LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)
LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.
LinuxSecurity.com: An update for openstack-tripleo-heat-templates is now available for Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Federal agency issues Notices of Violation to Datablocks and Sunlight Media for allegedly facilitating the installation of malware through online advertising The post Canada tackles malicious online advertising appeared first on WeLiveSecurity
LinuxSecurity.com: The dns-root-data update to 2017072601~deb8u2 broke dnsmasq’s init script, making dnsmasq no longer start when dns-root-data was installed.
Reading Time: ~2 min.Venmo’s Public Data Setting Shows All Researchers recently uncovered just how much data is available through the Venmo API, successfully tracking routines, high-volume transactions from vendors, and even monitoring relationships. Because Venmo’s privacy settings are set to public by default, many users have unknowingly contributed to the immense collection of user data […]
LinuxSecurity.com: The linux-base package has been updated to support the package of Linux 4.9 that was recently added to Debian 8. This resolves a dependency that was not satisfiable by the jessie and jessie-security suites.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: CVE-2015-1239 Fix for denial of service (process crash) via a crafted PDF.
security update
security update
LinuxSecurity.com: Fix heap memory corruption, CVE-2017-17833
LinuxSecurity.com: – Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) – Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) – Fix two-key 3DES (PR #390) – Fix accelerated CTR mode (PR #359) – Fix Fortuna PRNG (PR #363) – Fix compilation on platforms where cc doesn’t point to gcc (PR #382) […]
LinuxSecurity.com: This release fixes a directory and symbolic link traversal vulnerability in Archive::Zip::Archive Perl module that allows an attacker to writite into an arbitrary file accesible by a local user.
LinuxSecurity.com: Update to 0.26.5 (CVE-2018-10887, CVE-2018-10888)
LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.
LinuxSecurity.com: Linux 4.9 has been packaged for Debian 8 as linux-4.9. This provides a supported upgrade path for systems that currently use kernel packages from the “jessie-backports” suite.
LinuxSecurity.com: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Tech giant has 90 days to comply with ruling or faces further penalties over ‘anti-competitive’ practices The post Google slapped with €4.34bn fine by EU over antitrust violations appeared first on WeLiveSecurity
LinuxSecurity.com: An update for fluentd is now available for Red Hat OpenStack Platform 13.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: This is the Six-Month notification for the retirement of Red Hat Enterprise Linux 6.7 Extended Update Support (EUS). This notification applies only to those customers subscribed to the Extended Update Support (EUS) channel for Red Hat Enterprise Linux 6.7.
LinuxSecurity.com: unzip and untar target tasks in ant allows the extraction of files outside the target directory. A crafted zip or tar file submitted to an Ant build could create or overwrite arbitrary files with the
Thousands of British Airways passengers left stranded at Heathrow airport following incident The post British Airways cancelled flights at Heathrow after ‘IT system issue’ appeared first on WeLiveSecurity
LinuxSecurity.com: Jeriko One discovered two vulnerabilities in the ZNC IRC bouncer which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in
LinuxSecurity.com: A use-after-free was discovered in the MP4 demuxer of the VLC media player, which could result in the execution of arbitrary code if a malformed media file is played.
LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: CVE-2018-11439 Fix for a heap-based buffer over-read via a crafted audio file.
security update
security update
LinuxSecurity.com: New release (1:12.2.6-1) Security fix for CVE-2018-1128 Security fix for CVE-2018-1129 Security fix for CVE-2018-10861
LinuxSecurity.com: The package curl before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-libcurl-gnutls before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-libcurl-compat before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-curl before version 7.61.0-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: Several security issues were fixed in PolicyKit.
