LinuxSecurity.com: An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
ESET research reveals a successor to the infamous BlackEnergy APT group targeting critical infrastructure, quite possibly in preparation for damaging attacks The post GreyEnergy: Updated arsenal of one of the most dangerous threat actors appeared first on WeLiveSecurity
Reading Time: ~3 min.For the past 20 years, Webroot’s technology has been driven by our dedication to protecting users from malware, viruses, and other online threats. The release of Webroot® WiFi Security—a new virtual private network (VPN) app for phones, computers, and tablets—is the next step in fulfilling our commitment to protect everyone’s right to […]
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Several vulnerabilities have been discovered in GraphicsMagick, a set of command-line applications to manipulate image files, which could result in denial of service or the execution of arbitrary code if malformed image files are processed.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in Asterisk, an open source PBX and telephony toolkit, which may result in denial of service or information disclosure.
security update
security update
LinuxSecurity.com: ClamAV could be made to crash if it opened a specially crafted file.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: Nitin Venkatesh discovered a cross-site scripting vulnerability in moin, a Python clone of WikiWiki. A remote attacker can conduct cross-site scripting attacks via the GUI editor’s link dialogue. This only affects installations which have set up fckeditor (not enabled by default).
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.
In a new twist on the theme, the scammers have their sights set on book manuscripts, among other things The post Phishers are after something unusual in ploy targeting book publishers appeared first on WeLiveSecurity
LinuxSecurity.com: An update for tomcat is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Several security issues were fixed in Thunderbird.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2918
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:2916
security update
LinuxSecurity.com: Frediano Ziglio reported a missing check in the script to generate demarshalling code in the SPICE protocol client and server library. The generated demarshalling code is prone to multiple buffer overflows. An authenticated attacker can take advantage of this flaw to cause a denial
LinuxSecurity.com: Net-SNMP could be made to crash if it received specially crafted network traffic.
While the number of victims is lower than previously thought, the data accessed for millions of them is more sensitive than originally believed The post Facebook downgrades victim count, details data accessed in breach appeared first on WeLiveSecurity
Proper preparation can make all the difference when it comes to speaking at conferences The post The Occasional Orator Part 3 appeared first on WeLiveSecurity
LinuxSecurity.com: Requests could be made to expose sensitive information if it received a specially crafted HTTP header.
LinuxSecurity.com: Three vulnerabilities were discovered in the Open Ticket Request System which could result in privilege escalation or denial of service. For the stable distribution (stretch), these problems have been fixed in
LinuxSecurity.com: Updated texlive packages fix security vulnerability: A buffer overflow in the handling of Type 1 fonts allowed arbitrary code execution when a malicious font is loaded by one of the vulnerable tools: pdflatex, pdftex, dvips, or luatex (CVE-2018-17407).
LinuxSecurity.com: Updated firefox packages fix security vulnerabilities: A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered
LinuxSecurity.com: joernchen of Phenoelit discovered that git is prone to an arbitrary code execution vulnerability due to insufficient validation of submodule url and path via a specially crafted .gitmodules file in a project cloned with –recurse-submodules (CVE-2018-17456).
LinuxSecurity.com: Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue: A missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization
security update
security update
LinuxSecurity.com: spamassassin: Certain unclosed tags in crafted emails allow for scan timeouts and result in denial of service (CVE-2017-15705) * spamassassin: Local user code injection in the meta rule syntax (CVE-2018-11781) SL7 x86_64 spamassassin-3.4.0-4.el7_5.x86_64.rpm spamassassin-debuginfo-3.4.0-4.el7_5.x86_64.rpm – Scientific Linux Development Team
LinuxSecurity.com: This update fixes several vulnerabilities in Imagemagick, a graphical software suite. Various memory handling problems or incomplete input sanitising have been found in the coders for BMP, DIB, PICT, DCM, CUT and PSD.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer which could result in denial of service or the execution of arbitrary code.
security update
LinuxSecurity.com: The package wireshark-cli before version 2.6.4-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
Risk Level: Very Low. Type: Trojan.
Reading Time: ~2 min.Latest Windows 10 Update Removes User Files Microsoft recently pulled its latest update, version 1809, after several users complained about personal files being deleted. While some users were able to use third-party software to retrieve deleted files, users whose files wnet missing from the Documents folder are having a much trickier time […]
