Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Security Report Summary

Pythonic code review
Op-ed: I’m throwing in the towel on PGP, and I work in security
Dozens arrested in international DDoS-for-hire crackdown
Three serious Linux kernel security holes patched

LinuxSecurity.com: Multiple vulnerabilities have been found in Node.js, the worst of which can allow remote attackers to cause Denial of Service conditions.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Zabbix, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in Botan, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in SQUASHFS, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Bash could potentially lead to arbitrary code execution.

LinuxSecurity.com: A buffer overflow in Pixman might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: An integer overflow in TigerVNC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in XStream may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code.

security update

LinuxSecurity.com: Security fix for CVE-2016-6318

LinuxSecurity.com: This updates adds a patch to fix CVE-2016-9573 and CVE-2016-9572.

LinuxSecurity.com: update

LinuxSecurity.com: Multiple heap overflows in SoX may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in Docker could lead to the escalation of privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which allows local users to escalate privileges.

LinuxSecurity.com: Two vulnerabilities have been found in exFAT allowing remote attackers to execute arbitrary code or cause Denial of Service.

LinuxSecurity.com: Multiple heap overflows in SoX may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A heap-based buffer overflow vulnerability in libmms might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: update

LinuxSecurity.com: A vulnerability in Docker could lead to the escalation of privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which allows local users to escalate privileges.

security update

security update

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat OpenStack Platform 8.0 (Liberty). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat OpenStack Platform 9.0 (Mitaka). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security fix for CVE-2016-8740

LinuxSecurity.com: An update for rh-mariadb100-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for rh-mariadb101-mariadb is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact [More…]

The IoT: Gateway for enterprise hackers

security update

Where Cybercriminals Go To Buy Your Stolen Data

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenJPEG, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in CrackLib could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in Binutils, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in socat, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Coreutils could lead to the execution of arbitrary code or a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities were found in SQLite, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A buffer overflow in jq might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-7433, CVE-2016-7426, CVE-2016-7429, CVE-2016-9310,CVE-2016-9311

LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2016-8704, CVE-2016-8705,CVE-2016-8706.

LinuxSecurity.com: phpMyAdmin 4.6.5.1 (2016-11-26) =============================== A patch-levelrelease fixing two small issues: * an issue affecting a small number of usersusing $cfg[‘Servers’][$i][‘hide_db’] or $cfg[‘Servers’][$i][‘only_db’]. * anissue affecting the create table dialog where the partition selection tool wasoverzealous and made it difficult to create a new table. There are also minorimprovements to the Czech language file. phpMyAdmin […]

LinuxSecurity.com: php-gettext 1.0.12 ================== * Security fix for potential codeinjection bug (LP#1515334) * Do not assume mbstring functions are alwaysthere, pass text through if they aren’t (LP#734494)

LinuxSecurity.com: Security fix for CVE-2016-7433, CVE-2016-7426, CVE-2016-7429, CVE-2016-9310,CVE-2016-9311

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: The 4.8.11 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: Add fix for gstreamer FLIC decoder vulnerability

LinuxSecurity.com: Fix Integer overflow when allocating render buffer in vmnc decoder

LinuxSecurity.com: New upstream vesion, 1.17.27 . Security fix for CVE-2015-0860

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.5 Telco Extended Update Support, Red Hat Enterprise [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in ARJ, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mercurial, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSH, the worst of which allows remote attackers to cause Denial of Service.

LinuxSecurity.com: A buffer overflow in PECL HTTP might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in OpenSSL, the worst of which allows attackers to conduct a time based side-channel attack.

LinuxSecurity.com: New upstream version 2.50. – Fixes serious DLL hijacking attack:https://sourceforge.net/p/nsis/bugs/1125/

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Nghttp2 is vulnerable to a Denial of Service attack.

LinuxSecurity.com: Patch is vulnerable to a locally generated Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9296

LinuxSecurity.com: phpMyAdmin 4.6.5.1 (2016-11-26) =============================== A patch-levelrelease fixing two small issues: * an issue affecting a small number of usersusing $cfg[‘Servers’][$i][‘hide_db’] or $cfg[‘Servers’][$i][‘only_db’]. * anissue affecting the create table dialog where the partition selection tool wasoverzealous and made it difficult to create a new table. There are also minorimprovements to the Czech language file. phpMyAdmin […]

LinuxSecurity.com: Update to 1.10.1

LinuxSecurity.com: Add fix for gstreamer FLIC decoder vulnerability

LinuxSecurity.com: xen : various security flaws (#1397383) x86 null segments not always treated asunusable [XSA-191, CVE-2016-9386] x86 task switch to VM86 mode mis-handled[XSA-192, CVE-2016-9382] x86 segment base write emulation lacking canonicaladdress checks [XSA-193, CVE-2016-9385] guest 32-bit ELF symbol table loadleaking host data [XSA-194, CVE-2016-9384] x86 64-bit bit test instructionemulation broken [XSA-195, CVE-2016-9383] x86 software interrupt […]

LinuxSecurity.com: Libvirt is vulnerable to directory traversal when using Access Control Lists (ACL).

LinuxSecurity.com: Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in LinuxCIFS utils’ “cifscreds” PAM module might allow remote attackers to have an unspecified impact via unknown vectors.

LinuxSecurity.com: A vulnerability in DavFS2 allows local users to gain root privileges.

LinuxSecurity.com: Due to a design flaw, the output of GnuPG’s Random Number Generator (RNG) is predictable.

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

security update

2017 security predictions
Firefox zero-day: Mozilla races to patch bug used to attack Tor browser users
900,000 Deutsche Telekom Routers Disabled by Massive Cyber Attack

security update

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-9296

LinuxSecurity.com: Fix nfs_cleanup security race and permissions (rhbz#1395040).

LinuxSecurity.com: Update to 0.6.4

LinuxSecurity.com: https://www.drupal.org/SA-CORE-2016-005

LinuxSecurity.com: Fix nfs_cleanup security race and permissions (rhbz#1395040).