Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

Modern Cybersecurity Demands a Different Corporate Mindset

LinuxSecurity.com: The package chromium before version 67.0.3396.87-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package gnupg before version 2.2.8-1 is vulnerable to content spoofing.

LinuxSecurity.com: Several vulnerabilities were found in SPIP, a website engine for publishing, resulting in cross-site scripting and PHP injection. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: Multiple vulnerabilities have been found in Quassel, the worst of which could allow remote attackers to execute arbitrary code.

security update

LinuxSecurity.com: plexus-archiver: arbitrary file write vulnerability / arbitrary code execution using a specially crafted zip file (CVE-2018-1002200) SL7 noarch plexus-archiver-2.4.2-5.el7_5.noarch.rpm plexus-archiver-javadoc-2.4.2-5.el7_5.noarch.rpm – Scientific Linux Development Team

LinuxSecurity.com: An update for rh-maven33-plexus-archiver and rh-maven35-plexus-archiver is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for plexus-archiver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

74 Arrested in International Email Scam Schemes
UK watchdog issues $330k fine for Yahoo’s 2014 data breach

LinuxSecurity.com: Danny Grander discovered a directory traversal flaw in plexus-archiver, an Archiver plugin for the Plexus compiler system, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted Zip archive.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Ericsson’s Chris Price on the need for collaboration between open source communities and projects
Over 301,000 Open Jobs in Cybersecurity

LinuxSecurity.com: An update for Red Hat JBoss Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Jakub Wilk discovered a directory traversal flaw in the Archive::Tar module, allowing an attacker to overwrite any file writable by the extracting user via a specially crafted tar archive.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

security update

LinuxSecurity.com: Several security issues were fixed in GnuPG.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

security update

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

FBI Slaps New Charges Against Researcher Who Stopped WannaCry
GDPR will increase reported breaches and trigger a flood of ‘Right to be Forgotten’ requests

LinuxSecurity.com: An update for imgbased, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for RHEL-7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, execution of arbitrary code or bypass of JAR signature validation.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The package p7zip before version 16.02-5 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package flashplugin before version 30.0.0.113-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.

LinuxSecurity.com: The package firefox before version 60.0.2-1 is vulnerable to arbitrary code execution.

Chinese hackers stole undersea warfare data from US Navy contractor
How NATO Defends Against the Dark Side of the Web

LinuxSecurity.com: The package krb5 before version 1.16.1-1 is vulnerable to insufficient validation.

LinuxSecurity.com: The package chromium before version 67.0.3396.79-1 is vulnerable to access restriction bypass.

security update

security update

security update

security update

LinuxSecurity.com: Security fix for CVE-2018-8013. Updated to upstream release 1.10.

LinuxSecurity.com: This update fixes CVE-2016-10040, a stack overflow in QXmlSimpleReader due to a too lenient entityCharacterLimit in our version of the patch for CVE-2013-4549. (The limit was increased from the upstream 1024 to 65536 to address QTBUG-35459, an issue where the security fix was breaking existing real-world XML files. Unfortunately, that is too much to […]

Bug Bounty Payouts Up 73% Per Vulnerability: Bugcrowd
Survey Shows Florida at the Bottom for Consumer Cybersecurity

LinuxSecurity.com: Alexander Peslyak discovered that insufficient input sanitising of RFB packets in LibVNCServer could result in the disclosure of memory contents.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: Ivan Fratric discovered a buffer overflow in the Skia graphics library used by Firefox, which could result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: New gnupg2 packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and – -current to fix a security issue.

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Remove essentially unused pre_release tagging in spec file Fixup Makefile patch to include LDFLAGS in all linking commands

LinuxSecurity.com: DWARF5 and split dwarf, including GNU DebugFission, support.

What is the New York Cybersecurity Regulation? What you need to do to comply
#Infosec18: Nation State Hacking is Biggest Change in Cyber-Threat Landscape

LinuxSecurity.com: Several vulnerabilities were discovered in jruby, a Java implementation of the Ruby programming language. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop,

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

security update

LinuxSecurity.com: A security issue was fixed in Unbound.

LinuxSecurity.com: The package radare2 before version 2.6.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: 8u171 update

LinuxSecurity.com: 8u171 update

LinuxSecurity.com: Security fix for CVE-2017-13685 CVE-2017-15286

MyHeritage Alerts Users to Data Breach
Open-source security: Zip Slip critical flaw hits thousands of projects. Update now
#Infosec18: Regulation is Top Driver of Cybersecurity, Now & in the Future
Phishing Scams Target FIFA World Cup Attendees
North Korean hacking group Covellite abandons US targets
Security fail? One in three companies think paying hackers is worth the risk
Customer Data Flies Away with Ticketfly Hacker
5 Tips for Protecting SOHO Routers Against the VPNFilter Malware
Cybercrime Is Skyrocketing as the World Goes Digital
Fitness app PumpUp left users’ personal data exposed on server
Queen’s University Belfast Launches Cyber-Testing Labs
Open Redis Servers Infected with Malware

LinuxSecurity.com: Several security issues were fixed in procps-ng.

LinuxSecurity.com: **Version 2.8.41** (2018-05-25) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 Adding session authentication strategy to Guard

LinuxSecurity.com: **Version 4.0.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user

LinuxSecurity.com: Some more efail fixes, https://enigmail.net/index.php/en/download/changelog

security update

LinuxSecurity.com: Several security issues were fixed in Git.

LinuxSecurity.com: **Version 3.4.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user

security update