Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New expat packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Samba, the worst of which may allow execution of arbitrary code with root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xerces-C++, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in Tor, the worst of which could allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow bypassing of sandbox protection.

security update

security update

security update

security update

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

LinuxSecurity.com: gdk-pixbuf 2.36.2 release. * Remove the pixdata loader (#776004) * Fixinteger overflows in the jpeg loader (#775218) * Add an external thumbnailerfor images * Fix a NULL pointer dereference (#776026) * Fix a memory leak(#776020) * Support bmp headers with bitmask (#766890) * Add tests for scaling(#80925) * Handle compressed pixdata in resources (#776105) […]

LinuxSecurity.com: Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815, CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747)qemu: Divide by zero vulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921,CVE-2016-9922] Qemu: 9pfs: memory leakage via proxy/handle callbacks (#1402278)qemu ioport array overflow [XSA-199, CVE-2016-9637]

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

Hackers Suspected of Causing Second Power Outage in Ukraine

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

security update

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: The system could be made to expose sensitive information.

Home routers under attack in ongoing malvertisement blitz
Op-ed: Why I’m not giving up on PGP

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for vim is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Several security issues were fixed in Samba.

Box won’t say if it’s giving your secrets to the government
Turkey reportedly blocks Tor network nationwide
Financial Data Worth Millions Unwittingly Exposed In Ameriprise Accounts
7 Linux predictions for 2017

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

LinuxSecurity.com: Rebase to upstream 4.4.3: http://www.freeipa.org/page/Releases/4.4.3 —- -Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack against kerberized servicesby abusing password policy

LinuxSecurity.com: Security fix for CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960,CVE-2016-9961

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815,

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for BZ#1401985

LinuxSecurity.com: This release fixes CVE-2016-1249 (out-of-bound read when using server-sideprepared statements) and CVE-2016-1251 vulnerability (a use after free whenusing prepared statements).

LinuxSecurity.com: Security fix for CVE-2016-9844

LinuxSecurity.com: The 4.8.14 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: – Security fix for CVE-2016-8670 – Security fix for CVE-2016-6911 – Security fixfor CVE-2016-7568 – For Fedora 26 disabled two tests – they are failing becauseof freetype 2.7 (https://github.com/libgd/libgd/issues/302,https://github.com/libgd/libgd/issues/217)

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-9844

LinuxSecurity.com: Security Report Summary

security update

LinuxSecurity.com: ARM guests may induce host asynchronous abort [XSA-201, CVE-2016-9815,CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747) qemu: Divide by zerovulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921, CVE-2016-9922] Qemu:9pfs: memory leakage via proxy/handle callbacks (#1402278) qemu ioport arrayoverflow [XSA-199, CVE-2016-9637]

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

security update

security update

security update

0-days hitting Fedora and Ubuntu open desktops to a world of hurt
The Coolest Hacks Of 2016
9 lessons from 25 years of Linux kernel development
Trump, tech leaders avoided encryption and surveillance talk at summit

LinuxSecurity.com: Security Report Summary

security update

LinuxSecurity.com: Update to Chromium 55. Security fix for CVE-2016-5199, CVE-2016-5200,CVE-2016-5201, CVE-2016-5202, CVE-2016-9651, CVE-2016-5208, CVE-2016-5207,CVE-2016-5206, CVE-2016-5205, CVE-2016-5204, CVE-2016-5209, CVE-2016-5203,CVE-2016-5210, CVE-2016-5212, CVE-2016-5211, CVE-2016-5213, CVE-2016-5214,CVE-2016-5216, CVE-2016-5215, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219,CVE-2016-5221, CVE-2016-5220, CVE-2016-5222, CVE-2016-9650, CVE-2016-5223,CVE-2016-5226, CVE-2016-5225, CVE-2016-5224, CVE-2016-9652

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

LinuxSecurity.com: * Security fix for CVE-2016-9888

LinuxSecurity.com: Disable insecure FLX plugin (rhbz#1397441)

LinuxSecurity.com: vmncdec: Sanity-check width/height before using it —- Remove insecure nsfplugin (#1395126)

security update

LinuxSecurity.com: – update to the new upstream version (50.1.0) – fixed X Window crashes(mozbz#1271100)

LinuxSecurity.com: Update to Chromium 55. Security fix for CVE-2016-5199, CVE-2016-5200,CVE-2016-5201, CVE-2016-5202, CVE-2016-9651, CVE-2016-5208, CVE-2016-5207,CVE-2016-5206, CVE-2016-5205, CVE-2016-5204, CVE-2016-5209, CVE-2016-5203,CVE-2016-5210, CVE-2016-5212, CVE-2016-5211, CVE-2016-5213, CVE-2016-5214,CVE-2016-5216, CVE-2016-5215, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219,CVE-2016-5221, CVE-2016-5220, CVE-2016-5222, CVE-2016-9650, CVE-2016-5223,CVE-2016-5226, CVE-2016-5225, CVE-2016-5224, CVE-2016-9652

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

LinuxSecurity.com: Apport could be made to run programs as your login if it opened aspecially crafted file.

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Update LXC to the latest stable version. See[here](https://linuxcontainers.org/lxc/news/) for the list of changes.

LinuxSecurity.com: **Version 1.2.3** – Searching in both contacts and groups when LDAP addressbookwith group_filters option is used – Fix vulnerability in handling of mail()’s5th argument – Fix To: header encoding in mail sent with mail() method (#5475) -Fix flickering of header topline in min-mode (#5426) – Fix bug where folderslist would scroll to top when […]

LinuxSecurity.com: Update LXC to the latest stable version. See[here](https://linuxcontainers.org/lxc/news/) for the list of changes.

security update

security update

LinuxSecurity.com: This updates includes a rebase from tomcat 8.0.38 up to 8.0.39 which resolvesmultiple CVEs: * #1397493 – CVE-2016-6816 CVE-2016-6817 CVE-2016-8735 tomcat:various flaws