Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed GIF, TTF, SVG, TIFF, PCX, JPG or SFW files

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Cacti, the worst of which could lead to the remote execution of arbitrary code.

26,000 blockchain projects launched in 2016, 92 percent are now dead
Researchers find almost EVERY computer with an Intel Skylake and above CPU can be owned via USB
Vault 8: WikiLeaks Releases Source Code For Hive – CIA’s Malware Control System

LinuxSecurity.com: * Fix ppc64 KVM failure (bz #1501936) * CVE-2017-15038: 9p: information disclosure when reading extended attributes (bz #1499111) * CVE-2017-15268: potential memory exhaustion via websock connection to VNC (bz #1496882) —- qemu-pr-helper didn’t work due to a change in the libmultipath/libmpathpersist APIs exposed by device-mapper-multipath-devel. This has been fixed now. Other

LinuxSecurity.com: 1.6, multiple security fixes.

LinuxSecurity.com: – Update to 1.1.26 – CVE-2017-15194 Release notes: https://www.cacti.net/release_notes.php?version=1.1.26

LinuxSecurity.com: Security fix for CVE-2017-12629

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/52.4.0/releasenotes/

security update

security update

security update

security update

LinuxSecurity.com: Wen Bin discovered that bchunk, an application that converts a CD image in bin/cue format into a set of iso and cdr/wav tracks files, did not properly check its input. This would allow malicious users to crash the application or potentially execute arbitrary code.

What to consider when deploying a next-generation firewall

LinuxSecurity.com: An update that solves 29 vulnerabilities and has two fixes An update that solves 29 vulnerabilities and has two fixes An update that solves 29 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has 6 fixes is An update that solves 23 vulnerabilities and has 6 fixes is An update that solves 23 vulnerabilities and has 6 fixes is now available. now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in libxml2, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: It was discovered that the pg_ctlcluster, pg_createcluster and pg_upgradecluster commands handled symbolic links insecurely which could result in local denial of service by overwriting arbitrary files.

LinuxSecurity.com: Several vulnerabilities have been found in the PostgreSQL database system: CVE-2017-15098

LinuxSecurity.com: A vulnerabilitiy has been found in the PostgreSQL database system: Denial of service and potential memory disclosure in the json_populate_recordset() and jsonb_populate_recordset() functions.

security update

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

security update

LinuxSecurity.com: Update to ansible 2.4.1.0 with various bugfixes. See https://github.com/ansible/ansible/blob/stable-2.4/CHANGELOG.md for a full list of changes.

LinuxSecurity.com: Update to ansible 2.4.1.0 with various bugfixes. See https://github.com/ansible/ansible/blob/stable-2.4/CHANGELOG.md for a full list of changes.

LinuxSecurity.com: It was discovered that libpam4j, a Java library wrapper for the integration of PAM did not call pam_acct_mgmt() during authentication. As such a user who has a valid password, but a deactivated or disabled account could still log in.

LinuxSecurity.com: Marcin Noga discovered two vulnerabilities in LibreOffice, which could result in the execution of arbitrary code if a malformed PPT or DOC document is opened.

security update

security update

Tor patches flaw that could expose MacOS and Linux IP addresses

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium browser. CVE-2017-15398

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 33 vulnerabilities and has two fixes An update that solves 33 vulnerabilities and has two fixes An update that solves 33 vulnerabilities and has two fixes is now available. is now available.

security update

security update

Hackers Poison Google Search Results to Deliver Zeus Panda
A draft US law to secure election computers that isn’t braindead. Well, I’m stunned! I gotta lie dow

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 12 vulnerabilities and has four fixes An update that solves 12 vulnerabilities and has four fixes An update that solves 12 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. In addition, this message serves as an annoucment that security support for chromium in the oldstable release (jessie), Debian 8, is now discontinued.

security update

LinuxSecurity.com: This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed.

security update

security update

WAFNinja – Web Application Firewall Attack Tool – WAF Bypass
Unencrypted USB stick with 2.5GB of data detailing airport security found in street

security update

LinuxSecurity.com: Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. The Common Vulnerabilities and Exposures project identifies the following issues:

LinuxSecurity.com: Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. The Common Vulnerabilities and Exposures project identifies the following issues:

security update

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update for liblouis is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update for samba is now available for Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

If your websites use WordPress, put down that coffee and upgrade to 4.8.3.
Hackers abusing digital certs smuggle malware past security scanners
Official list of hacker and cyber crime movies
Introducing GoCrack: A Managed Password Cracking Tool

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes An update that solves 8 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in impersonation of Kerberos services, denial of service, sandbox bypass or HTTP header injection.

security update

LinuxSecurity.com: An update is now available for Red Hat JBoss Fuse and Red Hat JBoss A-MQ. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Web Server 2.1.2 for RHEL 6 and Red Hat JBoss Enterprise Web Server 2.1.2 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Web Server 2.1.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes An update that solves one vulnerability and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 36 vulnerabilities and has 22 fixes An update that solves 36 vulnerabilities and has 22 fixes An update that solves 36 vulnerabilities and has 22 fixes is now available. is now available.

LinuxSecurity.com: updated to aarch64-jdk8u151-b12 (from aarch64-port/jdk8u)

LinuxSecurity.com: 3.10.6 bz #1504256

LinuxSecurity.com: Security fix for CVE-2017-12629

LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (jessie), these problems have been fixed

security update

USB stick found in West London contained Heathrow security data
Fine, OK, no backdoors, says Deputy AG. Just keep PLAINTEXT copies of everyone’s messages

security update

LinuxSecurity.com: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

SSHGuard 2.1 Released

LinuxSecurity.com: This is the final notification for the End Of Life (EOL) of Red Hat ‘Stand-Alone’ Proxy. Red Hat Proxy ‘Stand-Alone’ (Proxy server directly connecting to the Red Hat Network): Systems registered as clients to RHN via a Red Hat Satellite

Mozilla devs discuss ditching Dutch CA, because cryptowars

LinuxSecurity.com: Several security issues have been corrected in multiple demuxers and decoders of the libav multimedia library. A full list of the changes is available at https://git.libav.org/?p=libav.git;a=blob;f=Changelog;hb=refs/tags/v11.11

security update

security update

LinuxSecurity.com: It was discovered that the bgpd daemon in the Quagga routing suite does not properly calculate the length of multi-segment AS_PATH UPDATE messages, causing bgpd to drop a session and potentially resulting in loss of network connectivity.

LinuxSecurity.com: An update that solves 30 vulnerabilities and has 38 fixes An update that solves 30 vulnerabilities and has 38 fixes An update that solves 30 vulnerabilities and has 38 fixes is now available. is now available.

LinuxSecurity.com: A vulnerability in Jython may lead to arbitrary code execution.

LinuxSecurity.com: It was discovered that git-annex, a tool to manage files with git without checking their contents in, did not correctly handle maliciously constructed ssh:// URLs. This allowed an attacker to run an arbitrary shell command.

LinuxSecurity.com: An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for tomcat6 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in Apache, the worst of which may result in the loss of secrets.

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JDK and JRE software suites, the worst of which can be remotely exploited without authentication. [More…]

LinuxSecurity.com: Niklas Abel discovered that insufficient input sanitising in the the ss-manager component of shadowsocks-libev, a lightweight socks5 proxy, could result in arbitrary shell command execution.

LinuxSecurity.com: An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 An update that solves three vulnerabilities and has 32 fixes is now available. fixes is now available.

security update

security update