Menu

Category Archives: GNU/Linux

Everything about GNU+Linux security

LinuxSecurity.com: New upstream version 2.50. – Fixes serious DLL hijacking attack:https://sourceforge.net/p/nsis/bugs/1125/

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Nghttp2 is vulnerable to a Denial of Service attack.

LinuxSecurity.com: Patch is vulnerable to a locally generated Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Security fix for CVE-2016-9296

LinuxSecurity.com: phpMyAdmin 4.6.5.1 (2016-11-26) =============================== A patch-levelrelease fixing two small issues: * an issue affecting a small number of usersusing $cfg[‘Servers’][$i][‘hide_db’] or $cfg[‘Servers’][$i][‘only_db’]. * anissue affecting the create table dialog where the partition selection tool wasoverzealous and made it difficult to create a new table. There are also minorimprovements to the Czech language file. phpMyAdmin […]

LinuxSecurity.com: Update to 1.10.1

LinuxSecurity.com: Add fix for gstreamer FLIC decoder vulnerability

LinuxSecurity.com: xen : various security flaws (#1397383) x86 null segments not always treated asunusable [XSA-191, CVE-2016-9386] x86 task switch to VM86 mode mis-handled[XSA-192, CVE-2016-9382] x86 segment base write emulation lacking canonicaladdress checks [XSA-193, CVE-2016-9385] guest 32-bit ELF symbol table loadleaking host data [XSA-194, CVE-2016-9384] x86 64-bit bit test instructionemulation broken [XSA-195, CVE-2016-9383] x86 software interrupt […]

LinuxSecurity.com: Libvirt is vulnerable to directory traversal when using Access Control Lists (ACL).

LinuxSecurity.com: Multiple vulnerabilities have been found in GD, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A vulnerability in LinuxCIFS utils’ “cifscreds” PAM module might allow remote attackers to have an unspecified impact via unknown vectors.

LinuxSecurity.com: A vulnerability in DavFS2 allows local users to gain root privileges.

LinuxSecurity.com: Due to a design flaw, the output of GnuPG’s Random Number Generator (RNG) is predictable.

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: An update for firefox is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

LinuxSecurity.com: A security update that fixes Calamares bug CAL-405:https://calamares.io/bugs/browse/CAL-405 When installing with a LUKS-encrypted`/` partition, Calamares was always creating a keyfile to decode `/` and storingit in the initramfs. It did that even with an unencrypted separate `/boot`partition. As a result, the keyfile would be stored in cleartext on the `/boot`partition, and it was possible […]

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Security fix for CVE-2016-9299

LinuxSecurity.com: Update to 1.9.9 (bugfix release for CVE-2016-7146, CVE-2016-7148)

security update

2017 security predictions
Firefox zero-day: Mozilla races to patch bug used to attack Tor browser users
900,000 Deutsche Telekom Routers Disabled by Massive Cyber Attack

security update

LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6, and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact [More…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-9296

LinuxSecurity.com: Fix nfs_cleanup security race and permissions (rhbz#1395040).

LinuxSecurity.com: Update to 0.6.4

LinuxSecurity.com: https://www.drupal.org/SA-CORE-2016-005

LinuxSecurity.com: Fix nfs_cleanup security race and permissions (rhbz#1395040).

LinuxSecurity.com: Update to 0.6.4

LinuxSecurity.com: https://www.drupal.org/SA-CORE-2016-005

LinuxSecurity.com: Fix nfs_cleanup security race and permissions (rhbz#1395040).

LinuxSecurity.com: https://www.drupal.org/SA-CORE-2016-005

LinuxSecurity.com: Fix for CVE-2016-9400

Extending Linux Executable Logging With The Integrity Measurement Architecture

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-8864

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Update to 4.4.2: Security fixes * A difference in cookie parsing betweenTornado and web browsers (especially when combined with Google Analytics) couldallow an attacker to set arbitrary cookies and bypass XSRF protection. Thecookie parser has been rewritten to fix this attack. Backwards-compatibilitynotes * Cookies containing certain special characters (in particular semicolonand square brackets) are […]

Locking Down Your Linux Server

security update

Linux Security Made Simple
Elegant 0-day unicorn underscores “serious concerns” about Linux security
Monitoring Network Load With nload: Part 2

security update

security update

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security fix for CVE-2016-7415

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Security fix for CVE-2016-1249

LinuxSecurity.com: 3.1.3

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: Security fix for CVE-2016-7504, CVE-2016-7505, CVE-2016-7506, CVE-2016-9017,CVE-2016-9108, CVE-2016-9109, CVE-2016-9294

LinuxSecurity.com: The 4.8.8 stable kernel update contains a number of important fixes across thetree. —- The 4.8.7 kernel rebase contains new hardware support, additionalfeatures, and a number of important bug fixes across the tree.

LinuxSecurity.com: 3.0.7

LinuxSecurity.com: – update to 1.8.18p1 – fixes CVE-2016-7076

U.S. says cybersecurity skills shortage is a myth
8 Books Security Pros Should Read

security update

LinuxSecurity.com: Several security issues were fixed in Python.

LinuxSecurity.com: Security Report Summary

A Hacker Took Over Tel Aviv’s Public Wi-Fi Network to Prove That He Could
38 Percent of Mobile Professionals Have Never Used a VPN
DoD, HackerOne kick off Hack the Army bug bounty challenge

LinuxSecurity.com: An update for memcached is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

LinuxSecurity.com: An update for memcached is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, [More…]

security update

security update

LinuxSecurity.com: New ntp packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. [More Info…]

LinuxSecurity.com: Security Report Summary

LinuxSecurity.com: Security Report Summary

Is encrypted e-mail a must in the Trump presidential era?
Your car will be recalled in 2017 thanks to poor open-source security

LinuxSecurity.com: A buffer overflow in TestDisk might allow remote attackers to execute arbitrary code.

LinuxSecurity.com: A path traversal attack in Tar may lead to the remote execution of arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Adobe Flash Player, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: A buffer overflow in RPCBind might allow remote attackers to cause a Denial of Service.

LinuxSecurity.com: Multiple vulnerabilities have been found in the Chromium web browser, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been found in Poppler, the worst of which allows remote attackers to execute arbitrary code.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in MIT Kerberos 5, the worst of which may allow remote attackers to cause Denial of Service.

LinuxSecurity.com: A vulnerability in MongoDB can lead to a Denial of Service condition.

LinuxSecurity.com: Multiple vulnerabilities have been found in imlib2, the worst of which allows for the remote execution of arbitrary code.

LinuxSecurity.com: – update to new upstream (50.0)

LinuxSecurity.com: The 4.8.8 stable update contains a number of important fixes across the tree.

LinuxSecurity.com: – update to new upstream (50.0)

LinuxSecurity.com: 3.1.3

LinuxSecurity.com: The 4.8.7 stable kernel update contains a number of important fixes across thetree.

LinuxSecurity.com: Security fix for CVE-2016-6170 —- Security fix for CVE-2016-8864

LinuxSecurity.com: Rebase to 1.5.3 to fix CVE-2016-9243