Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1669

LinuxSecurity.com: Batik could be made to expose sensitive information if it received a specially crafted XML.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.

Privacy International Launches GDPR Probe into Data Companies
Clear Linux Exploring Support For Windows WSL
GDPR latest: Fraudsters posing as banks in data protection emails phishing scam
One in Three HCOs Hit by Cyber-Attack
GDPR Oddsmakers: Who, Where, When Will Enforcement Hit First?
Xenotime Attack Group Expands Activity

LinuxSecurity.com: CVE-2017-18248 It was found that by submitting a print job with an invalid username, the CUPS server can be crashed, when D-Bus support is enabled (which

LinuxSecurity.com: Security fix for CVE-2018-10536 CVE-2018-10537 CVE-2018-10538 CVE-2018-10539 CVE-2018-10540

security update

LinuxSecurity.com: The gitlab security update announced as DSA-4206-1 caused regressions when creating merge requests (returning 500 Internal Server Errors) due to an issue in the patch to address CVE-2017-0920. Updated packages are now available to correct this issue.

Most Expensive Data Breaches Start with Third Parties: Report
Report: Hacker group behind Trisis Malware expanding Activity in Middle East

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2018-7866

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Gabriel Corona discovered that xdg-utils, a set of tools for desktop environment integration, is vulnerable to argument injection attacks. If the environment variable BROWSER in the victim host has a “%s” and the victim opens a link crafted by an attacker with xdg-open, the malicious

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, informations leaks or privilege escalation.

LinuxSecurity.com: An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

More Unsecure Wi-Fi and Phishing? Not So Flashy
UK: We’ll Return Fire Against Deadly State Cyber-Attacks

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

LinuxSecurity.com: The package thunderbird before version 52.8.0-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass, content spoofing and denial of service.

LinuxSecurity.com: This update provides mitigations for the Spectre v4 variant in x86-based micro processors. On Intel CPUs this requires updated microcode which is currently not released publicly (but your hardware vendor may have issued an update). For servers with AMD CPUs no microcode update is

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or attacks on encrypted emails.

security update

security update

LinuxSecurity.com: This update upgrades Thunderbird to version 52.8.0. * Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8 (CVE-2018-5150) * Mozilla: Backport critical security fixes in Skia (CVE-2018-5183) * Mozilla: Use-after-free with SVG animations and clip paths (CVE-2018-5154) * Mozilla: Use-after-free with SVG animations and text paths (CVE-2018-5155) * Mozilla: Integer overflow […]

LinuxSecurity.com: This update upgrades Thunderbird to version 52.8.0. * Mozilla: Memory safety bugs fixed in Firefox 60 and Firefox ESR 52.8 (CVE-2018-5150) * Mozilla: Backport critical security fixes in Skia (CVE-2018-5183) * Mozilla: Use-after-free with SVG animations and clip paths (CVE-2018-5154) * Mozilla: Use-after-free with SVG animations and text paths (CVE-2018-5155) * Mozilla: Integer overflow […]

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

Ransomware Most Commonly Used Malicious Software: How to Protect Your Business
Mobile Fraud Soars as Social Sites Help Scammers

security update

LinuxSecurity.com: Matthias Gerstner discovered that PackageKit, a DBus abstraction layer for simple software management tasks, contains an authentication bypass flaw allowing users without privileges to install local packages.

Salted Hash – SC 01: What an Apple phishing attack looks like
Malware campaign expands to add cryptocurrency mining and iOS phishing attacks

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: Several security issues were addressed in the Linux kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: Side channel execution mitigations were added to QEMU.

security update

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in privilege escalation.

Syrian Electronic Army Members Indicted for Conspiracy

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.

LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.

LinuxSecurity.com: The package libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-libcurl-compat before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: The package lib32-curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

Advance notification for upcoming end-of-life for Debian 8

security update

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1414

Tech Talk: As GDPR looms, companies rush to comply
2018: Scariest Year of Evil Things on the Internet
California Teen Arrested for Phishing Teachers to Change Grades

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: Security update for CVE-2017-17723, CVE-2017-17725, CVE-2018-5772

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

BYOD Threats Exposed: 61% of UK SMEs Suffer Cyber-Attacks
New Research Seeks to Shorten Attack Dwell Time

security update

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Updated collectd packages are now available for Red Hat OpenStack Platform 10.0 Operational Tools for RHEL 7. Red Hat Product Security has rated this update as having a security impact of

LinuxSecurity.com: An update for sensu is now available for Red Hat OpenStack Platform 10. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives adetailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Hans Jerry Illikainen discovered a type conversion vulnerability in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.

DHS Unveils National Cybersecurity Risk Strategy
IT Pros Worried About IoT But Not Prepared to Secure It

LinuxSecurity.com: The package curl before version 7.60.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

security update

LinuxSecurity.com: The package zathura-pdf-mupdf before version 0.3.3-3 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: The package runc before version 1.0.0rc5+19+g69663f0b-1 is vulnerable to privilege escalation.

LinuxSecurity.com: An update is now available for Red Hat JBoss Data Grid. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266

US Government Cybersecurity at a Crossroads
Airports Ill-Equipped to Deal with Major Cyber-Attacks