Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Security Report Summary

Massive Bug May Have Leaked User Data From Millions of Sites. So … Change Your Passwords
Here’s Why Net Neutrality is Essential in Trump’s America
Google shifts on email encryption tool, leaving its fate unclear

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Security Report Summary

security update

LinuxSecurity.com: This update rebases RPM to the official 4.13.0.1 release(http://rpm.org/wiki/Releases/4.13.0.1) which includes several importantsecurity and regression fixes.

LinuxSecurity.com: cirrus_bitblt_cputovideo does not check if memory region is safe [XSA-209,CVE-2017-2620] (#1425420)

LinuxSecurity.com: New release (1.10a). Security fix for CVE-2016-6265

LinuxSecurity.com: Security fix for CVE-2017-2616

LinuxSecurity.com: Security fix for CVE-2016-8745

LinuxSecurity.com: Security fix for CVE-2016-6265

Carders capitalize on Cloudflare problems, claim 150 million logins for sale
Google End-to-End encrypted email code goes open-source

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.6 Long Life. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.7.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.6.0-ibm is now available for Red Hat Enterprise Linux 5 Supplementary and Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

security update

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update prevents `python-cjson` from crashing when attempting to parseheavily nested JSON structures (which could be exploited for denial of servicepurposes, against any application that uses `python-cjson` to parse arbitraryinput).

LinuxSecurity.com: memory leak when destroying guest without PT devices [XSA-207] (#1422492) updatepatches for XSA-208 after upstream revision (no functional change) —- Qemu:net: mcf_fec: infinite loop while receiving data in mcf_fec_receive[CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] (#1414111)Qemu: audio: memory leakage in es1370 device [CVE-2017-5526] (#1414211) oobaccess in cirrus bitblt copy [XSA-208, CVE-2017-2615] (#1418243)

LinuxSecurity.com: This update prevents `python-cjson` from crashing when attempting to parseheavily nested JSON structures (which could be exploited for denial of servicepurposes, against any application that uses `python-cjson` to parse arbitraryinput).

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Fix for CVE-2017-5495

LinuxSecurity.com: Security fix for CVE-2017-2616

LinuxSecurity.com: Update to 0.7.10

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

security update

security update

security update

Netflix Debuts ‘Stethoscope’ Open-Source Security Tool
Malware Lets a Drone Steal Data by Watching a Computer’s Blinking LED

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Latest stable upstream release, includes security fix for CVE-2017-5593

LinuxSecurity.com: WARNING: Please note that this update comes with a slightly different syntax ofsesman.ini file, so if you edited this file by hand, you may need to look at the.rpmnew file and merge any required changes by hand. This release also createsthree files in /etc/xrdp directory if they don’t already exist or are empty: -rsakeys.ini […]

LinuxSecurity.com: Latest stable upstream release, includes security fix for CVE-2017-5593

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

Debugging a kernel in QEMU/libvirt – Part II

security update

LinuxSecurity.com: An update for python-oslo-middleware is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This release fixes pcregrep multi-line matching with –only-matching option, acrash when JIT-compiling some patterns (CVE-2017-6004) and a possible bufferoverflow when formatting a pcregrep error message.

LinuxSecurity.com: it was found that KDE plasma does not honor the setting for prompting whenexecuting executable files on the desktop. This update resolves this issue.

LinuxSecurity.com: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627,CVE-2017-5628.

LinuxSecurity.com: Update to the latest version, fixes a security issue.

LinuxSecurity.com: Security fix for CVE-2016-8745

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: it was found that KDE plasma does not honor the setting for prompting whenexecuting executable files on the desktop. This update resolves this issue.

LinuxSecurity.com: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627,CVE-2017-5628.

LinuxSecurity.com: Update to the latest version, fixes a security issue.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

At death’s door for years, widely used SHA1 function is now dead
Linux’s decade-old flaw: Major distros move to patch serious kernel bug
Salted Hash: RSAC 2017 Recap
“Secure” Trump website defaced by hacker claiming to be from Iraq

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Ruby Archive::Tar::Minitar is vulnerable to a directory traversal attack.

LinuxSecurity.com: Multiple vulnerabilities have been found in GPL Ghostscript, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

Kaspersky: No whiff of Linux in our OS because we need new start to secure IoT
Intent-Based Security Gains Momentum at RSA
12 steps to small business security
The 7 security threats to technology that scare experts the most
RSA: Elite cryptographers scoff at idea that law enforcement can ‘overcome’ encryption

LinuxSecurity.com: Multiple vulnerabilities have been found in tcpdump, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could lead to arbitrary code execution or cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could lead to the execution of arbitrary code on the host system.

LinuxSecurity.com: Multiple vulnerabilities have been found in Nagios, the worst of which could lead to privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could lead to the execution of arbitrary code on the host system.

LinuxSecurity.com: Multiple vulnerabilities have been found in libass, the worst of which have unknown impacts.

LinuxSecurity.com: Multiple vulnerabilities have been found in LibVNCServer/LibVNCClient, the worst of which allows remote attackers to execute arbitrary code when connecting to a malicious server.

LinuxSecurity.com: Multiple vulnerabilities have been found in Dropbear, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in Opus could cause memory corruption.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in TigerVNC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Security fix for CVE-2017-3135

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the GNU C Library, the worst of which allows context-dependent attackers to execute arbitrary code.