Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 10 articles for you...
210

Yamale High-Severity Advisory: CVE-2021-38305 Code Execution Risk

A high-severity code injection vulnerability has been disclosed in 23andMe's Yamale, a schema and validator for YAML, that could be trivially exploited by adversaries to execute arbitrary Python code.The flaw, tracked as CVE-2021-38305 (CVSS score: 7.8), involves manipulating the schema file provided as input to the tool to circumvent protections and achieve code execution. . Particularly, the issue resides in the schema parsing function, which allows any input passed to be evaluated and executed, resulting in a scenario where a specially-crafted string within the schema can be abused for the injection of system commands. Yamale is a Python package that allows developers to validate YAML — a data serialization language often used for writing configuration files — from the command line. The package is used by at least 224 repositories on GitHub. The link for this article located at The Hacker News is no longer available. . A critical vulnerability in the Yamale library enables attackers to execute arbitrary Python code by crafting malicious schema files.. Yamale Package, Code Injection Flaw, Python Security Bug, YAML Validation, High Severity Vulnerability. . Brittany Day

Calendar 2 Oct 07, 2021 User Avatar Brittany Day Security Vulnerabilities
83

Malicious PNG Files: A Threat of iFrame Injection by Sucuri

Security vendor Sucuri is warning that it's spotted an attack in the wild that embeds malicious code in PNG files. . The iFrame injection attack loaded a valid jquery.js file with very little to alert even the researcher that something else was going on. As the company writes in this blog post, the only red flag in the code was a loadFile() function downloading dron.png into the iFrame. The link for this article located at The Register UK is no longer available. . Uncover the hidden threat of the iFrame exploit that stealthily integrates harmful JPEG scripts, sidestepping security measures and endangering online safety.. iFrame Attack, PNG Malware, Code Injection, Web Threats, Sucuri Security. . LinuxSecurity.com Team

Calendar 2 Feb 05, 2014 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

PHP 5.3.9: Critical Advisory on Code Injection and DoS Threat

The PHP developers are working to fix a critical security vulnerability in PHP that they introduced with a recent security patch. The current stable release is affected; however, it is not yet clear whether the questionable patch was also applied to older versions.. The cause of the problem is the security update to PHP 5.3.9, which was written to prevent denial of service (DoS) attacks using hash collisions. To do so, the developers limited the maximum possible number of input parameters to 1,000 in php_variables.c using max_input_vars. Because of mistakes in the implementation, hackers can intentionally exceed this limit and inject and execute code. The bug is considered to be critical as code can be remotely injected over the web. The link for this article located at H Security is no longer available. . A severe vulnerability in PHP versions 5.3.9 has emerged, allowing for potential code injections and denial of service attacks stemming from a poorly executed patch fix.. PHP Security Fix, Code Injection Prevention, DoS Attack Alert. . LinuxSecurity.com Team

Calendar 2 Feb 03, 2012 User Avatar LinuxSecurity.com Team Vendors/Products
78

Ruby on Rails: 3.0.11 Critical XSS Issue Resolved in Update

The Ruby on Rails open source web framework has been updated to close a security hole in the translate helper method. According to the developers, a cross-site scripting (XSS) vulnerability in the helper method for i18n translations could be exploited by an attacker to insert arbitrary code into a page. . Rails 3.0.0 and later, as well as 2.3.x in combination with the rails_xss plug-in, are affected. Upgrading to 3.0.11 or 3.1.2 corrects the issue; the updates also address several non-security-related bugs. The link for this article located at H Security is no longer available. . Rails has patched a critical XSS flaw impacting all versions starting from 3.0.0, enhancing defenses against potential code injection threats.. Ruby on Rails Security, XSS Exploit Fix, Web Framework Update. . LinuxSecurity.com Team

Calendar 2 Nov 21, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
78

Oracle Java Update: 17 Critical Flaws Resolved For Code Injection

Oracle has released a cross-platform update for Java that addresses 17 vulnerabilities in the ubiquitous software platform.. All 17 vulnerabilities might be abused to inject code into vulnerable systems, and all but one affect how Java Runtime Environment client software runs in browsers. Java 6 update 26 for Windows, Linux and Solaris is designed to plug these multiple holes and is available for download from Oracle here. The last major update on this scale was three months ago. The link for this article located at The Register UK is no longer available. . Oracle has rolled out a new Java update addressing 17 serious vulnerabilities that may enable code execution in susceptible environments.. Java Security Update, Oracle Vulnerabilities, Cross-Platform Java Fixes. . LinuxSecurity.com Team

Calendar 2 Jun 08, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
78

Opera: 11.11 Critical Update Addresses Memory Error And Security Risk

With the update to version 11.11, the Opera developers have closed a critical security hole that enables attackers to inject malicious code. The vulnerability is found in the code for processing framesets: certain frame constructions cause a memory error that eventually allows attackers to inject malicious code. . Other internal changes mainly affect the browser's overall stability, for example, the developers have fixed the cause of a potential installer crash as well as another bug which caused the browser to crash when trying to access www.falk.de. The complete list of changes can be found at the Opera web site. Opera 11.11 is available to download for Windows, Mac OS X and Linux. The link for this article located at H Security is no longer available. . The new Opera 11.11 release addresses a major security vulnerability and enhances browser performance with multiple internal optimizations.. Opera Browser Update, Memory Hole Fix, Code Injection Prevention. . LinuxSecurity.com Team

Calendar 2 May 18, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
78

OpenBSD and DragonFlyBSD Face Major Threat from IPSec Buffer Overflow

A hole in the IPComp protocol implementation of certain operating systems can be exploited to compromise a server. IPComp is used for compressing individual IP datagrams mainly in conjunction with IPSec and other VPN technologies. According to Tavis Ormandy, certain embedded datagrams can cause a recursion after they have been unpacked, which results in a kernel stack overflow.. This reportedly allows attackers to inject arbitrary code into a system and, in all probability, execute it there. An attack could trigger a system crash even in the simplest of scenarios. Ormandy says that no previous authentication is required, and that attacks can also be launched using a forged sender address. The link for this article located at H Security is no longer available. . An unchecked input buffer in IPComp can cause a severe overflow issue, allowing attackers to insert malicious scripts that may lead to unauthorized system access and command execution. IPComp Exploit, FreeBSD Security, NetBSD Patch, Kernel Overflow. . LinuxSecurity.com Team

Calendar 2 Apr 06, 2011 User Avatar LinuxSecurity.com Team Vendors/Products
83

Home Depot Code Injection Attack: Malicious Code Exposure Detected

The website for do-it-yourself giant Home Depot has been . "Somebody managed to deface the site and inject that code, so that anyone visiting the site would have loaded the malicious code from this other site," explained Mike Menefee, founder of security website Infosec Island, which discovered the hack. The link for this article located at Fox News is no longer available. . Intrusive scripts were embedded within the Target website, putting users' data at risk.. Home Depot Security, Website Attack, Code Injection Threat. . LinuxSecurity.com Team

Calendar 2 Jan 12, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here