Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Update to upstream release 1.25.6

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

The laws that are ruining the Internet
Pirate Bay digs itself a new hole: Mining alt-coin in slurper browsers
5 Ways to Secure Wi-Fi Networks

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

security update

security update

LinuxSecurity.com: new upstream release —- * heap overflow in libwpd

LinuxSecurity.com: Rebase to the latest upstream version 2.0.14. This update contains security fix for CVS -2017-1000050.

LinuxSecurity.com: Update to version 1.3.0, see https://nih.at/libzip/NEWS.html for details. —- This update backports security fix for CVE-2017-14107.

LinuxSecurity.com: Security fix for CVE-2017-13735

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

APNIC-sponsored proposal could vastly improve DNS resilience against DDoS
The Pirate Bay hijacked users’ CPU power to secretly mine cryptocurrency Monero

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which may allow attackers to bypass intended restrictions.

LinuxSecurity.com: A vulnerability in SquirrelMail might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in module File::Path for Perl allows local attackers to set arbitrary mode values on arbitrary files bypassing security restrictions. [More…]

LinuxSecurity.com: Gentoo’s GIMPS ebuilds are vulnerable to privilege escalation due to improper permissions. A local attacker could use it to gain root privileges. [More…]

LinuxSecurity.com: A command injection vulnerability in Git may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A command injection vulnerability in Subversion may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file.

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in GDK-PixBuf, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Kpathsea allows remote attackers to execute arbitrary commands by manipulating the -tex option from mpost program.

LinuxSecurity.com: A vulnerability in Supervisor might allow remote attackers to execute arbitrary code. [More…]

LinuxSecurity.com: A vulnerability in chkrootkit may allow local users to gain root privileges.

LinuxSecurity.com: A vulnerability in mod_gnutls allows remote attackers to spoof clients via crafted certificates.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebkitGTK+, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

security update

security update

Linux 4.13 Kernel Launches With Accelerated Security Feature
Linus Torvalds Wants Attackers to Join Linux Kernel Development
$1M bounty offered for zero-day exploits targeting Tor Browser
Open Source Summit: Securing IoT is About Avoiding Anti-Patterns
How network automation can speed deployments and improve security
Next US Elections: Open Source vs. Commercial Software?
Windows 10’s Subsystem for Linux: Here’s how hackers could use it to hide malware
Startup That Sells Zero-Days to Governments Is Offering $1 Million For Tor Hacks

LinuxSecurity.com: Several security issues were fixed in tcpdump

LinuxSecurity.com: Several security issues were fixed in tcpdump.

security update

security update

LinuxSecurity.com: BlueZ could be made to expose sensitive information over bluetooth.

5 reasons why device makers cannot secure the IoT platform
Securing a Raspberry Pi
Hackers Could Silently Hack Your Cellphone And Computers Over Bluetooth

security update

security update

security update

Kernel Stack Protector and BlueBorne
Windows 10’s Built-In Linux Shell Could Be Abused to Hide Malware, Researchers Say
Equifax blames giant breach on vendor software flaw

security update

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 5 fixes is An update that solves 6 vulnerabilities and has 5 fixes is An update that solves 6 vulnerabilities and has 5 fixes is now available. now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has four fixes An update that solves 7 vulnerabilities and has four fixes An update that solves 7 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 21 vulnerabilities and has 92 fixes An update that solves 21 vulnerabilities and has 92 fixes An update that solves 21 vulnerabilities and has 92 fixes is now available. is now available.

LinuxSecurity.com: **Version 2.2.5** – 2017-08-30 * **Security** – Double-free in gdImagePngPtr(). **CVE-2017-6362** – Buffer over-read into uninitialized memory. **CVE-2017-7890** * **Fixed** – Fix #109: XBM reading fails with printed error – Fix #338: Fatal and normal libjpeg/ibpng errors not distinguishable – Fix #357: 2.2.4: Segfault in test suite – Fix #386:

LinuxSecurity.com: This update fixes CVE-2017-12858.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 58 fixes An update that solves two vulnerabilities and has 58 fixes An update that solves two vulnerabilities and has 58 fixes is now available. is now available.

security update

security update

Tor Project boosts support for anonymous mobile browsing
Scammers Are Targeting Naive Bitcoin Owners With Terribly Simple Trick
CISOs’ Salaries Expected to Edge Above $240,000 in 2018
On internet privacy, be very afraid
Microsoft Releases Long-Awaited Security Tool, Sets Linux Preview
MongoDB ransacking starts again: Hackers ransom 26,000 unsecured instances

LinuxSecurity.com: **Version 1.3.0** It contains fixes for two possible security problems. The problems were identified by Brian ‘geeknik’ Carpenter and Agostino Sarubbo using AFL. The changes are: * Support bzip2 compressed zip archives * Improve file progress callback code * Fix zip_fdopen() * CVE-2017-12858: Fix double free(). * CVE-2017-14107: Improve EOCD64 parsing.

security update

LinuxSecurity.com: GD library could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

LinuxSecurity.com: A vulnerability in MCollective might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Libidn2 2.0.4 (released 2017-08-30) integer overflow in bidi.c/_isBidi() * Fix integer overflow in puny_decode.c/decode_digit() * Improve docs * Fix idna_free() to idn_free() * Update fuzzer corpora

LinuxSecurity.com: Several security issues were fixed in FontForge.

LinuxSecurity.com: Qemu: usb: ohci: infinite loop due to incorrect return value [CVE-2017-9330] (#1457698) Qemu: nbd: segmentation fault due to client non-negotiation [CVE-2017-9524] (#1460173) Qemu: qemu-nbd: server breaks with SIGPIPE upon client abort [CVE-2017-10664] (#1466466) Qemu: exec: oob access during dma operation [CVE-2017-11334] (#1471640) revised full fix for XSA-226 (regressed

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Several security issues were fixed in Liblouis.

LinuxSecurity.com: An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes An update that solves 9 vulnerabilities and has two fixes is now available. is now available.

security update