Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: Per release notes: http://www.postgresql.org/docs/9.5/static/release-9-5-7.html

LinuxSecurity.com: Agostino Sarubbo discovered multiple vulnerabilities in zziplib, a library to access Zip archives, which could result in denial of service and potentially the execution of arbitrary code if a malformed archive is processed.

Docker Aims to Improve Linux Kernel Security With LinuxKit
pymultitor – Python Multi Threaded Tor Proxy

LinuxSecurity.com: https://lists.gnupg.org/pipermail/gnutls-devel/2017-June/008446.html

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9225 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

LinuxSecurity.com: Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

LinuxSecurity.com: It has been discovered that Tor, a connection-based low-latency anonymous communication system, contain a flaw in the hidden service code when receiving a BEGIN_DIR cell on a hidden service rendezvous circuit. A remote attacker can take advantage of this flaw to cause a

LinuxSecurity.com: – Update to upstream 3.5.13 release

LinuxSecurity.com: Security fix for CVE-2017-9432

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: Security fixes.

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: * fixed CVE-2017-6508 CRLF injection in the url_parse function in url.c * fixed use of .netrc

LinuxSecurity.com: This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

security update

security update

EtherApe – Graphical Network Monitor
A Porn Bot Sprung a Leak and We Got to See What Was Behind It

security update

LinuxSecurity.com: An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is now available. now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available.

Tor Browser 7.0 is released

LinuxSecurity.com: This update fixes CVEs 2017-7511 and 2017-9083.

LinuxSecurity.com: Upgrade FreeRADIUS to upstream v3.0.14 release. The release includes fixes for various issues, including security issues, one of which is CVE-2017-9148.

LinuxSecurity.com: This update fixes CVEs 2017-7511 and 2017-9083.

LinuxSecurity.com: Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash.

security update

LinuxSecurity.com: FreeRADIUS would allow unintended access over the network.

LinuxSecurity.com: USN-3253-1 introduced a regression in Nagios.

5 Tips For Choosing The Right Open Source Code
Encryption leaves authorities ‘not in a good place’: Former US intelligence chief
The Dark Web is the place to go to find bugs before public disclosure

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in FreeType, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: An out-of-bounds data access in minicom might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Wireshark, the worst of which allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in PCRE library allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Pidgin might allow remote attackers to execute arbitrary code.

Why you must patch the new Linux sudo security hole

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several security issues were fixed in Puppet.

CIA’s Pandemic Toolkit
Hackers leak 8 unaired episodes of ABC’s Steve Harvey’s Funderdome TV series

LinuxSecurity.com: A vulnerability in a bundled copy of PuTTY in FileZilla might allow remote attackers to execute arbitrary code or cause a denial of service. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: A vulnerability has been found in Libtirpc and RPCBind which may allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in ImageWorsener, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: Multiple vulnerabilities in D-Bus might allow an attacker to overwrite files with a fixed filename in arbitrary directories or conduct a symlink attack. [More…]

LinuxSecurity.com: A vulnerability in Git might allow remote attackers to bypass security restrictions.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow a remote attacker to cause a Denial of Service or gain elevated privileges from a guest VM. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Shadow, the worst of which might allow privilege escalation.

LinuxSecurity.com: Gentoo’s MUNGE ebuilds are vulnerable to privilege escalation due to improper permissions.

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: Update to 4.12 (#1456190)

LinuxSecurity.com: Security fix for CVE-2017-7494

LinuxSecurity.com: Update to latest stable release, include fixes for gnutls and gtk-vnc compatibility.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

LinuxSecurity.com: The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to create or remove directory trees. An attacker can take advantage of this flaw to set the mode on an attacker-chosen file to a attacker-chosen

security update

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

Phishing Campaigns Follow Trends

security update

security update

LinuxSecurity.com: Several vulnerabilities were discovered in NSS, a set of cryptographic libraries, which may result in denial of service or information disclosure.

LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, didn’t restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: OpenLDAP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in libsndfile.

Silk Road founder Ross Ulbricht loses appeal for new trial
Biker group charged with hacking hundreds of Jeeps, motorcycles in crime spree

LinuxSecurity.com: An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes is now available. is now available.

Secure XML Processing with JAXP on EAP 7
Shadow Brokers lay out pitch – and name price – for monthly zero-day subscription service
Blockchains are the new Linux, not the new internet

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to force password resets, and perform various cross-site scripting and cross-site request forgery attacks.

security update

security update