security update
LinuxSecurity.com: The package zathura-pdf-mupdf before version 0.3.3-3 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 5 and Red Hat JBoss Enterprise Application Platform 5 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update is now available for Red Hat JBoss Enterprise Application Platform. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: The package runc before version 1.0.0rc5+19+g69663f0b-1 is vulnerable to privilege escalation.
LinuxSecurity.com: An update is now available for Red Hat JBoss Data Grid. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266
The Dark Overlord, known for a number of breaches and cyber-extortion campaigns in the last two years, is believed to have made US$275,000 from various schemes The post Suspected member of The Dark Overlord arrested in Serbia appeared first on WeLiveSecurity
LinuxSecurity.com: New upstream bugfix release, includes security fix for CVE-2017-18266
With the deadline fast approaching SMBs are reminded of what is required to become compliant The post Last call for GDPR appeared first on WeLiveSecurity
LinuxSecurity.com: New php packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.
LinuxSecurity.com: New curl packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.
LinuxSecurity.com: OSS-fuzz, assisted by Max Dymond, discovered that cURL, an URL transfer library, could be tricked into reading data beyond the end of a heap based buffer when parsing invalid headers in an RTSP response.
LinuxSecurity.com: It was discovered that there was an issue in the curl a command-line tool for downloading (eg.) data over HTTP. curl could have be tricked into reading data beyond the end of a heap
security update
LinuxSecurity.com: Several security issues were fixed in PHP.
The move is intended to help address the mobile platform’s perennial problem – that many manufacturers of Android-powered devices are slow to get software updates out the door The post Google to require Android device-makers to roll out OS security patches regularly appeared first on WeLiveSecurity
Recent survey shows that adults in the US view computer hacking as a major threat to their quality of life The post Seven out of ten see criminal hacking as big risk to health, safety, prosperity appeared first on WeLiveSecurity
security update
Reading Time: ~2 min.Smartphone apps make life easier, more productive, and more entertaining. But can you trust every app you come across? Malicious mobile apps create easy access to your devices for Android and iOS malware to wreak havoc. And there are many untrusted and potentially dangerous apps lurking around in app stores determined to […]
A team of academics says that, if exploited, the vulnerabilities can reveal the plain text of encrypted emails, including those sent years ago The post Researchers reveal flaws that may expose encrypted emails to prying eyes appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in PHP.
Double zero-day vulnerabilities fused into one. A mysterious sample enables attackers to execute arbitrary code with the highest privileges on intended targets The post A tale of two zero-days appeared first on WeLiveSecurity
LinuxSecurity.com: A vulnerability has been found in mpv that may allow a remote attacker to execute arbitrary code.
LinuxSecurity.com: The package firefox before version 60.0-1 is vulnerable to multiple issues including arbitrary code execution, same-origin policy bypass, access restriction bypass, content spoofing, denial of service, information disclosure and sandbox escape.
LinuxSecurity.com: The package webkit2gtk before version 2.20.2-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package llpp before version 27-2 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: Fabian Vogt discovered that incorrect permission handling in the PAM module of the KDE Wallet could allow an unprivileged local user to gain ownership of arbitrary files.
LinuxSecurity.com: Security fix for CVE-2018-10380
LinuxSecurity.com: Security fix for CVE-2018-10380
Do you still remember how WannaCryptor ran its – winding – course? It was a tale that revealed a number of intriguing plot lines amid the ransomworm’s numerous twists and turns. The post WannaCryptor: The curious tale of a ravenous cryptoworm appeared first on WeLiveSecurity
