LinuxSecurity.com: https://www.libraw.org/news/libraw-0-18-11 —- CVE-2018-10529 fixed: out of bounds read in X3F parser CVE-2018-10528 fixed: possible stack overrun in X3F parser
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has 6 fixes is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
security update
LinuxSecurity.com: Harry Sintonen have discovered a cookie injection vulnerability in wget caused by insufficient input validation, enabling an external attacker to inject arbitrary cookie values cookie jar file, adding new
The answer may hinge on if you’re a glass-half-full or glass-half-empty kind of person. While we’re at it, how about regulators’ level of preparedness, anyway? The post Are firms and regulators prepared for GDPR? appeared first on WeLiveSecurity
Time does fly! It feels like only yesterday that a new strain of hitherto little-known malware achieved celebrity status among global ransomware campaigns The post 12 months on, what are the lessons learned from WannaCryptor? appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors and other implementation errors may lead to the execution of arbitrary code or denial of service.
Reading Time: ~2 min.Crypto Mining Makes the Jump to Excel With the recent Microsoft release supporting JavaScript within Excel, it was only a matter of time before the scripting service was manipulated to mine cryptocurrency. Mere hours after the release, the first proof of concept appeared, with easy-to-replicate steps to get CoinHive functioning. While this […]
LinuxSecurity.com: Several security issues were fixed in OpenJDK 8.
LinuxSecurity.com: Updated to latest upstream release (#1571443, #1573318, #1573319).
LinuxSecurity.com: Update to 1.10.1
security update
security update
Reading Time: ~2 min.Fake tech support scams aren’t going anywhere. In fact, recent data shows this type of social engineering attack is on the rise—with phony tech support calls, emails, and pop-ups peddling the digital equivalent of snake oil to unsuspecting internet users around the world. While many people have grown wise enough to spot […]
The infamous outbreak may no longer be causing mayhem worldwide but the threat that enabled it is still very much alive and posing a major threat to unpatched and unprotected systems The post One year later: EternalBlue exploit more popular now than during WannaCryptor outbreak appeared first on WeLiveSecurity
LinuxSecurity.com: New wget packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1319
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: Upstream details at : https://access.redhat.com/errata/RHSA-2018:1364
LinuxSecurity.com: The package freetype2 before version 2.9.1-1 is vulnerable to denial of service.
LinuxSecurity.com: Regenerate autoconf files using current tools so proper build flags from redhat- rpm-config are used. This applies hardened LDFLAGS. No functional change intended.
LinuxSecurity.com: Security fix for CVE-2018-1000156
LinuxSecurity.com: Security fix for CVE-2017-6888.
LinuxSecurity.com: ## 4.9.2 https://ckeditor.com/cke4/release/CKEditor-4.9.2 ### Security Updates – Fixed XSS vulnerability in the Enhanced Image (image2) plugin reported by Kyaw Min Thein. – Issue summary: It was possible to execute XSS inside CKEditor using the tag and specially crafted HTML. Please note that the default presets (Basic/Standard/Full) do not include this plugin, so you are […]
LinuxSecurity.com: Dancer2 0.206000 addresses several potential security issues. There is a potential RCE with regards to Storable. Dancer2 adds session ID validation to the session engine so that session backends based on Storable can reject malformed session IDs that may lead to exploitation of the RCE. Parsing requests now uses HTTP::Entity::Parser which reduces the amount […]
LinuxSecurity.com: Knot Resolver 2.3.0 (2018-04-23) ——– – fix CVE-2018-1110: denial of service triggered by malformed DNS messages (!550, !558, security!2, security!4) – increase resilience against slow lorris attack (security!5) Bugfixes ——– – validation: fix SERVFAIL in case of CNAME to NXDOMAIN in a single zone (!538) – validation: fix SERVFAIL for
LinuxSecurity.com: This release provides Perl 5.26.2 that fixes a heap buffer overflow in the pack() function and two overflows in regular expression engine.
security update
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft .NET Framework Device Guard is prone to a local security-bypass vulnerability; fixes are available.
Type: Vulnerability. Multiple Microsoft Azure IoT SDKs are prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local security-bypass vulnerability; fixes are available.
