Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

security update

security update

security update

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: Karsten Heymann discovered that the OpenLDAP directory server can be crashed by performing a paged search with a page size of 0, resulting in denial of service. This vulnerability is limited to the MDB storage backend.

LinuxSecurity.com: New sudo packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: Sudo could be made to overwrite files as the administrator.

How to build your own VPN if you’re (rightfully) wary of commercial options
82% of Databases Left Unencrypted in Public Cloud

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

LinuxSecurity.com: It was discovered that pattern-based ACLs in the Mosquitto MQTT broker could be bypassed. For the stable distribution (jessie), this problem has been fixed in

LinuxSecurity.com: A security fix for a systemd-resolved crash on a crafted DNS packet. Relevant only to systemd-resolved users (not enabled by default). No need to reboot or logout.

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: Fix for CVE-2016-8728 CVE-2016-8729 —- Rebuild with new jbig2dec

LinuxSecurity.com: An issue in `git-shell` could allow remote users to run an interactive pager. From the [update announcement](https://public- inbox.org/git/xmqq8tm5ziat.fsf@gitster.mtv.corp.google.com/): … fix a recently disclosed problem with “git shell”, which may allow a user who comes over SSH to run an interactive pager by causing it to spawn “git

LinuxSecurity.com: strongSwan could be made to crash or hang if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

LinuxSecurity.com: Several security issues were fixed in ImageMagick.

LinuxSecurity.com: USN-3212-1 caused a regression in LibTIFF.

LinuxSecurity.com: Two denial of service vulnerabilities were identified in strongSwan, an IKE/IPsec suite, using Google’s OSS-Fuzz fuzzing project. CVE-2017-9022

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

Democracy-minded DEF CON hackers promise punishing probe on US election computers

security update

security update

A wormable code-execution bug has lurked in Samba for 7 years. Patch now!

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: A vulnerability in Smb4K could allow local attackers to execute commands as root.

LinuxSecurity.com: Teeworlds client vulnerability in snap handling could result in execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

4 Reasons the Vulnerability Disclosure Process Stalls

LinuxSecurity.com: Firefox was updated to a new version.

LinuxSecurity.com: New samba packages are available for Slackware 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Samba could be made to run programs as an administrator.

Sn1per – Penetration Testing Automation Scanner
Hackers Unlock Samsung Galaxy S8 With Fake Iris

LinuxSecurity.com: Samba could be made to run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in jbig2dec.

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for samba3x is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Jakub Jirasek of Secunia Research discovered that libtasn1, a library used to handle Abstract Syntax Notation One structures, did not properly validate its input. This would allow an attacker to cause a crash by denial-of-service, or potentially execute arbitrary code, by

LinuxSecurity.com: steelo discovered a remote code execution vulnerability in Samba, a SMB/CIFS file, print, and login server for Unix. A malicious client with access to a writable share, can take advantage of this flaw by uploading a shared library and then cause the server to load and execute it.

LinuxSecurity.com: This updates fixes a security bug in the route manager, to prevent it from overwriting arbitrary files (CVE-2017-8921)

security update

security update

Yahoo retires ImageMagick library after 18-byte exploit leaks user email content

LinuxSecurity.com: An update for rpcbind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for libtirpc is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069

LinuxSecurity.com: The 4.10.16 stable kernel update contains a number of important fixes across the tree.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Fix for CVE-2017-6949, also bump to 4.12.0

LinuxSecurity.com: Fix for CVE-2017-6949, also bump to 4.12.0

LinuxSecurity.com: Security fix for CVE-2017-8849. https://www.kde.org/info/security/advisory-20170510-2.txt

security update

security update

Proposed PATCH Act forces US snoops to quit hoarding code exploits
Twitter abandons ‘Do Not Track’ privacy protection

security update

security update

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for openstack-heat is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Updated atomic-openshift-utils and openshift-ansible packages that fix two security issues and several bugs are now available for OpenShift Container Platform 3.5, 3.4, 3.3, and 3.2. [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New kdelibs packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: New freetype packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

Good news, OpenVPN fans: Your software’s only a little bit buggy
Will Linux protect you from ransomware attacks?
The RHSA notifications you want, right in your Inbox

LinuxSecurity.com:

The Ransomware Meltdown Experts Warned About Is Here