Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

UK ICO, USCourts.gov… Thousands of websites hijacked by hidden crypto-mining code after popular pl

LinuxSecurity.com: A request smuggling vulnerability was discovered in pound that may allow attackers to send a specially crafted http request to a web server or reverse proxy while pound may see a different set of requests. This facilitates several possible exploitations, such as partial cache

LinuxSecurity.com: CVE-2017-6419 CVE-2017-11423

LinuxSecurity.com: Mikhail Klementev, Ronnie Goodrich and Andrew Krasichkov discovered that missing restrictions in the implementation of the WEBSERVICE function in LibreOffice could result in the disclosure of arbitrary files readable by the user who opens a malformed document.

LinuxSecurity.com: The package sthttpd before version 2.27.1-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: WavPack could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: Mikhail Klementev, Ronnie Goodrich and Andrew Krasichkov discovered that missing restrictions in the implementation of the WEBSERVICE function in LibreOffice could result in the disclosure of arbitrary files readable by the user who opens a malformed document.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the librsvg renderer library that could result in data being leaked to remote attackers via a specially-crafted file.

LinuxSecurity.com: Chris Navarrete from Fortinet’s FortiGuard Labs discovered that Audacity, a multi-track audio editor, contains a vulnerability such that a .wav file with a crafted FORMATCHUNK structure (many channels) can result in

LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which could allow an attacker to take control of VirtualBox.

LinuxSecurity.com: Jonas Klempel discovered that, when parsing the AIA-Extension field of a client certificate, Apache Tomcat Native did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the

security update

security update

LinuxSecurity.com: It was discovered that the uwsgi_expand_path function in utils.c in Unbit uWSGI, an application container server, has a stack-based buffer overflow via a large directory length that can cause a denial-of-service (application crash) or stack corruption.

security update

LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted

LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted

LinuxSecurity.com: Security fix for CVE-2017-15698

LinuxSecurity.com: PostgreSQL could be made to expose sensitive information.

LinuxSecurity.com: The package clamav before version 0.99.3-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 70 fixes is now available.

Why Linux is better than Windows or macOS for security
Hackers Get Linux Running On Switch And Claim Nintendo Can’t Patch The Exploit

LinuxSecurity.com: Lalith Rallabhandi discovered that OmniAuth, a Ruby library for implementing multi-provider authentication in web applications, mishandled and leaked sensitive information. An attacker with access to the callback environment, such as in the case of a crafted web

LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package go-pie before version 1.9.4-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package go before version 1.9.4-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 44 fixes is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: Mailman could be made to run arbitrary code.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Security fix for CVE-2017-15698

LinuxSecurity.com: simplesamlphp, an authentication and federation application has been found vulnerable to Cross Site Scripting (XSS), signature validation byepass and using insecure connection charset.

LinuxSecurity.com: The mailman package has a Cross-site scripting (XSS) vulnerability in the web UI before 2.1.26 which allows remote attackers to inject arbitrary web script or HTML via a user-options URL

LinuxSecurity.com: A regression was detected in the previously issued fix for CVE-2018-6360. The patch released with DSA 4105-1 broke the feature of invoking mpv with raw YouTube ids. This update fixes this functionality issue. For reference, the relevant part of the original advisory text follows.

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

security update

security update

security update

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves 9 vulnerabilities and has 68 fixes is now available.

LinuxSecurity.com: Several security issues were fixed in Django.

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

DDoS attacks: How an 18-year-old got arrested for trying to knock out systems

LinuxSecurity.com: It was discovered that the webhook validation of Anymail, a Django email backends for multiple ESPs, is prone to a timing attack. A remote attacker can take advantage of this flaw to obtain a WEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events.

security update

LinuxSecurity.com: A vulnerabilities has been found in the PostgreSQL database system: CVE-2018-1053

LinuxSecurity.com: Two vulnerabilities were discovered in Libtasn1, a library to manage ASN.1 structures, allowing a remote attacker to cause a denial of service against an application using the Libtasn1 library.

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: Security fix for CVE-2018-6381

LinuxSecurity.com: This update includes a rebase from 8.0.47 to 8.0.49.

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

Abusing X.509 Digital Certificates for Covert Data Exchange
Hacking suspect Lauri Love wins landmark appeal against US extradition
Australian cops to enter kindergartens to teach kids not to cyber
Malware Exploiting Spectre, Meltdown Flaws Emerges

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate the speculative side channel attack known as Spectre variant 2.

LinuxSecurity.com: It was discovered that mpv, a media player, was vulnerable to remote code execution attacks. An attacker could craft a malicious web page that, when used as an argument in mpv, could execute arbitrary code in the host of the mpv user.

How I Got Paid $0 From the Uber Security Bug Bounty
Why cops won’t need a warrant to pull the data off your autonomous car
Open source turns 20 years old, looks to attract normal people

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: ClamAV 0.99.3 recommended for all ClamAV users. Please see details below: 1. ClamAV UAF (use-after-free) Vulnerabilities (CVE-2017-12374) ————————————————————— The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

security update

LinuxSecurity.com: It was discovered that an XHR/AJAX call did not properly encode user input in the “dokuwiki” wiki platform. This resulted in a reflected file download vulnerability.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: ‘landave’ discovered a heap-based buffer overflow vulnerability in the NCompress::NShrink::CDecoder::CodeReal method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Critical Infrastructure More Vulnerable Than Ever Before
GDPR: These are the organisations which are least prepared
Meltdown-Spectre: Malware is already being tested by attackers
A giant botnet is forcing Windows servers to mine cryptocurrency
What is microsegmentation? How getting granular improves network security
How to eliminate the default route for greater security

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0260

LinuxSecurity.com: Several security issues were fixed in Dovecot.

security update

LinuxSecurity.com: Dovecot could be made to crash if it received specially crafted input.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,