Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.

LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.

LinuxSecurity.com: OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transfer library, could be tricked into reading data beyond the end of a heap based buffer when parsing invalid headers in an RTSP response.

LinuxSecurity.com: It was discovered that there was an issue in the curl a command-line tool for downloading (eg.) data over HTTP. curl could have be tricked into reading data beyond the end of a heap

security update

LinuxSecurity.com: Several security issues were fixed in PHP.

Mexican Banks Lose Millions in SWIFT-like Attacks
Chili’s Suffers Data Breach
Major #eFail Vulnerability Exposes PGP Encrypted Email — UPDATED

security update

LinuxSecurity.com: Several security issues were fixed in PHP.

White Hat Spoofs 2FA, Sends User to Phishing Page
NCA: Organized Cybercrime Continues to Rise

LinuxSecurity.com: A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.

LinuxSecurity.com: The package firefox before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass, access restriction bypass, content spoofing, denial of service, information disclosure and sandbox escape.

LinuxSecurity.com: The package webkit2gtk before version 2.20.2-1 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package llpp before version 27-2 is vulnerable to multiple issues including arbitrary code execution and denial of service.

LinuxSecurity.com: Fabian Vogt discovered that incorrect permission handling in the PAM module of the KDE Wallet could allow an unprivileged local user to gain ownership of arbitrary files.

LinuxSecurity.com: Security fix for CVE-2018-10380

LinuxSecurity.com: Security fix for CVE-2018-10380

FBI: Reported Internet Crimes Topped $1.4 Billion Last Year
Open Source AI For Everyone: Three Projects to Know

LinuxSecurity.com: https://www.libraw.org/news/libraw-0-18-11 —- CVE-2018-10529 fixed: out of bounds read in X3F parser CVE-2018-10528 fixed: possible stack overrun in X3F parser

Cyberattack shuts down Tennessee election website

LinuxSecurity.com: An update that fixes three vulnerabilities is now available.

Phishing Threats Move to Mobile Devices
Report: More Breaches Despite Increasing Security Budgets
Phishing Attack Bypasses Two-Factor Authentication

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 6 fixes is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

security update

LinuxSecurity.com: Harry Sintonen have discovered a cookie injection vulnerability in wget caused by insufficient input validation, enabling an external attacker to inject arbitrary cookie values cookie jar file, adding new

Former Iranian Hacker Exposes Cyber-Efforts
Professionals ‘Lack Time’ or Ignore Critical Patch Application

LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.

LinuxSecurity.com: Updated to latest upstream release (#1571443, #1573318, #1573319).

LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.

LinuxSecurity.com: Update to 1.10.1

security update

security update

Online voting is impossible to secure. So why are some governments using it?
Small Firms Up to 20 Times More Likely to be Breached

LinuxSecurity.com: New wget packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1319

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1364

LinuxSecurity.com: The package freetype2 before version 2.9.1-1 is vulnerable to denial of service.

LinuxSecurity.com: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount […]

LinuxSecurity.com: ## 4.9.2 https://ckeditor.com/cke4/release/CKEditor-4.9.2 ### Security Updates – Fixed XSS vulnerability in the Enhanced Image (image2) plugin reported by Kyaw Min Thein. – Issue summary: It was possible to execute XSS inside CKEditor using the tag and specially crafted HTML. Please note that the default presets (Basic/Standard/Full) do not include this plugin, so you are […]

LinuxSecurity.com: Security fix for CVE-2017-6888.

LinuxSecurity.com: Security fix for CVE-2018-1000156

LinuxSecurity.com: Regenerate autoconf files using current tools so proper build flags from redhat- rpm-config are used. This applies hardened LDFLAGS. No functional change intended.

LinuxSecurity.com: This release provides Perl 5.26.2 that fixes a heap buffer overflow in the pack() function and two overflows in regular expression engine.

LinuxSecurity.com: Knot Resolver 2.3.0 (2018-04-23) ——– – fix CVE-2018-1110: denial of service triggered by malformed DNS messages (!550, !558, security!2, security!4) – increase resilience against slow lorris attack (security!5) Bugfixes ——– – validation: fix SERVFAIL in case of CNAME to NXDOMAIN in a single zone (!538) – validation: fix SERVFAIL for

security update

Trial set for Latvian accused of running malware operation
Equifax Update Clarifies Breach Details to SEC

LinuxSecurity.com: On May 8, fixes for CVE-2018-1087 and CVE-2018-8897 were released in linuxkernel version 4.4.0-124.148. These CVEs are both related to the way thatthe linux kernel handles certain interrupt and exception instructions. Ifan interrupt or exception instruction (INT3, SYSCALL, etc.) is immediatelypreceded by a MOV SS or POP SS instruction, the resulting interrupt will [More…]

Most Industrial Networks Vulnerable to Attack

LinuxSecurity.com: Harry Sintonen discovered that wget, a network utility to retrieve files from the web, does not properly handle ‘rn’ from continuation lines while parsing the Set-Cookie HTTP header. A malicious web server could use this flaw to inject arbitrary cookies to the cookie jar file, adding

security update

LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

Report: China’s Intelligence Apparatus Linked to Previously Unconnected Threat Groups
Linux Kernel Hardens Sound Drivers Against Spectre V1 Vulnerability

security update

LinuxSecurity.com: An XML external entity expansion vulnerability was discovered in the DataImportHandler of Solr, a search server based on Lucene, which could result in information disclosure.

Vulnerabilities on the Rise?
A GEORGIA HACKING BILL GETS CYBERSECURITY ALL WRONG

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: – fix stack-based buffer overflow in utils.c:checkmailpath() (CVE-2018-1100) – fix stack-based buffer overflow in gen_matches_files() (CVE-2018-1083) – fix stack-based buffer overflow in exec.c:hashcmd() (CVE-2018-1071)

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions or unsafe redirects. More information can be found in the upstream advisory at

security update

LinuxSecurity.com: – https://www.drupal.org/project/drupal/releases/7.59 – https://www.drupal.org/SA-CORE-2018-004

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.

LinuxSecurity.com: Red Hat Single Sign-On 7.2.2 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code.

Security Holes Make Home Routers Vulnerable
Hackers Leverage GDPR to Target Airbnb Customers

LinuxSecurity.com: This update includes the changes in tzdata 2018e for the Perl bindings. For the list of changes, see DLA-1371-1. For Debian 7 “Wheezy”, these problems have been fixed in version

LinuxSecurity.com: This update includes the changes in tzdata 2018e. Notable changes are: – North Korea switches back to +09 on 2018-05-05.

LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.