LinuxSecurity.com: This update fixes CVE-2018-20685 (the first “variant”) and backports several fixes to unbreak ECDSA authentication from PKCS#11, certificate authentication and so on.
LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).
LinuxSecurity.com: **Horde_Form 2.0.19** * [mjr] SECURITY: Prevent RCE vulnerability due to potential directory traversal in Image uploads (An independent security researcher has reported this vulnerability to SecuriTeam Secure Disclosure program).
LinuxSecurity.com: Patch for CVE-2016-10091
LinuxSecurity.com: Keegan Ryan discovered that NSS incorrectly handled ECDSA key generation. A local attacker could possibly use this issue to perform a cache-timing attack and recover private ECDSA keys (CVE-2018-0495). References:
LinuxSecurity.com: A heap use-after-free vulnerability in the server code of the file transfer extension, which can result in remote code execution. This attack appears to be exploitable via network connectivity (CVE-2018-6307).
LinuxSecurity.com: It was observed that URL’s which gets downloaded via “–log=” attribute stores sensitive information. This update fixes that. References: – https://bugs.mageia.org/show_bug.cgi?id=24112
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
security update
security update
LinuxSecurity.com: Several issues in wireshark, a tool that captures and analyzes packets off the wire, have been found by different people. These are basically issues with length checks or invalid memory access in
LinuxSecurity.com: libvncserver: Heap out-of-bounds write in rfbserver.c in rfbProcessFileTransferReadBuffer() allows for potential code execution (CVE-2018-15127) SL7 x86_64 libvncserver-0.9.9-13.el7_6.i686.rpm libvncserver-0.9.9-13.el7_6.x86_64.rpm libvncserver-debuginfo-0.9.9-13.el7_6.i686.rpm libvncserver-debuginfo-0.9.9-13.el7_6.x86_64.rpm libvncserver-devel-0.9.9-13.el7_6.i686.rpm [More…]
LinuxSecurity.com: Several security issues were fixed in libcaca.
Forget balaclavas or hoodies, these cybercriminals are hiding in plain sight The post What makes a cybercriminal? appeared first on WeLiveSecurity
Reading Time: ~2 min. For many MSPs, integrating their security solution with their remote monitoring and management (RMM) and professional service automation (PSA) platforms is essential for doing business. Together, these platforms help lower the cost of keeping up with each client, ensuring profitable margins for a healthy, growing business. For true providers of IT […]
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2019:0049
LinuxSecurity.com: An update for libvncserver is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: The v4.19.14 stable update contains important fixes across the tree.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
security update
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: An update for systemd is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
In our final report from CES we take a look at smart city initiatives The post CES: Smart cities and the challenge of securing the neighborhood appeared first on WeLiveSecurity
LinuxSecurity.com: New zsh packages are available for Slackware 14.0, 14.1, and 14.2 to fix security issues.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves one vulnerability and has 6 fixes is now available.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in systemd-journald. Two memory corruption flaws, via attacker-controlled alloca()s (CVE-2018-16864, CVE-2018-16865) and an out-of-bounds read flaw leading to an information leak (CVE-2018-16866), could allow an attacker to
LinuxSecurity.com: The package python2-django before version 1.11.18-1 is vulnerable to content spoofing.
LinuxSecurity.com: The package python-django before version 2.1.5-1 is vulnerable to content spoofing.
security update
LinuxSecurity.com: Due to kernel issue there is a way to reuse start_time of a process. This allows to duplicate process authorized by polkit. This update mitigates polkit issue #75 (slowfork): https://gitlab.freedesktop.org/polkit/polkit/issues/75
LinuxSecurity.com: An integer underflow was discovered in the CAF demuxer of the VLC media player. For the stable distribution (stretch), this problem has been fixed in
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 13 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes 9 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that solves one vulnerability and has one errata is now available.
LinuxSecurity.com: Resolves CVE-2018-16869
