Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

Critical Flaw Reported In phpMyAdmin Lets Attackers Damage Databases
Driving Open Standards in a Fragmented Networking Landscape

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The mysterious case of the Linux Page Table Isolation patches

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for CIP Safety, IWARP_MPA, NetBIOS, Profinet I/O and AMQP, which result in denial of dervice or the

security update

LinuxSecurity.com: Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service (application crash) or potentially the execution of arbitrary code if malformed files are opened.

security update

LinuxSecurity.com: Update to 1.9.9. This release addresses security vulnerabilities discovered by Cure53. Details can be found in the Security Audit Report: https://enigmail.net/ download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf

LinuxSecurity.com: A vulnerability has been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in resource exhaustion and denial of service.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service, information disclosure and potentially the execution of arbitrary code.

How Classical Cryptography Will Survive Quantum Computers

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

security update

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service, information disclosure or spoofing of sender’s email addresses.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

security update

LinuxSecurity.com: Update to 1.9.9. This release addresses security vulnerabilities discovered by Cure53. Details can be found in the Security Audit Report: https://enigmail.net/ download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf

LinuxSecurity.com: Update to 0.8.3, fixing CVE-2017-15612 and CVE-2017-16876

LinuxSecurity.com: A vulnerability was found in the Mercurial version control system which could lead to remote arbitrary code execution.

2018 Security Predictions – Double Up on Linux Attacks
New ibm linux-only mainframe delivers breakthrough security for next-gen applications
Introduction to GPG Encryption and git-crypt
One Small Step to Harden USB Over IP on Linux
Kubernetes, standardization, and security dominated 2017 Linux container news
Hackers Can Rickroll Thousands of Sonos and Bose Speakers Over the Internet
Best practices when running Node.js with port 80 (Ubuntu / Linode)
How to Generate CSR (Certificate Signing Request) in Linux
The state of Linux security in 2017
Gaps in software slowing down security professionals
FreeBSD-Based TrueOS 17.12 Focuses on Faster Boot, Bhyve and LibreSSL Support
The hacks that left us exposed in 2017

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available.

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed.

LinuxSecurity.com: Patch for CVE-2016-6328

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-13866](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13866), [CVE-2017-13870](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13870), [CVE-2017-7156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7156), [CVE-2017-13856](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13856)

LinuxSecurity.com: Update to upstream 14.7.4 release to address AST-2017-012 security issue —- Update to upstream 14.7.3 release for security alert AST-2017-013 —- Update to upstream 14.7.2 release for bug fixes

LinuxSecurity.com: Update to version 0.0.11, see http://metadata.ftp- master.debian.org/changelogs/main/s/sensible-utils/sensible- utils_0.0.11_changelog for details.

LinuxSecurity.com: Disable SSHv1 options.

LinuxSecurity.com: Update to 0.8.3, fixing CVE-2017-15612 and CVE-2017-16876

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Thunderbird mail client including information leaks, unintended JavaScript execution and sender address spoofing.

LinuxSecurity.com: Update to version 0.0.11, see http://metadata.ftp- master.debian.org/changelogs/main/s/sensible-utils/sensible- utils_0.0.11_changelog for details.

LinuxSecurity.com: Update to upstream 13.18.4 release to address AST-2017-012/CVE-2017-17664 security issue

LinuxSecurity.com: – update to the latest upstream pre-release (fixes CVE-2017-1000211)

LinuxSecurity.com: Disable SSHv1 options.

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

security update

LinuxSecurity.com: Hanno B?ck found several buffer overflows in GIMP, the GNU Image Manipulation Program, which could lead to application crash or other unspecified behaviour if a user opened untrusted input files.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client, which may lead to denial of service or other unspecified impact.

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

LinuxSecurity.com: An update that fixes 17 vulnerabilities is now available. An update that fixes 17 vulnerabilities is now available. An update that fixes 17 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities were discovered in Enigmail, an OpenPGP extension for Thunderbird, which could result in a loss of confidentiality, faked signatures, plain text leaks and denial of service. Additional information can be found under

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several vulnerabilities were discovered in rsync, a fast, versatile, remote (and local) file-copying tool, allowing a remote attacker to bypass intended access restrictions or cause a denial of service.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

security update

security update

security update

Detecting ROBOT and other vulnerabilities using Red Hat testing tools.

LinuxSecurity.com: Hanno Boeck, Juraj Somorovsky and Craig Young discovered that the TLS implementation in Bouncy Castle is vulnerable to an adaptive chosen ciphertext attack against RSA keys.

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. The Common Vulnerabilities and Exposures project identifies the following issues.

LinuxSecurity.com: Gabriel Corona reported that sensible-browser from sensible-utils, a collection of small utilities used to sensibly select and spawn an appropriate browser, editor or pager, does not validate strings before launching the program specified by the BROWSER environment variable,

LinuxSecurity.com: Multiple vulnerabilities were discovered in Enigmail, an OpenPGP extension for Thunderbird, which could result in a loss of confidentiality, faked signatures, plain text leaks and denial of service. Additional information can be found under

security update

LinuxSecurity.com: This is the One-Year notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.

How To Tell If Your Linux Server Has Been Compromised
Another Cyberattack Spotted Targeting Mideast Critical Infrastructure Organizations
Massive leak exposes data on 123 million US households

LinuxSecurity.com: Francesco Sirocco discovered a flaw in otrs2, the Open Ticket Request System, which could result in session information disclosure when cookie support is disabled. A remote attacker can take advantage of this flaw to take over an agent’s session if the agent is tricked into clicking a

LinuxSecurity.com: Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened.

LinuxSecurity.com: CVE-2017-17432 It was discovered that malformed jumbogram packets could result in denial of service against OpenAFS, an implementation of the Andrew

LinuxSecurity.com: Francesco Sirocco discovered a flaw in otrs2, the Open Ticket Request System, which could result in session information disclosure when cookie support is disabled. A remote attacker can take advantage of this flaw to take over an agent’s session if the agent is tricked into clicking a

LinuxSecurity.com: An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata An update that solves 32 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available. An update that fixes 26 vulnerabilities is now available.

Bolt Will Tackle Thunderbolt 3 Security on Linux
Linux Privilege Escalation – Tradecraft Security Weekly

LinuxSecurity.com: New ruby packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: An update for rh-ruby24-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix for CVE-2017-1000158

security update

security update

security update

LinuxSecurity.com: An update for cfme, cfme-appliance, and cfme-gemset is now available for CloudForms Management Engine 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Malware Decompiler Tool Goes Open Source
Firefox users are ticked after Mozilla secretly installed Mr. Robot add-on

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was discovered that there was a command-injection vulnerability in kildclient, a “MUD” multiplayer real-time virtual world game. For Debian 7 “Wheezy”, this issue has been fixed in kildclient version