Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: – new upstream (51.0)

LinuxSecurity.com: * CVE-2016-6836: vmxnet: Information leakage in vmxnet3_complete_packet (bz#1366370) * CVE-2016-7909: pcnet: Infinite loop in pcnet_rdra_addr (bz #1381196)* CVE-2016-7994: virtio-gpu: memory leak in resource_create_2d (bz #1382667) *CVE-2016-8577: 9pfs: host memory leakage in v9fs_read (bz #1383286) *CVE-2016-8578: 9pfs: potential NULL dereferencein 9pfs routines (bz #1383292) *CVE-2016-8668: OOB buffer access in rocker switch emulation (bz #1384898) *CVE-2016-8669: […]

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

LinuxSecurity.com: Update to ansible 2.2.1. Fixes several CVEs as well as a number of otherbugfixes. See: https://github.com/ansible/ansible/blob/stable-2.2/CHANGELOG.mdfor full changes.

Firefox 51 delivers a mix of security, performance and reliability tweaks, implements FLAC audio sup

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

This new ransomware ‘bluff’ trick is costing victims big, even though their files are never really i

LinuxSecurity.com: Multiple vulnerabilities have been found in Oracle’s JRE and JDK software suites, the worst of which may allow execution of arbitrary code

LinuxSecurity.com: Multiple vulnerabilities have been found in X.Org X Server, the worst of which may allow authenticated attackers to read from or send information to arbitrary X11 clients.

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: Security fix for console video game music emu vulnerability in the fullyoptional audacious-plugins-exotic subpackage: CVE-2016-9957, CVE-2016-9958,CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-6814

LinuxSecurity.com: Update to 0.8.0-6.git97f52c1

LinuxSecurity.com: Rebase to latest upstream gitrev 20161120

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Update from 3.8.1 to 3.8.2. Also fixes console video game music emuvulnerability in the fully optional audacious-plugins-exotic subpackage:CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960, CVE-2016-9961

LinuxSecurity.com: Security fix for CVE-2016-2120, CVE-2016-7068, CVE-2016-7072, CVE-2016-7073,CVE-2016-7074

LinuxSecurity.com: Fix validation logic in the base consumer The base consumer is intended to onlyderive its validation switch from the on-disk configuration if the child classdoesn’t override the validate_signatures switch. There was a bug here where thedefault value provided in the base class made it appear as if *all* childconsumers had turned *off* validation, which […]

LinuxSecurity.com: This update fixes a security problem with the EDE package.

Why Linux Installers Need to Add Security Features
Keeping Linux devices secure with rigorous long-term maintenance
Linux Is Part of the IoT Security Problem, Dev Tells Linux Conference

LinuxSecurity.com: An update for mysql is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in WebP, the worst of which could allow a remote attacker to cause a Denial of Service condition.

LinuxSecurity.com: An update for squid is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for squid34 is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in LibRaw, the worst of which may allow attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ADOdb, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in ICU, the worst of which could cause a Denial of Service condition.

LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: ## Version 2.2.4 – 2017-01-18 ### Security – gdImageCreate() doesn’t check foroversized images and as such is prone to DoS vulnerabilities. (CVE-2016-9317)- double-free in gdImageWebPtr() (CVE-2016-6912) – potential unsigned underflowin gd_interpolation.c – DOS vulnerability in gdImageCreateFromGd2Ctx() ###Fixed – Fix #354: Signed Integer Overflow gd_io.c – Fix #340: System frozen -Fix OOB reads of the […]

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: The 4.9.5 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update addresses the following vulnerabilities: *[CVE-2016-7656](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7656),[CVE-2016-7635](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7635),[CVE-2016-7654](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7654),[CVE-2016-7639](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7639),[CVE-2016-7645](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7645),[CVE-2016-7652](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7652),[CVE-2016-7641](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7641),[CVE-2016-7632](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7632),[CVE-2016-7599](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7599),[CVE-2016-7592](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7592),[CVE-2016-7589](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7589),[CVE-2016-7623](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7623),[CVE-2016-7586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7586)Additional fixes: * Create GLX OpenGL contexts using version 3.2 (core profile)when available to reduce the memory consumption on Mesa based drivers. * Improvememory pressure handler to reduce the CPU usage on memory pressure situations. *Fix a regression in WebKitWebView title notify signal emission that caused thesignal to […]

LinuxSecurity.com: Multiple vulnerabilities have been found in zlib, the worst of which could allow attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in DirectFB, all of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in DCRaw might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in Lua might allow context-dependent attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libupnp, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in DBD::mysql, the worst of which might allow an attacker to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in PPP might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which could cause a Denial of Service condition.

LinuxSecurity.com: check valid input arguments for nla_reserve() (rh #1414305, CVE-2017-0386)

security update

security update

security update

Protesters Called To Join Inauguration Day DDoS Attack
Rsync errors lead to data breach at Canadian ISP, KWIC Internet
Encrypted email service ProtonMail opens door for Tor users

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in cURL, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in NSS, the worst of which could allow remote attackers to obtain access to private key information.

LinuxSecurity.com: Multiple vulnerabilities have been found in irssi, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A heap-based buffer overflow in CVS might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in IcedTea allowing remote attackers to affect confidentiality, integrity, and availability through various vectors.

LinuxSecurity.com: An update for java-1.8.0-oracle is now available for Oracle Java for Red Hat Enterprise Linux 6 and Oracle Java for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for python-XStatic-jquery-ui is now available for Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Updated openstack-cinder packages that fix one security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7. [More…]

LinuxSecurity.com: An update for openstack-cinder is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact [More…]

How to Keep Hackers out of Your Linux Machine Part 1: Top Two Security Tips
Google Infrastructure Security Design Overview

security update

LinuxSecurity.com: **Version 5.2.22** (January 5th 2017) * **SECURITY** Fix[CVE-2017-5223](https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-5223),local file disclosure vulnerability if content passed to `msgHTML()` is sourcedfrom unfiltered user input. Reported by Yongxiang Li of Asiasecurity. The fixfor this means that calls to `msgHTML()` without a `$basedir` will not importimages with relative URLs, and relative URLs containing `..` will be ignored. *Add simple […]

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: Security fix for CVE-2016-9888

LinuxSecurity.com: This new point release fixes a security vulnerability in wrestool. For furtherdetails see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850017

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel-rt is now available for Red Hat Enterprise MRG 2.5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for qemu-kvm is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

Understanding The Basics Of Two-Factor Authentication
Advances in SSL: 5 Strategies For Secure, High-Performance Load Balancers

LinuxSecurity.com: An update for runc is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: An update for docker is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for docker-latest is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: NVIDIA graphics drivers could be made to crash under certain conditions.

LinuxSecurity.com: Multiple vulnerabilities have been found in libxml2, the worst of which could lead to the execution of arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: Security fix for CVE-2016-9131, CVE-2016-9147, CVE-2016-9444

LinuxSecurity.com: This update avoids a malicious repository writing to files outside the localstorage root.

LinuxSecurity.com: An update for bind is now available for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for bind97 is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Multiple vulnerabilities have been found in file, the worst of which could allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in MiniUPnPc might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: A buffer overflow in xdelta might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in VLC might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Pidgin, the worst of which could lead to execution of arbitrary code.

Free IoT Vulnerability Scanner Hunts Enterprise Threats
The CSO guide to top security conferences

security update

security update

security update

Just in Time for Trump, the NSA Loosens Its Privacy Rules