Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: build experimental command line interface “kresc”

Zero-Day Exploit Surfaces that May Affect Millions of IoT Users
Let’s harden Internet crypto so quantum computers can’t crack it

LinuxSecurity.com: It was discovered that ruby-mixlib-archive, a Chef Software’s library used to handle various archive formats, was vulnerable to a directory traversal attack. This allowed attackers to overwrite arbitrary files by using a malicious tar archive containing “..” in its entries.

LinuxSecurity.com: An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is now available. now available.

LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is An update that solves one vulnerability and has 6 fixes is now available. now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

security update

security update

LinuxSecurity.com: LibTIFF could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: OpenLDAP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: This is an update fixing CVE-2017-10965 and CVE-2017-10966.

IBM’s Plan To Encrypt Unthinkable Amounts of Sensitive Data
Linux Users Urged to Update as a New Threat Exploits SambaCry

LinuxSecurity.com: An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is An update that solves one vulnerability and has 8 fixes is now available. now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Several security issues were fixed in ICU.

LinuxSecurity.com: * various flaws: CVE-2017-7515 CVE-2017-9775 CVE-2017-9776 CVE-2017-9865 —- * CVE-2017-9406 CVE-2017-9408 various memory leak flaws

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function Additionally sqlite has been updated to version 3.19.3, and spatialite-tools rebuilt for the update.

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function Additionally sqlite has been updated to version 3.19.3, and spatialite-tools rebuilt for the update.

LinuxSecurity.com: The 4.11.10 update contains a number of important fixes across the tree

Unix: How random is random?
White House released voter-fraud commenters’ sensitive personal information
Want to kill your IT security team? Put the top hacker in charge

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: File /etc/sysconfig/httpd is ghosted now —- Version update —- Security fix for CVE-2017-3167 CVE-2017-3169 CVE-2017-7659 CVE-2017-7668 CVE-2017-7679

LinuxSecurity.com: This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078,

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

LinuxSecurity.com: Jeffrey Altman, Viktor Dukhovni, and Nicolas Williams reported that Heimdal, an implementation of Kerberos 5 that aims to be compatible with MIT Kerberos, trusts metadata taken from the unauthenticated plaintext (Ticket), rather than the authenticated and encrypted KDC response. A

security update

security update

security update

security update

LinuxSecurity.com: Samba could allow unintended access to network services.

LinuxSecurity.com: Heimdal could allow unintended access to network services.

LinuxSecurity.com: Clément Berthaux from Synaktiv discovered a signature forgery vulnerability in knot, an authoritative-only DNS server. This vulnerability allows an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

LinuxSecurity.com: Felix Wilhelm discovered that the Evince document viewer made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Security fix for CVE-2017-10989: Heap-buffer overflow in the getNodeSize function

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

Kerberos bypass, login theft bug slain by Microsoft, Linux slingers
Black Hat to Host Discussion on Diversity

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: New mariadb packages are available for Slackware 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

LinuxSecurity.com: updated to 2.6.1 (security bugfix release)

LinuxSecurity.com: New upstream release fixing moderate security issue CVE-2017-7526.

How Active Intrusion Detection Can Seek and Block Attacks

LinuxSecurity.com: – CVE-2017-1000083: Evince command injection vulnerability in CBT handler (#1468488)

LinuxSecurity.com: https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

LinuxSecurity.com: – Update to 1.1.12 – Fix Cross-site Scripting (XSS) issue with link.php (CVE-2017-10970) Release notes: https://www.cacti.net/release_notes.php?version=1.1.11 Release notes: https://www.cacti.net/release_notes.php?version=1.1.12

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: updated to 2.6.1 (security bugfix release)

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

security update

LinuxSecurity.com: An integer overflow has been found in the HTTP range module of Nginx, a high-performance web and reverse proxy server, which may result in information disclosure.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Evince could be made run programs as your login if it opened a specially crafted file.

What is new in OpenSSH 7.4 (in RHEL 7.4)?
Hackers able to turbo-charge DJI drones way beyond what’s legal

LinuxSecurity.com: Updated to the latest version; Security fix for CVE-2017-10788

LinuxSecurity.com: An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes An update that solves 15 vulnerabilities and has 162 fixes is now available. is now available.

security update

security update

LinuxSecurity.com: This update updates QtWebEngine to the 5.9.1 release, a security and bugfix release from the 5.9 branch. QtWebEngine 5.9.1 is part of the Qt 5.9.1 release, but only the QtWebEngine component is included in this update. The update fixes the following security issues in QtWebEngine 5.9.0: CVE-2017-5070, CVE-2017-5071, CVE-2017-5075, CVE-2017-5076, CVE-2017-5077, CVE-2017-5078,

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

Linux Foundation launches Open Security Controller Project

LinuxSecurity.com: https://github.com/libexpat/libexpat/blob/R_2_2_1/expat/Changes

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017

Desperately Seeking Security: 6 Skills Most In Demand

security update

LinuxSecurity.com: New libtirpc packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: New rpcbind packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: Multiple vulnerabilities have been found in libcroco, the worst of which may have unspecified impacts.

LinuxSecurity.com: Two security issues have been discovered in the X.org X server, which may lead to privilege escalation or an information leak. For the oldstable distribution (jessie), these problems have been fixed

LinuxSecurity.com: A vulnerability in MAN DB allows local users to gain root privileges.

security update

LinuxSecurity.com: A vulnerability in Gajim might allow remote attackers to intercept encrypted communications.

LinuxSecurity.com: New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: update

LinuxSecurity.com: A vulnerability in RoundCube may allow authenticated users to bypass security restrictions.

LinuxSecurity.com: Multiple vulnerabilities have been found in VLC, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: Update to new ISC supported version 9.9.10.

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: update

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: Update to latest upstream release in order to fix CVE-2017-9735

LinuxSecurity.com: This is new version with security fixes for CVE-2017-9468, CVE-2017-9469.

LinuxSecurity.com: New stable upstream release, primarily includes security fixes for CVE-2017-10794, CVE-2017-10799, CVE-2017-10800 See also http://www.graphicsmagick.org/NEWS.html#july-4-2017