Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in privilege escalation.

Syrian Electronic Army Members Indicted for Conspiracy

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: The package libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Advance notification for upcoming end-of-life for Debian 8

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1414

Tech Talk: As GDPR looms, companies rush to comply
2018: Scariest Year of Evil Things on the Internet
California Teen Arrested for Phishing Teachers to Change Grades

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

BYOD Threats Exposed: 61% of UK SMEs Suffer Cyber-Attacks
New Research Seeks to Shorten Attack Dwell Time

security update

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Updated collectd packages are now available for Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

DHS Unveils National Cybersecurity Risk Strategy
IT Pros Worried About IoT But Not Prepared to Secure It

LinuxSecurity.com: The package curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

security update

LinuxSecurity.com: The package zathura-pdf-mupdf before version 0.3.3-3 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package runc before version 1.0.0rc5+19+g69663f0b-1 is vulnerable to privilege escalation.

LinuxSecurity.com: An update is now available for Red Hat JBoss Data Grid. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

US Government Cybersecurity at a Crossroads
Airports Ill-Equipped to Deal with Major Cyber-Attacks

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transfer library, could be tricked into reading data beyond the end of a heap based buffer when parsing invalid headers in an RTSP response.

LinuxSecurity.com: It was discovered that there was an issue in the curl a command-line tool for downloading (eg.) data over HTTP. curl could have be tricked into reading data beyond the end of a heap

security update

LinuxSecurity.com: Several security issues were fixed in PHP.

Mexican Banks Lose Millions in SWIFT-like Attacks
Chili’s Suffers Data Breach
Major #eFail Vulnerability Exposes PGP Encrypted Email — UPDATED

security update

LinuxSecurity.com: Several security issues were fixed in PHP.

White Hat Spoofs 2FA, Sends User to Phishing Page
NCA: Organized Cybercrime Continues to Rise

LinuxSecurity.com: A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: The package firefox before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass, access restriction bypass, content spoofing, denial of service, information disclosure and sandbox escape.

LinuxSecurity.com: The package webkit2gtk before version 2.20.2-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package llpp before version 27-2 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Fabian Vogt discovered that incorrect permission handling in the PAM module of the KDE Wallet could allow an unprivileged local user to gain ownership of arbitrary files.

LinuxSecurity.com: Security fix for CVE-2018-10380

LinuxSecurity.com: Security fix for CVE-2018-10380

FBI: Reported Internet Crimes Topped $1.4 Billion Last Year
Open Source AI For Everyone: Three Projects to Know

LinuxSecurity.com: https://www.libraw.org/news/libraw-0-18-11 —- CVE-2018-10529 fixed: out of bounds read in X3F parser CVE-2018-10528 fixed: possible stack overrun in X3F parser

Cyberattack shuts down Tennessee election website

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Phishing Threats Move to Mobile Devices
Report: More Breaches Despite Increasing Security Budgets
Phishing Attack Bypasses Two-Factor Authentication

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 6 fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

LinuxSecurity.com: Harry Sintonen have discovered a cookie injection vulnerability in wget caused by insufficient input validation, enabling an external attacker to inject arbitrary cookie values cookie jar file, adding new

Former Iranian Hacker Exposes Cyber-Efforts
Professionals ‘Lack Time’ or Ignore Critical Patch Application

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.

LinuxSecurity.com: Updated to latest upstream release (#1571443, #1573318, #1573319).

LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.

LinuxSecurity.com: Update to 1.10.1

security update

security update