Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: openSUSE: openSUSE 11.3 has reached end of SUSE support

Who the Hell Is This ‘Crypto-Genius?’
Spectre and Meltdown: What you need to know going forward

LinuxSecurity.com: An update that solves 14 vulnerabilities and has three An update that solves 14 vulnerabilities and has three An update that solves 14 vulnerabilities and has three fixes is now available. fixes is now available.

security update

LinuxSecurity.com: The package linux-hardened before version 4.14.11.a-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: The package linux-zen before version 4.14.11-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The package linux-lts before version 4.9.74-1 is vulnerable to multiple issues including denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 11.0 (Ocata). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: The package linux before version 4.14.11-1 is vulnerable to multiple issues including access restriction bypass, denial of service, privilege escalation and information disclosure.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 19 fixes is An update that solves 5 vulnerabilities and has 19 fixes is An update that solves 5 vulnerabilities and has 19 fixes is now available. now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 35 fixes is An update that solves 5 vulnerabilities and has 35 fixes is An update that solves 5 vulnerabilities and has 35 fixes is now available. now available.

Researchers Discover Two Major Flaws in the World’s Computers

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, information leaks, privilege escalation or the execution of arbitrary code.

LinuxSecurity.com: Multiple researchers have discovered a vulnerability in Intel processors, enabling an attacker controlling an unprivileged process to read memory from arbitrary addresses, including from the kernel and all other processes running on the system.

LinuxSecurity.com: An industry-wide issue was found in the way many modern microprocessordesigns have implemented speculative execution of instructions (a commonlyused performance optimization). There are three primary variants of theissue which differ in the way the speculative execution can be exploited.Variant CVE-2017-5715 triggers the speculative execution by utilizingbranch target injection. It relies on the presence of […]

LinuxSecurity.com: An update for microcode_ctl is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0023

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0029

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0030

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0008

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0013

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is An update that solves 5 vulnerabilities and has 13 fixes is now available. now available.

LinuxSecurity.com: An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes is now available. is now available.

LinuxSecurity.com: An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is An update that solves 5 vulnerabilities and has 26 fixes is now available. now available.

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0014

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0012

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:0007

LinuxSecurity.com: It was discovered that there were two vulnerabilities in the imagemagick image manipulation program: CVE-2017-1000445: A null pointer dereference in the MagickCore

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for linux-firmware is now available for Red Hat Enterprise Linux 7.3 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Today’s CPU vulnerability: what you need to know

LinuxSecurity.com: Upstream announcement: Welcome to **phpMyAdmin 4.7.7**, a regular maintenance release containing bug fixes and a security fix. The security vulnerability is a XSRF/CSRF flaw; you can read more at https://www.phpmyadmin.net/security/PMASA-2017-9/ As a result of this, we recommend all users upgrade immediately. A CVE-ID has been requested but not yet

LinuxSecurity.com: Jason Crain discovered a overflow vulnerability in the poppler PDF rendering library. For Debian 7 “Wheezy”, this issue has been fixed in poppler version

Ransomware to hit cloud computing in 2018, predicts MIT
Critical Flaw Reported In phpMyAdmin Lets Attackers Damage Databases
Driving Open Standards in a Fragmented Networking Landscape

LinuxSecurity.com: An update for eap7-jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6 and Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7.

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 7.0 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

The mysterious case of the Linux Page Table Isolation patches

LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for CIP Safety, IWARP_MPA, NetBIOS, Profinet I/O and AMQP, which result in denial of dervice or the

security update

LinuxSecurity.com: Several vulnerabilities were discovered in GIMP, the GNU Image Manipulation Program, which could result in denial of service (application crash) or potentially the execution of arbitrary code if malformed files are opened.

security update

LinuxSecurity.com: Update to 1.9.9. This release addresses security vulnerabilities discovered by Cure53. Details can be found in the Security Audit Report: https://enigmail.net/ download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf

LinuxSecurity.com: A vulnerability has been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in resource exhaustion and denial of service.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service, information disclosure and potentially the execution of arbitrary code.

How Classical Cryptography Will Survive Quantum Computers

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

security update

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code, denial of service, information disclosure or spoofing of sender’s email addresses.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

security update

LinuxSecurity.com: Update to 1.9.9. This release addresses security vulnerabilities discovered by Cure53. Details can be found in the Security Audit Report: https://enigmail.net/ download/other/Enigmail%20Pentest%20Report%20by%20Cure53%20-%20Excerpt.pdf

LinuxSecurity.com: Update to 0.8.3, fixing CVE-2017-15612 and CVE-2017-16876

LinuxSecurity.com: A vulnerability was found in the Mercurial version control system which could lead to remote arbitrary code execution.

2018 Security Predictions – Double Up on Linux Attacks
New ibm linux-only mainframe delivers breakthrough security for next-gen applications
Introduction to GPG Encryption and git-crypt
One Small Step to Harden USB Over IP on Linux
Kubernetes, standardization, and security dominated 2017 Linux container news
Hackers Can Rickroll Thousands of Sonos and Bose Speakers Over the Internet
Best practices when running Node.js with port 80 (Ubuntu / Linode)
How to Generate CSR (Certificate Signing Request) in Linux
The state of Linux security in 2017
Gaps in software slowing down security professionals
FreeBSD-Based TrueOS 17.12 Focuses on Faster Boot, Bhyve and LibreSSL Support
The hacks that left us exposed in 2017

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available. An update that fixes 14 vulnerabilities is now available.

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed.

LinuxSecurity.com: Patch for CVE-2016-6328

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-13866](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13866), [CVE-2017-13870](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13870), [CVE-2017-7156](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7156), [CVE-2017-13856](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13856)

LinuxSecurity.com: Update to upstream 14.7.4 release to address AST-2017-012 security issue —- Update to upstream 14.7.3 release for security alert AST-2017-013 —- Update to upstream 14.7.2 release for bug fixes

LinuxSecurity.com: Update to version 0.0.11, see http://metadata.ftp- master.debian.org/changelogs/main/s/sensible-utils/sensible- utils_0.0.11_changelog for details.

LinuxSecurity.com: Disable SSHv1 options.

LinuxSecurity.com: Update to 0.8.3, fixing CVE-2017-15612 and CVE-2017-16876

LinuxSecurity.com: Multiple security issues have been found in the Mozilla Thunderbird mail client including information leaks, unintended JavaScript execution and sender address spoofing.

LinuxSecurity.com: Update to version 0.0.11, see http://metadata.ftp- master.debian.org/changelogs/main/s/sensible-utils/sensible- utils_0.0.11_changelog for details.

LinuxSecurity.com: Update to upstream 13.18.4 release to address AST-2017-012/CVE-2017-17664 security issue

LinuxSecurity.com: – update to the latest upstream pre-release (fixes CVE-2017-1000211)

LinuxSecurity.com: Disable SSHv1 options.

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Several vulnerabilities have been discovered in the interpreter for the Ruby language. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

security update

LinuxSecurity.com: Hanno B?ck found several buffer overflows in GIMP, the GNU Image Manipulation Program, which could lead to application crash or other unspecified behaviour if a user opened untrusted input files.