Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

New Linux Systemd security holes uncovered
Governments need to embrace AI for the good of the people

LinuxSecurity.com: New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in systemd-journald. Two memory corruption flaws, via attacker-controlled alloca()s (CVE-2018-16864, CVE-2018-16865) and an out-of-bounds read flaw leading to an information leak (CVE-2018-16866), could allow an attacker to

LinuxSecurity.com: The package python2-django before version 1.11.18-1 is vulnerable to content spoofing.

LinuxSecurity.com: The package python-django before version 2.1.5-1 is vulnerable to content spoofing.

security update

LinuxSecurity.com: Due to kernel issue there is a way to reuse start_time of a process. This allows to duplicate process authorized by polkit. This update mitigates polkit issue #75 (slowfork): https://gitlab.freedesktop.org/polkit/polkit/issues/75

Hacker ‘BestBuy’ sentenced to prison for operating Mirai DDoS botnet
Facebook staff discussed cashing in on user data, reports say

LinuxSecurity.com: An integer underflow was discovered in the CAF demuxer of the VLC media player. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: Resolves CVE-2018-16869

LinuxSecurity.com: Resolves CVE-2018-16869

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

security update

LinuxSecurity.com: The package wireshark-cli before version 2.6.6-1 is vulnerable to multiple issues including information disclosure and denial of service.

LinuxSecurity.com: The package systemd before version 240.0-3 is vulnerable to multiple issues including arbitrary file overwrite and information disclosure.

OXO International discloses data breach, customer data over two years impacted
What happens when the cops get hit with malware, too?
Reddit Locks Down Accounts After Security Incident

LinuxSecurity.com: read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header (CVE-2017-14502).

LinuxSecurity.com: Terminology before 1.3.1 allows Remote Code Execution because popmedia is mishandled, as demonstrated by an unsafe “cat README.md” command when e}pn is used. A popmedia control sequence can allow the malicious execution of executable file formats registered in the X desktop share MIME types (/usr/share/applications). The control sequence defers

LinuxSecurity.com: fix CVE-2019-3498 python-django: Content spoofing via URL path in

LinuxSecurity.com: backport anti-phishing fixes

LinuxSecurity.com: **Horde_Image 2.5.4** * [mjr] SECURITY: Fix potential RCE in the text method when using the Imagemagick backend. * [mjr] SECURITY: Sanitize image type parameter (PR: 2, Fariskhi Vidyan). * [mjr] Fix issues with escaping single and double quote characters in the text method when using the Imagemagick backend.

LinuxSecurity.com: A bug in the server implementation of RTSP-over-HTTP in live could allow a denial-of-service attack. A bug in the server implementation of RTSP-over-HTTP could allow a buffer overflow, which could result in the execution of arbitrary code

LinuxSecurity.com: An authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request (CVE-2018-20217). References:

LinuxSecurity.com: A vulnerability was found in mbedTLS which allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites (CVE-2018-19608). References:

LinuxSecurity.com: Security fix for CVE-2018-1000532, new non-root permissions and a few smaller fixes. Fix a directory traversal issue introduced with the fix for CVE-2018-1000532, and refuses to run as setuid root or via sudo to avoid any more priviledge escalation issue. —- Security fix for CVE-2018-1000532 and a few smaller fixes

LinuxSecurity.com: libgxps 0.3.1 release. – Fix font scaling when converting xps to pdf – Handle errors returned by archive_read_data in GXPSArchive – Ensure gxps_archive_read_entry() fills the GError in case of failure – Make the pdf generated by xpstopdf to be 96 dpi – Fix OUTPUT FILE description in man pages – Clear the GError before […]

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in libcaca, a graphics library that outputs text: integer overflows, floating point exceptions or invalid memory reads may lead to a denial-of-service (application crash) if a malformed image file is processed.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Django could be made to expose spoofed information over the network.

LinuxSecurity.com: Several security issues were fixed in NSS.

This old ransomware is using an unpleasant new trick to try and make you pay up
Ethereum Classic hackers steal over $1.1M with 51% attacks

LinuxSecurity.com: Updates for rh-dotnet21-dotnet and rh-dotnet22-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The avidemux package has been updated to version 2.7.1. Avidemux includes a bundled copy of the ffmpeg libraries, which have been updated from version 3.3.3 to version 3.3.9, fixing several security issues and other bugs.

LinuxSecurity.com: The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file (CVE-2018-11468). DISCOUNT through version 2.2.3a is vulnerable to a Heap-based

LinuxSecurity.com: Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact (CVE-2018-16391).

LinuxSecurity.com: Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947).

LinuxSecurity.com: It was found that when a retry task in ansible run with -vvv fails, it will log the raw return code, stdout and stderr from ssh which could have contained sensitive data (CVE-2018-16876). References:

LinuxSecurity.com: A leaky data conversion exposing a manager oracle (CVE-2018-16869). References: – https://bugs.mageia.org/show_bug.cgi?id=24080 – https://lists.opensuse.org/opensuse-updates/2018-12/msg00120.html

LinuxSecurity.com: A flaw was found in GNU Coreutils through 8.29 in chown-core.c. The functions chown and chgrp do not prevent replacement of a plain file with a symlink during use of the POSIX “-R -L” options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition (CVE-2017-18018).

LinuxSecurity.com: Double free in QXmlStreamReader (CVE-2018-15518). Denial of Service on malformed BMP file in QBmpHandler (CVE-2018-19873). References:

LinuxSecurity.com: It was discovered that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, performed insufficient sanitising of SVG elements.

LinuxSecurity.com: It was discovered that malformed URLs could spoof the content of the default 404 page of Django, a Python web development framework. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: The package elfutils before version 0.175-1 is vulnerable to denial of service.

How Facebook’s privacy woes might change the rules of the road in 2019
Top 4 enterprise tech trends to watch in 2019

LinuxSecurity.com: A NULL pointer dereference flaw was found in the way dcraw processed images. An attacker could potentially use this flaw to crash dcraw by tricking it into processing crafted images (CVE-2018-5801). References:

LinuxSecurity.com: A flaw was found in libao. The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 can cause a denial of service(memory corruption) via a crafted mp3 file (CVE-2017-11548). References:

LinuxSecurity.com: NULL pointer dereference in the function aubio_source_avcodec_readframe which may lead to DoS when playing a crafted audio file (CVE-2017-17554). A crash in aubio_pitch_set_unit (CVE-2018-14522).

LinuxSecurity.com: This is the final notification for the retirement of Red Hat Enterprise Linux 6.6 Telco Update Service (TUS). This notification applies only to those customers subscribed to the Telco Update Service (TUS) channel for Red Hat Enterprise Linux 6.6.

Major US newspapers crippled by Ryuk ransomware attack
Marriott Sheds New Light on Massive Breach
Singapore Airlines data breach affects 284 accounts, exposes travel details

LinuxSecurity.com: It was discovered that there was a content-spoofing vulnerability in the default 404 pages in the Django web development framework. For more information, please see:

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0022

Singapore Airlines customer logs into account, sees stranger’s personal data
Town of Salem Data Breach Exposes 7.6 Million Gamers’ Accounts

LinuxSecurity.com: This release (4.3.1) contains bug fixes only: – Fix checkspell detected typos (#531) – Heap overflow packet2tree and get_l2len (#530) This is Tcpreplay suite 4.3.0 This release contains several bug fixes and enhancements: – Fix maxOS TOS checksum failure (#524) – TCP sequence edits seeding (#514) – Fix issues identifed by Codacy (#493) – […]

LinuxSecurity.com: This release (4.3.1) contains bug fixes only: – Fix checkspell detected typos (#531) – Heap overflow packet2tree and get_l2len (#530) This is Tcpreplay suite 4.3.0 This release contains several bug fixes and enhancements: – Fix maxOS TOS checksum failure (#524) – TCP sequence edits seeding (#514) – Fix issues identifed by Codacy (#493) – […]

LinuxSecurity.com: Since version 1.19 Wget stores the URL and in certain cases the ‘Referer’ URL within extended attributes (xattrs) of the file system – by default. This includes username + password and other credentials or private data *if* those have been used within the URLs. Anyone with read access to

LinuxSecurity.com: Florian Stuelpner discovered that Samba is vulnerable to infinite query recursion caused by CNAME loops, resulting in denial of service (CVE-2018-14629). Alex MacCuish discovered that a user with a valid certificate or smart

LinuxSecurity.com: A flaw was found in units. units_cur doesn’t sanitize downloaded data. This allows a maliciously intended server to execute arbitrary code remotely on the client (rhbz#1598913). References:

LinuxSecurity.com: A vulnerability was in found in PowerDNS Authoritative Server. The issue is a memory leak occurring while parsing some malformed records, due to the fact that some memory is allocated parsing a record and is not always properly released if the record is not valid. It allows an authorized user to cause a denial […]

LinuxSecurity.com: A vulnerability was in found in PowerDNS Recursor. The issue is a memory leak occurring while parsing some malformed records, due to the fact that some memory is allocated parsing a record and is not always properly released if the record is not valid. It allows a malicious auth server to cause a denial […]

LinuxSecurity.com: Eyal Itkin discovered FreeRDP incorrectly handled certain stream encodings. A malicious server could use this issue to cause FreeRDP to crash, resulting in a denial of service, or possibly execute arbitrary code (CVE-2018-8784, CVE-2018-8785).

LinuxSecurity.com: Potential object injection vulnerability (CVE-2018-19296). References: – https://bugs.mageia.org/show_bug.cgi?id=24055 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/DAZQPUD7WZXMJ2KIQY5P2I2UI545YPYO/

LinuxSecurity.com: Use-after-free vulnerability in Decoder.cpp in libpgf before 6.15.32 (CVE-2015-6673). References: – https://bugs.mageia.org/show_bug.cgi?id=24101

LinuxSecurity.com: Several vulnerabilities were discovered in libextractor which may lead to denial of service or memory disclosure if a malformed OLE file is processed (CVE-2018-20430, CVE-2018-20431). References:

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 13 vulnerabilities and has three fixes is now available.

LinuxSecurity.com: An update that solves 11 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.