Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0102

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0101

Salted Hash Ep 15: The state of security now and the not too distant future

LinuxSecurity.com: An update for rh-eclipse46-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: It was discovered that Smarty, a PHP template engine, was vulnerable to code-injection attacks. An attacker was able to craft a filename in comments that could lead to arbitrary code execution on the host running Smarty.

security update

LinuxSecurity.com: An update for java-1.6.0-sun is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several security issues were fixed in GIMP.

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for libvirt is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: It was discovered that PHP5 was vulnerable to a reflected cross-site scripting (XSS) attack on the PHAR 404 error page by manipulating the URI of a request for a .phar file. This issue is only exploitable if the web server is configured to handle phar files using PHP5.

Rogue Chrome, Firefox Extensions Hijack Browsers; Prevent Easy Removal
Mozilla mandates that new Firefox features rely on encrypted connections

security update

Man Admits to Directing DDoS Attacks Across the US

LinuxSecurity.com: It was discovered that there was a denial-of-service attack in the libgd2 image library. A corrupt file could have exploited a signedness confusion leading to an infinite loop.

LinuxSecurity.com: It was discovered that there was an injection vulnerability in the rsync file-copying tool. For Debian 7 “Wheezy”, this issue has been fixed in rsync version

LinuxSecurity.com: The cPanel Security Team discovered that awstats, a log file analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution.

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.

LinuxSecurity.com: The package bind before version 9.11.2.P1-1 is vulnerable to denial of service.

LinuxSecurity.com: The package perl-xml-libxml before version 2.0130-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package transmission-cli before version 2.92-8 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package nrpe before version 3.2.1-3 is vulnerable to arbitrary command execution.

LinuxSecurity.com: The package irssi before version 1.0.6-1 is vulnerable to denial of service.

LinuxSecurity.com: An update for java-1.7.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix permissions on rootsh log directory to limit it to root.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0094

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0093

LinuxSecurity.com:

LinuxSecurity.com: This is new version of irssi. It contains security fixes for CVE-2018-5205 CVE-2018-5206 CVE-2018-5207 CVE-2018-5208 .

LinuxSecurity.com: – Resolves: #1510351 – CVE-2017-14992 – built docker @projectatomic/docker-1.13.1 commit 584d391 – built docker-novolume-plugin commit 385ec70 – built rhel-push-plugin commit af9107b – built docker-lvm-plugin commit 8647404 – built docker-runc @projectatomic/docker-1.13.1 commit 1c91122 – built docker-containerd @projectatomic/docker-1.13.1 commit 62a9c60 – built

The first lawsuits to save net neutrality have been filed

LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)

LinuxSecurity.com: Security fix for CVE-2018-5702 (Mitigate dns rebinding attacks against daemon)

LinuxSecurity.com: – Update to 52.5.3 – Patched for mozilla bug-1427870 (spectre mitigation)

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: It was discovered that multiple encryption key classes in the Librariescomponent of OpenJDK did not properly synchronize access to their internaldata. This could possibly cause a multi-threaded Java application to applyweak encryption to data because of the use of a key that was zeroed out.(CVE-2018-2579)Note: If the web browser plug-in provided by the icedtea-web […]

security update

LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274

LinuxSecurity.com: Rebase `osc` and `osc-source_validator` to new versions for security fixes for CVE-2017-9274

Mental Models & Security: Thinking Like a Hacker
Android security: This newly discovered snooping tool has remarkable spying abilities
Spectre and Meltdown patches causing trouble as realistic attacks get closer

LinuxSecurity.com: Multiple vulnerabilities have been found in rsync, the worst of which could allow remote attackers to bypass access restrictions.

security update

LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red

LinuxSecurity.com: The Check Point Research Team discovered that the XBMC media center allows arbitrary file write when a malicious subtitle file is downloaded in zip format. This update requires the new dependency libboost-regex1.49.

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, and Red Hat Enterprise Linux 7.3

LinuxSecurity.com: Jayachandran Palanisamy of Cygate AB reported that BIND, a DNS server implementation, was improperly sequencing cleanup operations, leading in some cases to a use-after-free error, triggering an assertion failure and crash in named.

LinuxSecurity.com: An update that solves 14 vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Transmission could be made to run arbitraty code.

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338 —- Upstream release

LinuxSecurity.com: Qtpass password generation had a bug where only a 1000 different passwords where possible https://github.com/IJHack/QtPass/issues/338

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has three fixes is now available.

Smart card forwarding with Fedora
Congress Renews Warrantless Surveillance-And Makes It Even Worse
The “Doublespeak” of Responsible Encryption
Wi-Fi Alliance announces WPA3 to secure modern networks
How I’ve captured all passwords trying to ssh into my server

LinuxSecurity.com: This release does a complete update of the CA list. This includes removing the StartCom and WoSign certificates to as they are now untrusted by the major browser vendors.

LinuxSecurity.com: New kernel packages are available for Slackware 14.0 and 14.2 to fix security issues.

LinuxSecurity.com: A vulnerability has been discovered in GraphicsMagick, a collection of image processing tools, which may result in a denial of service.

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat CloudForms 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: It was discovered that multiple integer overflows in the GIF image loader in the GDK Pixbuf library may result in denial of service and potentially the execution of arbitrary code if a malformed image file is opened.

security update

LinuxSecurity.com: Several security issues were fixed in GDK-PixBuf.

LinuxSecurity.com: David Sopas discovered that Kohana, a PHP framework, was vulnerable to a Cross-site scripting (XSS) attack that allowed remote attackers to inject arbitrary web script or HTML by bypassing the strip_image_tags protection mechanism in system/classes/Kohana/Security.php. This issue

Inside Uber’s $100,000 Payment to a Hacker, and the Fallout

LinuxSecurity.com: Multiple vulnerabilities have been found in PolarSSL, the worst of which may allow remote attackers to execute arbitrary code.