Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: The system could be made to run programs as an administrator.

Honeypots and the Internet of Things

LinuxSecurity.com: Disable executable stack for aarch64 builds.

LinuxSecurity.com: This update addresses CVE-2017-1000366, a vulnerability in the dynamic linker allowing local privilege escalation.

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: Update to .104. Fix mp3 playback. Security fix for CVE-2017-5087, CVE-2017-5088, CVE-2017-5089

LinuxSecurity.com: Rebuild for new luajit

LinuxSecurity.com: Alvaro Munoz and Christian Schneider discovered that jython, an implementation of the Python language seamlessly integrated with Java, is prone to arbitrary code execution triggered when sending a serialized function to the deserializer.

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat7, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Aniket Nandkishor Kulkarni discovered that in tomcat8, a servlet and JSP engine, static error pages used the original request’s HTTP method to serve content, instead of systematically using the GET method. This could under certain conditions result in undesirable results,

LinuxSecurity.com: Several security issues were fixed in the kernel.

security update

security update

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the GNU C Library, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in mbed TLS, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Kodi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A header injection vulnerability in GNU Wget might allow remote attackers to inject arbitrary HTTP headers.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

Stack Clash vulnerabilities smash Linux defenses in the quest for root access
pyrasite – Inject Code Into Running Python Processes

LinuxSecurity.com: An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes An update that solves four vulnerabilities and has 35 fixes is now available. is now available.

LinuxSecurity.com: An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata An update that solves 10 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: For changes see https://www.mozilla.org/en-US/thunderbird/52.2.0/releasenotes/

LinuxSecurity.com: Fixes CVE-2017-9502 (Windows builds only)

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

security update

security update

security update

security update

LinuxSecurity.com: An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.

WikiLeaks emits CIA’s Wi-Fi pwnage tool docs
Security-Oriented Alpine Linux 3.6.2 OS Adds Linux Kernel 4.9.32 and Tor 0.3.0.8
Ubuntu 17.10 to Improve Secure Boot for Booting Windows from GRUB, Enable PIE
How to install Linux on a Chromebook (and why you should)

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one An update that solves three vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Update to a bugfix release of yara.

LinuxSecurity.com: Update to a bugfix release of yara.

LinuxSecurity.com: Upstream 3.2.8 —- Upstream 3.2.7 (important security fix) —- Security fix for CVE-2013-7458

LinuxSecurity.com: Mostly a bugfix update, but includes an update of the keyboard/mouse hwdb and various small fixes and a minor security issue and a boot issue on virtualized systems with no VGA console. No need to reboot or log out.

LinuxSecurity.com: Security fix for CVE-2017-9433

LinuxSecurity.com: – new upstream update (54.0)

LinuxSecurity.com: **Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

LinuxSecurity.com: * Bump to 1.7.6 * Security fix for CVE-2017-8932

LinuxSecurity.com: This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

LinuxSecurity.com: Rebuild with new bochs version

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

security update

Enhancing the security of the OS with cryptography changes in Red Hat Enterprise Linux 7.4

security update

security update

LinuxSecurity.com: It was discovered that RT::Authen::ExternalAuth, an external authentication module for Request Tracker, is vulnerable to timing side-channel attacks for user passwords. Only ExternalAuth in DBI (database) mode is vulnerable.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

LinuxSecurity.com: libmwaw could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: zziplib could be made to crash or run programs as your login if it opened a specially crafted file.

Brit hacker admits he siphoned info from US military satellite network
CIA has been hacking into Wi-Fi routers for years, leaked documents show
Cybersecurity labor crunch to hit 3.5 million unfilled jobs by 2021
Buggy devices and lazy operators make VoLTE a security nightmare
Parrot Security OS Devs Mock systemd: It’s an Immature Init System for GNU/Linux

LinuxSecurity.com: – new upstream update (54.0)

LinuxSecurity.com: Update to version 1.8.2. The upstream release notes: https://mail.gnome.org/archives/ftp-release-list/2017-June/msg00015.html

LinuxSecurity.com: **Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

security update

The 15 worst data security breaches of the 21st Century
DevSecOps is Not a Security Panacea
BlackArch Linux Ethical Hacking and Pen Testing OS Now Offers over 1,800 Tools

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2, and -current to fix security issues.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Update to a bugfix release of yara.

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages.

Pirates dance around AACS 2 encryption to offer UHD Blu-Ray movies online
Raspberry Pi sours thanks to mining malware

LinuxSecurity.com: It was discovered that a side channel attack in the EdDSA session key handling in Libgcrypt may result in information disclosure. For the stable distribution (jessie), this problem has been fixed in

security update