LinuxSecurity.com: New release (1:12.2.2-1), security fix for CVE-2017-16818
LinuxSecurity.com: Update to latest version. Contains security fixes for CVE-2017-15090, CVE-2017-15092, CVE-2017-15093 and CVE-2017-15094
LinuxSecurity.com: Upstream annoucement: [WordPress 4.9.1 Security and Maintenance Release](https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and- maintenance-release/)
LinuxSecurity.com: This is an update fixing denial of service (CVE-2017-16944). —- This is an update fixing use-after-free (CVE-2017-16943).
LinuxSecurity.com: Fix to directory traversal attacks (CVE-2017-17042).
LinuxSecurity.com: * CVE-2017-1000256: libvirt: TLS certificate verification disabled for clients (bz #1503687) * Fix qemu image locking with shared disks (bz #1513447)
LinuxSecurity.com: * Ver. 19.3.6.4
LinuxSecurity.com: The simplesamlphp package in wheezy is vulnerable to multiple attacks on authentication-related code, leading to unauthorized access and information disclosure.
LinuxSecurity.com: Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-15407
A breakdown of the ‘spending pie’ shows that the ‘security services’ segment is projected to make up nearly 60% of the total IT security budgets, followed by the ‘infrastructure protection’ segment on a little over 18%. The post Enterprise security spend to continue to trend higher appeared first on WeLiveSecurity
LinuxSecurity.com: An update for org.ovirt.engine-root is now available for Red Hat Virtualization Manager version 4.1. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
security update
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft PowerPoint is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Exchange Server is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft SharePoint is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer are prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Excel is prone to a remote code-execution vulnerability; fixes are available.
security update
security update
As 2017 comes to a close, we’re looking back at the 10 most significant (or simply the most devastating) cybersecurity stories of the year. Read through the list below to see which attacks, data breaches, and other events left a lasting impact on both the security industry and the global online community overall. Which story […]
Besides delivering the promised functionalities, the malicious apps can display fake notifications and login forms seemingly coming from legitimate banking applications, harvest credentials entered into the fake forms, as well as intercept text messages to bypass SMS-based 2-factor authentication. The post Banking malware on Google Play targets Polish banks appeared first on WeLiveSecurity
Businesses are often sent fake invoices and waybills which install ransomware. Teach staff to avoid these. If questionable, ask your IT dept to look at it. E-cards have been a target in the past and may be used again in holiday-themed attacked. The post Happy holidays, scam spotters! appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: It discovered that the Private Browsing mode in the Mozilla Firefox web browser allowed to fingerprint a user across multiple sessions via IndexedDB.
LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the oldstable distribution (jessie), these problems have been fixed
LinuxSecurity.com: – fix NTLM buffer overflow via integer overflow (CVE-2017-8816) – fix FTP wildcard out of bounds read (CVE-2017-8817)
LinuxSecurity.com: Update to latest upstream version.
security update
security update
LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for CIP Safety, IWARP_MPA, NetBIOS, Profinet I/O and AMQP, which result in denial of dervice or the execution of arbitrary code.
LinuxSecurity.com: An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two An update that solves three vulnerabilities and has two fixes is now available. fixes is now available.
LinuxSecurity.com: This is a cumulative update to the Mozilla CA certificates trust list version 2.20, which has been published as part of Mozilla NSS 3.34.1. It also includes the changes that were previously released as version 2.18 as part of NSS 3.34. For additional details, please refer to the release notes of NSS 3.34.1 https://developer.mozilla.org/en-
LinuxSecurity.com: Patch CVE-2017-16927.
LinuxSecurity.com: Upstream released new version. See https://collectd.org/news.shtml#news106 for the list of changes. Fixes CVE-2017-16820 (double free in snmp plugin)
LinuxSecurity.com: New openssl packages are available for Slackware 14.2 and -current to fix security issues.
security update
security update
security update
As we reported in September, in campaigns we detected in two different countries, man-in-the-middle attacks had been used to spread FinFisher, with the “man” in both cases most likely operating at the ISP level. The post StrongPity2 spyware replaces FinFisher in MitM campaign – ISP involved? appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available. An update that fixes 18 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 41 vulnerabilities is now available. An update that fixes 41 vulnerabilities is now available. An update that fixes 41 vulnerabilities is now available.
LinuxSecurity.com: An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes is now available. is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes An update that solves 5 vulnerabilities and has three fixes is now available. is now available.
