Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: it was found that KDE plasma does not honor the setting for prompting whenexecuting executable files on the desktop. This update resolves this issue.

LinuxSecurity.com: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627,CVE-2017-5628.

LinuxSecurity.com: Update to the latest version, fixes a security issue.

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

At death’s door for years, widely used SHA1 function is now dead
Linux’s decade-old flaw: Major distros move to patch serious kernel bug
Salted Hash: RSAC 2017 Recap
“Secure” Trump website defaced by hacker claiming to be from Iraq

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Ruby Archive::Tar::Minitar is vulnerable to a directory traversal attack.

LinuxSecurity.com: Multiple vulnerabilities have been found in GPL Ghostscript, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

Kaspersky: No whiff of Linux in our OS because we need new start to secure IoT
Intent-Based Security Gains Momentum at RSA
12 steps to small business security
The 7 security threats to technology that scare experts the most
RSA: Elite cryptographers scoff at idea that law enforcement can ‘overcome’ encryption

LinuxSecurity.com: Multiple vulnerabilities have been found in tcpdump, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in PHP, the worst of which could lead to arbitrary code execution or cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xen, the worst of which could lead to the execution of arbitrary code on the host system.

LinuxSecurity.com: Multiple vulnerabilities have been found in Nagios, the worst of which could lead to privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could lead to the execution of arbitrary code on the host system.

LinuxSecurity.com: Multiple vulnerabilities have been found in libass, the worst of which have unknown impacts.

LinuxSecurity.com: Multiple vulnerabilities have been found in LibVNCServer/LibVNCClient, the worst of which allows remote attackers to execute arbitrary code when connecting to a malicious server.

LinuxSecurity.com: Multiple vulnerabilities have been found in Dropbear, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in Opus could cause memory corruption.

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in TigerVNC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Security fix for CVE-2017-3135

LinuxSecurity.com: Multiple vulnerabilities have been found in MuPDF, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in the GNU C Library, the worst of which allows context-dependent attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in NTFS-3G allows local users to gain root privileges.

LinuxSecurity.com: Security fix for CVE-2017-5595

LinuxSecurity.com: Security fix for CVE-2017-5595

LinuxSecurity.com: Update to 0.6.1

LinuxSecurity.com: An update for openssl is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Backport upstream fix to force limit and offset to be numeric

LinuxSecurity.com: Backport upstream fix to force limit and offset to be numeric

LinuxSecurity.com: USN-3199-1 introduced a regression in the Python Cryptography Toolkit whichcaused programs which relied on the original behavior to fail.

LinuxSecurity.com: Multiple vulnerabilities have been found in ImageMagick, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Programs using the Python Cryptography Toolkit could be made to crash or runprograms if they receive specially crafted network traffic or other input.

LinuxSecurity.com: Security Report Summary

security update

Xen Project asks to limit security vulnerability advisories
How Google reinvented security and eliminated the need for firewalls

security update

LinuxSecurity.com: Applications using libgc could be made to crash or run programs asyour login.

New ASLR-busting JavaScript is about to make drive-by exploits much nastier
A Chip Flaw Strips Away Hacking Protections for Millions of Devices
At RSA, doubts abound over US action on cybersecurity

LinuxSecurity.com: Qemu: net: mcf_fec: infinite loop while receiving data in mcf_fec_receive[CVE-2016-9776] Qemu: audio: memory leakage in ac97 [CVE-2017-5525] Qemu: audio:memory leakage in es1370 device [CVE-2017-5526] oob access in cirrus bitblt copy[XSA-208, CVE-2017-2615]

LinuxSecurity.com: – update to the latest upstream pre-release (fixes CVE-2016-9179)

LinuxSecurity.com: The newest upstream commit, fixing CVE-2017-5953 vim: Tree length values notvalidated properly when handling a spell file

LinuxSecurity.com: Security fix for CVE-2016-7922, CVE-2016-7923, CVE-2016-7924, CVE-2016-7925,CVE-2016-7926, CVE-2016-7927, CVE-2016-7928, CVE-2016-7929, CVE-2016-7930,CVE-2016-7931, CVE-2016-7932, CVE-2016-7933, CVE-2016-7934, CVE-2016-7935,CVE-2016-7936, CVE-2016-7937, CVE-2016-7938, CVE-2016-7939, CVE-2016-7940,CVE-2016-7973, CVE-2016-7974, CVE-2016-7975, CVE-2016-7983, CVE-2016-7984,CVE-2016-7985, CVE-2016-7986, CVE-2016-7992, CVE-2016-7993, CVE-2016-8574,CVE-2016-8575, CVE-2017-5202, CVE-2017-5203, CVE-2017-5204, CVE-2017-5205,CVE-2017-5341, CVE-2017-5342, CVE-2017-5482, CVE-2017-5483, CVE-2017-5484,CVE-2017-5485, CVE-2017-5486

LinuxSecurity.com: Security fix for CVE-2017-3135

LinuxSecurity.com: The 4.9.9 update contains a number of important fixes across the tree

LinuxSecurity.com: Security fix for CVE-2017-2586, CVE-2017-2587 and CVE-2017-5849, —- Addlicense information file copyright_summary —- New version of netpbm isavailable (10.77.00)

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

security update

security update

security update

Researcher develops ransomware attack that targets water supply
CrowdStrike attempts to sue NSS Labs to prevent test release, court denies request
Newly discovered flaw undermines HTTPS connections for almost 1,000 sites

LinuxSecurity.com: Update to 3.20.7, fixing a serious password extraction sweep attack on thepassword manager [(#752738)](https://bugzilla.gnome.org/show_bug.cgi?id=752738)

LinuxSecurity.com: An update for java-1.7.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: New tcpdump packages are available for Slackware 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. NOTE: These updates also require the updated libpcap package. [More Info…]

LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Graphviz and the extent of these vulnerabilities are unspecified.

LinuxSecurity.com: A vulnerability in Lsyncd allows execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in GnuTLS, the worst of which may allow execution of arbitrary code.

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Minor upstream release fixing CVE-2016-8610, CVE-2017-3731, CVE-2017-3732.

LinuxSecurity.com: Important change: * most of the utilities were move to the new sub-package”server-utils” Other enhancements: (see changelog) * CVE fixes, SPECfilefixes, patches revision, tests blacklist revisions * Preparation and testing ofthe Cracklib plugin to be added

LinuxSecurity.com: Add upstream patches fixing CVE-2016-9577 and CVE-2016-9578

LinuxSecurity.com: gnome-boxes 3.20.4 release, fixing a possible security issue with storing theexpress installation password in clear text. – Store the user password in thekeyring during an express installation. – Fix typo in debug string. – Fix printfformat strings.

LinuxSecurity.com: Version 1.1.26 (released 24-Jan-2017) * security fix: escape nav_data name toavoid XSS attack Version 1.1.25 (released 15-Sep-2016) * fix _rev2optrevassertion on long input

Arby’s Gets Roasted in Breach of 300K Payment Cards

LinuxSecurity.com: Update to 2.1

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

LinuxSecurity.com: Security fix for CVE-2017-5884, CVE-2017-5885

LinuxSecurity.com: * various security relevant flaws

LinuxSecurity.com: January 2017 security fixes – http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html#AppendixJAVA

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Security Report Summary