Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Updated to the latest version; Security fix for CVE-2017-10788

LinuxSecurity.com: An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes is now available. is now available.

security update

security update

LinuxSecurity.com: This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078,

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Linux Foundation launches Open Security Controller Project

LinuxSecurity.com: https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

Desperately Seeking Security: 6 Skills Most In Demand

security update

LinuxSecurity.com: New libtirpc packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: New rpcbind packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: Multiple vulnerabilities have been found in libcroco, the worst of which may have unspecified impacts.

LinuxSecurity.com: Two security issues have been discovered in the X.org X server, which may lead to privilege escalation or an information leak. For the oldstable distribution (jessie), these problems have been fixed

LinuxSecurity.com: A vulnerability in MAN DB allows local users to gain root privileges.

security update

LinuxSecurity.com: A vulnerability in Gajim might allow remote attackers to intercept encrypted communications.

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: update

LinuxSecurity.com: A vulnerability in RoundCube may allow authenticated users to bypass security restrictions.

LinuxSecurity.com: Multiple vulnerabilities have been found in VLC, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: update

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: This is new version with security fixes for CVE-2017-9468, CVE-2017-9469.

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

LinuxSecurity.com: Update to annulen-branch of qt5-qtwebkit, which contains a lot of security fixes. Drop-in replacement for the old unmaintained qt5-qtwebkit

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

Black Hat Survey: Security Pros Expect Major Breaches in Next Two Years

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes is now available. is now available.

LinuxSecurity.com: Clément Berthaux from Synaktiv discovered two vulnerabilities in BIND, a DNS server implementation. They allow an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

LinuxSecurity.com: A vulnerability has been found in GNOME applet for NetworkManager allowing local attackers to access the local filesystem.

LinuxSecurity.com: A vulnerability in feh might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in phpMyAdmin might allow remote attackers to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in JasPer, the worst of which could could allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in virglrenderer, the worst of which could allow local guest OS users to cause a Denial of Service condition. [More…]

Cloud computing security: This is where you’ll be spending the money
How to Achieve an Optimal Security Posture

LinuxSecurity.com: poppler could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata is now available. is now available.

security update

security update

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Several security issues were fixed in Thunderbird.

LinuxSecurity.com: It was discovered that jabberd2, a Jabber instant messenger server, allowed anonymous SASL connections, even if disabled in the configuration.

LinuxSecurity.com: An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: **Horde_Image 2.5.1** * [mjr] SECURITY: Fix more potential places for command injections. —- **Horde_Image 2.5.0** * [mjr] **SECURITY**: Prevent DOS attack by preventing an infinite loop in certain conditions (CVE-2017-9773, reported by Fariskhi Vidyan). * [mjr] **SECURITY**: Prevent RCE attacks by properly sanitizing shell arguments (CVE-2017-9774, reported by Fariskhi

LinuxSecurity.com: Security fix for CVE-2017-9604

LinuxSecurity.com: Security fix for CVE-2016-7968

LinuxSecurity.com: CVE-2017-9604 kmail: Send Later with Delay bypasses OpenPGP

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is now available. now available.

GnuPG crypto library cracked, look for patches
Tor Browser 7.0.2 is released

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea, the worst of which may allow execution of arbitrary code.

A Man-in-the-Middle Attack against a Password Reset System
HTTPS Certificate Revocation is broken, and it’s time for some new tools
With a single wiretap order, US authorities listened in on 3.3 million phone calls

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: * [7.56](https://www.drupal.org/project/drupal/releases/7.56) * [SA- CORE-2017-003](https://www.drupal.org/SA-CORE-2017-003)

LinuxSecurity.com: New upstream release fixing moderate security issue CVE-2017-7526.

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

security update

LinuxSecurity.com: Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal and Yuval Yarom discovered that Libgcrypt is prone to a local side-channel attack allowing full key recovery for RSA-1024.

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: A fix for an out-of-bounds write in systemd-resolved after a crafted DNS packet (CVE-2017-9445). No need to reboot or log out.

LinuxSecurity.com: xen: various flaws (#1463247) blkif responses leak backend stack data [XSA-216] page transfer may allow PV guest to elevate privilege [XSA-217] Races in the grant table unmap code [XSA-218] x86: insufficient reference counts during shadow emulation [XSA-219] x86: PKRU and BND* leakage between vCPU-s [XSA-220] stale P2M mappings due to insufficient error checking [XSA-222] […]

LinuxSecurity.com: Updates to the latest upstream OpenVPN 2.3.17, containing security updates for CVE-2017-7508, CVE-2017-7520 and CVE-2017-7521.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes is now available. is now available.

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New glibc packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New httpd packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New kernel packages are available for Slackware 14.1 to fix security issues.

LinuxSecurity.com: New libgcrypt packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.