LinuxSecurity.com: A vulnerability in the HTML_QuickForm package has been found which potentially allows remote code execution. References: – https://bugs.mageia.org/show_bug.cgi?id=24185
LinuxSecurity.com: It was discovered that libcaca incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service (CVE-2018-20544). It was discovered that libcaca incorrectly handled certain images. An
LinuxSecurity.com: An issue has been found in PowerDNS Recursor where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced using Lua (CVE-2019-3806).
Risk Level: Very Low. Type: Trojan.
Everybody loves quizzes. So why not take this one and hone your phish-spotting prowess? The post Can you spot the phish? Take Google’s test appeared first on WeLiveSecurity
LinuxSecurity.com: Security fix for CVE-2018-20551, CVE-2018-20481, CVE-2018-20650 and CVE-2018-18897.
LinuxSecurity.com: – xattr: strip credentials from any URL that is stored (CVE-2018-20483)
LinuxSecurity.com: Security fix for CVE-2019-5010 in Python. Anaconda is joined because an unrelated fix was done there that allowed to remove a workaround in Python.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes four vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Reading Time: ~3 min. Fitness trackers and other digital wearables have unlocked a new era of convenience and engagement in consumer health. Beyond general fitness trackers, you can find wearables for a variety of purposes; some help diabetics, some monitor for seizure activity, and some can aid in senior citizens’ health and quality of life. […]
The plugin’s users are recommended to change their passwords on WPML’s website following havoc reportedly wrought by a disgruntled ex-employee The post Former employee blamed for hack of WordPress plugin maker appeared first on WeLiveSecurity
LinuxSecurity.com: New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
LinuxSecurity.com: Multiple vulnerabilities were found in the journald component of systemd which can lead to a crash or code execution. CVE-2018-16864
LinuxSecurity.com: Fix for CVE-2019-5885 Upgrade notes available at https://github.com/matrix- org/synapse/blob/v0.34.0/UPGRADE.rst#upgrading-to-v0340 – Note this continues to use Python 2.
LinuxSecurity.com: Several vulnerabilities have been resolved in libjpeg-turbo, Debian’s default JPEG implemenation. CVE-2016-3616
France’s data protection watchdog issues the first major penalty under the EU’s new privacy regime The post Google fined €50 million for violating EU data privacy rules appeared first on WeLiveSecurity
A strong password is a great start, but there are more ways to make sure that your email is as secure as possible The post Email security does not end with your password appeared first on WeLiveSecurity
LinuxSecurity.com: It was discovered that aria2 (the lightweight command-line download utility) can store passed user credentials in a log file when using the –log option. This might allow local users to obtain sensitive information by reading this file.
security update
If you use Twitter for Android and want your tweets to be private, you may want to play safe and review your settings The post Twitter bug may have exposed private tweets of Android users for years appeared first on WeLiveSecurity
LinuxSecurity.com: admin: Prevent access if any authentication agent isn’t available
LinuxSecurity.com: Fix for use after free in affile_dw_reap
LinuxSecurity.com: libssh versions 0.6 and above have an authentication bypass vulnerability in the server code. By presenting the server an SSH2_MSG_USERAUTH_SUCCESS message in place of the SSH2_MSG_USERAUTH_REQUEST message which the server would expect to initiate authentication, the attacker could successfully authentciate
