RHEL (Red Hat Enterprise Linux) and CentOS Linux 7 users have received a new Linux kernel security update fixing several vulnerabilities affecting the Intel graphics drivers. . The new Linux kernel security update comes exactly two months after the previous one and it’s here to fix three security vulnerabilities discovered by various security researchers in the Intel graphics drivers (i915), as well as three other security flaws. The three security vulnerabilities affecting the Intel graphics drivers are CVE-2020-12362 , an integer overflow that could allow a privileged user to escalate his/her privileges via local access, CVE-2020-12363 , an input validation flaw, and CVE-2020-12364 , a null pointer reference, both of which allowing a privileged user to initiate a denial-of-service (DoS) attack via local access The link for this article located at 9 to 5 Linux is no longer available. . The latest Linux kernel upgrade for RHEL and CentOS 7 addresses Intel graphics performance concerns, enhancing overall system security significantly.. kernel update, RHEL security, CentOS security, graphics flaw, local privilege escalation. . Brittany Day
A sample program hit the Internet on Wednesday, showing by example how malicious coders could compromise Windows computers by using a flaw in the handling of a widespread graphics format by Microsoft's software. . . .. Security professionals expect the release of the program to herald a new round of attacks by viruses and Trojan horses incorporating the code to circumvent security on Windows computers that have not been updated. The flaw, in the way Microsoft's software processes JPEG graphics, could allow a program to take control of a victim's computer when the user opens a JPEG file. "Within days, you'll likely see (attacks) using this code as a basis," said Vincent Weafer, senior director of security response for antivirus-software company Symantec. "This is dangerous in a sense that everyone processes JPEG files to some degree." The program is the latest example of "exploit code," a sample that shows others how to create attack programs that can take advantage of a particular flaw. Such code preceded the Sasser worm by two days and the MSBlast worm by nine days. . Experts in cybersecurity anticipate that the launch of the software will signal the beginning of a fresh wave of assaults from malicious software and harmful code.. JPEG Exploit, Windows Threat, Malware Code, Security Vulnerability. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.