Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. The Common Vulnerabilities and Exposures project identifies the following problems:

LinuxSecurity.com: An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata An update that solves one vulnerability and has one errata is now available. is now available.

LinuxSecurity.com: libmwaw could be made to crash or run programs as your login if it opened a specially crafted file.

LinuxSecurity.com: zziplib could be made to crash or run programs as your login if it opened a specially crafted file.

Brit hacker admits he siphoned info from US military satellite network
CIA has been hacking into Wi-Fi routers for years, leaked documents show
Cybersecurity labor crunch to hit 3.5 million unfilled jobs by 2021
Buggy devices and lazy operators make VoLTE a security nightmare
Parrot Security OS Devs Mock systemd: It’s an Immature Init System for GNU/Linux

LinuxSecurity.com: – new upstream update (54.0)

LinuxSecurity.com: Update to version 1.8.2. The upstream release notes: https://mail.gnome.org/archives/ftp-release-list/2017-June/msg00015.html

LinuxSecurity.com: **Rebase to 10.1.24** Plugin oqgraph enabled Plugin jemalloc enabled Sphinx engine enabled Build dependecies Bison and Libarchive added, others corrected Disabling Mroonga engine for i686 architecture, as it is not supported by MariaDB **Removed patches: (fixed by upstream)** Patch5: %{pkgnamepatch}-file-contents.patch Patch14: %{pkgnamepatch}-example-config-

security update

The 15 worst data security breaches of the 21st Century
DevSecOps is Not a Security Panacea
BlackArch Linux Ethical Hacking and Pen Testing OS Now Offers over 1,800 Tools

LinuxSecurity.com: Firefox could be made to crash or run programs as your login if it opened a malicious website.

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2, and -current to fix security issues.

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Update to a bugfix release of yara.

security update

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages.

Pirates dance around AACS 2 encryption to offer UHD Blu-Ray movies online
Raspberry Pi sours thanks to mining malware

LinuxSecurity.com: It was discovered that a side channel attack in the EdDSA session key handling in Libgcrypt may result in information disclosure. For the stable distribution (jessie), this problem has been fixed in

security update

security update

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: Per release notes: http://www.postgresql.org/docs/9.5/static/release-9-5-7.html

LinuxSecurity.com: Agostino Sarubbo discovered multiple vulnerabilities in zziplib, a library to access Zip archives, which could result in denial of service and potentially the execution of arbitrary code if a malformed archive is processed.

Docker Aims to Improve Linux Kernel Security With LinuxKit
pymultitor – Python Multi Threaded Tor Proxy

LinuxSecurity.com: https://lists.gnupg.org/pipermail/gnutls-devel/2017-June/008446.html

LinuxSecurity.com: Gajim 0.16.8 * Fix rejoining MUCs after connection loss * Fix Groupchat invites * Fix encoding problems with newer GnuPG versions * Fix old messages randomly reappearing in the chat window * Fix some problems with IBB filetransfer * Make XEP-0146 Commands opt-in * Improve sending messages to your own resources * Improve reliability […]

LinuxSecurity.com: Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9225 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

LinuxSecurity.com: Multiple security flaws were found on oniguruma currently being shipped on Fedora. This new rpm should fix the issue. Fixed CVEs: CVE-2017-9226 CVE-2017-9224 CVE-2017-9227 CVE-2017-9229 CVE-2017-9228

LinuxSecurity.com: It has been discovered that Tor, a connection-based low-latency anonymous communication system, contain a flaw in the hidden service code when receiving a BEGIN_DIR cell on a hidden service rendezvous circuit. A remote attacker can take advantage of this flaw to cause a

LinuxSecurity.com: – Update to upstream 3.5.13 release

LinuxSecurity.com: Security fix for CVE-2017-9432

LinuxSecurity.com: fixes buffer overflows for flac and pcm

LinuxSecurity.com: FIx for CVE-2017-8366

LinuxSecurity.com: Security fixes.

LinuxSecurity.com: Security fix for CVE-2017-5645

LinuxSecurity.com: * fixed CVE-2017-6508 CRLF injection in the url_parse function in url.c * fixed use of .netrc

LinuxSecurity.com: This release fixes a possible setting arbitrary mode on an arbitrary file in rmtree() and remove_tree() calls known as CVE-2017-6512.

security update

security update

EtherApe – Graphical Network Monitor
A Porn Bot Sprung a Leak and We Got to See What Was Behind It

security update

LinuxSecurity.com: An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is An update that solves 8 vulnerabilities and has 68 fixes is now available. now available.

LinuxSecurity.com: An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available. An update that fixes 8 vulnerabilities is now available.

Tor Browser 7.0 is released

LinuxSecurity.com: This update fixes CVEs 2017-7511 and 2017-9083.

LinuxSecurity.com: Upgrade FreeRADIUS to upstream v3.0.14 release. The release includes fixes for various issues, including security issues, one of which is CVE-2017-9148.

LinuxSecurity.com: This update fixes CVEs 2017-7511 and 2017-9083.

LinuxSecurity.com: Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash.

security update

LinuxSecurity.com: FreeRADIUS would allow unintended access over the network.

LinuxSecurity.com: USN-3253-1 introduced a regression in Nagios.

5 Tips For Choosing The Right Open Source Code
Encryption leaves authorities ‘not in a good place’: Former US intelligence chief
The Dark Web is the place to go to find bugs before public disclosure

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available. An update that fixes 16 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in FreeType, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: An out-of-bounds data access in minicom might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Wireshark, the worst of which allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in PCRE library allows remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A vulnerability in Pidgin might allow remote attackers to execute arbitrary code.

Why you must patch the new Linux sudo security hole

LinuxSecurity.com: Multiple vulnerabilities have been found in WebKitGTK+, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: The system could be made to run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in the Linux kernel.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: Several security issues were fixed in Puppet.

CIA’s Pandemic Toolkit
Hackers leak 8 unaired episodes of ABC’s Steve Harvey’s Funderdome TV series

LinuxSecurity.com: A vulnerability in a bundled copy of PuTTY in FileZilla might allow remote attackers to execute arbitrary code or cause a denial of service. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: A vulnerability has been found in Libtirpc and RPCBind which may allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in ImageWorsener, the worst of which allows remote attackers to cause a Denial of Service condition or have other unspecified impact. [More…]

LinuxSecurity.com: Multiple vulnerabilities in D-Bus might allow an attacker to overwrite files with a fixed filename in arbitrary directories or conduct a symlink attack. [More…]

LinuxSecurity.com: A vulnerability in Git might allow remote attackers to bypass security restrictions.