Besides the usual suspects among the worst of passwords, a handful of notable – but similarly poor – choices make their debuts The post The most popular passwords of 2018 revealed: Are yours on the list? appeared first on WeLiveSecurity
LinuxSecurity.com: Updated packages are now available for Red Hat Gluster Storage 3.4 Web Administration on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: – Update to 2.14.1 – CVE-2018-19608 (#1656784) Release notes: https://tls.mbed.org/tech- updates/releases/mbedtls-2.14.1-2.7.8-and-2.1.17-released Security Advisory: https://tls.mbed.org/tech-updates/security-advisories/mbedtls-security- advisory-2018-03 —- – Update to 2.14.0 Release notes:
LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644
LinuxSecurity.com: New upstream version 1.8.2. Fix low priority security issue with TLS: https://www.redhat.com/archives/libguestfs/2018-December/msg00047.html —- New upstream version 1.8.1. —- Rebase to new stable version 1.8.0. —- nbdkit metapackage should depend on versioned -server subpackage etc. —- New upstream version 1.6.3.
LinuxSecurity.com: Fixes CVE-2018-16855 (Crafted query can cause a denial of service) —- New upstream release with security fixes for CVE-2018-10851, CVE-2018-14626 and CVE-2018-14644
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
LinuxSecurity.com: Cache side-channel variant of the Bleichenbacher attack.(CVE-2018-12404) References: – https://bugs.mageia.org/show_bug.cgi?id=23972 – https://developer.mozilla.org/en-US/docs/Mozilla/Projects/NSS/NSS_3.36.6_release_notes
LinuxSecurity.com: A buffer overflow and out-of-bounds read can occur in TextureStorage11 within the ANGLE graphics library, used for WebGL content. This results in a potentially exploitable crash (CVE-2018-17466). A use-after-free vulnerability can occur after deleting a selection
LinuxSecurity.com: – Buffer overflow using computed size of canvas element. (CVE-2018-12359) – Use-after-free when using focus(). (CVE-2018-12360) – Integer overflow in SwizzleData. (CVE-2018-12361)
LinuxSecurity.com: It was discovered there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack (CVE-2018-19208). References:
LinuxSecurity.com: A vulnerability in Scala could result in privilege escalation.
LinuxSecurity.com: Multiple vulnerabilities have been found in SpamAssassin, the worst of which may lead to remote code execution.
LinuxSecurity.com: Multiple vulnerabilities have been found in CouchDB, the worst of which could lead to the remote execution of code.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves 8 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: Several vulnerabilities have been discovered in Samba, a SMB/CIFS file, print, and login server for Unix. The Common Vulnerabilities and Exposures project identifies the following issues:
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Reading Time: ~2 min. Clemson Supercomputer Susceptible to Cryptojacking IT staff at Clemson University have been working to remove the recent introduction of a cryptominer on its supercomputer, known as Palmetto. As they compromised the system for the mining of Monero, the attackers’ ploy was only spotted due to spikes in computing power and rising operating […]
LinuxSecurity.com: This update fixes libstdc++ std::future support on armel, which is necessary to get firefox-esr and thunderbird updates built on that architecture.
As the threat of bogus apps continues, what can we do to protect ourselves against these fraudulent practices? The post How to protect yourself as the threat of scam apps grows appeared first on WeLiveSecurity
security update
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5.9 Long Life. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: The package firefox before version 64.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass and access restriction bypass.
Reading Time: ~2 min. Virtual Private Networks (VPNs) are quickly becoming a fundamental necessity for staying safe online. From large corporations to family households, people are turning to VPNs to ensure their data is encrypted end to end. But as with any emerging technology, it’s easy to become overwhelmed with new and untested VPN options. […]
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves three vulnerabilities and has one errata is now available.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com:
LinuxSecurity.com: Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or bypass of the same-origin policy.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows Azure Pack is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Dynamics NAV is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft PowerPoint is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Exchange Server is prone to a security bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Excel is prone to an information-disclosure vulnerability; fixes are available.
