Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update for wpa_supplicant is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update for rh-sso7-keycloak is now available for Red Hat Single Sign-On 7.1 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: An update for rh-sso7-keycloak is now available for Red Hat Single Sign-On 7.1 for RHEL 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Red Hat Single Sign-On 7.1.3 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: More info: https://koji.fedoraproject.org/koji/buildinfo?buildID=982578

Severe flaw in WPA2 protocol leaves Wi-Fi traffic open to eavesdropping
Linux vulnerable to privilege escalation

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which

LinuxSecurity.com: Fix the for the Key Reinstallation Attacks in FT handshake (CVE-2017-13082) – Fix PTK rekeying to generate a new ANonce – Prevent reinstallation of an already in-use group key and extend protection of GTK/IGTK reinstallation of WNM-Sleep Mode cases (CVE-2017-13078,

LinuxSecurity.com: New upstream version

LinuxSecurity.com: xserver 1.19.5 —- Update to xserver 1.19.4, multiple stability fixes.

LinuxSecurity.com: Fix the for the Key Reinstallation Attacks in FT handshake (CVE-2017-13082) – Fix PTK rekeying to generate a new ANonce – Prevent reinstallation of an already in-use group key and extend protection of GTK/IGTK reinstallation of WNM-Sleep Mode cases (CVE-2017-13078,

LinuxSecurity.com: This is security update fixing possible buffer overflow in loadbuf function.

LinuxSecurity.com: Security fix for CVE-2017-13720 and CVE-2017-13722

LinuxSecurity.com: 6.9.9-19

LinuxSecurity.com: 6.9.9-19

LinuxSecurity.com: Update to 1.4.15. Fixes CVE-2017-8911

LinuxSecurity.com: Update to Open vSwitch 2.8.1 Includes security fix for CVE-2017-14970

LinuxSecurity.com: New upstream version

LinuxSecurity.com: Mathy Vanhoef of the imec-DistriNet research group of KU Leuven discovered multiple vulnerabilities in the WPA protocol, used for authentication in wireless networks. Those vulnerabilities applies to both the access point (implemented in hostapd) and the station (implemented in wpa_supplicant).

security update

LinuxSecurity.com: Fix CVE-2017-2887

LinuxSecurity.com: A vulnerability found in Shadow may allow remote attackers to cause a Denial of Service condition or produce other unspecified behaviors.

LinuxSecurity.com: A null pointer dereference in GnuTLS might allow attackers to cause a Denial of Service condition.

LinuxSecurity.com: 3.94 and patch for CVE-2017-15056

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: update to upstream release 0.3.1.7 —- update to upstream release 0.2.9.12 (SECURITY) (#1494860)

LinuxSecurity.com: Security fix for buffer overflow due to long input filenames [see Bug 1422550 and 1422545]

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

What is a firewall?
500 million PCs are being used for stealth cryptocurrency mining online

LinuxSecurity.com: Multiple vulnerabilities have been found in WebkitGTK+, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Graphite, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Puppet Agent, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GNU Libtasn1, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in elfutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

LinuxSecurity.com: Security fix for buffer overflow due to long input filenames [see Bug 1422550 and 1422545]

LinuxSecurity.com: An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update is now available for Red Hat JBoss BRMS. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

security update

LinuxSecurity.com: An update for httpd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

LinuxSecurity.com: Security fix for CVE-2017-1495

10 layers of Linux container security
Apache Patches Optionsbleed Flaw in HTTP Server
Secure Messaging with Onion Services, a How-To

LinuxSecurity.com: An update for rh-mysql57-mysql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: These releases are about hardening `git shell` that is used on servers against an unsafe user input, which `git cvsserver` copes with poorly. From the release notes: * “git cvsserver” no longer is invoked by “git shell” by default, as it is old and largely unmaintained. * Various Perl scripts did not use safe_pipe_capture() […]

security update

security update

LinuxSecurity.com: Martin Thomson discovered that nss, the Mozilla Network Security Service library, is prone to a use-after-free vulnerability in the TLS 1.2 implementation when handshake hashes are generated. A remote attacker can take advantage of this flaw to cause an application using the nss

LinuxSecurity.com: Several vulnerabilities were discovered in WordPress, a web blogging tool. They would allow remote attackers to exploit path-traversal issues, perform SQL injections and various cross-site scripting attacks.

LinuxSecurity.com: An update that fixes 47 vulnerabilities is now available. An update that fixes 47 vulnerabilities is now available. An update that fixes 47 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 143 vulnerabilities is now available. An update that fixes 143 vulnerabilities is now available. An update that fixes 143 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 140 vulnerabilities is now available. An update that fixes 140 vulnerabilities is now available. An update that fixes 140 vulnerabilities is now available.

LinuxSecurity.com: 6.9.9-15 —- Rebuilt for ImageMagick 6.9.9-13

LinuxSecurity.com: 6.9.9-15 —- Rebuilt for ImageMagick 6.9.9-13

LinuxSecurity.com: update to upstream release 0.2.9.12 (SECURITY) (#1494860)

LinuxSecurity.com: 6.9.9-15 —- Rebuilt for ImageMagick 6.9.9-13

Accenture left a huge trove of highly sensitive data on exposed servers

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

SELinux blocks loading kernel modules

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in PCRE2, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Pacemaker, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A vulnerability in OCaml may allow local users to gain root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in privilege escalation.

LinuxSecurity.com: A vulnerability in Munin allows local attackers to overwrite any file accessible to the www-data user.

LinuxSecurity.com: A vulnerability in sudo allows local users to gain root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in ICU, the worst of which could allow remote code execution.

LinuxSecurity.com: A stack-based buffer overflow was found in file, possibly resulting in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in RubyGems, the worst of which allows execution of arbitrary code.

LinuxSecurity.com: Christian Boxd?rfer discovered a vulnerability in the handling of FreeDesktop.org .desktop files in Nautilus, a file manager for the GNOME desktop environment. An attacker can craft a .desktop file intended to run malicious commands but displayed as a innocuous document file in Nautilus. An

LinuxSecurity.com: Security fix for CVE-2017-6419 and CVE-2017-11423

security update

security update

LinuxSecurity.com: CVE-2017-14491 CVE-2017-14492 CVE-2017-14493 CVE-2017-14494 CVE-2017-14495 CVE-2017-14496

LinuxSecurity.com: It was discovered that the Tor onion service could leak sensitive information to log files if the “SafeLogging” option is set to “0”. The oldstable distribution (jessie) is not affected.

LinuxSecurity.com: Several vulnerabilities have been discovered in cURL, an URL transfer library. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: Security fix for CVE-2017-12150 CVE-2017-12151 CVE-2017-12163

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 14.04 LTS Summary: Several security issues were fixed in Ruby. Software Description: – ruby1.9.1: Object-oriented scripting language Details: It was discovered that Ruby incorrectly handled certain inputs. [More…]

LinuxSecurity.com: A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 12.04 ESM Summary: Several security issues were fixed in Dnsmasq. Software Description: – dnsmasq: Small caching DNS proxy and DHCP/TFTP server Details: USN-3430-1 fixed several vulnerabilities in Dnsmasq. This update [More…]

LinuxSecurity.com: A security issue affects these releases of Ubuntu and its derivatives: – Ubuntu 17.04 – Ubuntu 16.04 LTS – Ubuntu 14.04 LTS Summary: poppler could be made to crash if opened a specially crafted file. Software Description: – poppler: PDF rendering library Details: It was discovered that Poppler incorrectly handled certain files. [More…]

security update

security update

security update

security update

security update

security update

Blockchain skills: Don’t Try to Block the Chain
Black Hat Europe 2017: New Briefings Announced

LinuxSecurity.com: **nag 4.2.17** * [jan] SECURITY: Fix unauthorized access to task exports. * [jan] Fix regression when exporting single tags to iCalendar CATEGORIES. * [jan] Officially support PHP 7.

LinuxSecurity.com: **passwd 5.0.7** * [jan] Officially support PHP 7. * [jan] SECURITY: Fix open redirects.

LinuxSecurity.com: **wicked 2.0.8** * [jan] SECURITY: Fix unauthorized access to page attachments.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.