Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow a remote attacker to cause a Denial of Service or gain elevated privileges from a guest VM. [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Shadow, the worst of which might allow privilege escalation.

LinuxSecurity.com: Gentoo’s MUNGE ebuilds are vulnerable to privilege escalation due to improper permissions.

LinuxSecurity.com: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents

LinuxSecurity.com: Update to 4.12 (#1456190)

LinuxSecurity.com: Security fix for CVE-2017-7494

LinuxSecurity.com: Update to latest stable release, include fixes for gnutls and gtk-vnc compatibility.

LinuxSecurity.com: – update to 1.8.20p2 – added sudo package to dnf/yum protected packages —- – update to 1.8.20p1 – fixes CVE-2017-1000367

LinuxSecurity.com: Fixed CVE-2017-6508: CRLF injection in the url_parse function in url.c

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: Update to chromium 58. Move chrome-remote-desktop to user systemd service. Security fixes for CVE-2017-5068, CVE-2017-5057, CVE-2017-5058, CVE-2017-5059, CVE-2017-5060, CVE-2017-5061, CVE-2017-5062, CVE-2017-5063, CVE-2017-5064, CVE-2017-5065, CVE-2017-5066, CVE-2017-5067, CVE-2017-5069 —- Security fix for CVE-2017-5055, CVE-2017-5054, CVE-2017-5052, CVE-2017-5056, CVE-2017-5053

LinuxSecurity.com: fix insufficient escaping of user-supplied data (CVE-2017-7692)

LinuxSecurity.com: The cPanel Security Team reported a time of check to time of use (TOCTTOU) race condition flaw in File::Path, a core module from Perl to create or remove directory trees. An attacker can take advantage of this flaw to set the mode on an attacker-chosen file to a attacker-chosen

security update

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

LinuxSecurity.com: Security fixes for CVE-2017-9078 CVE-2017-9079

Phishing Campaigns Follow Trends

security update

security update

LinuxSecurity.com: Several vulnerabilities were discovered in NSS, a set of cryptographic libraries, which may result in denial of service or information disclosure.

LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, didn’t restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: OpenLDAP could be made to crash if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in libsndfile.

Silk Road founder Ross Ulbricht loses appeal for new trial
Biker group charged with hacking hundreds of Jeeps, motorcycles in crime spree

LinuxSecurity.com: An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes An update that solves two vulnerabilities and has 5 fixes is now available. is now available.

Secure XML Processing with JAXP on EAP 7
Shadow Brokers lay out pitch – and name price – for monthly zero-day subscription service
Blockchains are the new Linux, not the new internet

LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool. They would allow remote attackers to force password resets, and perform various cross-site scripting and cross-site request forgery attacks.

security update

security update

security update

security update

security update

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make […]

LinuxSecurity.com: Karsten Heymann discovered that the OpenLDAP directory server can be crashed by performing a paged search with a page size of 0, resulting in denial of service. This vulnerability is limited to the MDB storage backend.

LinuxSecurity.com: New sudo packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: Sudo could be made to overwrite files as the administrator.

How to build your own VPN if you’re (rightfully) wary of commercial options
82% of Databases Left Unencrypted in Public Cloud

LinuxSecurity.com: An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes An update that solves one vulnerability and has three fixes is now available. is now available.

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for sudo is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

security update

LinuxSecurity.com: It was discovered that pattern-based ACLs in the Mosquitto MQTT broker could be bypassed. For the stable distribution (jessie), this problem has been fixed in

LinuxSecurity.com: A security fix for a systemd-resolved crash on a crafted DNS packet. Relevant only to systemd-resolved users (not enabled by default). No need to reboot or logout.

LinuxSecurity.com: This update addresses the following vulnerabilities: * [CVE-2017-2496](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2496), [CVE-2017-2539](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2539), [CVE-2017-2510](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2510) Additional fixes: * Fix URL shown in the title of beforeunload dialogs. * Focus

LinuxSecurity.com: Fix for CVE-2016-8728 CVE-2016-8729 —- Rebuild with new jbig2dec

LinuxSecurity.com: An issue in `git-shell` could allow remote users to run an interactive pager. From the [update announcement](https://public- inbox.org/git/xmqq8tm5ziat.fsf@gitster.mtv.corp.google.com/): … fix a recently disclosed problem with “git shell”, which may allow a user who comes over SSH to run an interactive pager by causing it to spawn “git

LinuxSecurity.com: strongSwan could be made to crash or hang if it received specially crafted network traffic.

LinuxSecurity.com: Several security issues were fixed in WebKitGTK+.

LinuxSecurity.com: Several security issues were fixed in ImageMagick.

LinuxSecurity.com: USN-3212-1 caused a regression in LibTIFF.

LinuxSecurity.com: Two denial of service vulnerabilities were identified in strongSwan, an IKE/IPsec suite, using Google’s OSS-Fuzz fuzzing project. CVE-2017-9022

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for nss is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

security update

Democracy-minded DEF CON hackers promise punishing probe on US election computers

security update

security update

A wormable code-execution bug has lurked in Samba for 7 years. Patch now!

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: A vulnerability in Smb4K could allow local attackers to execute commands as root.

LinuxSecurity.com: Teeworlds client vulnerability in snap handling could result in execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could allow for privilege escalation.

LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available. An update that fixes 9 vulnerabilities is now available.

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

4 Reasons the Vulnerability Disclosure Process Stalls

LinuxSecurity.com: Firefox was updated to a new version.

LinuxSecurity.com: New samba packages are available for Slackware 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.

LinuxSecurity.com: Samba could be made to run programs as an administrator.

Sn1per – Penetration Testing Automation Scanner
Hackers Unlock Samsung Galaxy S8 With Fake Iris

LinuxSecurity.com: Samba could be made to run programs as an administrator.

LinuxSecurity.com: Several security issues were fixed in jbig2dec.

LinuxSecurity.com: MiniUPnP could be made to crash or run programs if it received specially crafted network traffic.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update for samba3x is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: An update for samba4 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

LinuxSecurity.com: An update for samba is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

LinuxSecurity.com: Jakub Jirasek of Secunia Research discovered that libtasn1, a library used to handle Abstract Syntax Notation One structures, did not properly validate its input. This would allow an attacker to cause a crash by denial-of-service, or potentially execute arbitrary code, by

LinuxSecurity.com: steelo discovered a remote code execution vulnerability in Samba, a SMB/CIFS file, print, and login server for Unix. A malicious client with access to a writable share, can take advantage of this flaw by uploading a shared library and then cause the server to load and execute it.

LinuxSecurity.com: This updates fixes a security bug in the route manager, to prevent it from overwriting arbitrary files (CVE-2017-8921)

security update

security update

Yahoo retires ImageMagick library after 18-byte exploit leaks user email content

LinuxSecurity.com: An update for rpcbind is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability