LinuxSecurity.com: OpenJDK: incorrect handling of Reference clones can lead to sandbox bypass (Hotspot, 8192025) (CVE-2018-2814) * OpenJDK: unrestricted deserialization of data from JCEKS key stores (Security, 8189997) (CVE-2018-2794) * OpenJDK: insufficient consistency checks in deserialization of multiple classes (Security, 8189977) (CVE-2018-2795) * OpenJDK: unbounded memory allocation during deserializati [More…]
LinuxSecurity.com: Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.60, which includes additional changes. Please see the MySQL 5.5 Release Notes and Oracle’s Critical Patch Update advisory for
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
The challenges facing critical infrastructure systems The post RSA 2018: Hacking the grid appeared first on WeLiveSecurity
Simply throwing more staff at the patching problem won’t cut it, a study suggests. The post Rough patch, or how to shut the window of (unpatched) opportunity appeared first on WeLiveSecurity
LinuxSecurity.com: New gd packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084
LinuxSecurity.com: Security fix for CVE-2018-1086 and CVE-2018-1079
LinuxSecurity.com: It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities that could result in infinite loops in different dissectors. Other issues are related to crash in dissectors that are
LinuxSecurity.com: Two vulnerabilities were found in OpenCV, the “Open Computer Vision Library”. CVE-2018-5268
Securely keeping track of data and security applications The post RSA 2018: Untangling the enterprise security mess appeared first on WeLiveSecurity
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
LinuxSecurity.com: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 6 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact
Can the electoral processes be protected? The post Trends 2018: Democracy hack appeared first on WeLiveSecurity
LinuxSecurity.com: Wojciech Regula discovered an XML External Entity vulnerability in the XML Parser of the mindmap loader in freeplane, a Java program for working with mind maps, resulting in potential information disclosure if a malicious mind map file is opened.
LinuxSecurity.com: Version 2.1.3 (March 5th, 2018) ——————————- **Security fixes** * Attributes that have URI values weren’t properly sanitized if the values contained character entities. Using character entities, it was possible to construct a URI value with a scheme that was not allowed that would slide through unsanitized. This security issue was introduced in Bleach 2.1. […]
security update
security update
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan, Worm.
An interview with ESET’s Lukáš Štefanko on the thin line between what deserves the name “security app” and what can be called fake. The post Fake or not fake – that is the question appeared first on WeLiveSecurity
As Internet crime knows no borders, mutual legal assistance involving various nations and, by extension, requests for extraditing suspected cyber-offenders are sometimes part and parcel of prosecution efforts. The post Quarterly cybercrime digest: Extraditions and more appeared first on WeLiveSecurity
LinuxSecurity.com: The Citrix Security Response Team discovered that corosync, a cluster engine implementation, allowed an unauthenticated user to cause a denial-of-service by application crash.
LinuxSecurity.com: – update to the latest upstream release (fixes CVE-2018-1000168)
LinuxSecurity.com: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: https://apps.ankiweb.net/docs/changes.html
LinuxSecurity.com: New upstream release with security fix for CVE-2018-1084
LinuxSecurity.com: Update to latest upstream version.
LinuxSecurity.com: update to latest upstream release, which fixes the following vulnerabilities: – CVE-2018-1100 – stack-based buffer overflow in utils.c:checkmailpath() – CVE-2018-1083 – stack-based buffer overflow in compctl.c:gen_matches_files() – CVE-2018-1071 – stack-based buffer overflow in exec.c:hashcmd()
LinuxSecurity.com: Removing dependency on wireshark metapackage from wireshark-cli —- Added wireshark-qt to wireshark metapackage —- – New version 2.4.5 – Contains fixes for CVE-2018-7419, CVE-2018-7418, CVE-2018-7417, CVE-2018-7420, CVE-2018-7320, CVE-2018-7336, CVE-2018-7337, CVE-2018-7334, CVE-2018-7335, CVE-2018-6836, CVE-2018-5335, CVE-2018-5334, CVE-2017-6014, CVE-2017-9616,
security update
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
LinuxSecurity.com: This update doesn’t fix a vulnerability in linux-tools, but provides support for building Linux kernel modules with the “retpoline” mitigation for CVE-2017-5715 (Spectre variant 2).
