Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Should we open source election software?
Despite Risks, Nearly Half of IT Execs Don’t Rethink Cybersecurity after an Attack

LinuxSecurity.com: This is an update to the latest upstream release, which disables the UDP port by default (CVE-2018-1000115).

LinuxSecurity.com: It was discovered that gunicorn, an event-based HTTP/WSGI server was susceptible to HTTP Response splitting. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, execution of arbitrary code or bypass of JAR signature validation.

LinuxSecurity.com: CVE-2018-7033 An issue that could be used for SQL Injection attacks against SlurmDBD has been fixed.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the image loading library for Simple DirectMedia Layer 1.2, which could result in denial of service or the execution of arbitrary code if malformed image files are opened.

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

New Phishing Attack Targets 550M Email Users Worldwide
Most federal IT contractors don’t protect emails from fraud

LinuxSecurity.com: It has been discovered that Tor, a connection-based low-latency anonymous communication system, contains a protocol-list handling bug that could be used to remotely crash directory authorities with a null-pointer exception (TROVE-2018-001).

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2018-6056

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

security update

LinuxSecurity.com: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. — https://www.genivia.com/advisory.html

LinuxSecurity.com: Update to newer release of Tika including security fixes for CVE-2016-4434 and CVE-2016-6809.

LinuxSecurity.com: The v4.16.4 update contains fixes across the tree

LinuxSecurity.com: Security fix for [CVE-2018-10194](https://access.redhat.com/security/cve/cve-2018-10194).

LinuxSecurity.com: New upstream release – This release fixes CVE-2018-1106 which is a moderate security issue.

LinuxSecurity.com: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. — https://www.genivia.com/advisory.html

LinuxSecurity.com: Rebase to qpdf-7.1.1 because of CVEs

LinuxSecurity.com: Rebase to qpdf-7.1.1 because of CVEs

What is tar and why does OpenShift Container Application Platform use it?

LinuxSecurity.com: A remote code execution vulnerability has been found within multiple subsystems of Drupal. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised.

Two-fifths of UK Firms Suffered Attack or Security Breach in 2017
Linux Launches Deep Learning Foundation For Open Source Growth In AI

LinuxSecurity.com: New openvpn packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Update to latest upstream release and security fix for CVE-2017-12626

LinuxSecurity.com: Update security update jdk8u171-b10

LinuxSecurity.com: Upstream announcement: Welcome to **phpMyAdmin 4.8.0.1**, which fixes a security flaw found in phpMyAdmin. This version fixes a security flaw found in version 4.8.0 where an attacker can manipulate a user in to following a specially-crafted link, allowing the attacker to execute arbitrary SQL commands on the server. For more information, please see

LinuxSecurity.com: Security fix for CVE-2018-9918

LinuxSecurity.com: **Version 1.6.4** – 2018-04-13 * Security fixes in some edge case scenarios, recommended update for all users * Fixed regression in version guessing of path repositories * Fixed removing aliased packages from the repository, which might resolve some odd update bugs * Fixed updating of package URLs for GitLab * Fixed run-script –list failing […]

LinuxSecurity.com: – don’t list nologin in /etc/shells (#1378893)

LinuxSecurity.com: Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846. Additionally, we back-ported some minor fixes from the master

LinuxSecurity.com: Updated Boost libraries are available that fix compatibility with CUDA 9.x compilers and fix a possible integer overflow in Boost.Regex.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update for apr is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, Red Hat Enterprise

security update

WEI Mortgage uncovers email phishing scheme and data breach

LinuxSecurity.com: An update for rh-mysql56-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: CVE-2017-17833 An issue has been found in openslp that is related to heap memory

LinuxSecurity.com: An update that solves 18 vulnerabilities and has 29 fixes is now available.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: A remote code execution vulnerability has been found in Drupal, a fully-featured content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-004

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2, fixes several bugs, and adds various enhancements are now available for Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.1.2 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Updated packages that provide Red Hat JBoss Enterprise Application Platform 7.1.2 and fix several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: **Version 1.6.4** – 2018-04-13 * Security fixes in some edge case scenarios, recommended update for all users * Fixed regression in version guessing of path repositories * Fixed removing aliased packages from the repository, which might resolve some odd update bugs * Fixed updating of package URLs for GitLab * Fixed run-script –list failing […]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, and Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions.

LinuxSecurity.com: Several security issues were fixed in MySQL.

UK Financial Sector Must Improve Collaboration: Report
Email security in 2018

LinuxSecurity.com: It was discovered that psensor, a server for monitoring hardware sensors remotely, was prone to a directory traversal vulnerability because the create_response function in server/server.c lacks a check for whether a file is under the webserver directory.

LinuxSecurity.com: librelp: Stack-based buffer overflow in relpTcpChkPeerName function in src/tcp.c (CVE-2018-1000140) SL6 x86_64 librelp-1.2.7-3.el6_9.1.x86_64.rpm librelp-debuginfo-1.2.7-3.el6_9.1.x86_64.rpm librelp-1.2.7-3.el6_9.1.i686.rpm librelp-debuginfo-1.2.7-3.el6_9.1.i686.rpm librelp-devel-1.2.7-3.el6_9.1.i686.rpm librelp-devel-1.2.7-3.el6_9.1.x86_64.rpm i386 librelp-1.2 [More…]

LinuxSecurity.com: It was discovered that there was an XML external entity expansion (XXE) vulnerability in lucene-solr, a search engine library for Java. It could be exploited to read arbitrary local files from the Solr server

LinuxSecurity.com: An update for librelp is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for librelp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for PackageKit is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).

LinuxSecurity.com: An update for python-paramiko is now available for Red Hat Ansible Engine 2.4 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: The system could be made to crash under certain conditions.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

security update

Join us in San Francisco at the 2018 Red Hat Summit

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple vulnerabilities were found in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: An update for rh-perl524-perl is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: A vulnerability has been found in librelp that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in unADF that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in mbed TLS, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Gentoo’s tenshi ebuild is vulnerable to privilege escalation due to the way pid files are handled.

LinuxSecurity.com: Multiple vulnerabilities have been found in Quagga, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ClamAV, the worst of which may allow remote attackers to execute arbitrary code.

Cybercrime Economy Generates $1.5 Trillion a Year
Email attacks continue to cause headaches for companies

LinuxSecurity.com: It was discovered that there was an issue in the gunicorn HTTP server for Python applicatons where CRLF sequences could result in an attacker tricking the server into returning arbitrary headers.

LinuxSecurity.com: Security fix for CVE-2018-1000115, which disables the UDP port by default.

LinuxSecurity.com: Updated to securityupdate u171

security update

security update

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: Security fix for CVE-2017-18197

LinuxSecurity.com: Upstream announcement: **Version 1.3.6** This is a security update to the stable version 1.3. It primarily fixes a recently discovered IMAP command injection vulnerability caused by insufficient input validation within the archive plugin. Details about the vulnerability are published under CVE-2018-9846. Additionally, we back-ported some minor fixes from the master

LinuxSecurity.com: – update to the latest upstream release (fixes CVE-2018-1000168)

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: This release provides Perl 5.24.4 that fixes a heap buffer overflow in the pack() function and two overflows in the regular expression engine.

LinuxSecurity.com: Security fix for CVE-2017-18197