Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Updated to latest upstream release (#1571443, #1573318, #1573319).

LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.

LinuxSecurity.com: Update to 1.10.1

security update

security update

Online voting is impossible to secure. So why are some governments using it?
Small Firms Up to 20 Times More Likely to be Breached

LinuxSecurity.com: New wget packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1319

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1364

LinuxSecurity.com: The package freetype2 before version 2.9.1-1 is vulnerable to denial of service.

LinuxSecurity.com: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount […]

LinuxSecurity.com: ## 4.9.2 https://ckeditor.com/cke4/release/CKEditor-4.9.2 ### Security Updates – Fixed XSS vulnerability in the Enhanced Image (image2) plugin reported by Kyaw Min Thein. – Issue summary: It was possible to execute XSS inside CKEditor using the tag and specially crafted HTML. Please note that the default presets (Basic/Standard/Full) do not include this plugin, so you are […]

LinuxSecurity.com: Security fix for CVE-2017-6888.

LinuxSecurity.com: Security fix for CVE-2018-1000156

LinuxSecurity.com: Regenerate autoconf files using current tools so proper build flags from redhat- rpm-config are used. This applies hardened LDFLAGS. No functional change intended.

LinuxSecurity.com: This release provides Perl 5.26.2 that fixes a heap buffer overflow in the pack() function and two overflows in regular expression engine.

LinuxSecurity.com: Knot Resolver 2.3.0 (2018-04-23) ——– – fix CVE-2018-1110: denial of service triggered by malformed DNS messages (!550, !558, security!2, security!4) – increase resilience against slow lorris attack (security!5) Bugfixes ——– – validation: fix SERVFAIL in case of CNAME to NXDOMAIN in a single zone (!538) – validation: fix SERVFAIL for

security update

Trial set for Latvian accused of running malware operation
Equifax Update Clarifies Breach Details to SEC

LinuxSecurity.com: On May 8, fixes for CVE-2018-1087 and CVE-2018-8897 were released in linuxkernel version 4.4.0-124.148. These CVEs are both related to the way thatthe linux kernel handles certain interrupt and exception instructions. Ifan interrupt or exception instruction (INT3, SYSCALL, etc.) is immediatelypreceded by a MOV SS or POP SS instruction, the resulting interrupt will [More…]

Most Industrial Networks Vulnerable to Attack

LinuxSecurity.com: Harry Sintonen discovered that wget, a network utility to retrieve files from the web, does not properly handle ‘rn’ from continuation lines while parsing the Set-Cookie HTTP header. A malicious web server could use this flaw to inject arbitrary cookies to the cookie jar file, adding

security update

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

Report: China’s Intelligence Apparatus Linked to Previously Unconnected Threat Groups
Linux Kernel Hardens Sound Drivers Against Spectre V1 Vulnerability

security update

LinuxSecurity.com: An XML external entity expansion vulnerability was discovered in the DataImportHandler of Solr, a search server based on Lucene, which could result in information disclosure.

Vulnerabilities on the Rise?
A GEORGIA HACKING BILL GETS CYBERSECURITY ALL WRONG

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: – fix stack-based buffer overflow in utils.c:checkmailpath() (CVE-2018-1100) – fix stack-based buffer overflow in gen_matches_files() (CVE-2018-1083) – fix stack-based buffer overflow in exec.c:hashcmd() (CVE-2018-1071)

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions or unsafe redirects. More information can be found in the upstream advisory at

security update

LinuxSecurity.com: – https://www.drupal.org/project/drupal/releases/7.59 – https://www.drupal.org/SA-CORE-2018-004

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Red Hat Single Sign-On 7.2.2 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code.

Security Holes Make Home Routers Vulnerable
Hackers Leverage GDPR to Target Airbnb Customers

LinuxSecurity.com: This update includes the changes in tzdata 2018e for the Perl bindings. For the list of changes, see DLA-1371-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018e. Notable changes are: – North Korea switches back to +09 on 2018-05-05.

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

What to do after a data breach: 5 steps to minimize risk
UK Phisher Pleads Guilty to Just Eat Scam

security update

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing because of an incomplete fix for CVE-2017-7525.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

Fedora 28 “Cutting Edge” Linux Distro Released With New Features
A critical security flaw in popular industrial software put power plants at risk

LinuxSecurity.com: An update for rh-php70-php is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for go-toolset-7 and go-toolset-7-golang is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A buffer overflow in Python might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability was discovered in hesiod which may allow remote attackers to gain root privileges.

LinuxSecurity.com: Two vulnerabilities were found in the Quassel IRC client, which could result in the execution of arbitrary code or denial of service. Note that you need to restart the ‘quasselcore’ service after upgrading

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

security update

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Virtualization 4 Management Agent for RHEL 7 and Red Hat Virtualization Manager 4.1. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

City of London Police Takes Cybercrime Fight to Businesses
A Quarter of UK CNI Firms Have Suffered Cyber-Attack Outages

LinuxSecurity.com: Update to 1.8.8

LinuxSecurity.com: Red Hat Mobile Application Platform 4.6.0 Release – Container Images 2. Description: Red Hat Mobile Application Platform (RHMAP) 4.6.0 consists of three main components:

Cyber Security Breaches Survey 2018
North Korea Ramps Up ‘Operation GhostSecret’ Cyber Espionage Campaign

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

Cloud Misconceptions Are Pervasive Across Enterprises
Why Hackers Love Healthcare

LinuxSecurity.com: An update for openvswitch is now available for Fast Datapath for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.4. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.5. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Serious vulnerabilities were found in the libvorbis library, commonly used to encode and decode audio in OGG containers. 2017-14633

LinuxSecurity.com: Updated Boost libraries are available that fix compatibility with CUDA 9.x compilers and fix a possible integer overflow in Boost.Regex.

LinuxSecurity.com: Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).

LinuxSecurity.com: Security fix for CVE-2018-1088 (Privilege escalation via gluster_shared_storage when snapshot scheduling is enabled)

LinuxSecurity.com: Information leak via crafted user-supplied CDROM [XSA-258] (#1571867) x86: PV guest may crash Xen with XPTI [XSA-259] (#1571878)

security update

security update

security update

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.1. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from