Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: A vulnerability in NTFS-3G allows local users to gain root privileges.

LinuxSecurity.com: Security fix for CVE-2017-5595

LinuxSecurity.com: Security fix for CVE-2017-5595

LinuxSecurity.com: Update to 0.6.1

LinuxSecurity.com: An update for openssl is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Backport upstream fix to force limit and offset to be numeric

LinuxSecurity.com: Backport upstream fix to force limit and offset to be numeric

LinuxSecurity.com: USN-3199-1 introduced a regression in the Python Cryptography Toolkit whichcaused programs which relied on the original behavior to fail.

LinuxSecurity.com: Multiple vulnerabilities have been found in ImageMagick, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Programs using the Python Cryptography Toolkit could be made to crash or runprograms if they receive specially crafted network traffic or other input.

LinuxSecurity.com: Security Report Summary

security update

Xen Project asks to limit security vulnerability advisories
How Google reinvented security and eliminated the need for firewalls

security update

LinuxSecurity.com: Applications using libgc could be made to crash or run programs asyour login.

New ASLR-busting JavaScript is about to make drive-by exploits much nastier
A Chip Flaw Strips Away Hacking Protections for Millions of Devices
At RSA, doubts abound over US action on cybersecurity

LinuxSecurity.com: Qemu: net: mcf_fec: infinite loop while receiving data in mcf_fec_receive[CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] Qemu: audio:memory leakage in es1370 device [CVE-2017-5526] oob access in cirrus bitblt copy[XSA-208, CVE-2017-2615]

LinuxSecurity.com: – update to the latest upstream pre-release (fixes CVE-2016-9179)

LinuxSecurity.com: The newest upstream commit, fixing CVE-2017-5953 vim: Tree length values notvalidated properly when handling a spell file

LinuxSecurity.com: Security fix for CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925,CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929, CVE-2016-7930,CVE-2016-7931, CVE-2016-7932, CVE-2016-7933, CVE-2016-7934, CVE-2016-7935,CVE-2016-7936, CVE-2016-7937, CVE-2016-7938, CVE-2016-7939, CVE-2016-7940,CVE-2016-7973, CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984,CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993, CVE-2016-8574,CVE-2016-8575, CVE-2017-5202, CVE-2017-5203, CVE-2017-5204, CVE-2017-5205,CVE-2017-5341, CVE-2017-5342, CVE-2017-5482, CVE-2017-5483, CVE-2017-5484,CVE-2017-5485, CVE-2017-5486

LinuxSecurity.com: Security fix for CVE-2017-3135

LinuxSecurity.com: The 4.9.9 update contains a number of important fixes across the tree

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00)

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

security update

security update

security update

Researcher develops ransomware attack that targets water supply
CrowdStrike attempts to sue NSS Labs to prevent test release, court denies request
Newly discovered flaw undermines HTTPS connections for almost 1,000 sites

LinuxSecurity.com: Update to 3.20.7, fixing a serious password extraction sweep attack on thepassword manager [(#752738)](https://bugzilla.gnome.org/show_bug.cgi?id=752738)

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: New tcpdump packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. NOTE: These updates also require the updated libpcap package. [More Info…]

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Graphviz and the extent of these vulnerabilities are unspecified.

LinuxSecurity.com: A vulnerability in Lsyncd allows execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GnuTLS, the worst of which may allow execution of arbitrary code.

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.

LinuxSecurity.com: Important change: * most of the utilities were move to the new sub-package”server-utils” Other enhancements: (see changelog) * CVE fixes, SPECfilefixes, patches revision, tests blacklist revisions * Preparation and testing ofthe Cracklib plugin to be added

LinuxSecurity.com: Add upstream patches fixing CVE-2016-9577 and CVE-2016-9578

LinuxSecurity.com: gnome-boxes 3.20.4 release, fixing a possible security issue with storing theexpress installation password in clear text. – Store the user password in thekeyring during an express installation. – Fix typo in debug string. – Fix printfformat strings.

LinuxSecurity.com: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name toavoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrevassertion on long input

Arby’s Gets Roasted in Breach of 300K Payment Cards

LinuxSecurity.com: Update to 2.1

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: * various security relevant flaws

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Security Report Summary

How to Manage the Security Vulnerabilities of Your Open Source Product

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary and Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

security update

LinuxSecurity.com: Upstream 3.2.7 (important security fix)

LinuxSecurity.com: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name toavoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrevassertion on long input

LinuxSecurity.com: Important change: * Most of the utilities were move to the new sub-package”server-utils” Other enhancements: (see changelog) * CVE fixes, SPECfilefixes, patches revision, tests blacklist revisions * Preparation and testing ofthe Cracklib plugin to be added

LinuxSecurity.com: BitlBee 3.5.1 (30 Jan 2017) =========================== – purple: Fix crash onfile transfer requests from unknown contacts. This was the result of anincomplete fix in the previous release and may result in remote DoS. Read thefull security advisory at: https://bugs.bitlbee.org/ticket/1282 – After someinvestigation we decided to reclassify a crash fix from the previous release asa […]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Update to 2.78.0. Fixes bug #1409216

Do you know where that open source came from?

LinuxSecurity.com: gnome-boxes 3.22.4 release, fixing a possible security issue with storing theexpress installation password in clear text. – Store the user password in thekeyring during an express installation. – Fix typo in debug string in vm-configurator. – Fix printf format strings in the selectiontoolbar.

LinuxSecurity.com: Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.

LinuxSecurity.com: Update to 2.78.0. Fixes bug #1409216

LinuxSecurity.com: An update for ntp is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for spice is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for spice-server is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in RTMPDump, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Update to 3.22.6: * Fix minor memory leak[(#682723)](https://bugzilla.gnome.org/show_bug.cgi?id=682723) * Fix seriouspassword extraction sweep attack on password manager[(#752738)](https://bugzilla.gnome.org/show_bug.cgi?id=752738) * Fix adblockerblocking too much stuff, breaking Twitter[(#777714)](https://bugzilla.gnome.org/show_bug.cgi?id=777714)

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.7.0/releasenotes/

Kali Linux on the Raspberry Pi: 3, 2, 1, and Zero

security update

LinuxSecurity.com: The 4.9.7 update contains a number of important fixes across the tree

LinuxSecurity.com: Welcome to **phpMyAdmin 4.6.6**, a release containing security and bug fixes.This release includes many security fixes of various levels of severity. Werecommend all users upgrade to this release immediately. For full information onthe vulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and […]

LinuxSecurity.com: The 4.9.7 update contains a number of important fixes across the tree

LinuxSecurity.com: 3.1.4

LinuxSecurity.com: Welcome to **phpMyAdmin 4.6.6**, a release containing security and bug fixes.This release includes many security fixes of various levels of severity. Werecommend all users upgrade to this release immediately. For full information onthe vulnerabilities fixed and mitigation factors for users who are unable toupgrade, refer to the ChangeLog file included with this release and […]

Privacy-Focused Tails 2.10 Linux Includes Security Updates, New Tools
Linux: The 10 best privacy and security distributions

LinuxSecurity.com: This release turns on HTTPS encyption all over the publishing plugins. Usersusing Tumblr and Yandex.Fotki publishing are strongly advised to change theirpasswords and reauthenticate Shotwell to those services after upgrade. Users ofPicasa and Youtube publishing are strongly advised to reauthenticate (Log outand back in) Shotwell to those services after upgrade. Changes in shotwell0.24.5 release: […]

LinuxSecurity.com: This release turns on HTTPS encyption all over the publishing plugins. Usersusing Tumblr and Yandex.Fotki publishing are strongly advised to change theirpasswords and reauthenticate Shotwell to those services after upgrade. Users ofPicasa and Youtube publishing are strongly advised to reauthenticate (Log outand back in) Shotwell to those services after upgrade. Changes in shotwell0.24.5 release: […]

LinuxSecurity.com: This update should make OpenLDAP up to date with latest NSS, notably: – fixolcTLSProtocolMin handling – fix TLS_CIPHER_SUITE parsing – update a list ofciphers to fit latest NSS development – make use of NSS global settings for`DEFAULTS’ TLS_CIPHER_SUITE keyword Additionaly, slapd should start correctlyafter network is online, now.

LinuxSecurity.com: Update wavpack to 5.1.0

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rabbitmq-server is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]