Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: CVE-2016-3189 bzip2: heap use after free in bzip2recover

LinuxSecurity.com: Update to 2.46 Fixes various security issues, seehttp://www.mozilla.org/security/known-vulnerabilities/seamonkey.html for moreinfo. No more includes Chatzilla and DOM Inspector in the package — installthem yourself now (as usual other addons) from https://addons.mozilla.org

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: An integer overflow in LZO might allow remote attackers to execute arbitrary code or cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in HDF5 which could lead to the arbitrary execution of code.

LinuxSecurity.com: Multiple vulnerabilities have been found in memcached which could lead to the remote execution of arbitrary code.

LinuxSecurity.com: An integer overflow in musl might allow an attacker to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in libotr and Pidgin OTR, allowing remote attackers to execute arbitrary code.

LinuxSecurity.com: An update for ipa is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which [More…]

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581. —- This update adds apatch to fix CVE-2016-9573 and CVE-2016-9572.

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

Deprecation of Insecure Algorithms and Protocols in RHEL 6.9

LinuxSecurity.com: Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird the worst of which could lead to the execution of arbitrary code.

security update

security update

LinuxSecurity.com: A vulnerability in mod_wsgi could lead to privilege escalation.

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New samba packages are available for Slackware 14.2 and -current to fix security issues. [More Info…]

LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: This update adds security sandboxing to tracker-extract.

LinuxSecurity.com: Update to latest jquery1 stable, with backport fix for XSS vulnerability.)

LinuxSecurity.com: fix for “TLS SecurityMode.required bypass via StripTLS attack”(rhbz#1406703,1406704)

security update

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Updated to 2.1.4

LinuxSecurity.com: This update contains a **SECURITY** fix for an issue with potentially seriousconsequences but very limited scope. If an administrator of a wiki you talked tousing python-wikitcms were malicious, they could cause arbitrary code executionas the user running wikitcms. No-one besides a wiki administrator could do this,as it requires crafting the wiki’s response to an […]

LinuxSecurity.com: Update to 2.2.4 with backport for XSS vulnerability.

LinuxSecurity.com: Security fix for CVE-2016-4330, CVE-2016-4331, CVE-2016-4332, CVE-2016-4333

LinuxSecurity.com: two security flaws (#1406840) x86 PV guests may be able to mask interrupts[XSA-202, CVE-2016-10024] x86: missing NULL pointer check in VMFUNC emulation[XSA-203, CVE-2016-10025] x86: Mishandling of SYSCALL singlestep duringemulation [XSA-204, CVE-2016-10013] (#1406260)

LinuxSecurity.com: * Mon Dec 12 2016 Norvald H. Ryeng – 5.7.17-1 -Update to MySQL 5.7.17, for various fixes described athttps://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html – Add newplugin: connnection_control.so – Add MySQL Group Replication:group_replication.so – Add numactl-devel to buildreq and enable NUMA support (ifavailable) – Simplify boost path – Build compat-openssl10 in rawhide for now -Reqs. in -devel packages was […]

LinuxSecurity.com: – fix floating point buffer overflow issues (CVE-2016-9586)

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security fix for CVE-2016-8743, CVE-2016-2161, CVE-2016-0736

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: New expat packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New openssh packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Multiple vulnerabilities have been found in Samba, the worst of which may allow execution of arbitrary code with root privileges.

LinuxSecurity.com: Multiple vulnerabilities have been found in Xerces-C++, the worst of which may allow remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities were found in Tor, the worst of which could allow remote attackers to cause a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Firejail, the worst of which may allow bypassing of sandbox protection.

security update

security update

security update

security update

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

LinuxSecurity.com: gdk-pixbuf 2.36.2 release. * Remove the pixdata loader (#776004) * Fixinteger overflows in the jpeg loader (#775218) * Add an external thumbnailerfor images * Fix a NULL pointer dereference (#776026) * Fix a memory leak(#776020) * Support bmp headers with bitmask (#766890) * Add tests for scaling(#80925) * Handle compressed pixdata in resources (#776105) […]

LinuxSecurity.com: Security fix for CVE-2016-2125, CVE-2016-2126

LinuxSecurity.com: ### Botan 1.10.14 ### * NOTE WELL: Botan 1.10.x is supported for securitypatches only until 2017-12-31 * Fix integer overflow during BER decoding, foundby Falko Strenzke. This bug is not thought to be directly exploitable butupgrading ASAP is advised. (CVE-2016-9132) * Fix two cases where (in errorsituations) an exception would be thrown from a […]

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815, CVE-2016-9816, CVE-2016-9817, CVE-2016-9818] (#1399747)qemu: Divide by zero vulnerability in cirrus_do_copy (#1399055) [CVE-2016-9921,CVE-2016-9922] Qemu: 9pfs: memory leakage via proxy/handle callbacks (#1402278)qemu ioport array overflow [XSA-199, CVE-2016-9637]

LinuxSecurity.com: The 4.8.15 stable kernel update contains a number of important fixes across thetree.

Hackers Suspected of Causing Second Power Outage in Ukraine

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: – Fixed crash in auth process when auth-policy was configured and authenticationwas aborted/failed without a username set. – director: If two users haddifferent tags but the same hash, the users may have been redirected to thewrong tag’s hosts. – Index files may have been thought incorrectly lost, causing”Missing middle file seq=..” to be logged […]

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

LinuxSecurity.com: Security fix for CVE-2016-9036, CVE-2016-9037

security update

security update

security update

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: Several security issues were fixed in the kernel.

LinuxSecurity.com: The system could be made to expose sensitive information.

LinuxSecurity.com: The system could be made to expose sensitive information.

Home routers under attack in ongoing malvertisement blitz
Op-ed: Why I’m not giving up on PGP

LinuxSecurity.com: An update for gstreamer-plugins-bad-free is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for gstreamer-plugins-good is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: An update for vim is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Several security issues were fixed in Samba.

Box won’t say if it’s giving your secrets to the government
Turkey reportedly blocks Tor network nationwide
Financial Data Worth Millions Unwittingly Exposed In Ameriprise Accounts
7 Linux predictions for 2017

LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: This update fixes CVE-2016-9580 and CVE-2016-9581.

LinuxSecurity.com: Rebase to upstream 4.4.3: http://www.freeipa.org/page/Releases/4.4.3 —- -Fixes 1395311 – CVE-2016-9575 ipa: Insufficient permission check in certprofile-mod – Fixes 1370493 – CVE-2016-7030 ipa: DoS attack against kerberized servicesby abusing password policy

LinuxSecurity.com: Security fix for CVE-2016-9957, CVE-2016-9958, CVE-2016-9959, CVE-2016-9960,CVE-2016-9961

LinuxSecurity.com: x86 CMPXCHG8B emulation fails to ignore operand size override [XSA-200,CVE-2016-9932] (#1404262) —- ARM guests may induce host asynchronous abort[XSA-201, CVE-2016-9815,

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for BZ#1401985

LinuxSecurity.com: This release fixes CVE-2016-1249 (out-of-bound read when using server-sideprepared statements) and CVE-2016-1251 vulnerability (a use after free whenusing prepared statements).

LinuxSecurity.com: Security fix for CVE-2016-9844

LinuxSecurity.com: The 4.8.14 stable kernel update contains a number of important fixes across thetree.