Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: The system could be made to crash if it received specially craftednetwork traffic.

LinuxSecurity.com: The system could be made to crash if it received specially craftednetwork traffic.

LinuxSecurity.com: Several security issues were fixed in the kernel.

security update

Shopping for W2s, Tax Data on the Dark Web
Security flaws in Pentagon systems “easily” exploited by hackers

security update

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: A vulnerability in Ansible may allow rogue clients to execute commands on the Ansible controller.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.6 Advanced Update Support and Red Hat Enterprise Linux 6.6 Telco Extended Update Support. [More…]

Half the Web Is Now Encrypted. That Makes Everyone Safer

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for libtiff is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in PCSC-Lite, the worst of which could lead to privilege escalation.

LinuxSecurity.com: flatpak 0.8.2 release, fixing a security issue that could lead to sandboxescaping. For details, see https://github.com/flatpak/flatpak/releases/tag/0.8.2

LinuxSecurity.com: The 4.9.6 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: This is an security update fixing CVE-2017-5193, CVE-2017-5194, CVE-2017-5195,CVE-2017-5196, CVE-2017-5356.

LinuxSecurity.com: A heap-buffer overflow vulnerability was discovered in pycrypto leading toarbitrary code execution. All users of pycrypto’s AES module that allow the modeof operation to be specified by an attacker, check for ECB explicitly and createthe objects without specifying an IV are vulnerable to this issue. This isCVE-2013-7459.

LinuxSecurity.com: The 4.9.6 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: This is an security update fixing CVE-2017-5193, CVE-2017-5194, CVE-2017-5195,CVE-2017-5196, CVE-2017-5356.

MongoDB ransom attacks continue to plague administrators

LinuxSecurity.com: Multiple vulnerabilities have been found in HarfBuzz, the worst of which could allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for nagios is now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

security update

LinuxSecurity.com: Security Report Summary

security update

LinuxSecurity.com: Update to 6.2.4

LinuxSecurity.com: Update to Firefox 51.0.1. —- – new upstream version (51.0.1)

LinuxSecurity.com: Security fix for CVE-2016-10164

LinuxSecurity.com: This is a security update for these CVEs: *[CVE-2016-9601](https://bugzilla.redhat.com/show_bug.cgi?id=1410021) – *Heap-buffer overflow in jbig2_image_new function* This update also solves possiblelicensing issues with ghostscritpt’s source code.

LinuxSecurity.com: Update to 7.0.4

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: A null pointer dereference in libpng might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in SQUASHFS, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: An integer overflow in libXpm might allow remote attackers to execute arbitrary code or cause a Denial of Service Condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in FFmpeg, the worst of which may allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Firewalld allows firewall configurations to be modified by unauthenticated users.

LinuxSecurity.com: Multiple vulnerabilities have been found in Perl, the worst of which could allow remote attackers to execute arbitrary code.

security update

security update

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

LinuxSecurity.com: Update to the latest stable version. See https://ikiwiki.info/news/ for the listof changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.

LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for puppet-swift is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

security update

Securing MySQL DBMS

security update

LinuxSecurity.com: An update for ansible is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: – new upstream (51.0)

LinuxSecurity.com: * CVE-2016-6836: vmxnet: Information leakage in vmxnet3_complete_packet (bz#1366370) * CVE-2016-7909: pcnet: Infinite loop in pcnet_rdra_addr (bz #1381196)* CVE-2016-7994: virtio-gpu: memory leak in resource_create_2d (bz #1382667) *CVE-2016-8577: 9pfs: host memory leakage in v9fs_read (bz #1383286) *CVE-2016-8578: 9pfs: potential NULL dereferencein 9pfs routines (bz #1383292) *CVE-2016-8668: OOB buffer access in rocker switch emulation (bz #1384898) *CVE-2016-8669: […]

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

Firefox 51 delivers a mix of security, performance and reliability tweaks, implements FLAC audio sup

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

This new ransomware ‘bluff’ trick is costing victims big, even though their files are never really i

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org X Server, the worst of which may allow authenticated attackers to read from or send information to arbitrary X11 clients.

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: Security fix for console video game music emu vulnerability in the fullyoptional audacious-plugins-exotic subpackage: CVE-2016-9957, CVE-2016-9958,CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-6814

LinuxSecurity.com: Update to 0.8.0-6.git97f52c1

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

LinuxSecurity.com: This update fixes a security problem with the EDE package.

Why Linux Installers Need to Add Security Features
Keeping Linux devices secure with rigorous long-term maintenance
Linux Is Part of the IoT Security Problem, Dev Tells Linux Conference

LinuxSecurity.com: An update for mysql is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in WebP, the worst of which could allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in LibRaw, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ADOdb, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ICU, the worst of which could cause a Denial of Service condition.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: ## Version 2.2.4 – 2017-01-18 ### Security – gdImageCreate() doesn’t check foroversized images and as such is prone to DoS vulnerabilities. (CVE-2016-9317)- double-free in gdImageWebPtr() (CVE-2016-6912) – potential unsigned underflowin gd_interpolation.c – DOS vulnerability in gdImageCreateFromGd2Ctx() ###Fixed – Fix #354: Signed Integer Overflow gd_io.c – Fix #340: System frozen -Fix OOB reads of the […]

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update addresses the following vulnerabilities: *[CVE-2016-7656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7656),[CVE-2016-7635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7635),[CVE-2016-7654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7654),[CVE-2016-7639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7639),[CVE-2016-7645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7645),[CVE-2016-7652](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7652),[CVE-2016-7641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7641),[CVE-2016-7632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7632),[CVE-2016-7599](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7599),[CVE-2016-7592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7592),[CVE-2016-7589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7589),[CVE-2016-7623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7623),[CVE-2016-7586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7586)Additional fixes: * Create GLX OpenGL contexts using version 3.2 (core profile)when available to reduce the memory consumption on Mesa based drivers. * Improvememory pressure handler to reduce the CPU usage on memory pressure situations. *Fix a regression in WebKitWebView title notify signal emission that caused thesignal to […]