Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Fix IV Reuse in GCM Mode.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has two fixes An update that solves 6 vulnerabilities and has two fixes An update that solves 6 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata is now available. is now available.

Hacker Who Stopped WannaCry Charged With Writing Banking Malware

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: Security fix for CVE-2016-6127 CVE-2017-5361 CVE-2017-5943 CVE-2017-5944

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Security fix for CVE-2016-6127 CVE-2017-5361 CVE-2017-5943 CVE-2017-5944

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes is now available. is now available.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Amazon Echo hacked to allow continuous remote eavesdropping
It’s 2017 and Hayes AT modem commands can hack luxury cars

LinuxSecurity.com: Security fix for CVE-2016-6127 CVE-2017-5361 CVE-2017-5943 CVE-2017-5944

AI quickly cooks malware that AV software can’t spot
Security This Week: The Very Best Hacks From Black Hat and Defcon
12 signs you’ve been hacked — and how to fight back

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

security update

LinuxSecurity.com: Fix /tmp race conditions in libDeployPkg (CVE-2015-5191).

LinuxSecurity.com: * various security fixes (https://github.com/glpi-project/glpi/issues/2475, https://github.com/glpi-project/glpi/issues/2476, https://github.com/glpi- project/glpi/issues/2492), * fix regressions on self service portal: * self-service users should not be auto assigned as tech * type and category fields are not selectable

LinuxSecurity.com: Update to 2.48 Fixes various security issues, see http://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for more info.

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: Apache HTTP Server could be made to crash or leak sensitive information if it received specially crafted network traffic.

LinuxSecurity.com: * various security fixes (https://github.com/glpi-project/glpi/issues/2475, https://github.com/glpi-project/glpi/issues/2476, https://github.com/glpi- project/glpi/issues/2492), * fix regressions on self service portal: * self-service users should not be auto assigned as tech * type and category fields are not selectable

LinuxSecurity.com: Update to 2.48 Fixes various security issues, see http://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for more info.

True random numbers are here – what that means for data centers
Long Live Gopher: The Techies Keeping the Text-Driven Internet Alive

LinuxSecurity.com: A denial of service vulnerability was discovered in Varnish, a state of the art, high-performance web accelerator. Specially crafted HTTP requests can cause the Varnish daemon to assert and restart, clearing the cache in the process.

LinuxSecurity.com: New gnupg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

security update

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: Fixes CVE-2017-11671. Fixed bugs (http://gcc.gnu.org/PRNNNNN): 31468, 43434, 45053, 49244, 50345, 53915, 56469, 60818, 60992, 61636, 61729, 62045, 64238, 65542, 65705, 65972, 66295, 66669, 67353, 67440, 68163, 68491, 68972, 69264, 69699, 69804, 69823, 69953, 70601, 70844, 70878, 71294, 71310, 71444, 71458, 71510, 71778, 71838, 72775, 73650, 75964, 76731, 77333, 77563, 77728, 77850,

LinuxSecurity.com: New version, security fix for CVE-2017-1000381.

LinuxSecurity.com: V1.0 final release —- bump runc commit —- Update to latest release candidate

LinuxSecurity.com: Fix for multiple CVEs

LinuxSecurity.com: Security fix for CVE-2017-7525

LinuxSecurity.com: Fix for multiple CVEs

LinuxSecurity.com: New version, security fix for CVE-2017-1000381.

Def Con hackers showed how easily voting machines can be hacked

LinuxSecurity.com: A security issues were fixed in Bash.

LinuxSecurity.com: Tyler Bohan of Talos discovered that FreeRDP, a free implementation of the Remote Desktop Protocol (RDP), contained several vulnerabilities that allowed a malicious remote server or a man-in-the-middle to either cause a DoS by forcibly terminating the client, or execute

LinuxSecurity.com: USN 3366-1 introduced a regression in OpenJDK 8.

LinuxSecurity.com: Several security issues were fixed in Apache HTTP Server.

LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.

LinuxSecurity.com: Update to latest snapshot that contains fixes for the latest Talos discovered CVEs.

LinuxSecurity.com: Fix for multiple CVEs

LinuxSecurity.com: Several security issues were fixed in NSS.

security update

security update

LinuxSecurity.com: Update to 5.2.24: fixes XSS vulnerability CVE-2017-11503.

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.57, which includes additional changes, such as performance improvements, bug fixes, new features, and possibly incompatible

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: In DSA 3918 Thunderbird was upgraded to the latest ESR series. This update upgrades Enigmail, the OpenPGP extention for Thunderbird, to version 1.9.8.1 to restore full compatibility.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

Privacy Isn’t Dead. It’s More Popular Than Ever
‘SambaCry’ malware scum return with a Windows encore
How a Bug in an Obscure Chip Exposed a Billion Smartphones to Hackers

LinuxSecurity.com: New squashfs-tools packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: MinGW cross compiled librsvg 2.40.18 release, fixing CVE-2017-11464 (division- by-zero in the Gaussian blur code).

LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available. An update that fixes 21 vulnerabilities is now available.

BlackHat: FBI Talks Avalanche Botnet Takedown
Black Hat speaker denied entry to US in another needless hit to security research

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-7018](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7018), [CVE-2017-7030](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7030), [CVE-2017-7034](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7034), [CVE-2017-7037](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7037),

LinuxSecurity.com: ## 2.8.25 (2017-07-17) * security #23507 [Security] validate empty passwords again (xabbuh) * bug #23526 [HttpFoundation] Set meta refresh time to 0 in RedirectResponse content (jnvsor) * bug #23540 Disable inlining deprecated services (alekitto) * bug #23468 [DI] Handle root namespace in service definitions (ro0NL) * bug #23256 [Security] Fix authentication.failure event

LinuxSecurity.com: – Upgrade to upstream v3.0.15 release. See upstream ChangeLog for details (in freeradius-doc subpackage). – Resolves: Bug#1471848 CVE-2017-10978 freeradius: Out-of-bounds read/write due to improper output buffer size check in make_secret() – Resolves: Bug#1471860 CVE-2017-10983 freeradius: Out-of-bounds read in

LinuxSecurity.com: This update fixes multiple security vulnerabilities (CVE-2017-7515, CVE-2017-9775, CVE-2017-9776, CVE-2017-9865).

LinuxSecurity.com: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129

LinuxSecurity.com: * Bump to 1.8.3 * Security fix for CVE-2017-8932 * add support for 28+bit OIDs in asn1

security update

security update

security update

LinuxSecurity.com: This release fixes a use-after-free in replaceChild() call.

LinuxSecurity.com: * CVE-2017-7718: cirrus: OOB read access issue (bz #1443443) * CVE-2016-9603: cirrus: heap buffer overflow via vnc connection (bz #1432040) * CVE-2017-7377: 9pfs: fix file descriptor leak (bz #1437872) * CVE-2017-7980: cirrus: OOB r/w access issues in bitblt (bz #1444372) * CVE-2017-8112: vmw_pvscsi: infinite loop in pvscsi_log2 (bz #1445622) * CVE-2017-8309: audio: host memory […]

LinuxSecurity.com: Multiple vulnerabilities were found in in qemu, a fast processor emulator: CVE-2017-9310

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in sandbox bypass, use of insecure cryptography, side channel attacks, information disclosure, the execution of arbitrary code, denial of service or

LinuxSecurity.com: Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. Debian follows the extended support releases (ESR) of Thunderbird.

LinuxSecurity.com: This release fixes a use-after-free in replaceChild() call.

Post Quantum Cryptography
Linux file manager flaw leaves security “Bad Taste”
Pathetic patching leaves over 70,000 Memcached servers still up for grabs
A Clever New Tool Shuts Down Ransomware Before It’s Too Late

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: This update includes the latest stable release of _Apache Subversion_, version **1.9.6**. ### User-visible changes: #### Client-side bugfixes: * cp/mv: improve error message when target is an unversioned dir * merge: reduce memory usage with large amounts of mergeinfo ([issue 4667](https://issues.apache.org/jira/browse/SVN-4667)) #### Server-side

Writing Windows or Linux apps? Microsoft just launched a cloud-powered bug hunter to find the flaws

LinuxSecurity.com: Fix CVE-2017-11368 (remote triggerable assertion failure in krb5kdc)

LinuxSecurity.com: librsvg 2.40.18 release, fixing CVE-2017-11464 (division-by-zero in the Gaussian blur code). For details, see https://mail.gnome.org/archives/ftp-release- list/2017-July/msg00078.html

security update

70,000 Memcached Servers Can Be Hacked Using Eight-Month-Old Flaws