Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: Fix low-severity CVE-2018-20217 (an authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request.)

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.

LinuxSecurity.com: **MariaDB C / C++ connector** Release notes: https://mariadb.com/kb/en/library/mariadb-connector-c-307-release-notes/ Maintainer notes: Marking as a security update, beacuse of fixed resource leaks. Moving libmariadb pkgconfig file to this package from mariadb- devel. Test with MariaDB-3:10.2.19-2

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Go, the worst which could lead to the execution of arbitrary code.

Anonymous social network Blind left user data exposed
Researcher publishes proof-of-concept code for creating Facebook worm
China hacked the US Navy and stole personal info on at least 100K sailors
Iranian APT Group Pegged for Shamoon Disk Wiping Attacks
Caribou Coffee Card Breach Hits 265 Stores

LinuxSecurity.com: New netatalk packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: **MariaDB 10.3.11** Release notes: https://mariadb.com/kb/en/mariadb-10311-release-notes/ CVEs fixed: CVE-2018-3282 CVE-2016-9843 CVE-2018-3174 CVE-2018-3143 CVE-2018-3156 CVE-2018-3251 CVE-2018-3185 CVE-2018-3277 CVE-2018-3162 CVE-2018-3173 CVE-2018-3200 CVE-2018-3284

LinuxSecurity.com: Security experts at Tencent’s Blade security team have discovered a critical vulnerability in SQLite database software (nicknamed “Magellan”).

LinuxSecurity.com: Daniel Axtens discovered a double-free and use-after-free vulnerability in libarchive’s RAR decoder that can result in a denial-of-service (application crash) or may have other unspecified impact when a malformed RAR archive is processed.

LinuxSecurity.com: This kernel update is based on the upstream 4.14.89 and fixes atleast the following security issues: Cross-hyperthread Spectre v2 mitigation is now provided by the Single Thread Indirect Branch Predictors (STIBP) support. Note that STIBP also

security update

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Update to 4.2.5

LinuxSecurity.com: Upstream announcement: The phpMyAdmin team is pleased to announce the release of **phpMyAdmin version 4.8.4**. Among other bug fixes, this contains several important security fixes. The security fixes involve: * Local file inclusion (https://www.phpmyadmin.net/security/PMASA-2018-6/), * XSRF/CSRF vulnerabilities allowing a specially-crafted URL to perform harmful operations

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for netatalk fixes the following issues: Security issue fixed:

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. Description: Description: This update for keepalived to version 2.0.10 fixes the following issues: Security issues fixed (bsc#1015141): – CVE-2018-19044: Fixed a check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats – CVE-2018-19045: Fixed mode when […]

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. Description: Description: This update for keepalived to version 2.0.10 fixes the following issues: Security issues fixed (bsc#1015141): – CVE-2018-19044: Fixed a check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats – CVE-2018-19045: Fixed mode when […]

Celebrating 20 Years of OpenSSL
The 18 biggest data breaches of the 21st century

LinuxSecurity.com: Two more security issues have been corrected in the libav multimedia library. This is a follow-up announcement for DLA-1611-1. CVE-2015-6823

security update

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

Facebook defends giving tech giants access to extensive user data
Mayday! NASA Warns Employees of Personal Information Breach

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3854

LinuxSecurity.com: Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.

LinuxSecurity.com: An update that solves two vulnerabilities and has 11 fixes is now available. Description: Description: This update for salt fixes the following issues: – Crontab module fix: file attributes option missing (boo#1114824) – Fix git_pillar merging across multiple __env__ repositories (boo#1112874) – Bugfix: unable to detect os arch when RPM is not installed (boo#1114197) […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_111 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for the Linux Kernel 3.12.61-52_141 fixes one issue. The following security issue was fixed:

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for ovmf fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for libnettle fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. Description: Description: This update for tiff fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that fixes one vulnerability is now available. Description: Description: This update for git fixes the following issues: Security issue fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for bluez fixes the following issues: Security issues fixed:

LinuxSecurity.com: An update that solves three vulnerabilities and has four fixes is now available. Description: Description: This new package for go1.11 fixes the following issues: Security issues fixed: – CVE-2018-16873: Fixed a remote code execution in go get, when executed [More…] with the -u flag (bsc#1118897) with the -u flag (bsc#1118897) [More…] – CVE-2018-16874: Fixed […]

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3834

LinuxSecurity.com: Update to 2.7.5 bugfix release. Fix for CVE-2018-16876

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.5. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for ansible is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Save the Children Hit by $1m BEC Scam
Cybercriminals Change Tactics to Outwit Machine-Learning Defense

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in wmi_set_ie. […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed: – CVE-2018-9568: Prevent possible memory corruption due to type confusion in sk_clone_lock. This could lead to local privilege escalation (bsc#1118319). – CVE-2018-5848: Fixed an unsigned integer overflow in […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. This update for the Linux Kernel 3.12.74-60_64_88 fixes several issues. The following security issues were fixed:

phpMyAdmin Releases Critical Software Update – Patch Your Sites Now!
Facebook bug exposed unposted photos of 6.8 million users

LinuxSecurity.com: Updated packages are now available for Red Hat Gluster Storage 3.4 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:

Critical SQLite Flaw Leaves Millions of Apps Vulnerable to Hackers

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: New upstream version 1.8.2. Fix low priority security issue with TLS: https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html —- New upstream version 1.8.1. —- Rebase to new stable version 1.8.0. —- nbdkit metapackage should depend on versioned -server subpackage etc. —- New upstream version 1.6.3.

LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: – Buffer overflow using computed size of canvas element. (CVE-2018-12359) – Use-after-free when using focus(). (CVE-2018-12360) – Integer overflow in SwizzleData. (CVE-2018-12361)

LinuxSecurity.com: It was discovered there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack (CVE-2018-19208). References:

LinuxSecurity.com: Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: – https://bugs.mageia.org/show_bug.cgi?id=23972 – https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes

LinuxSecurity.com: A buffer overflow and out-of-bounds read can occur in TextureStorage11 within the ANGLE graphics library, used for WebGL content. This results in a potentially exploitable crash (CVE-2018-17466). A use-after-free vulnerability can occur after deleting a selection

LinuxSecurity.com: A vulnerability in Scala could result in privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in SpamAssassin, the worst of which may lead to remote code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in CouchDB, the worst of which could lead to the remote execution of code.

Facebook could face billion dollar fine for data breaches

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

Blockchains should have ‘privacy by design’ for GDPR compliance
Fake Bomb Threat Emails Demanding Bitcoins Sparked Chaos Across US, Canada

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

Rhode Island sues Google after latest Google+ API leak
Apache Misconfig Leaks Data on 120 Million Brazilians

LinuxSecurity.com: This update fixes libstdc++ std::future support on armel, which is necessary to get firefox-esr and thunderbird updates built on that architecture.

security update

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,