Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update for rabbitmq-server is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rabbitmq-server is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rabbitmq-server is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

Mozilla: Everyone’s scared of hackers but clueless about fending them off
Hire a DDoS service to take down your enemies
Debunking 5 Myths About DNS

LinuxSecurity.com: New pidgin packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Red Hat Product Security Risk Report 2016
Malware found preinstalled on 38 Android phones used by 2 companies

LinuxSecurity.com: Security Report Summary

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update fixes a possible heap buffer overflow.

LinuxSecurity.com: Security fix for

LinuxSecurity.com: This kdelibs3 (KDE 3 compatibility libraries) update fixes the security issues:* CVE-2016-6232 (karchive): Extraction of tar files possible to arbitrary systemlocations * CVE-2017-6410 (kio): Information Leak when accessing https whenusing a malicious PAC file for the KDE 3 compatibility libraries. (Securityupdates for KDE Frameworks 5 (kf5-karchive resp. kf5-kio) and for the KDE 4compatibility libraries […]

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.8.0/releasenotes/

Operation Rosehub patches Java vulnerabilities in open source projects

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security fix for CVE-2016-9422, CVE-2016-9423, CVE-2016-9424, CVE-2016-9425,CVE-2016-9428, CVE-2016-9426, CVE-2016-9429, CVE-2016-9430, CVE-2016-9431,CVE-2016-9432, CVE-2016-9433, CVE-2016-9434, CVE-2016-9435, CVE-2016-9436,CVE-2016-9437, CVE-2016-9438, CVE-2016-9439, CVE-2016-9440, CVE-2016-9441,CVE-2016-9442, CVE-2016-9443, CVE-2016-9622, CVE-2016-9623, CVE-2016-9624,CVE-2016-9625, CVE-2016-9626, CVE-2016-9627, CVE-2016-9628, CVE-2016-9629,CVE-2016-9631, CVE-2016-9630, CVE-2016-9632, CVE-2016-9633 And new upstream20170102 as well

LinuxSecurity.com: Security fix for integer underflow

security update

LinuxSecurity.com: This update fixes a possible heap buffer overflow.

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.8.0/releasenotes/

LinuxSecurity.com: Security update for integer underflow

LinuxSecurity.com: * various security relevant flaws

security update

security update

security update

Hackers exploit Apache Struts vulnerability to compromise corporate web servers
WikiLeaks publishes docs from what it says is trove of CIA hacking tools
Google’s ‘SHA-1 Countdown Clock’ Could Undermine Enterprise Security
Wikileaks Just Dumped a Cache of Information on Alleged CIA Hacking Tools

LinuxSecurity.com: Fixed CVE 2017-2590: freeipa: ipa: Insufficient permission check for ca-del, ca-disable and ca-enable commands [fedora-all]

LinuxSecurity.com: * [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) *[Moderately Critical – Information disclosure – SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: This is a new upstream feature and security release. Improvements include:bypass; pre-filter — fast packet keywords; TLS improvements; ICS protocoladditions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction;NIC offloading disabled by default; unix socket enabled by default; and AppLayer stats. Documentation: http://suricata.readthedocs.io/en/suricata-3.2/

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: * [7.x-1.21](https://www.drupal.org/project/metatag/releases/7.x-1.21) *[Moderately Critical – Information disclosure – SA-CONTRIB-2017-019](https://www.drupal.org/node/2852937)

LinuxSecurity.com: cirrus_bitblt_cputovideo does not check if memory region is safe [XSA-209,CVE-2017-2620] (#1425420)

LinuxSecurity.com: – Update to 1.0.4 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.phphttp://www.cacti.net/release_notes_1_0_4.php

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: This is a new upstream feature and security release. Improvements include:bypass; pre-filter — fast packet keywords; TLS improvements; ICS protocoladditions: DNP3 CIP/ENIP; SHA1/SHA256 for file matching, logging & extraction;NIC offloading disabled by default; unix socket enabled by default; and AppLayer stats. Documentation: http://suricata.readthedocs.io/en/suricata-3.2/

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

security update

LinuxSecurity.com: An update for ansible and openshift-ansible is now available for Red Hat OpenShift Container Platform 3.2, Red Hat OpenShift Container Platform 3.3, and Red Hat OpenShift Container Platform 3.4. [More…]

HackerOne offers bug bounty service for free to open-source projects
The Border Patrol can take your password. Now what?

LinuxSecurity.com: Security fix for CVE-2017-6060 CVE-2017-5896 —- Add comment with explanationof disabled debuginfo

LinuxSecurity.com: – Update to 1.0.4 Release notes: http://www.cacti.net/release_notes_1_0_0.phphttp://www.cacti.net/release_notes_1_0_1.phphttp://www.cacti.net/release_notes_1_0_2.phphttp://www.cacti.net/release_notes_1_0_3.phphttp://www.cacti.net/release_notes_1_0_4.php

security update

LinuxSecurity.com: Security fix in CA certificate chain verification (better check untrusted CAcertificates from peer, more strict error handling).

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2017-3135 (unaffected), fixes regression made byCVE-2016-8864

LinuxSecurity.com: Security fix for CVE-2017-2626

LinuxSecurity.com: Security fix for CVE-2017-2625

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2017-6410

LinuxSecurity.com: Security fix for CVE-2017-6410

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2017-3135 (unaffected), fixes regression made byCVE-2016-8864

LinuxSecurity.com: new upstream release 2.5.3, fixing leaks

security update

LinuxSecurity.com: An update for python-oslo-middleware is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for ipa is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

This old ransomware variant is back – with sneaky new tricks
Three Years after Heartbleed, How Vulnerable Are You?

LinuxSecurity.com: Security fix for CVE-2017-2625

LinuxSecurity.com: The 4.9.13 update contains a number of important fixes across the tree

LinuxSecurity.com: The 4.9.13 update contains a number of important fixes across the tree.

LinuxSecurity.com: WARNING: Please note that this update comes with a slightly different syntax ofsesman.ini file, so if you edited this file by hand, you may need to look at the.rpmnew file and merge any required changes by hand. This release also createsthree files in /etc/xrdp directory if they don’t already exist or are empty: -rsakeys.ini […]

How Threat Modeling Helps Discover Security Vulnerabilities

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support and Red Hat Enterprise Linux 6.5 Telco Extended Update Support. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

Famed Hacker Kevin Mitnick Shows You How to Go Invisible Online
Researchers find “severe” flaw in WordPress plugin with 1 million installs

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

security update

security update

LinuxSecurity.com: The newest upstream commit, CVE-2017-6350 vim: Integer overflow at anunserialize_uep memory allocation site, CVE-2017-6349 vim: Integer overflow at au_read_undo memory allocation site

LinuxSecurity.com: fix CVE-2017-3156 (rhbz#1425455,1425458)

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00) —- add missing directives about bundled librariesjasper and jbigkit —- New version of netpbm is available (10.76.00)

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-puppet-modules is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

Massive Bug May Have Leaked User Data From Millions of Sites. So … Change Your Passwords