Menu

Category Archives: Security

Articles about security

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2017-18267, CVE-2018-13988, CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149

LinuxSecurity.com: Security fix for CVE-2018-16869

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit

LinuxSecurity.com: Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or memory disclosure if a malformed OLE file is processed.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

security update

security update

First-Ever UEFI Rootkit Tied to Sednit APT

LinuxSecurity.com: A XML External Entity (XXE) vulnerability was discovered in c3p0, a library for JDBC connection pooling, that may be used to resolve information outside of the intended sphere of control.

LinuxSecurity.com: Multiple security issues were found in libarchive, a multi-format archive and compression library: Processing malformed RAR archives could result in denial of service or the execution of arbitrary code and malformed WARC, LHarc, ISO, Xar or CAB archives could result in denial of service.

LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code.

LinuxSecurity.com: Some vulnerabilities were discovered in ghostscript, an interpreter for the PostScript language and for PDF.

Guardzilla Home Cameras Open to Anyone Wanting to Watch Their Footage
Hijacking Online Accounts Via Hacked Voicemail Systems
35C3 Day One: Security, Art and Hacking

Reading Time: ~2 min. Amazon User Receives Thousands of Alexa-Recorded Messages Upon requesting all his user data from Amazon, one user promptly received over 1,700 recorded messages from an Alexa device. Unfortunately, the individual didn’t own such a device. The messages were from a device belonging to complete stranger, and some of them could have easily […]

Analysis of the latest Emotet propagation campaign

An analysis of the workings of this new Emotet campaign, which has affected various countries in Latin America by taking advantage of Microsoft Office files to hide its malicious activity The post Analysis of the latest Emotet propagation campaign appeared first on WeLiveSecurity

LinuxSecurity.com: Fixed a stack-based buffer over-read in the print_prefix function (CVE-2018-19519). References: – https://bugs.mageia.org/show_bug.cgi?id=24077

LinuxSecurity.com: A flaw was found in the i18n gem before 0.8.0 for Ruby. The Hash#slice in lib/i18n/core_ext/hash.rb allows remote attackers to cause a denial of service (application crash) via a call in a situation where :some_key is present in keep_keys but not present in the hash (CVE-2014-10077).

FTC issues warning about a Netflix phishing scam
The most interesting and important hacks of 2018
GDPR’s impact was too soft in 2018, but next year will be different

LinuxSecurity.com: A possible regression was found in the recent security update for libphp-phpmailer, announced as DLA 1591-1. During backporting a new variable have accidentally introduced to a conditional statement from

LinuxSecurity.com: Update to new upstream version 1.5.5 (rhbz#1660413, rhbz#1660414)

LinuxSecurity.com: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

FTC Warns of Netflix Phishing Scam Making Rounds
It’s the end of 2018, and this is your year in security

LinuxSecurity.com: The Shopify Application Security Team discovered that ruby-sanitize, a whitelist-based HTML sanitizer, is prone to a HTML injection vulnerability. A specially crafted HTML fragment can cause to allow non- whitelisted attributes to be used on a whitelisted HTML element.

What should you do with your old devices

Disposal of old tech requires thought and effort and the need to cleanse the device of any personal data is just one of the concerns The post What should you do with your old devices appeared first on WeLiveSecurity

Over 19,000 Orange modems are leaking WiFi credentials
Two-factor authentication can save you from hackers

LinuxSecurity.com: Kaspersky Lab discovered several vulnerabilities in libvncserver, a C library to implement VNC server/client functionalities.

LinuxSecurity.com: Security fix for CVE-2018-16737, CVE-2018-16738, CVE-2018-16758

LinuxSecurity.com: Update to new upstream version 1.5.5 (rhbz#1660413, rhbz#1660414)

LinuxSecurity.com: A security issue fixed upstream in sqlite3 has been announced: https://www.openwall.com/lists/oss-security/2018/12/21/1 The issue is fixed in 3.25.3. References:

LinuxSecurity.com: There is a use-after-free in monit that shows up if you run it for a while on an active system with address sanitizer enabled. References: – https://bugs.mageia.org/show_bug.cgi?id=24049

LinuxSecurity.com: The updated packages fix several bugs and some security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=24041 – https://www.thunderbird.net/en-US/thunderbird/60.4.0/releasenotes/

security update

19K Orange Livebox Modems Open to Attack
Top 2018 Security and Privacy Stories
Congress approves act that opens US government data to the public
Hacker steals ten years worth of data from San Diego school district

LinuxSecurity.com: Multiple vulnerabilities have been found in libsndfile, the library for reading and writing files containing sampled sound. CVE-2017-8361

2019: The Year Ahead in Cybersecurity
Over 500K School Staff and Students Hit by Breach
Facebook let Netflix, Spotify read your private messages
What is ransomware? How these attacks work and how to recover from them
Could you speak up a bit? I didn’t catch your password

LinuxSecurity.com: – Fix double-free in CEmuopl::~CEmuopl() (#1635881, CVE-2018-17825)

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2018-5783, CVE-2018-11254, CVE-2018-11255, CVE-2018-11256, CVE-2018-12982, CVE-2018-14320, CVE-2018-19532

LinuxSecurity.com: This update fixes multiple security vulnerabilities: CVE-2018-5783, CVE-2018-11254, CVE-2018-11255, CVE-2018-11256, CVE-2018-12982, CVE-2018-14320, CVE-2018-19532

LinuxSecurity.com: – Fix double-free in CEmuopl::~CEmuopl() (#1635881, CVE-2018-17825)

LinuxSecurity.com: Several issues were corrected in nagios3, a monitoring and management system for hosts, services and networks. CVE-2018-18245

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3833

LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3831

Critical Bug Patched in Schneider Electric Vehicle Charging Station
San Diego School District Data Breach Hits 500k Students
2018: A Banner Year for Breaches
India authorizes 10 agencies to intercept, monitor, and decrypt citizens’ data
Facebook suspends accounts for pushing false info in Alabama election

LinuxSecurity.com: Fix low-severity CVE-2018-20217 (an authenticated user who can obtain a TGT using an older encryption type (DES, DES3, or RC4) can cause an assertion failure in the KDC by sending an S4U2Self request.)

LinuxSecurity.com: Version update + Security fix for CVE-2018-19131 and CVE-2018-19132

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes two vulnerabilities is now available.

LinuxSecurity.com: An update that fixes one vulnerability is now available.

LinuxSecurity.com: An update that fixes four vulnerabilities is now available.

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: An update that solves three vulnerabilities and has 5 fixes is now available.

LinuxSecurity.com: **MariaDB C / C++ connector** Release notes: https://mariadb.com/kb/en/library/mariadb-connector-c-307-release-notes/ Maintainer notes: Marking as a security update, beacuse of fixed resource leaks. Moving libmariadb pkgconfig file to this package from mariadb- devel. Test with MariaDB-3:10.2.19-2

LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.

LinuxSecurity.com: Multiple vulnerabilities have been found in Go, the worst which could lead to the execution of arbitrary code.

Anonymous social network Blind left user data exposed
Researcher publishes proof-of-concept code for creating Facebook worm
New email extortion scam warns “Pay $4,000 or a hitman is coming for you”
China hacked the US Navy and stole personal info on at least 100K sailors
Iranian APT Group Pegged for Shamoon Disk Wiping Attacks
Caribou Coffee Card Breach Hits 265 Stores

LinuxSecurity.com: New netatalk packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Your two-minute infosec roundup: Drone arrests, Alexa bot hack, Windows zero-day, and more

LinuxSecurity.com: **MariaDB 10.3.11** Release notes: https://mariadb.com/kb/en/mariadb-10311-release-notes/ CVEs fixed: CVE-2018-3282 CVE-2016-9843 CVE-2018-3174 CVE-2018-3143 CVE-2018-3156 CVE-2018-3251 CVE-2018-3185 CVE-2018-3277 CVE-2018-3162 CVE-2018-3173 CVE-2018-3200 CVE-2018-3284

LinuxSecurity.com: Security experts at Tencent’s Blade security team have discovered a critical vulnerability in SQLite database software (nicknamed “Magellan”).

LinuxSecurity.com: Daniel Axtens discovered a double-free and use-after-free vulnerability in libarchive’s RAR decoder that can result in a denial-of-service (application crash) or may have other unspecified impact when a malformed RAR archive is processed.

LinuxSecurity.com: This kernel update is based on the upstream 4.14.89 and fixes atleast the following security issues: Cross-hyperthread Spectre v2 mitigation is now provided by the Single Thread Indirect Branch Predictors (STIBP) support. Note that STIBP also

security update

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit sqlite rebased to version 3.26.0 per: https://sqlite.org/releaselog/3_26_0.html spatialite-tools rebuilt for latest sqlite version

LinuxSecurity.com: Update to 4.2.5

LinuxSecurity.com: Upstream announcement: The phpMyAdmin team is pleased to announce the release of **phpMyAdmin version 4.8.4**. Among other bug fixes, this contains several important security fixes. The security fixes involve: * Local file inclusion (https://www.phpmyadmin.net/security/PMASA-2018-6/), * XSRF/CSRF vulnerabilities allowing a specially-crafted URL to perform harmful operations

FBI Denies Service to 15 DDoS-for-Hire Sites, Charges Operators

Reading Time: ~5 min. The cybersecurity landscape is in constant flux, keeping our team busy researching the newest threats to keep our customers safe. As the new year approaches, we asked our cybersecurity experts to predict which security trends will have the most impact in 2019 and what consumers should prepare for. Continued Growth of […]

Caribou Coffee, Bruegger’s Bagels Bitten by Months-Long Breach
SPARE: Five tips for a safer online shopping experience

There is still some time left to pick up some last-minute shopping before it’s too late but in the rush to do so don’t forget to do it safely The post SPARE: Five tips for a safer online shopping experience appeared first on WeLiveSecurity

Reading Time: ~2 min. Facebook API Bug Reveals Photos from 6.8 Million Users Facebook announced this week that an API bug had been found that allowed third-party apps to access all user photos, rather than only those posted to their timeline. The vulnerability was only available for 12 days in mid-September, but could still impact […]