Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.

LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at

LinuxSecurity.com: The package qtpass before version 1.2.1-1 is vulnerable to private key recovery.

security update

LinuxSecurity.com: Tavis Ormandy discovered a vulnerability in the Transmission BitTorrent client; insecure RPC handling between the Transmission daemon and the client interface(s) may result in the execution of arbitrary code if a user visits a malicious website while Transmission is running.

LinuxSecurity.com: Rebased to 1.37.0.

security update

LinuxSecurity.com: Philip Huppert discovered the Shibboleth service provider is vulnerable to impersonation attacks and information disclosure due to mishandling of DTDs in the XMLTooling XML parsing library. For additional details please refer to the upstream advisory at

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.

LinuxSecurity.com: It was discovered that gifsicle, a tool for manipulating GIF image files, contained a flaw that could lead to arbitrary code execution. For the oldstable distribution (jessie), this problem has been fixed

Let’s Encrypt disables TLS-SNI-01 validation
Linux vs Meltdown: Ubuntu gets second update after first one fails to boot
FBI chief claims encryption is an ‘urgent public safety issue’

LinuxSecurity.com: Security fix for CVE-2017-1000501

security update

LinuxSecurity.com: A vulnerability in PySAML2 might allow remote attackers to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in TigerVNC, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in icoutils, the worst of which may lead to arbitrary code execution.

LinuxSecurity.com: The package intel-ucode before version 20180108-1 is vulnerable to access restriction bypass.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2017-11732

Fedora 28 Looking To Replace Glibc’s libcrypt With libxcrypt
Adobe patches information leak vulnerability

LinuxSecurity.com: Stephan Zeisberg discovered that poco, a collection of open source C++ class libraries, did not correctly validate file paths in ZIP archives. An attacker could leverage this flaw to create or overwrite arbitrary files.

security update

security update

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: Security fix for CVE-2017-17784 CVE-2017-17785 CVE-2017-17786 CVE-2017-17787 CVE-2017-17788 CVE-2017-17789

LinuxSecurity.com: Security fix for CVE-2017-1000456.

LinuxSecurity.com: Microcode update for AMD cpus

security update

security update

LinuxSecurity.com: A vulnerability has been found in LibXfont and LibXfont2 which may allow for arbitrary file access.

LinuxSecurity.com: PySAML2 could allow authentication without a password.

LinuxSecurity.com: Fixes https://bitcointalk.org/index.php?topic=2702103.0 Changelog: https://github.com/spesmilo/electrum/blob/master/RELEASE-NOTES —- Fixes https://bitcointalk.org/index.php?topic=2702103.0

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0061

LinuxSecurity.com: An update that fixes 46 vulnerabilities is now available.

Hackers target Winter Olympics with new custom-built fileless malware
How to hack public Wi-Fi to mine for cryptocurrency
Is a Good Offense the Best Defense Against Hackers?

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Several vulnerabilities were found in PHP, a widely-used open source general purpose scripting language: CVE-2017-11142

LinuxSecurity.com: Several vulnerabilities were found in PHP, a widely-used open source general purpose scripting language: CVE-2017-11144

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 32 vulnerabilities and has 7 fixes is now available.

security update

LinuxSecurity.com: Opencv 3.3 and earlier has problems while reading data, which might result in either buffer overflows or integer overflows.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Updated to version 3.1.1 Fixes https://bitcointalk.org/index.php?topic=2702103.0 —- Updated to version 3.1

LinuxSecurity.com: openSUSE: openSUSE 11.3 has reached end of SUSE support

Who the Hell Is This ‘Crypto-Genius?’
Spectre and Meltdown: What you need to know going forward

LinuxSecurity.com: An update that solves 14 vulnerabilities and has three An update that solves 14 vulnerabilities and has three An update that solves 14 vulnerabilities and has three fixes is now available. fixes is now available.

security update

LinuxSecurity.com: The package linux-hardened before version 4.14.11.a-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: The package linux-zen before version 4.14.11-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The package linux-lts before version 4.9.74-1 is vulnerable to multiple issues including denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The package linux before version 4.14.11-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 19 fixes is An update that solves 5 vulnerabilities and has 19 fixes is An update that solves 5 vulnerabilities and has 19 fixes is now available. now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 35 fixes is An update that solves 5 vulnerabilities and has 35 fixes is An update that solves 5 vulnerabilities and has 35 fixes is now available. now available.

Researchers Discover Two Major Flaws in the World’s Computers

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, information leaks, privilege escalation or the execution of arbitrary code.

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in Intel processors, enabling an attacker controlling an unprivileged process to read memory from arbitrary addresses, including from the kernel and all other processes running on the system.

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessordesigns have implemented speculative execution of instructions (a commonlyused performance optimization). There are three primary variants of theissue which differ in the way the speculative execution can be exploited.Variant CVE-2017-5715 triggers the speculative execution by utilizingbranch target injection. It relies on the presence of […]

LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0023

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0029

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0030

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0008

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0013

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is now available. now available.

LinuxSecurity.com: An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes is now available. is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is now available. now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0014

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0012

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0007

LinuxSecurity.com: It was discovered that there were two vulnerabilities in the imagemagick image manipulation program: CVE-2017-1000445: A null pointer dereference in the MagickCore

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Today’s CPU vulnerability: what you need to know

LinuxSecurity.com: Upstream announcement: Welcome to **phpMyAdmin 4.7.7**, a regular maintenance release containing bug fixes and a security fix. The security vulnerability is a XSRF/CSRF flaw; you can read more at https://www.phpmyadmin.net/security/PMASA-2017-9/ As a result of this, we recommend all users upgrade immediately. A CVE-ID has been requested but not yet

LinuxSecurity.com: Jason Crain discovered a overflow vulnerability in the poppler PDF rendering library. For Debian 7 “Wheezy”, this issue has been fixed in poppler version

Ransomware to hit cloud computing in 2018, predicts MIT