The latest ESET research offers a rare glimpse into the mechanics of a particularly stealthy and resilient backdoor that the Turla cyberespionage group can fully control via PDF files attached to emails The post Turla: In and out of its unique Outlook backdoor appeared first on WeLiveSecurity
LinuxSecurity.com: Dariusz Tytko, Michal Sajdak and Qualys Security discovered that OpenSSH, an implementation of the SSH protocol suite, was prone to a user enumeration vulnerability. This would allow a remote attacker to check whether a specific user account existed on the target server.
LinuxSecurity.com: New libX11 packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
Type: Vulnerability. Microsoft Internet Explorer is prone to an unspecified arbitrary code-execution vulnerability; fixes are available.
LinuxSecurity.com: An update for mutt is now available for Red Hat Enterprise Linux 6 and Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: wpa_supplicant and hostapd could be made to expose sensitiveinformation if it received a crafted message.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Internet-connected irrigation systems suffer from security gaps that could be exploited by attackers aiming, for example, to deplete a city’s water reserves, researchers warn The post Smart irrigation systems vulnerable to attacks, warn researchers appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in OpenJDK 10.
LinuxSecurity.com: USN-3742-2 introduced regressions in the Linux Hardware Enablement(HWE) kernel for Ubuntu 12.04 ESM.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2439
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2462
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2526
LinuxSecurity.com: ClamAV, an anti-virus utility for Unix, has released the version 0.100.1. Installing this new version is required to make use of all current virus signatures and to avoid warnings.
security update
LinuxSecurity.com: An attacker could trick APT into installing altered packages.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update for openstack-keystone is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: An update for openvswitch is now available for Red Hat OpenStack Platform 12.0 (Pike). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: Multiple researchers have discovered a vulnerability in the way the Intel processor designs have implemented speculative execution of instructions in combination with handling of page-faults. This flaw could allow an attacker controlling an unprivileged process to read
An overview of some of the cyberattacks that Canadian organizations faced in the summer months of 2018 The post A heated summer for cybersecurity in Canada appeared first on WeLiveSecurity
LinuxSecurity.com: An update for rh-postgresql95-postgresql is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
LinuxSecurity.com: CVE-2018-14767 Fix for missing input validation, which could result in denial of service and potentially the execution of arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities were discovered in Jetty, a Java servlet engine and webserver which could result in HTTP request smuggling. For the stable distribution (stretch), these problems have been fixed in
LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)
LinuxSecurity.com: New upstream release fixing YSA-2018-03 (#1613863)
LinuxSecurity.com: New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
security update
security update
security update
LinuxSecurity.com: Several vulnerabilities were discovered in Mutt, a text-based mailreader supporting MIME, GPG, PGP and threading, potentially leading to code execution, denial of service or information disclosure when connecting to a malicious mail/NNTP server.
Risk Level: Very Low. Type: Trojan.
