Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

LinuxSecurity.com: Update to annulen-branch of qt5-qtwebkit, which contains a lot of security fixes. Drop-in replacement for the old unmaintained qt5-qtwebkit

LinuxSecurity.com: Update to new ISC supported version 9.9.10-P2 including security fixes.

Black Hat Survey: Security Pros Expect Major Breaches in Next Two Years

LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available. An update that fixes 11 vulnerabilities is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes An update that solves two vulnerabilities and has 14 fixes is now available. is now available.

LinuxSecurity.com: Clément Berthaux from Synaktiv discovered two vulnerabilities in BIND, a DNS server implementation. They allow an attacker to bypass TSIG authentication by sending crafted DNS packets to a server.

LinuxSecurity.com: A vulnerability has been found in GNOME applet for NetworkManager allowing local attackers to access the local filesystem.

LinuxSecurity.com: A vulnerability in feh might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in phpMyAdmin might allow remote attackers to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in JasPer, the worst of which could could allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in virglrenderer, the worst of which could allow local guest OS users to cause a Denial of Service condition. [More…]

Cloud computing security: This is where you’ll be spending the money
How to Achieve an Optimal Security Posture

LinuxSecurity.com: poppler could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one An update that solves two vulnerabilities and has one errata is now available. errata is now available.

LinuxSecurity.com: An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata An update that solves 17 vulnerabilities and has one errata is now available. is now available.

security update

security update

LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Several security issues were fixed in Thunderbird.

LinuxSecurity.com: It was discovered that jabberd2, a Jabber instant messenger server, allowed anonymous SASL connections, even if disabled in the configuration.

LinuxSecurity.com: An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes An update that solves 16 vulnerabilities and has two fixes is now available. is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 —- Update to 10.1.

LinuxSecurity.com: **Horde_Image 2.5.1** * [mjr] SECURITY: Fix more potential places for command injections. —- **Horde_Image 2.5.0** * [mjr] **SECURITY**: Prevent DOS attack by preventing an infinite loop in certain conditions (CVE-2017-9773, reported by Fariskhi Vidyan). * [mjr] **SECURITY**: Prevent RCE attacks by properly sanitizing shell arguments (CVE-2017-9774, reported by Fariskhi

LinuxSecurity.com: Security fix for CVE-2017-9604

LinuxSecurity.com: Security fix for CVE-2016-7968

LinuxSecurity.com: CVE-2017-9604 kmail: Send Later with Delay bypasses OpenPGP

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes An update that solves 23 vulnerabilities and has four fixes is now available. is now available.

LinuxSecurity.com: An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is An update that solves 6 vulnerabilities and has 12 fixes is now available. now available.

GnuPG crypto library cracked, look for patches
Tor Browser 7.0.2 is released

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea, the worst of which may allow execution of arbitrary code.

A Man-in-the-Middle Attack against a Password Reset System
HTTPS Certificate Revocation is broken, and it’s time for some new tools
With a single wiretap order, US authorities listened in on 3.3 million phone calls

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: * [7.56](https://www.drupal.org/project/drupal/releases/7.56) * [SA- CORE-2017-003](https://www.drupal.org/SA-CORE-2017-003)

LinuxSecurity.com: New upstream release fixing moderate security issue CVE-2017-7526.

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

LinuxSecurity.com: globus-ftp-client * Adapt to Perl 5.26 – POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don’t attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data […]

security update

LinuxSecurity.com: Daniel J. Bernstein, Joachim Breitner, Daniel Genkin, Leon Groot Bruinderink, Nadia Heninger, Tanja Lange, Christine van Vredendaal and Yuval Yarom discovered that Libgcrypt is prone to a local side-channel attack allowing full key recovery for RSA-1024.

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: – http://www.zabbix.com/rn3.0.8 – http://www.zabbix.com/rn3.0.9 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew308 – https://www.zabbix.com/documentation/3.0/manual/introduction/whatsnew309

LinuxSecurity.com: A fix for an out-of-bounds write in systemd-resolved after a crafted DNS packet (CVE-2017-9445). No need to reboot or log out.

LinuxSecurity.com: xen: various flaws (#1463247) blkif responses leak backend stack data [XSA-216] page transfer may allow PV guest to elevate privilege [XSA-217] Races in the grant table unmap code [XSA-218] x86: insufficient reference counts during shadow emulation [XSA-219] x86: PKRU and BND* leakage between vCPU-s [XSA-220] stale P2M mappings due to insufficient error checking [XSA-222] […]

LinuxSecurity.com: Updates to the latest upstream OpenVPN 2.3.17, containing security updates for CVE-2017-7508, CVE-2017-7520 and CVE-2017-7521.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes An update that solves two vulnerabilities and has 9 fixes is now available. is now available.

LinuxSecurity.com: New kernel packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New glibc packages are available for Slackware 14.2 and -current to fix security issues.

LinuxSecurity.com: New httpd packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: New kernel packages are available for Slackware 14.1 to fix security issues.

LinuxSecurity.com: New libgcrypt packages are available for Slackware 14.2 and -current to fix a security issue.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: CVE-2017-1000381: c-ares NAPTR parser out of bounds access

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

How to keep Debian Linux patched with latest security updates automatically
Linux: A Hacker’s Preference
A critical flaw allows hacking Linux machines with just a malicious DNS Response

LinuxSecurity.com: An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata An update that solves 5 vulnerabilities and has one errata is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

What Are Linux Logs? How to View Them, Most Important Directories, and More
New Research Shows Cybersecurity Battleground Shifting to Linux and Web Servers

LinuxSecurity.com: An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes An update that solves three vulnerabilities and has 6 fixes is now available. is now available.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

security update

LinuxSecurity.com: Several issues were discovered in openvpn, a virtual private network application. CVE-2017-7479

LinuxSecurity.com: The security update announced as DSA-3886-1 caused regressions for some applications using Java – including jsvc, LibreOffice and Scilab – due to the fix for CVE-2017-1000364. Updated packages are now available to correct this issue. For reference, the relevant part of the original

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

LinuxSecurity.com: systemd-resolved could be made to crash or run programs if it received a specially crafted DNS response.

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

Idea to encrypt Web traffic at rest hits the IETF’s Standard Track
How to secure your CMS with out patching
Even weak hackers can pull off a password reset MitM attack via account registration

LinuxSecurity.com: An update that contains security fixes can now be installed. An update that contains security fixes can now be installed. An update that contains security fixes can now be installed.

3 security tips for software developers

LinuxSecurity.com: A vulnerability in KAuth and KDELibs allows local users to gain root privileges.