LinuxSecurity.com: The package webkit2gtk before version 2.22.4-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package flashplugin before version 31.0.0.153-1 is vulnerable to arbitrary code execution.
LinuxSecurity.com: The package lib32-libtiff before version 4.0.10-1 is vulnerable to multiple issues including arbitrary code execution, denial of service and information disclosure.
LinuxSecurity.com: It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path
LinuxSecurity.com: A critical vulnerability in Adobe Flash Player 31.0.0.148 and earlier versions. Successful exploitation could lead to arbitrary code execution in the context of the current user. (CVE-2018-15981) References:
LinuxSecurity.com: In Poppler 0.68.0, the Parser::getObj() function in Parser.cc may cause infinite recursion via a crafted file. A remote attacker can leverage this for a DoS attack. (CVE-2018-16646) An issue was discovered in Poppler 0.71.0. There is a reachable abort in
LinuxSecurity.com: The ghostscript 9.26 update is focusing on security issues, including solving several (well publicised) real and potential exploits. For other fixes in this release, see the referenced News.
LinuxSecurity.com: Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, incomplete TLS identity verification, information disclosure or the execution of arbitrary code.
LinuxSecurity.com: mod_perl could be made to run programs contrary to expectations.
LinuxSecurity.com: Several security vulnerabilities were discovered in the JasPer JPEG-2000 library. CVE-2015-5203
LinuxSecurity.com: It was discovered that there was an XSS vulnerability in the ruby-rack web-server library. A malicious request could impact the HTTP/HTTPS scheme being returned
The software giant takes passwords one step closer to obsolescence as it now enables users to log into their Microsoft accounts with more modern forms of authentication The post Who needs passwords? Microsoft now lets you in with your face or security key appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: CVE-2018-0735 Samuel Weiser reported a timing vulnerability in the OpenSSL ECDSA signature generation, which might leak information to recover the
LinuxSecurity.com: The update for ceph issued as DSA-4339-1 caused a build regression for the i386 builds. Updated packages are now available to address this issue. For reference, the original advisory text follows.
LinuxSecurity.com: An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. (CVE-2018-18751)
LinuxSecurity.com: This is a service release to update the stable version 1.3 of Roundcube Webmail. It contains fixes to several bugs backported from the master branch including a security fix for a reported XSS vulnerability (in handling invalid style tag content) plus updates to ensure compatibility with PHP 7.3 and recent versions of Courier-IMAP, Dovecot […]
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:3409
Reading Time: ~4 min.As digital natives become more immersed in and dependent upon technology, they are likely to experience “cyber fatigue,” which can be thought of cybersecurity complacency. Paired with the invincible feeling that often accompanies being young, this can be a dangerous combination. It’s easy to mistakenly believe that hacked devices and identity theft […]
LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.7.72 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
The breach exposed the personal data of 160,000 people and cost the telecom company £77 million The post Two Brits jailed for TalkTalk hack appeared first on WeLiveSecurity
LinuxSecurity.com: It was discovered that there was a remote denial-of-service vulnerability in ruby-i18n, a I18n and localization solution for Ruby. An application crash could be engineering a situation where `:some_key` is
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 18 vulnerabilities is now available.
LinuxSecurity.com: A stack based buffer overflow vulnerability was found in liblivemedia, the LIVE555 RTSP server library. This issue might be leveraged by remote attackers to cause code execution, by sending a crafted packet.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has three fixes is now available.
security update
LinuxSecurity.com: The package grafana before version 5.3.4-1 is vulnerable to arbitrary filesystem access.
In August 2018, Sednit’s operators deployed two new Zebrocy components, and since then we have seen an uptick in Zebrocy deployments, with targets in Central Asia, as well as countries in Central and Eastern Europe, notably embassies, ministries of foreign affairs, and diplomats. The post Sednit: What’s going on with Zebrocy? appeared first on WeLiveSecurity
ESET researchers identified 21 distinct websites that had been compromised including some particularly notable government and media sites The post OceanLotus: New watering hole attack in Southeast Asia appeared first on WeLiveSecurity
LinuxSecurity.com: It was discovered that mishandled search requests in servers/slapd/search.c:do_search() in 389-ds-base allows for denial of service (CVE-2018-14648). References:
LinuxSecurity.com: mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user’s credentials. If the header value is not present in the charset conversion table, a fallback mechanism is used to truncate it to a two characters value to allow a quick retry (for example,
LinuxSecurity.com: Assertion failure in BPMDetect class in BPMDetect.cpp (CVE-2018-17096). Out-of-bounds heap write in WavOutFile::write() (CVE-2018-17097). Heap corruption in WavFileBase class in WavFile.cpp (CVE-2018-17098). References:
LinuxSecurity.com: Multiple vulnerabilities have been discovered in uriparser, an Uniform Resource Identifiers (URIs) parsing library.
LinuxSecurity.com: The package chromium before version 70.0.3538.110-1 is vulnerable to information disclosure.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec. CVE-2017-17480
LinuxSecurity.com: Red Hat OpenShift Container Platform release 3.9.51 is now available with updates to packages and images that fix several bugs. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
