Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

How to keep Debian Linux patched with latest security updates automatically
Linux: A Hacker’s Preference
A critical flaw allows hacking Linux machines with just a malicious DNS Response

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

What Are Linux Logs? How to View Them, Most Important Directories, and More
New Research Shows Cybersecurity Battleground Shifting to Linux and Web Servers

LinuxSecurity.com: An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes is now available. is now available.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

security update

LinuxSecurity.com: Several issues were discovered in openvpn, a virtual private network application. CVE-2017-7479

LinuxSecurity.com: The security update announced as DSA-3886-1 caused regressions for some applications using Java – including jsvc, LibreOffice and Scilab – due to the fix for CVE-2017-1000364. Updated packages are now available to correct this issue. For reference, the relevant part of the original

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: systemd-resolved could be made to crash or run programs if it received a specially crafted DNS response.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

Idea to encrypt Web traffic at rest hits the IETF’s Standard Track
How to secure your CMS with out patching
Even weak hackers can pull off a password reset MitM attack via account registration

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

3 security tips for software developers

LinuxSecurity.com: A vulnerability in KAuth and KDELibs allows local users to gain root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in LibreOffice, the worst of which allows for the remote execution of arbitrary code.

LinuxSecurity.com: A vulnerability in FreeRADIUS might allow remote attackers to bypass authentication.

LinuxSecurity.com: Several vulnerabilities have been found in VLC, the VideoLAN project’s media player. Processing malformed subtitles or movie files could lead to denial of service and potentially the execution of arbitrary code.

security update

LinuxSecurity.com: Fixes CVE-2017-9462.

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: Rebase to the newest upstream release. This release contains only bug fixes, most notably fixes for many CVEs. There are no new features.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Expat, an XML parsing C library. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

LinuxSecurity.com: Two vulnerabilities were discovered in Drupal, a fully-featured content management framework. The Common Vulnerabilities and Exposures project identifies the following issues:

Basic Security Testing with Kali Linux

LinuxSecurity.com: An update that solves one vulnerability and has 27 fixes is An update that solves one vulnerability and has 27 fixes is An update that solves one vulnerability and has 27 fixes is now available. now available.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 50 vulnerabilities is now available. An update that fixes 50 vulnerabilities is now available. An update that fixes 50 vulnerabilities is now available.

security update

security update

security update

security update

security update

LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-3167

LinuxSecurity.com: Multiple vulnerabilities have been found in Vim and gVim, the worst of which might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: An out-of-bounds write in Graphite might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in jbig2dec, the worst of which might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Several security issues were fixed in OpenVPN.

LinuxSecurity.com: Multiple vulnerabilities have been found in Urban Terror, the worst of which allows for the remote execution of arbitrary code.

LinuxSecurity.com: It was discovered that Flatpak, an application deployment framework for desktop apps insufficiently restricted file permissinons in third-party repositories, which could result in privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in libksba which might allow remote attackers to obtain sensitive information or crash an libksba-based application. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in the Graphite font rendering engine which might result in denial of service or the execution of arbitrary code if a malformed font file is processed.

LinuxSecurity.com: An update that fixes 12 vulnerabilities is now available. An update that fixes 12 vulnerabilities is now available. An update that fixes 12 vulnerabilities is now available.

LinuxSecurity.com: For changes see https://www.mozilla.org/en-US/thunderbird/52.2.0/releasenotes/

LinuxSecurity.com: This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

security update

LinuxSecurity.com: New openvpn packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Emeric Boit of ANSSI reported that SPIP, a website engine for publishing, insufficiently sanitises the value from the X-Forwarded-Host HTTP header field. An unauthenticated attacker can take advantage of this flaw to cause remote code execution.

LinuxSecurity.com: The system could be made to run programs as an administrator.

Honeypots and the Internet of Things

LinuxSecurity.com: Disable executable stack for aarch64 builds.

LinuxSecurity.com: This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: Update to .104. Fix mp3 playback. Security fix for CVE-2017-5087, CVE-2017-5088, CVE-2017-5089

LinuxSecurity.com: Rebuild for new luajit

LinuxSecurity.com: Alvaro Munoz and Christian Schneider discovered that jython, an implementation of the Python language seamlessly integrated with Java, is prone to arbitrary code execution triggered when sending a serialized function to the deserializer.

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat7, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat8, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Several security issues were fixed in the kernel.

security update

security update

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the GNU C Library, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in mbed TLS, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Kodi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A header injection vulnerability in GNU Wget might allow remote attackers to inject arbitrary HTTP headers.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

Stack Clash vulnerabilities smash Linux defenses in the quest for root access
pyrasite – Inject Code Into Running Python Processes

LinuxSecurity.com: An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes is now available. is now available.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: For changes see https://www.mozilla.org/en-US/thunderbird/52.2.0/releasenotes/

LinuxSecurity.com: Fixes CVE-2017-9502 (Windows builds only)

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

security update

security update

security update

security update

LinuxSecurity.com: An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.

WikiLeaks emits CIA’s Wi-Fi pwnage tool docs
Security-Oriented Alpine Linux 3.6.2 OS Adds Linux Kernel 4.9.32 and Tor 0.3.0.8
Ubuntu 17.10 to Improve Secure Boot for Booting Windows from GRUB, Enable PIE
How to install Linux on a Chromebook (and why you should)