LinuxSecurity.com: Minor security update from upstream fixing CVE-2018-0739
LinuxSecurity.com: New version 2.1.26 (#1370156, #1304360)
LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/
LinuxSecurity.com: Update to latest upstream version.
LinuxSecurity.com: Python Crypto could expose sensitive information.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in Ming: CVE-2018-6358
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
LinuxSecurity.com: A vulnerability in SPICE VDAgent could allow local attackers to execute arbitrary commands.
LinuxSecurity.com: Multiple vulnerabilities have been found in QEMU, the worst of which may allow an attacker to execute arbitrary code.
LinuxSecurity.com: Multiple vulnerabilities have been discovered in libvirt, the worst of which may result in the execution of arbitrary commands.
LinuxSecurity.com: Multiple vulnerabilities were discovered in mailx, the worst of which may allow a remote attacker to execute arbitrary commands.
LinuxSecurity.com: This update fixes assorted CVEs in LibOFX.
LinuxSecurity.com: Fixes for CVE-2018-1002150.
LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.
LinuxSecurity.com: **PHP version 7.1.16** (29 Mar 2018) **Core:** * Fixed bug php#76025 (Segfault while throwing exception in error_handler). (Dmitry, Laruence) * Fixed bug php#76044 (‘date: illegal option — -‘ in ./configure on FreeBSD). (Anatol) **FPM:** * Fixed bug php#75605 (Dumpable FPM child processes allow bypassing opcache access controls). (Jakub Zelenka) **GD:** * Fixed bug php#73957
LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2
LinuxSecurity.com: rebase and fixed CVE-2018-1000140
LinuxSecurity.com: https://nodejs.org/en/blog/release/v8.11.0/
LinuxSecurity.com: Lilith of Cisco Talos discovered several buffer overflow vulnerabilities in the SDL Image library which can be leveraged by attackers to execute arbitrary code via specially crafted image files.
LinuxSecurity.com: New patch packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue.
LinuxSecurity.com: Multiple invalid frees and buffer-overflow vulnerabilities were discovered in sam2p, a utility to convert raster images and other image formats, that may lead to a denial-of-service (application crash) or unspecified other impact.
security update
Most of the White House’s email domains have yet to deploy an email authentication protocol known as DMARC that is designed to reduce the risk of attackers impersonating legitimate email addresses for distributing spam or phishing messages. The post Study: White House email domains at risk of being misused for phishing scams appeared first on […]
LinuxSecurity.com: Fixes for CVE-2018-1002150.
LinuxSecurity.com: Update to the latest upstream release, which fixes CVE-2017-14062.
LinuxSecurity.com: Update to 3.6.5
LinuxSecurity.com: – spec cleanup, silent rpmlint – remove upstreamed patches, fixes rhbz #1507577 – update to 1.2.2
LinuxSecurity.com: This update includes the latest upstream release of the Apache HTTP Server, version 2.4.33. A number of security vulnerabilities are fixed in this release: * *Low*: Possible out of bound read in mod_cache_socache (CVE-2018-1303) * *Low*: Possible out of bound access after failure in reading the HTTP request (CVE-2018-1301) * *Low*: Weak Digest auth […]
LinuxSecurity.com: This update includes the latest upstream release of mod_http2, version 1.10.16. This includes a security fix (CVE-2018-1302): When an HTTP/2 stream was destroyed after being handled, mod_http2 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerabilty hard to trigger in usual […]
LinuxSecurity.com: Mozilla: Vorbis audio processing out of bounds write (MFSA 2018-08) (CVE-2018-5146) SL6 x86_64 libvorbis-1.2.3-5.el6_9.1.i686.rpm libvorbis-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.i686.rpm libvorbis-debuginfo-1.2.3-5.el6_9.1.x86_64.rpm libvorbis-devel-1.2.3-5.el6_9.1.i686.rpm libvorbis-devel-1.2.3-5.el6_9.1.x86_64.rpm i386 libvorbis-1.2.3 [More…]
LinuxSecurity.com: An update that solves 6 vulnerabilities and has one errata is now available.
security update
LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
LinuxSecurity.com: An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
LinuxSecurity.com: An update for libvorbis is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Reading Time: ~3 min.When WannaCry ransomware spread throughout the world last year by exploiting vulnerabilities for which there were patches, we security “pundits” stepped up the call to patch, as we always do. In a post on LinkedIn Greg Thompson, Vice President of Global Operational Risk & Governance at Scotiabank expressed his frustration with the […]
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Cybercriminals are believed to have stolen information for more than five million credit and debit cards that shoppers had used at dozens of Saks Fifth Avenue, Saks Off 5th and Lord & Taylor stores mainly in the United States between May 2017 and March 2018. The post Saks and Lord & Taylor stores suffer data […]
ESET researchers have analyzed a newly discovered set of apps on Google Play, Google’s official Android app store, that pose as security applications. Instead of security, all they provide is unwanted ads and ineffective pseudo-security. The post Beware ad slingers thinly disguised as security apps appeared first on WeLiveSecurity
LinuxSecurity.com: Several security issues were fixed in the Linux kernel.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: The package drupal before version 8.5.1-1 is vulnerable to arbitrary code execution.
security update
security update
