Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Several security issues were fixed in OpenJDK 7.

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for tcmu-runner is now available for Red Hat Gluster Storage 3.3.1 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: CVE-2017-15369 CVE-2017-15587 CVE-2017-9216 CVE-2017-14685 CVE-2017-14686 CVE-2017-14687

LinuxSecurity.com: Harden the Slurm build and allows it to operate in full relro with GOT sections of the ELF binaries marked read-only.

LinuxSecurity.com: Security fix for CVE-2017-12629

security update

LinuxSecurity.com: rebase to version 1.2.2, solves CVE-2017-16227, solves error produced by install script

LinuxSecurity.com: An update for apr is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for procmail is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat OpenShift Container Platform 3.7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Berkeley DB could be made to expose sensitive information.

LinuxSecurity.com: Berkeley DB could be made to expose sensitive information.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to crash or run programs as an administrator.

LinuxSecurity.com: Samba could be made to expose sensitive information over the network.

LinuxSecurity.com: formail could be made to crash or run programs if it processed specially crafted mail.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6 and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact

LinuxSecurity.com: An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now available. now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is An update that solves 33 vulnerabilities and has 7 fixes is now available. now available.

security update

security update

LinuxSecurity.com: An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three An update that solves two vulnerabilities and has three fixes is now available. fixes is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes An update that solves two vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

LinuxSecurity.com: Two vulnerabilities were discovered in the Open Ticket Request System which could result in disclosure of database credentials or the execution of arbitrary shell commands by logged-in agents.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

security update

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: **Update** – Fixed chain-build – Remove hard dependency of bash-completion from fedpkg **rpkg** – Ignore TestModulesCli if openidc-client is unavailable (cqi) – Port mbs-build to rpkg (mprahl) – Add .vscode to .gitignore (mprahl) – Fix TestPatch.test_rediff in order to run with old version of mock (cqi) – Allow to specify alternative Copr config file […]

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: update to 9.5.10, per release notes http://www.postgresql.org/docs/9.5/static/release-9-5-10.html

LinuxSecurity.com: Tobias Schneider discovered that libspring-ldap-java, a Java library for Spring-based applications using the Lightweight Directory Access Protocol, would under some circumstances allow authentication with a correct username but an arbitrary password.

LinuxSecurity.com: update to 9.6.6 per release notes: https://www.postgresql.org/docs/9.6/static/release-9-6-6.html

LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.

security update

security update

LinuxSecurity.com: Fixes a command injection vulnerability (CVE-2008-7319)

LinuxSecurity.com: Change default COPR URL route from http://copr.fedoraproject.org to https://copr.fedorainfracloud.org

Linus Torvalds: ‘I don’t trust security people to do sane things’
White House Releases New Charter for Using, Disclosing Security Vulnerabilities
Captain Crunch aka John Draper banned from DefCon for sexual misconduct

LinuxSecurity.com: New libtiff packages are available for Slackware 14.2 and -current to fix security issues.

security update

LinuxSecurity.com: A security update for .NET Core on RHEL is now available. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: A use-after-free vulnerability was discovered in XML::LibXML, a Perl interface to the libxml2 library, allowing an attacker to execute arbitrary code by controlling the arguments to a replaceChild() call.

LinuxSecurity.com: Jakub Wilk reported a heap-based buffer overflow vulnerability in procmail’s formail utility when processing specially-crafted email headers. A remote attacker could use this flaw to cause formail to crash, resulting in a denial of service or data loss.

security update

security update

security update

security update

security update

LinuxSecurity.com: New libplist packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.

LinuxSecurity.com: Rod Widdowson of Steading System Software LLP discovered a coding error in the OpenSAML library, causing the DynamicMetadataProvider class to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform.

LinuxSecurity.com: Rod Widdowson of Steading System Software LLP discovered a coding error in the “Dynamic” metadata plugin of the Shibboleth Service Provider, causing the plugin to fail configuring itself with the filters provided and omitting whatever checks they are intended to perform.

security update

security update

Security is from Mars, Developers are from Venus……or ARE they?

LinuxSecurity.com: It was discovered that jackson-databind, a Java library used to parse JSON and other data formats, improperly validated user input prior to deserializing: following DSA-4004-1 for CVE-2017-7525, an additional set of classes was identified as unsafe for deserialization.

YASAT – A Simple Security Auditing Tool
After a year of intensely investigating password theft, here’s what Google found
Homeland Security team remotely hacked a Boeing 757

LinuxSecurity.com: An update for openstack-aodh is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

LinuxSecurity.com: Update to 6.20170925 * https://hackage.haskell.org/package/git- annex-6.20170925/changelog Security fix for CVE-2017-12976.

LinuxSecurity.com: ‘shamger’ and Carlo Cannas discovered that a programming error in Varnish, a state of the art, high-performance web accelerator, may result in disclosure of memory contents or denial of service.

10 best Linux distros for privacy fiends and security buffs in 2017

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for php is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for jboss-ec2-eap is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 6.4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

security update

Linux 4.14 arrives and Linus says it should have fewer 0-days

LinuxSecurity.com: An update for rh-eclipse46-jackson-databind is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for rh-eclipse47-jackson-databind is now available for Red Hat Developer Tools. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Multiple vulnerabilities have been found in eGroupWare, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability was discovered in VDE which may allow local users to gain root privileges.

security update

LinuxSecurity.com: An update that fixes 19 vulnerabilities is now available. An update that fixes 19 vulnerabilities is now available. An update that fixes 19 vulnerabilities is now available.

LinuxSecurity.com: This update includes a rebase from 8.0.46 up to 8.0.47 which resolves a single CVE along with various other bugs/features: rhbz#1497682 CVE-2017-12617 tomcat: Remote Code Execution bypass for CVE-2017-12615