Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

State of the SOC? Depends on Who You Ask
New Malware Variant Hits With Ransomware or Cryptomining

LinuxSecurity.com: Fix CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI

LinuxSecurity.com: Several security vulnerabilities were found in Bouncy Castle, a Java implementation of cryptographic algorithms. CVE-2016-1000338

LinuxSecurity.com: New upstream version

LinuxSecurity.com: ## 3.3.17 (2018-05-25) * security #cve-2018-11407 [Ldap] cast to string when checking empty passwords * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 migrating session for UsernamePasswordJsonAuthenticationListener * security #cve-2018-11386

LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.

LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.

Digital India Susceptible to Security Breaches
UK Banks Must Produce Backup Plans for Cyberattacks

LinuxSecurity.com: There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered “valid” or otherwise should be trusted.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

security update

security update

LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.

Fortnum & Mason: 23,000 Affected by Data Hack
Machine Learning, Cloud, Compliance and Business Awareness Drive Cybersecurity

LinuxSecurity.com: Several vulnerabilities were found in phpMyAdmin, the web-based MySQL administration interface, including SQL injection attacks, denial of service, arbitrary code execution, cross-site scripting, server-side request forgery, authentication bypass, and file system traversal.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: Some security vulnerabilities were found in Mercurial which allow authenticated users to trigger arbitrary code execution and unauthorized data access in certain server configuration. Malformed patches and repositories can also lead to crashes and arbitrary code

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.

California’s New Privacy Law Gives GDPR-Compliant Orgs Little to Fear
Iranian Attackers Spoof Security Site for Phishing Lure

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in Exiv2.

LinuxSecurity.com: The package git-annex before version 6.20180626-1 is vulnerable to multiple issues including arbitrary filesystem access and information disclosure.

LinuxSecurity.com: The package gitlab before version 11.0.1-1 is vulnerable to multiple issues including cross-site scripting and insufficient validation.

NHS Developer Error Leads to Data Leak
Ransomware: Not dead, just getting a lot sneakier

LinuxSecurity.com: Fabian Henneke discovered a cross-site scripting vulnerability in the password change form of GOsa, a web-based LDAP administration program. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: Several vulnerabilites have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.

LinuxSecurity.com: libsoup could be made to crash if it received a specially crafted input.

LinuxSecurity.com: Two vulnerabilities affecting the cups printing server were found which can lead to arbitrary IPP command execution and denial of service.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2001

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1979

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1997

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1965

HMRC: 29% Increase in Malicious Site Deactivations
Two-Fifths of UK CEOs See Cyber-Attacks as Inevitable

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: glibc: Buffer overflow in glob with GLOB_TILDE (CVE-2017-15670) * glibc: Buffer overflow during unescaping of user names with the ~ operator (CVE-2017-15804) SL6 x86_64 glibc-2.12-1.212.el6.i686.rpm glibc-2.12-1.212.el6.x86_64.rpm glibc-common-2.12-1.212.el6.x86_64.rpm glibc-debuginfo-2.12-1.212.el6.i686.rpm glibc-debuginfo-2.12-1.212.el6.x86_64.rpm glibc-debuginfo- [More…]

LinuxSecurity.com: libvirt: Resource exhaustion via qemuMonitorIORead() method (CVE-2018-5748) * libvirt: Incomplete fix for CVE-2018-5748 triggered by QEMU guest agent (CVE-2018-1064) SL6 x86_64 libvirt-0.10.2-64.el6.x86_64.rpm libvirt-client-0.10.2-64.el6.i686.rpm libvirt-client-0.10.2-64.el6.x86_64.rpm libvirt-debuginfo-0.10.2-64.el6.i686.rpm libvirt-debuginfo-0.10.2-64.el6.x86_64.rpm [More…]

LinuxSecurity.com: samba: Null pointer indirection in printer server process (CVE-2018-1050) SL6 x86_64 libsmbclient-3.6.23-51.el6.i686.rpm libsmbclient-3.6.23-51.el6.x86_64.rpm samba-client-3.6.23-51.el6.x86_64.rpm samba-common-3.6.23-51.el6.i686.rpm samba-common-3.6.23-51.el6.x86_64.rpm samba-debuginfo-3.6.23-51.el6.i686.rpm samba-debuginfo-3.6.23-51.el6.x86_64.rpm samba-winb [More…]

LinuxSecurity.com: zsh: Stack-based buffer overflow in gen_matches_files() at compctl.c (CVE-2018-1083) * zsh: buffer overflow when scanning very long directory paths for symbolic links (CVE-2014-10072) * zsh: buffer overrun in symlinks (CVE-2017-18206) * zsh: buffer overflow in utils.c:checkmailpath() can lead to local arbitrary code execution (CVE-2018-1100) SL6 x86_64 zsh-4.3.11-8.el6.x86_64.rpm [More…]

Phishing Cited by SMBs as Top Attack Threat
Natural Language Processing Fights Social Engineers

security update

Adidas US Website Hit by Data Breach
The 6 Worst Insider Attacks of 2018 – So Far

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

Ticketmaster Breach Discovered in April, Says Bank
Cyber-Attacks Caused 18 Days of NHS Downtime

LinuxSecurity.com: CVE-2017-7651 fix to avoid extraordinary memory consumption by crafted CONNECT packet from unauthenticated client

LinuxSecurity.com: CVE-2017-12872 / CVE-2017-12868 The (1) Htpasswd authentication source in the authcrypt module and (2)

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Hundreds of Hotels Hit in FastBooking Breach
Cyber Risk at All-Time High for UK Financial Sector

security update

security update

LinuxSecurity.com: – fix out-of-bounds read via a crafted ELF file (CVE-2018-10360)

LinuxSecurity.com: The 4.17.2 kernel rebase contains new drivers, new features, and a number of important fixes across the tree. —- The v4.16.17 update includes important fixes across the tree

NSA Leaker Winner Pleads Guilty
IEEE Calls for Strong Encryption

LinuxSecurity.com: Several vulnerabilities have been discovered in exiv2, a C++ library and a command line utility to manage image metadata, resulting in denial of service, heap-based buffer over-read/overflow, memory exhaustion, and

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Various security issues were discovered in Graphicsmagick, a collection of image processing tools. Heap-based buffer overflows or overreads may lead to a denial of service or disclosure of in-memory information or other unspecified impact by processing a malformed image file.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor: CVE-2018-12891

LinuxSecurity.com: Two flaws were discovered in ruby-passenger for Ruby Rails and Rack support that allowed attackers to spoof HTTP headers or exploit a race condition which made privilege escalation under certain conditions possible.

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code, denial of service, cross-site request forgery or information disclosure.

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for patch is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Midsized Organizations More Secure Than Large Ones