security update
LinuxSecurity.com: It was discovered that Wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for PCP, ADB, NBAP, UMTS MAC, IEEE 802.11, SIGCOMP, LDSS, GSM A DTAP and Q.931, which result in denial of service or the execution of arbitrary code.
LinuxSecurity.com: The redmine security update announced as DSA-4191-1 caused regressions with multi-value fields while doing queries on project issues due to an bug in the patch to address CVE-2017-15569. Updated packages are now available to correct this issue.
LinuxSecurity.com: CVE-2016-9396
LinuxSecurity.com: Security fix for CVE-2016-5003, CVE-2016-5002
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1780
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1779
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1777
LinuxSecurity.com: Man Yue Mo, Lars Krapf and Pierre Ernst discovered that Batik, a toolkit for processing SVG images, did not properly validate its input. This would allow an attacker to cause a denial-of-service, mount cross-site scripting attacks, or access restricted files on the
LinuxSecurity.com: It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum.
LinuxSecurity.com: New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues.
Security researchers have demonstrated how attackers could cause physical damage to hard drives, and cause PCs to crash, just by playing sounds through a computer’s speaker. The post An acoustic attack can bluescreen your Windows computer appeared first on WeLiveSecurity
Healthcare sectors, critical manufacturing, food production and transportation also said to be targets for cybercriminals The post Trends 2018: Critical infrastructure attacks on the rise appeared first on WeLiveSecurity
LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL7 noarch xmlrpc-client-3.1.3-9.el7_5.noarch.rpm xmlrpc-common-3.1.3-9.el7_5.noarch.rpm xmlrpc-javadoc-3.1.3-9.el7_5.noarch.rpm xmlrpc-server-3.1.3-9.el7_5.noarch.rpm – Scientific Linux Development Team
LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the
LinuxSecurity.com: Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service. CVE-2018-1093
LinuxSecurity.com: Upstream security fixes related to .gitmodules handling. From the [upstream announcement](https://public-inbox.org/git/xmqqy3g2flb6.fsf@gitster- ct.c.googlers.com/): “` * Submodule “names” come from the untrusted .gitmodules file, but we blindly append them to $GIT_DIR/modules to create our on-disk repo paths. This means you can do bad things by putting “../” into the
Whether travelling to enjoy the matches in person, or watching from home, fans should be on the lookout for foul play The post World Cup scams: how to avoid an own goal appeared first on WeLiveSecurity
Embedded within the agency’s European Cybercrime Centre (EC3), the new team will also work together with law enforcement globally in an effort to reduce the size of the underground illegal economy The post Europol sets up EU-wide team to fight dark web crime appeared first on WeLiveSecurity
How we can help protect a generation for which digital is the way of the world? The post More curious, less cautious: Protecting kids online appeared first on WeLiveSecurity
Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Mercedes Keyless Entry Leads to Car Theft It was discovered this week that criminals […]
LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 24 vulnerabilities is now available.
LinuxSecurity.com: Applications using Oslo middleware could be made to expose sensitiveinformation.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in the libtiff library and the included tools, which may result in denial of service: CVE-2017-11613
LinuxSecurity.com: The Qualys Research Labs discovered multiple vulnerabilities in procps, a set of command line and full screen utilities for browsing procfs. The Common Vulnerabilities and Exposures project identifies the following problems:
LinuxSecurity.com: Several security issues were fixed in libytnef.
LinuxSecurity.com: An update for xmlrpc is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: xmlrpc: Deserialization of untrusted Java object through tag (CVE-2016-5003) SL6 noarch xmlrpc3-client-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-3.0-4.17.el6_9.noarch.rpm xmlrpc3-client-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-common-devel-3.0-4.17.el6_9.noarch.rpm xmlrpc3-javadoc-3.0-4.17.el6_9.noarch.rpm xmlrpc3-server-3.0-4.17.el6_9.noarch.rpm [More…]
LinuxSecurity.com: An update for procps is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
security update
LinuxSecurity.com: Several security issues were fixed in the kernel.
LinuxSecurity.com: Several vulnerabilities have been found in the Apache HTTPD server. CVE-2017-15710
LinuxSecurity.com: Git contains multiple vulnerabilities that allow for the remote execution of arbitrary code.
LinuxSecurity.com: The package strongswan before version 5.6.2-2 is vulnerable to denial of service.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: The package wireshark-cli before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package wireshark-common before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package wireshark-qt before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: The package wireshark-gtk before version 2.6.1-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
LinuxSecurity.com: An update for kernel is now available for Red Hat Enterprise Linux 7.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
