Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Russia behind compromise of seven states’ voter registration systems
Why Blockchain Will Serve New IT Purposes in 2018

LinuxSecurity.com: An update for rh-dotnet20-dotnet, rh-dotnetcore10-dotnetcore, and rh-dotnetcore11-dotnetcore is now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: It was discovered that the Net::FTP module did not properly process filenames in combination with certain operations. A remote attacker could exploit this flaw to execute arbitrary commands by setting up a malicious FTP server and tricking a user or Ruby application into downloading files with specially crafted names using the Net::FTP module. (CVE-2017-17405) […]

LinuxSecurity.com: quagga: Double free vulnerability in bgpd when processing certain forms of UPDATE message allowing to crash or potentially execute arbitrary code (CVE-2018-5379) SL7 x86_64 quagga-0.99.22.4-5.el7_4.i686.rpm quagga-0.99.22.4-5.el7_4.x86_64.rpm quagga-debuginfo-0.99.22.4-5.el7_4.i686.rpm quagga-debuginfo-0.99.22.4-5.el7_4.x86_64.rpm quagga-contrib-0.99.22.4-5.el7_4.x86_64. [More…]

security update

security update

security update

LinuxSecurity.com: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: create a separate user for dnsmasq.

LinuxSecurity.com: The textbook ElGamal implementation is not secure. PyCrypto and some other implementations use the wrong algorithm, which may lead to some information disclosure simply by looking at the encrypted text. For a full description, see https://github.com/dlitz/pycrypto/issues/253 This update includes a fix for this problem backported from pycryptodome.

LinuxSecurity.com: Use default RPM build flags and configure parameters (#1539097) Remove group writable bit from some config files (#1528445)

Let’s talk about PCI-DSS

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0350

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0349

LinuxSecurity.com: The package mbedtls before version 2.7.0-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 40 fixes is now available.

LinuxSecurity.com: Two vulnerabilities have been found in Solr, a search server based on Lucene, which could result in the execution of arbitrary code or path traversal.

LinuxSecurity.com: Kelby Ludwig and Scott Cantor discovered that the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to incorrect XML parsing. For additional details please refer to the upstream advisory at

LinuxSecurity.com: Joonun Jang discovered several problems in wavpack, an audio compression format suite. Incorrect processing of input resulted in several heap- and stack-based buffer overflows, leading to application crash or potential code execution.

LinuxSecurity.com: From upstream announcement: **Security fix: phpMyAdmin 4.7.8 is released** Welcome to phpMyAdmin 4.7.8, a security releaes also containing regular maintenance bug fixes. The security fix relates to a self-XSS vulnerability in the central columns feature that is reported as PMASA-2018-1 https://www.phpmyadmin.net/security/PMASA-2018-1/. Thanks to Mayur Udiniya

LinuxSecurity.com: A flaw was found in the AWT component of OpenJDK. An untrusted Java application or applet could use this flaw to bypass certain Java sandbox restrictions. (CVE-2018-2641) * It was discovered that the LDAPCertStore class in the JNDI component of OpenJDK failed to securely handle LDAP referrals. An attacker could possibly use this flaw […]

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: gcab: Extracting malformed .cab files causes stack smashing potentially leading to arbitrary code execution (CVE-2018-5345) SL7 x86_64 gcab-debuginfo-0.7-4.el7_4.i686.rpm gcab-debuginfo-0.7-4.el7_4.x86_64.rpm libgcab1-0.7-4.el7_4.i686.rpm libgcab1-0.7-4.el7_4.x86_64.rpm gcab-0.7-4.el7_4.x86_64.rpm libgcab1-devel-0.7-4.el7_4.i686.rpm libgcab1-devel-0.7-4.el7_4.x86 [More…]

LinuxSecurity.com: An update for gcab is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: It was discovered that there was an arbitrary command execution vulnerability in the Go programming language. The “go get” implementation did not correctly validate “import path”

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available.

LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35

LinuxSecurity.com: This update updates QtWebEngine to the 5.10.1 bugfix and security release. QtWebEngine 5.10.1 is part of the Qt 5.10.1 release, but only the QtWebEngine component is included in this update. This update includes: * Security fixes from Chromium up to version 64.0.3282.140. Including: CVE-2017-15407, CVE-2017-15409, CVE-2017-15410, CVE-2017-15411, CVE-2017-15415, CVE-2017-15416,

LinuxSecurity.com: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35

LinuxSecurity.com: CVE-2017-13194 Fix for a flaw in libvpx related to odd frame width, which may lead to a denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Drupal content management framework. For additional information, please refer to the upstream advisory at https://www.drupal.org/sa-core-2018-001

LinuxSecurity.com: It was discovered that there was a remote denial of service vulnerability in the imagemagick graphics library via a specially- crafted TIFF file.

LinuxSecurity.com: This update includes the changes in tzdata 2018c for the Perl bindings. For the list of changes, see DLA-1291-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018c. Notable changes are: – S?o Tom? and Pr?ncipe switched from +00 to +01. – Brazil’s DST will now start on November’s first Sunday.

LinuxSecurity.com: The package unixodbc before version 2.3.5-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package lib32-wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package wavpack before version 5.1.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package phpmyadmin before version 4.7.8-1 is vulnerable to cross- site scripting.

security update

security update

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2017-5715

LinuxSecurity.com: It was discovered that there was an issue in the CUPS printer framework where remote attackers could execute arbitrary commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding.

LinuxSecurity.com: Several security issues were fixed in WavPack.

LinuxSecurity.com: This update doesn’t fix a vulnerability in GCC itself, but instead provides support for building retpoline-enabled Linux kernel updates. For the stable distribution (stretch), this problem has been fixed in

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: On February 22, fixes for CVE-2017-5715 were released into the Ubuntu Xenialkernel version 4.4.0-116.140. This CVE, also known as “Spectre,” is caused by flaws in the design of speculative execution hardware in the computer’sCPU, and could be used to access sensitive information in kernel memory. [More…]

LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in Squid3, a fully featured web proxy cache. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: It was discovered that there where a number of vulnerabilities in irssi, the terminal based IRC client: – CVE-2018-7050: Null pointer dereference for an “empty” nick.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has 19 fixes is now available.

LinuxSecurity.com: The package libmspack before version 1:0.6alpha-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for rh-maven35-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The package strongswan before version 5.6.2-1 is vulnerable to denial of service.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Security fix for CVE-2018-6942.

LinuxSecurity.com: New upstream release, including security fixes for CVE-2016-10713, CVE-2018-6951, CVE-2018-6952.

JDK approach to address deserialization Vulnerability

LinuxSecurity.com: It was discovered that there was a uncontrolled memory allocation issue in zziplib, a ZIP archive library. Remote attackers could leverage this vulnerability to cause a denial of service via a specially-crafted file.

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has two fixes is now available.

Oracle open-sources DTrace under the GPL

LinuxSecurity.com: A vulnerability has been found in Ruby which may allow for arbitrary command execution.

LinuxSecurity.com: A vulnerability in LibreOffice might allow remote attackers to read arbitrary files.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in MySQL, the worst of which may allow remote execution of arbitrary code.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 44 fixes is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.12

LinuxSecurity.com: Bind could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

New EU Privacy Law May Weaken Security
Meltdown-Spectre flaws: We’ve found new attack variants, say researchers
Raw sockets backdoor gives attackers complete control of some Linux servers

security update

security update

LinuxSecurity.com: Several vulnerabilities have been discovered in Quagga, a routing daemon. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Krzysztof Sieluzycki discovered that the notifier for removable devices in the KDE Plasma workspace performed insufficient sanitisation of FAT/VFAT volume labels, which could result in the execution of arbitrary shell commands if a removable device with a malformed disk label is

LinuxSecurity.com: BIND, a DNS server implementation, was found to be vulnerable to a denial of service flaw was found in the handling of DNSSEC validation. A remote attacker could use this flaw to make named exit unexpectedly with an

security update

LinuxSecurity.com: The package irssi before version 1.1.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.