Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

?Dios m?o! Spain blocks DNS to silence Catalan independence vote sites

LinuxSecurity.com: New gegl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

security update

security update

LinuxSecurity.com: This release fixes a crash when parsing an empty code string of a codewscope type.

LinuxSecurity.com: Multiple vulnerabilities have been found in RAR and UnRAR, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Libplist could be made to crash if it opened a specially crafted file.

LinuxSecurity.com: The 4.13.3 stable update contains a number of important fixes across the tree.

1.4 Million New Phishing Sites Launched Each Month
Beyond public key encryption

LinuxSecurity.com: A vulnerability in libsoup might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available. An update that fixes 15 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Tcpdump, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: This update fixes CVE-2017-14348. —- This update fixes CVE-2017-13735.

LinuxSecurity.com: Fix for possible buffer overrun in kodak_65000 decoder Fix for possible heap overrun in Canon makernotes parser Fix for CVE-2017-13735 CVE-2017-14265: Additional check for X-Trans CFA pattern data —- Patch for CVE-2017-14348

LinuxSecurity.com: Upgrade to 1.5.3 and also note that 1.5.1 fixed CVE-2017-11424.

LinuxSecurity.com: # Security fixes – fix crash in edge case where a .pc file has misquoting in a fragment list. # Other bug fixes: – fix logic edge case when comparing relocated paths

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites, and IcedTea, the worst of which may allow execution of arbitrary code. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Mercurial, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Postfix may allow local users to gain root privileges.

LinuxSecurity.com: A vulnerability in Exim may allow local users to gain root privileges.

LinuxSecurity.com: A command injection vulnerability in CVS may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Chromium, the worst of which could result in the execution of arbitrary code.

security update

The Pirate Bay Takes Heat for Testing Monero Mining
Joomla patches eight-year-old critical CMS bug

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: New libxml2 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: Update to upstream release 1.25.6

LinuxSecurity.com: * [7.x-3.18](https://www.drupal.org/project/views/releases/7.x-3.18) * [7.x-3.17](https://www.drupal.org/project/views/releases/7.x-3.17) * [Moderately Critical – Access Bypass – DRUPAL-SA- CONTRIB-2017-068](https://www.drupal.org/node/2902604)

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

LinuxSecurity.com: – Related: CVE-2017-6362 remove problematic function

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Equifax’s disastrous Struts patching blunder: THOUSANDS of other orgs did it too
Cloud Security Error Exposes Half a Million Voters’ Personal Information

LinuxSecurity.com: An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two An update that solves four vulnerabilities and has two fixes is now available. fixes is now available.

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

LinuxSecurity.com: Update to upstream release 1.25.6

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

The laws that are ruining the Internet
Pirate Bay digs itself a new hole: Mining alt-coin in slurper browsers
5 Ways to Secure Wi-Fi Networks

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

security update

security update

security update

LinuxSecurity.com: new upstream release —- * heap overflow in libwpd

LinuxSecurity.com: Rebase to the latest upstream version 2.0.14. This update contains security fix for CVS -2017-1000050.

LinuxSecurity.com: Update to version 1.3.0, see https://nih.at/libzip/NEWS.html for details. —- This update backports security fix for CVE-2017-14107.

LinuxSecurity.com: Security fix for CVE-2017-13735

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

LinuxSecurity.com: Many security fixes, bug fixes, and other changes from the previous version 6.9.3.0. See the [6.9 branch ChangeLog](https://github.com/ImageMagick/ImageMagi ck/blob/3fd358e2ac34977fda38a2cf4d88a1cb4dd2d7c7/ChangeLog). Dependent packages are mostly straight rebuilds, a couple also include bugfix version updates.

APNIC-sponsored proposal could vastly improve DNS resilience against DDoS
The Pirate Bay hijacked users’ CPU power to secretly mine cryptocurrency Monero

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which may allow attackers to bypass intended restrictions.

LinuxSecurity.com: A vulnerability in SquirrelMail might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in module File::Path for Perl allows local attackers to set arbitrary mode values on arbitrary files bypassing security restrictions. [More…]

LinuxSecurity.com: Gentoo’s GIMPS ebuilds are vulnerable to privilege escalation due to improper permissions. A local attacker could use it to gain root privileges. [More…]

LinuxSecurity.com: A command injection vulnerability in Git may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A command injection vulnerability in Subversion may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: GDK-PixBuf could be made to crash or run programs as your login if it opened a specially crafted file.

security update

LinuxSecurity.com: Multiple vulnerabilities have been found in GDK-PixBuf, the worst of which could result in the execution of arbitrary code.

LinuxSecurity.com: A vulnerability in Kpathsea allows remote attackers to execute arbitrary commands by manipulating the -tex option from mpost program.

LinuxSecurity.com: A vulnerability in Supervisor might allow remote attackers to execute arbitrary code. [More…]

LinuxSecurity.com: A vulnerability in chkrootkit may allow local users to gain root privileges.

LinuxSecurity.com: A vulnerability in mod_gnutls allows remote attackers to spoof clients via crafted certificates.

LinuxSecurity.com: Multiple vulnerabilities have been found in WebkitGTK+, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Binutils, the worst of which may allow remote attackers to cause a Denial of Service condition. [More…]

security update

security update

Linux 4.13 Kernel Launches With Accelerated Security Feature
Linus Torvalds Wants Attackers to Join Linux Kernel Development
$1M bounty offered for zero-day exploits targeting Tor Browser
Open Source Summit: Securing IoT is About Avoiding Anti-Patterns
How network automation can speed deployments and improve security
Next US Elections: Open Source vs. Commercial Software?
Windows 10’s Subsystem for Linux: Here’s how hackers could use it to hide malware
Startup That Sells Zero-Days to Governments Is Offering $1 Million For Tor Hacks

LinuxSecurity.com: Several security issues were fixed in tcpdump

LinuxSecurity.com: Several security issues were fixed in tcpdump.

security update