Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Multiple vulnerabilities have been found in zlib, the worst of which could allow attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in DirectFB, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in DCRaw might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in Lua might allow context-dependent attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libupnp, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in DBD::mysql, the worst of which might allow an attacker to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in PPP might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could cause a Denial of Service condition.

LinuxSecurity.com: check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386)

security update

security update

security update

Protesters Called To Join Inauguration Day DDoS Attack
Rsync errors lead to data breach at Canadian ISP, KWIC Internet
Encrypted email service ProtonMail opens door for Tor users

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in NSS, the worst of which could allow remote attackers to obtain access to private key information.

LinuxSecurity.com: Multiple vulnerabilities have been found in irssi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A heap-based buffer overflow in CVS might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea allowing remote attackers to affect confidentiality, integrity, and availability through various vectors.

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Updated openstack-cinder packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…]

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

How to Keep Hackers out of Your Linux Machine Part 1: Top Two Security Tips
Google Infrastructure Security Design Overview

security update

LinuxSecurity.com: **Version 5.2.22** (January 5th 2017) * **SECURITY** Fix[CVE-2017-5223](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5223),local file disclosure vulnerability if content passed to `msgHTML()` is sourcedfrom unfiltered user input. Reported by Yongxiang Li of Asiasecurity. The fixfor this means that calls to `msgHTML()` without a `$basedir` will not importimages with relative URLs, and relative URLs containing `..` will be ignored. *Add simple […]

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: Security fix for CVE-2016-9888

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

Understanding The Basics Of Two-Factor Authentication
Advances in SSL: 5 Strategies For Secure, High-Performance Load Balancers

LinuxSecurity.com: An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for docker-latest is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: NVIDIA graphics drivers could be made to crash under certain conditions.

LinuxSecurity.com: Multiple vulnerabilities have been found in libxml2, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: This update avoids a malicious repository writing to files outside the localstorage root.

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for bind97 is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in file, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in MiniUPnPc might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in xdelta might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in VLC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Pidgin, the worst of which could lead to execution of arbitrary code.

Free IoT Vulnerability Scanner Hunts Enterprise Threats
The CSO guide to top security conferences

security update

security update

security update

Just in Time for Trump, the NSA Loosens Its Privacy Rules
First came mass MongoDB ransacking: Now copycat ransoms hit Elasticsearch
Guccifer 2.0, alleged Russian cyberspy, returns to deride U.S.
Suspected NSA tool hackers dump more cyberweapons in farewell

security update

security update

LinuxSecurity.com: A vulnerability in runC could lead to privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in execution of arbitrary code or privilege escalation.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla SeaMonkey, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for java-1.6.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Update to 0.24.6

LinuxSecurity.com: New upstream release

security update

LinuxSecurity.com: Fix [CVE-2016-9962] Insecure opening of file-descriptor allows privilege FixBZ#1412148 – containerd: container did not start before the specified timeout—- use container-selinux >= 2:2.0-2

security update

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Hacker Steals 900 GB of Cellebrite Data
Exitmap – Tor Exit Relay Scanner

LinuxSecurity.com: New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8605

LinuxSecurity.com: fix CVE-2016-8741 (rhbz#1409836,1409835)

LinuxSecurity.com: update to 3.2.10.RELEASE, fix CVE-2016-9879

LinuxSecurity.com: Update to the latest upstream release 1.3.2, also with some security fixes (seebug #1193445 from the native flac package).

LinuxSecurity.com: Security fix for CVE-2016-8605

security update

Debugging a kernel in QEMU/libvirt

LinuxSecurity.com: Multiple vulnerabilities have been found in phpMyAdmin, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Flex might generate code with a buffer overflow making applications using such scanners vulnerable to the execution of arbitrary code.

LinuxSecurity.com: A vulnerability has been found in Vim and gVim concerning how certain modeline options are treated.

LinuxSecurity.com: A vulnerability in vzctl might allow attackers to gain control over ploop containers.

LinuxSecurity.com: A heap-based buffer overflow in c-ares might allow remote attackers to cause a Denial of Service condition.