A reflection on how acknowledging the cumulative nature of cyber-threats and understanding its implications can benefit our digital security The post What is threat cumulativity and what does it mean for digital security? appeared first on WeLiveSecurity
LinuxSecurity.com: Multiple issues were fixed in Qt. CVE-2018-15518 A double-free or corruption during parsing of a specially crafted
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
security update
LinuxSecurity.com: This update includes the changes in tzdata 2018i for the Perl bindings. For the list of changes, see DLA-1625-1. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: This update includes the changes in tzdata 2018i. Notable changes are: – Qyzylorda, Kazakhstan moved from +06 to +05 on 2018-12-21. A new
LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For Debian 8 “Jessie”, this problem has been fixed in version
LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.
LinuxSecurity.com: Fix CVEs as described in related RHBZ bug.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
The message starts off with the kind of information that is apt to send shivers down the spines of many binge-watchers The post This Netflix-themed scam prompts FTC to issue warning appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: Multiple security issues have been found in Thunderbird, which may lead to the execution of arbitrary code or denial of service. For the stable distribution (stretch), this problem has been fixed in
LinuxSecurity.com: Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment. (CVE-2018-19149) References:
LinuxSecurity.com: An issue was discovered in lxml before 4.2.5. lxml/html/clean.py in the lxml.html.clean module does not remove javascript: URLs that use escaping, allowing a remote attacker to conduct XSS attacks, as demonstrated by “j a v a s c r i p t:” in Internet Explorer (CVE-2018-19787).
LinuxSecurity.com: Possible denial of service vulnerability due to a missing check in Lib/wave.py to verify that at least one channel is provided (CVE-2017-18207). Python’s elementtree C accelerator failed to initialise Expat’s hash
LinuxSecurity.com: Graphicsmagick has been updated to fix several bugs and security issues. References: – https://bugs.mageia.org/show_bug.cgi?id=23157 – http://www.graphicsmagick.org/NEWS.html#november-17-2018
LinuxSecurity.com: debian-security-support, the Debian security support coverage checker, has been updated in jessie. The jessie relevant changes are: * Mark jasperreports as end-of-life in Jessie.
Did malware disrupt newspaper deliveries in major US cities? Here’s what’s known about the incident so far and the leading suspect: Ryuk ransomware. Plus, advice on defending your organization against such attacks. The post Ransomware vs. printing press? US newspapers face “foreign cyberattack” appeared first on WeLiveSecurity
As the curtain slowly falls on yet another eventful year in cybersecurity, let’s look back on some of the finest malware analysis by ESET researchers in 2018 The post 2018: Research highlights from ESET’s leading lights appeared first on WeLiveSecurity
LinuxSecurity.com: It was discovered that there was a potential denial of service vulnerability in tar, the GNU version of the tar UNIX archiving utility.
LinuxSecurity.com: Updated to 3.3.4. Security fix by upstream: Anti-Phishing protection.. Server-provided text will not appear in user-facing GUI windows anymore. Server error messages are instead parsed and mapped to predefined strings.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: Multiple vulnerabilities have been found in Rust, the worst which may allow local attackers to execute arbitrary code.
LinuxSecurity.com: A vulnerability in GKSu might allow attackers to execute arbitrary commands.
LinuxSecurity.com: An update that fixes 6 vulnerabilities is now available.
LinuxSecurity.com: An update that solves four vulnerabilities and has 17 fixes is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that solves 9 vulnerabilities and has four fixes is now available.
LinuxSecurity.com: An update that fixes 5 vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: **Archive_Tar version 1.4.4** * Fix Bug #21058: Long symlinks are not supported [mrook] * Fix Bug #23782: Prevent phar:// files from being extracted [mrook] — **PEAR** * drop deprecated option used when running `pear run-tests`
LinuxSecurity.com: This update fixes CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149.
LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.
LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
security update
LinuxSecurity.com: This update fixes CVE-2017-18267, CVE-2018-13988, CVE-2018-16646, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149
LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616
LinuxSecurity.com: This update fixes CVE-2018-18088 and CVE-2018-6616
LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.
LinuxSecurity.com: Update to leptonica-1.77.0, see http://www.leptonica.com/source/version- notes.html for details.
LinuxSecurity.com: Security fix for fts3/4 corrupt database exploit
LinuxSecurity.com: Security fix for CVE-2018-16869
LinuxSecurity.com: Several vulnerabilities were discovered in libextractor, a library to extract arbitrary meta-data from files, which may lead to denial of service or memory disclosure if a malformed OLE file is processed.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
security update
security update
LinuxSecurity.com: A XML External Entity (XXE) vulnerability was discovered in c3p0, a library for JDBC connection pooling, that may be used to resolve information outside of the intended sphere of control.
LinuxSecurity.com: Multiple security issues were found in libarchive, a multi-format archive and compression library: Processing malformed RAR archives could result in denial of service or the execution of arbitrary code and malformed WARC, LHarc, ISO, Xar or CAB archives could result in denial of service.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code.
LinuxSecurity.com: Some vulnerabilities were discovered in ghostscript, an interpreter for the PostScript language and for PDF.
Reading Time: ~2 min. Amazon User Receives Thousands of Alexa-Recorded Messages Upon requesting all his user data from Amazon, one user promptly received over 1,700 recorded messages from an Alexa device. Unfortunately, the individual didn’t own such a device. The messages were from a device belonging to complete stranger, and some of them could have easily […]
