Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: – https://www.drupal.org/SA-CORE-2018-002 – https://www.drupal.org/SA- CORE-2018-001

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: – https://www.drupal.org/SA-CORE-2018-002 – https://www.drupal.org/SA- CORE-2018-001

What are the advantages of open source software?
Red Hat looks beyond Linux

LinuxSecurity.com: Ansible and its dependencies have been deprecated in the Red Hat Enterprise Linux 7 Extras channel. 2. Description: Ansible and its dependencies will no longer be updated through the Extras

LinuxSecurity.com: Kubernetes and its dependencies have been deprecated in the Red Hat Enterprise Linux 7 Extras channel. 2. Description: The kubernetes packages provide utilities for container cluster management.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for libvorbis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for pcs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for glibc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for openssh is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for xdg-user-dirs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for krb5 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for policycoreutils is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

LinuxSecurity.com: Minor security update from upstream fixing CVE-2018-0739

LinuxSecurity.com: New version 2.1.26 (#1370156, #1304360)

LinuxSecurity.com: Update to latest upstream version.

LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/

LinuxSecurity.com: Python Crypto could expose sensitive information.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2018-6358

The Linux Foundation launches a deep learning foundation

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

LinuxSecurity.com: A vulnerability in SPICE VDAgent could allow local attackers to execute arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in libvirt, the worst of which may result in the execution of arbitrary commands.

LinuxSecurity.com: Multiple vulnerabilities were discovered in mailx, the worst of which may allow a remote attacker to execute arbitrary commands.

LinuxSecurity.com: This update fixes assorted CVEs in LibOFX.

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.

LinuxSecurity.com: **PHP version 7.1.16** (29 Mar 2018) **Core:** * Fixed bug php#76025 (Segfault while throwing exception in error_handler). (Dmitry, Laruence) * Fixed bug php#76044 (‘date: illegal option — -‘ in ./configure on FreeBSD). (Anatol) **FPM:** * Fixed bug php#75605 (Dumpable FPM child processes allow bypassing opcache access controls). (Jakub Zelenka) **GD:** * Fixed bug php#73957

LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2

LinuxSecurity.com: rebase and fixed CVE-2018-1000140

LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/

Engineering Group and Open Source Initiative Partner for Enhanced Leadership in Open Source
OPEN SOURCE WON. SO, NOW WHAT?

LinuxSecurity.com: Lilith of Cisco Talos discovered several buffer overflow vulnerabilities in the SDL Image library which can be leveraged by attackers to execute arbitrary code via specially crafted image files.

LinuxSecurity.com: New patch packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Multiple invalid frees and buffer-overflow vulnerabilities were discovered in sam2p, a utility to convert raster images and other image formats, that may lead to a denial-of-service (application crash) or unspecified other impact.

security update

Lawmakers press Linux on security of open-source software
Email Fraud is a Top Business Risk for 2018
Iran ‘the New China’ as a Pervasive Nation-State Hacking Threat

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.

LinuxSecurity.com: Fixes for CVE-2018-1002150.

LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2

LinuxSecurity.com: Update to 3.6.5

LinuxSecurity.com: This update includes the latest upstream release of the Apache HTTP Server, version 2.4.33. A number of security vulnerabilities are fixed in this release: * *Low*: Possible out of bound read in mod_cache_socache (CVE-2018-1303) * *Low*: Possible out of bound access after failure in reading the HTTP request (CVE-2018-1301) * *Low*: Weak Digest auth […]

LinuxSecurity.com: This update includes the latest upstream release of mod_http2, version 1.10.16. This includes a security fix (CVE-2018-1302): When an HTTP/2 stream was destroyed after being handled, mod_http2 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerabilty hard to trigger in usual […]

LinuxSecurity.com: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 libvorbis-1.2.3-5.el6_9.1.i686.rpm libvorbis-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.i686.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-devel-1.2.3-5.el6_9.1.i686.rpm libvorbis-devel-1.2.3-5.el6_9.1.x86_64.rpm i386 libvorbis-1.2.3 [More…]

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

security update

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libvorbis is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The package drupal before version 8.5.1-1 is vulnerable to arbitrary code execution.

security update

security update

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

White House Lags Far Behind on Email Security Benchmark
No, Panera Bread Doesn’t Take Security Seriously
Facebook Expands Bug Bounty Amid Spiraling Privacy Scandal
Saks, Lord & Taylor Payment Card Breach Affects 5 Million
GoScanSSH Malware Avoids US Military, South Korea Targets

LinuxSecurity.com: Multiple vulnerabilities have been found in glibc, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were discovered in libxslt, the worst of which may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: Michal Kedzior found two vulnerabilities in LDAP Account Manager, a web front-end for LDAP directories. CVE-2018-8763

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, unauthorized access, sandbox bypass or HTTP header injection.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two fixes is now available.

security update

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.1 for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: It was discovered that there was a local privilege escalation vulnerability in beep, an “advanced PC speaker beeper”. For Debian 7 “Wheezy”, this issue has been fixed in beep version

LinuxSecurity.com: Multiple vulnerabilities were found in the rubygems package management framework, embedded in JRuby, a pure-Java implementation of the Ruby programming language.

LinuxSecurity.com: It was discovered that a race condition in beep (if configured as setuid via debconf) allows local privilege escalation. For the oldstable distribution (jessie), this problem has been fixed

security update

security update

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.

Report Shows Ransomware is the New Normal

LinuxSecurity.com: Several security issues were fixed in Dovecot.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal-based IRC client which can result in denial of service. For the stable distribution (stretch), these problems have been fixed in

LinuxSecurity.com: Multiple vulnerabilities were found in rubygems, a package management framework for Ruby. CVE-2018-1000075

LinuxSecurity.com: James Davis discovered two issues in Django, a high-level Python web development framework, that can lead to a denial-of-service attack. An attacker with control on the input of the django.utils.html.urlize() function or django.utils.text.Truncator’s chars() and words() methods

Purism Librem 13: A Security-Focused Powerhouse of a Linux Laptop