Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: The package krb5 before version 1.16.1-1 is vulnerable to insufficient validation.

LinuxSecurity.com: The package chromium before version 67.0.3396.79-1 is vulnerable to access restriction bypass.

security update

security update

security update

security update

LinuxSecurity.com: Security fix for CVE-2018-8013. Updated to upstream release 1.10.

LinuxSecurity.com: This update fixes CVE-2016-10040, a stack overflow in QXmlSimpleReader due to a too lenient entityCharacterLimit in our version of the patch for CVE-2013-4549. (The limit was increased from the upstream 1024 to 65536 to address QTBUG-35459, an issue where the security fix was breaking existing real-world XML files. Unfortunately, that is too much to […]

Bug Bounty Payouts Up 73% Per Vulnerability: Bugcrowd
Survey Shows Florida at the Bottom for Consumer Cybersecurity

LinuxSecurity.com: Alexander Peslyak discovered that insufficient input sanitising of RFB packets in LibVNCServer could result in the disclosure of memory contents.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: Marcus Brinkmann discovered that GnuGPG performed insufficient sanitisation of file names displayed in status messages, which could be abused to fake the verification status of a signed email.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes is now available.

LinuxSecurity.com: Ivan Fratric discovered a buffer overflow in the Skia graphics library used by Firefox, which could result in the execution of arbitrary code. For the oldstable distribution (jessie), this problem has been fixed

LinuxSecurity.com: New gnupg2 packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and – -current to fix a security issue.

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Satellite 5.6 and Red Hat Satellite 5.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Remove essentially unused pre_release tagging in spec file Fixup Makefile patch to include LDFLAGS in all linking commands

LinuxSecurity.com: DWARF5 and split dwarf, including GNU DebugFission, support.

What is the New York Cybersecurity Regulation? What you need to do to comply
#Infosec18: Nation State Hacking is Biggest Change in Cyber-Threat Landscape

LinuxSecurity.com: Several vulnerabilities were discovered in jruby, a Java implementation of the Ruby programming language. They would allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop,

LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available.

security update

LinuxSecurity.com: A security issue was fixed in Unbound.

LinuxSecurity.com: The package radare2 before version 2.6.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: 8u171 update

LinuxSecurity.com: 8u171 update

LinuxSecurity.com: Security fix for CVE-2017-13685 CVE-2017-15286

MyHeritage Alerts Users to Data Breach
Open-source security: Zip Slip critical flaw hits thousands of projects. Update now
#Infosec18: Regulation is Top Driver of Cybersecurity, Now & in the Future
Phishing Scams Target FIFA World Cup Attendees
North Korean hacking group Covellite abandons US targets
Security fail? One in three companies think paying hackers is worth the risk
Customer Data Flies Away with Ticketfly Hacker
5 Tips for Protecting SOHO Routers Against the VPNFilter Malware
Cybercrime Is Skyrocketing as the World Goes Digital
Fitness app PumpUp left users’ personal data exposed on server
Queen’s University Belfast Launches Cyber-Testing Labs
Open Redis Servers Infected with Malware

LinuxSecurity.com: Several security issues were fixed in procps-ng.

LinuxSecurity.com: **Version 2.8.41** (2018-05-25) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas-grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 Adding session authentication strategy to Guard

LinuxSecurity.com: **Version 4.0.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user

LinuxSecurity.com: Some more efail fixes, https://enigmail.net/index.php/en/download/changelog

security update

LinuxSecurity.com: Several security issues were fixed in Git.

LinuxSecurity.com: **Version 3.4.11** (2018-05-25) * bug #27364 [DI] Fix bad exception on uninitialized references to non-shared services (nicolas-grekas) * bug #27359 [HttpFoundation] Fix perf issue during MimeTypeGuesser intialization (nicolas- grekas) * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user

security update

security update

LinuxSecurity.com: Several security issues were fixed in Liblouis.

LinuxSecurity.com: CVE-2016-9396

LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for rh-java-common-xmlrpc is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

security update

security update

LinuxSecurity.com: It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, SIGCOMP, LDSS, GSM A DTAP and Q.931, which result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: The redmine security update announced as DSA-4191-1 caused regressions with multi-value fields while doing queries on project issues due to an bug in the patch to address CVE-2017-15569. Updated packages are now available to correct this issue.

LinuxSecurity.com: CVE-2016-9396

LinuxSecurity.com: Security fix for CVE-2016-5003, CVE-2016-5002

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1780

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1779

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1777

LinuxSecurity.com: Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the

LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum.

LinuxSecurity.com: New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL7 noarch xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm – Scientific Linux Development Team

LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the

LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service. CVE-2018-1093

LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: Applications using Oslo middleware could be made to expose sensitiveinformation.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service: CVE-2017-11613

LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in procps, a set of command line and full screen utilities for browsing procfs. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several security issues were fixed in libytnef.

LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL6 noarch xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm [More…]

LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710

An Industry In Transition: Key Tech Trends In 2018
FBI to all router users: Reboot now to neuter Russia’s VPNFilter malware

LinuxSecurity.com: Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code.

LinuxSecurity.com: The package strongswan before version 5.6.2-2 is vulnerable to denial of service.

LinuxSecurity.com: The package wireshark-common before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-cli before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-qt before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: The package wireshark-gtk before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Several vulnerabilities were discovered in qemu, a fast processor emulator. CVE-2017-15038

LinuxSecurity.com: Etienne Stalmans discovered that git, a fast, scalable, distributed revision control system, is prone to an arbitrary code execution vulnerability exploitable via specially crafted submodule names in a .gitmodules file.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1726