Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: Security fix for CVE-2018-6381

LinuxSecurity.com: This update includes a rebase from 8.0.47 to 8.0.49.

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.

Abusing X.509 Digital Certificates for Covert Data Exchange
Hacking suspect Lauri Love wins landmark appeal against US extradition
Australian cops to enter kindergartens to teach kids not to cyber
Malware Exploiting Spectre, Meltdown Flaws Emerges

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 to mitigate the speculative side channel attack known as Spectre variant 2.

LinuxSecurity.com: It was discovered that mpv, a media player, was vulnerable to remote code execution attacks. An attacker could craft a malicious web page that, when used as an argument in mpv, could execute arbitrary code in the host of the mpv user.

How I Got Paid $0 From the Uber Security Bug Bounty
Why cops won’t need a warrant to pull the data off your autonomous car
Open source turns 20 years old, looks to attract normal people

LinuxSecurity.com: Security fix for CVE-2017-17969 (from Debian)

LinuxSecurity.com: ClamAV 0.99.3 recommended for all ClamAV users. Please see details below: 1. ClamAV UAF (use-after-free) Vulnerabilities (CVE-2017-12374) ————————————————————— The ClamAV AntiVirus software versions 0.99.2 and prior contain a vulnerability that could

LinuxSecurity.com: This is a security fix release that fixes a sandbox escape in the flatpak dbus proxy. This issue was found by Gabriel Campana of The Google Security Team. Major changes in 0.10.3 * Fix dbus proxy vulnerability in authentication phase * Make permission handling ignore unknown permissions for forwards compatibility * Removed incorrect error […]

security update

LinuxSecurity.com: It was discovered that an XHR/AJAX call did not properly encode user input in the “dokuwiki” wiki platform. This resulted in a reflected file download vulnerability.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: ‘landave’ discovered a heap-based buffer overflow vulnerability in the NCompress::NShrink::CDecoder::CodeReal method in p7zip, a 7zr file archiver with high compression ratio. A remote attacker can take advantage of this flaw to cause a denial-of-service or, potentially the

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

Critical Infrastructure More Vulnerable Than Ever Before
GDPR: These are the organisations which are least prepared
Meltdown-Spectre: Malware is already being tested by attackers
A giant botnet is forcing Windows servers to mine cryptocurrency
What is microsegmentation? How getting granular improves network security
How to eliminate the default route for greater security

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0262

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0260

LinuxSecurity.com: Several security issues were fixed in Dovecot.

security update

LinuxSecurity.com: Dovecot could be made to crash if it received specially crafted input.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-15420

LinuxSecurity.com: An update that fixes 89 vulnerabilities is now available.

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: curl could be made to expose sensitive information.

LinuxSecurity.com: Several security issues were fixed in curl.

security update

Georgia bill poses potential threat to cybersecurity researchers
Flaws in Gas Station Software Let Hackers Change Prices, Steal Fuel, Erase Evidence
Camera makers resist encryption, despite warnings from photographers

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHBA-2018:0169

Torvalds Releases Linux 4.15 With Improved Meltdown, Spectre Patches

LinuxSecurity.com: openSUSE: openSUSE Leap 42.2 has reached end of SUSE support

LinuxSecurity.com: The package mupdf-tools before version 1.12.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package zathura-pdf-mupdf before version 0.3.2-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package mupdf-gl before version 1.12.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package libmupdf before version 1.12.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: The package mupdf before version 1.12.0-2 is vulnerable to arbitrary code execution.

LinuxSecurity.com: An update for collectd is now available for Red Hat OpenStack Platform 12.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service or URL spoofing. For the oldstable distribution (jessie), these problems have been fixed

LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.

LinuxSecurity.com: An update for openstack-nova is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for erlang is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

Keylogger found on thousands of WordPress-based sites

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: The package lib32-glibc before version 2.26-11 is vulnerable to privilege escalation.

LinuxSecurity.com: The package glibc before version 2.26-11 is vulnerable to privilege escalation.

security update

security update

LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: A vulnerability has been discovered in Fossil allowing for user-assisted remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 10 vulnerabilities is now available.

security update

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: A vulnerability has been discovered in the libtiff image processing library which may result in an application crash and denial of service.

LinuxSecurity.com: A vulnerability has been discovered in the libtiff image processing library which may result in an application crash and denial of service.

How We Built an Intrusion Detection System on AWS using Open Source Tools
DevOps and Security: How to Overcome Cultural Challenges and Transform to True DevSecOps
Beware! Undetectable CrossRAT malware targets Windows, MacOS, and Linux systems

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.