. This update fixes that. References: – https://bugs.mageia.org/show_bug.cgi?id=24112

LinuxSecurity.com: A heap use-after-free vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity (CVE-2018-6307).

LinuxSecurity.com: Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495). References:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in

LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]

LinuxSecurity.com: Several security issues were fixed in libcaca.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0049

LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The v4.19.14 stable update contains important fixes across the tree.