Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

First came mass MongoDB ransacking: Now copycat ransoms hit Elasticsearch
Guccifer 2.0, alleged Russian cyberspy, returns to deride U.S.
Suspected NSA tool hackers dump more cyberweapons in farewell

security update

security update

LinuxSecurity.com: A vulnerability in runC could lead to privilege escalation.

LinuxSecurity.com: Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in execution of arbitrary code or privilege escalation.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla SeaMonkey, the worst of which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for java-1.6.0-openjdk is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Update to 0.24.6

LinuxSecurity.com: New upstream release

security update

LinuxSecurity.com: Fix [CVE-2016-9962] Insecure opening of file-descriptor allows privilege FixBZ#1412148 – containerd: container did not start before the specified timeout—- use container-selinux >= 2:2.0-2

security update

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Hacker Steals 900 GB of Cellebrite Data
Exitmap – Tor Exit Relay Scanner

LinuxSecurity.com: New gnutls packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New irssi packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New bind packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. [More Info…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8605

LinuxSecurity.com: fix CVE-2016-8741 (rhbz#1409836,1409835)

LinuxSecurity.com: update to 3.2.10.RELEASE, fix CVE-2016-9879

LinuxSecurity.com: Update to the latest upstream release 1.3.2, also with some security fixes (seebug #1193445 from the native flac package).

LinuxSecurity.com: Security fix for CVE-2016-8605

security update

Debugging a kernel in QEMU/libvirt

LinuxSecurity.com: Multiple vulnerabilities have been found in phpMyAdmin, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Flex might generate code with a buffer overflow making applications using such scanners vulnerable to the execution of arbitrary code.

LinuxSecurity.com: A vulnerability has been found in Vim and gVim concerning how certain modeline options are treated.

LinuxSecurity.com: A vulnerability in vzctl might allow attackers to gain control over ploop containers.

LinuxSecurity.com: A heap-based buffer overflow in c-ares might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in 7-Zip, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: A vulnerability in BIND might allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in phpBB, the worst of which may allow remote attackers to inject arbitrary web script or HTML.

LinuxSecurity.com: Multiple vulnerabilities have been found in PgBouncer, the worst of which may allow an attacker to bypass authentication.

LinuxSecurity.com: Multiple vulnerabilities have been found in Botan, the worst of which might allow remote attackers to obtain ECDSA secret keys.

LinuxSecurity.com: Gentoo’s NGINX ebuilds are vulnerable to privilege escalation due to the way log files are handled.

LinuxSecurity.com: Multiple vulnerabilities have been found in Expat, the worst of which may allow execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libTIFF, the worst of which may allow execution of arbitrary code.

MongoDB ransacked: Now 27,000 databases hit in mass ransom attacks
GitHub secret key finder released to public
Trump Plans To Build Anti-Hacking Team
Hacker: Lol, I pwned FBI.gov! Web devs: Nuh-uh, no you didn’t

LinuxSecurity.com: Multiple vulnerabilities have been found in Python, the worst of which could lead to arbitrary code execution.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]

LinuxSecurity.com: Update —- Update to 0.11 —- Update —- Update. **WARNING:** if youare using your own config file, add “` include /etc/sway/config.d/* “` Atthe end of it, otherwise nothing will work on Wayland

LinuxSecurity.com: MinGW cross compiled libpng 1.6.27 release, fixing a potential security issue.For details, see https://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: This update fixes an old NULL pointer dereference bug in png_set_text_2()discovered and patched by Patrick Keshishian (CVE-2016-10087). The potential”NULL dereference” bug has existed in libpng since version 0.71 of June 26,1995. To be vulnerable, an application has to load a text chunk into the pngstructure, then delete all text, then add another text chunk […]

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Update to Samba 4.4.9 —- Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/

LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport

LinuxSecurity.com: **Version 5.4.5** (2016-12-29) * SECURITY FIX: fixed CVE-2016-10074 bydisallowing potentially unsafe shell characters Prior to 5.4.5, the mailtransport (Swift_Transport_MailTransport) was vulnerable to passing arbitraryshell arguments if the “From”, “ReturnPath” or “Sender” header came from anon-trusted source, potentially allowing Remote Code Execution * deprecatedthe mail transport

security update

security update

security update

LinuxSecurity.com: New upstream release

LinuxSecurity.com: Update to the latest upstream release

LinuxSecurity.com: This update includes the latest stable release of _Apache Subversion_, version**1.9.5**. #### Client-side bugfixes: * fix accessing non-existent paths duringreintegrate merge * fix handling of newly secured subdirectories in workingcopy * info: remove trailing whitespace in –show-item=revision ([issue4660](http://subversion.tigris.org/issues/show_bug.cgi?id=4660)) * fix recordingwrong revisions for tree conflicts * gpg-agent: improve discovery of gpg-agentsockets * gpg-agent: fix […]

LinuxSecurity.com: Update to 4.5.1.

LinuxSecurity.com: For changes see: https://www.mozilla.org/en-US/thunderbird/45.6.0/releasenotes/

LinuxSecurity.com: **Version 5.2.21** (December 28th 2016) * Fix missed number update in versionfile – no functional changes —- **Version 5.2.20** (December 28th 2016) ***SECURITY** Critical security update for CVE-2016-10045 please update now!Thanks to [Dawid Golunski](https://legalhackers.com) and Paul Buonopane(Zenexer). —- ** Version 5.2.19** (December 26th 2016) * Minor cleanup** Version 5.2.18** (December 24th 2016) * **SECURITY** […]

KillDisk Ransomware Now Targets Linux, Prevents Boot-Up, Has Faulty Encryption

security update

LinuxSecurity.com: An update for puppet-tripleo is now available for Red Hat OpenStack Platform 10.0 (Newton). Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover

LinuxSecurity.com: libpng 1.6.27 release, fixing a potential security issue. For details, seehttps://sourceforge.net/p/png-mng/mailman/message/35575076/

LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox and Thunderbird the worst of which could lead to the execution of arbitrary code.

Security-Oriented Kodachi 3.6 Linux OS Improves VPN and Tor Connectivity, More
LG threatens to put Wi-Fi in every appliance it releases in 2017
US government subcontractor leaks confidential military personnel data
Linux 2017: With great power comes great responsibility
Ransomware Has Evolved, And Its Name Is Doxware

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for gstreamer1-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer1-plugins-good is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)

LinuxSecurity.com: – Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check incertprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack againstkerberized services by abusing password policy —- – Fixes 1395311 -CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes1370493 – CVE-2016-7030 ipa: DoS attack against kerberized services by abusingpassword policy

LinuxSecurity.com: upstream version 1.0.9 (BZ#1406277)

LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

Obama’s Russian Hacking Retaliation Is Biggest “Since the Cold War”
White Hat Hacker Launches Public Support Site

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]