Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Cyberwar predictions for 2019: The stakes have been raised
Dunkin’ Donuts Serves Up Data Breach Alert
Disorganized crime and state-backed hackers: How the cybercrime and cyberwar landscape is constantly

LinuxSecurity.com: The kdeconnect-kde package has been updated to version 1.3.3, which fixes an issue with modern encryption algorithms being disabled with SSH, and also fixes several bugs and updates compatibility with the Android app.

security update

security update

LinuxSecurity.com: A regression issue has been resolved in the poppler PDF rendering shared library introduced with version 0.26.5-2+deb8u5.

LinuxSecurity.com: Jayakrishna Menon and Christophe Hauser discovered an integer overflow vulnerability in Perl_my_setenv leading to a heap-based buffer overflow with attacker-controlled input.

LinuxSecurity.com: Several vulnerabilities were found in QEMU, a fast processor emulator: CVE-2016-2391

These are the worst hacks, cyberattacks, and data breaches of 2018
Marriott says 500 million Starwood guest records stolen in massive data breach

LinuxSecurity.com: Among others, Andre Heinicke from gpg4win.org found several issues of nsis, a tool for creating quick and user friendly installers for Microsoft Windows operating systems.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code if malformed image files are processed.

LinuxSecurity.com: Several local side channel attacks and a denial of service via large Diffie-Hellman parameters were discovered in OpenSSL, a Secure Sockets Layer toolkit.

security update

Dell suffers security breach, reset customer passwords (but didn’t tell customers why until now)
Encryption is the best way to protect payment card transaction data

LinuxSecurity.com: A SQL injection in PostgreSQL may allow attackers to execute arbitrary SQL statements.

LinuxSecurity.com: Multiple vulnerabilities have been found in libsndfile, the worst of which might allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: Multiple security vulnerabilities were found in libarchive, a multi-format archive and compression library. Heap-based buffer over-reads, NULL pointer dereferences and out-of-bounds reads allow remote attackers to cause a denial-of-service (application crash) via

LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Multiple vulnerabilities were discovered in the implementation of the Perl programming language. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several security vulnerabilities were discovered in Ghostscript, an interpreter for the PostScript language, which could result in denial of service, the creation of files or the execution of arbitrary code if a malformed Postscript file is processed (despite the dSAFER sandbox being

LinuxSecurity.com: The package samba before version 4.9.3-1 is vulnerable to multiple issues including denial of service and access restriction bypass.

LinuxSecurity.com: The package powerdns-recursor before version 4.1.8-1 is vulnerable to denial of service.

Distributing Malware By Becoming an Admin on an Open-Source Project
Pegasus gov’t spyware used to target colleague of slain drug cartel journalist

LinuxSecurity.com: An update for rh-ruby25-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-ruby23-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSL, the worst of which may lead to a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in RPM, the worst of which could allow a remote attacker to escalate privileges.

LinuxSecurity.com: The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.1 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file. (CVE-2017-5950)

LinuxSecurity.com: Buffer overflows in URL auth code if there is a “mount” definition that enables URL authentication. A malicious client could send long HTTP headers, leading to a buffer overflow and potential remote code execution (CVE-2018-18820).

security update

security update

Uber fined ?900,000 by UK, Dutch privacy regulators over 2016 data breach
EU Voters Worried About Election Hacking and Disinformation

LinuxSecurity.com: USN-3804-1 introduced a regression in OpenJDK.

LinuxSecurity.com: Several security issues were fixed in Git.

LinuxSecurity.com: Several vulnerabilities were discovered in Ghostscript, the GPL PostScript/PDF interpreter, which may result in denial of service or the execution of arbitrary code if a malformed Postscript file is processed (despite the -dSAFER sandbox being enabled).

LinuxSecurity.com: Several security issues were fixed in Samba.

LinuxSecurity.com: USN-3816-1 caused a regression in systemd-tmpfiles.

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update for rh-nginx114-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-nginx112-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-dotnet21-dotnet is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A vulnerability in spice-gtk could allow an attacker to remotely execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Libav, the worst of which may allow a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Tablib might allow remote attackers to execute arbitrary python commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for sos-collector is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for NetworkManager is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-nginx110-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-nginx18-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The frustratingly simple techniques of ‘human hacking’ – and how to fight them
LinkedIn violated data protection by using 18M email addresses of non-members to buy targeted ads on

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: gnuplot5, a command-line driven interactive plotting program, has been examined with fuzzing by Tim Blazytko, Cornelius Aschermann, Sergej Schumilo and Nils Bars.

security update

DoS Vulnerabilities Found in Linux Kernel, Unpatched
Security News This Week: Amazon Won’t Say How Many Customer Emails It

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: A vulnerability in xml-security-c, a library for the XML Digital Security specification, has been found. Different KeyInfo combinations, like signatures without public key, result in incomplete DSA structures that

LinuxSecurity.com: Multiple vulnerabilities have been found in Exiv2, the worst of which could result in a Denial of Service condition.

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GPL Ghostscript, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Asterisk, the worst of which could result in a Denial of Service condition.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

Ukrainian police arrest hacker who infected over 2,000 users with DarkComet RAT
Mirai Evolves From IoT Devices to Linux Servers

LinuxSecurity.com: USN-3801-1 caused some minor regressions in Firefox.

LinuxSecurity.com: Two security vulnerabilities were discovered in OTRS, a Ticket Request System, that may lead to privilege escalation or arbitrary file write. CVE-2018-19141

LinuxSecurity.com: It was discovered that a buffer overflow in liveMedia, a set of C++ libraries for multimedia streaming could result in the execution of arbitrary code when parsing a malformed RTSP stream.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: CVE-2015-5297 Numerical overflow in pointer arithmetic.

LinuxSecurity.com: mod_perl could be made to run programs contrary to expectations.

LinuxSecurity.com: The package flashplugin before version 31.0.0.153-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package webkit2gtk before version 2.22.4-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-libtiff before version 4.0.10-1 is vulnerable to multiple issues including arbitrary code execution, denial of service and information disclosure.

LinuxSecurity.com: It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path