Risk Level: Very Low. Type: Trojan.
If undetected by a user’s security solution or content- or ad-blocker, the script ran in the background unbeknown to the user until the webpage was closed. A number of the affected websites, including that of the ICO, were also offline for hours in the aftermath of the attack. The post US and UK government websites […]
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: It was discovered that there was an input validation vulnerability in the librsvg renderer library that could result in data being leaked to remote attackers via a specially-crafted file.
LinuxSecurity.com: Chris Navarrete from Fortinet’s FortiGuard Labs discovered that Audacity, a multi-track audio editor, contains a vulnerability such that a .wav file with a crafted FORMATCHUNK structure (many channels) can result in
LinuxSecurity.com: Multiple vulnerabilities have been found in VirtualBox, the worst of which could allow an attacker to take control of VirtualBox.
LinuxSecurity.com: Jonas Klempel discovered that, when parsing the AIA-Extension field of a client certificate, Apache Tomcat Native did not correctly handle fields longer than 127 bytes. The result of the parsing error was to skip the
security update
security update
LinuxSecurity.com: It was discovered that the uwsgi_expand_path function in utils.c in Unbit uWSGI, an application container server, has a stack-based buffer overflow via a large directory length that can cause a denial-of-service (application crash) or stack corruption.
security update
LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted
LinuxSecurity.com: Meh Chang discovered a buffer overflow flaw in a utility function used in the SMTP listener of Exim, a mail transport agent. A remote attacker can take advantage of this flaw to cause a denial of service, or potentially the execution of arbitrary code via a specially crafted
LinuxSecurity.com: Security fix for CVE-2017-15698
LinuxSecurity.com: PostgreSQL could be made to expose sensitive information.
LinuxSecurity.com: The package clamav before version 0.99.3-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 70 fixes is now available.
LinuxSecurity.com: Lalith Rallabhandi discovered that OmniAuth, a Ruby library for implementing multi-provider authentication in web applications, mishandled and leaked sensitive information. An attacker with access to the callback environment, such as in the case of a crafted web
LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package plasma-workspace before version 5.12.0-1 is vulnerable to arbitrary command execution.
LinuxSecurity.com: The package go-pie before version 1.9.4-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package go before version 1.9.4-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 44 fixes is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
Type: Vulnerability. Microsoft Internet Information Services is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Adobe Flash Player is prone to an unspecified remote code-execution vulnerability; fixes are available.
LinuxSecurity.com: Mailman could be made to run arbitrary code.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Security fix for CVE-2017-15698
This is aimed at improving security at the time of the handshake, which is when the key is being exchanged. As a result, WPA3 is poised to provide robust security even if short or weak passwords are used, i.e. those that don’t contain a combination of letters, numbers and symbols. The post How will WPA3 […]
LinuxSecurity.com: simplesamlphp, an authentication and federation application has been found vulnerable to Cross Site Scripting (XSS), signature validation byepass and using insecure connection charset.
LinuxSecurity.com: The mailman package has a Cross-site scripting (XSS) vulnerability in the web UI before 2.1.26 which allows remote attackers to inject arbitrary web script or HTML via a user-options URL
The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. New Variant of Scarab Ransomware With a few interesting changes to the original Scarab ransomware, Scarabey is […]
LinuxSecurity.com: A regression was detected in the previously issued fix for CVE-2018-6360. The patch released with DSA 4105-1 broke the feature of invoking mpv with raw YouTube ids. This update fixes this functionality issue. For reference, the relevant part of the original advisory text follows.
LinuxSecurity.com: An update that solves two vulnerabilities and has 17 fixes is now available.
security update
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
security update
security update
LinuxSecurity.com: An update for flash-plugin is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
LinuxSecurity.com: An update that solves 9 vulnerabilities and has 68 fixes is now available.
LinuxSecurity.com: Several security issues were fixed in Django.
LinuxSecurity.com: Security fixes for CVE-2017-17485 and CVE-2018-5968.
According to US authorities, the enterprise aimed at becoming the premier destination for the buying and selling of stolen payment card data and forged identification documents. It is believed that the losses that the Infraud Organization had intended to cause were north of $2.2 billion. The post Global cybercrime behemoth busted, 36 people indicted appeared […]
LinuxSecurity.com: An update is now available for Red Hat JBoss Core Services. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: It was discovered that the webhook validation of Anymail, a Django email backends for multiple ESPs, is prone to a timing attack. A remote attacker can take advantage of this flaw to obtain a WEBHOOK_AUTHORIZATION secret and post arbitrary email tracking events.
security update
LinuxSecurity.com: A vulnerabilities has been found in the PostgreSQL database system: CVE-2018-1053
Type: Vulnerability. Adobe Flash Player is prone to an remote code-execution vulnerability; fixes are available.
