Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A high-risk RCE bug impacting PHP-based websites running a vulnerable version of the web-app creation tool Zend Framework and some Laminas Project releases has been discovered and disputed by Zend. Regardless of the dispute, Zend has issued a patch addressing this vulnerability which "provides type checking of the $streamName property before performing a cleanup operation (which results in an unlink() operation, which, previously, could have resulted in an implied call to an an object’s __toString() method) in the Laminas\Http\Response\Stream destructor". . Versions of the popular developer tool Zend Framework and its successor Laminas Project can be abused by an attacker to execute remote code on PHP-based websites, if they are running web-based applications that are vulnerable to attack. However, those that maintain Zend Framework emphasize that the conditions under which a web app can be abused first require the application author to write code that is “inherently insecure.” For that reason, the current maintainers of Zend Framework are contesting whether or not the vulnerability classification is correct. “We are contesting the vulnerability, and consider our patch a security tightening patch, and not a vulnerability patch,” said Matthew Weier O’Phinney, Zend product owner and principal engineer in an email-based interview with Threatpost. The link for this article located at ThreatPost is no longer available. . Critical vulnerability detected in Zend Framework and Laminas Project, demanding urgent updates to protect PHP applications.. remote Code Execution,Zend Framework,Laminas Project,PHP Security,Web Application Threat. . Brittany Day
The U.S. Computer Emergency Readiness Team (US-CERT) has disclosed a flaw in Intel chips that could allow hackers to gain control of Windows and other operating systems, security experts say.. The flaw was disclosed the vulnerability in a security advisory released last week. Hackers could exploit the flaw to execute malicious code with kernel privileges, said a report in the Bitdefender blog. The link for this article located at InfoWorld is no longer available. . The flaw was disclosed the vulnerability in a security advisory released last week. Hackers could ex. computer, emergency, readiness, (us-cert), disclosed, intel, chips. . LinuxSecurity.com Team
Google March 24 paid out $8,500 for six Chrome Web browser flaws found by enterprising developers. The company also issued two new SSL certificates to protect against the Comodo certificate issue.. Google March 24 sewed up six security holes in its Chrome Web browser with an upgrade to the stable and beta channels for Chrome 10.0.648.204 for Windows, Mac, Linux and Chrome Frame. The search engine, which in this upgrade also added support for the browser's password manager on Linux and fortified Chrome's performance and stability, paid out $8,500 to the discoverers of the six vulnerabilities, all of which were rated high risk. The link for this article located at eWeek is no longer available. . Google enhances Chrome security by addressing six critical vulnerabilities in the March 24 release, rewarding developers with $8,500.. Chrome Security Flaws, Browser Upgrade, High-Risk Issues. . LinuxSecurity.com Team
Google has released version 10.0.648.204 of its Chrome web browser, a maintenance and security update to the Chrome 10 stable branch. The update addresses a total of six vulnerabilities in the WebKit-based browser that can be "exploited by malicious people to compromise a system" and rates all of them with a "High" priority. Secunia, for example, rates the vulnerabilities as highly critical.. According to Google, one of the high risk issues relates to a buffer error in base string handling, while two others have to do with use-after-free, where memory is deallocated but later accessed, in the frame loader and in HTMLCollection. The other issues range from a stale pointer in CSS handling and in SVG text handling, as well as a DOM tree corruption bug. The update also includes several performance and stability fixes and adds support for the browser's password manager on Linux systems. As part of its Chromium Security Reward programme, Google rewarded those who reported security vulnerabilities with a total of $8,500, of which $7,000 went to developer Sergey Glazunov alone. Further details of the Chrome vulnerabilities are being withheld until "a majority of users are up-to-date with the fix". The link for this article located at H Security is no longer available. . The recent update from Microsoft addresses multiple critical vulnerabilities, such as heap corruption and privilege escalation flaws within Windows.. Chrome 10 Update, Google Browser Security, Memory Management Issue. . LinuxSecurity.com Team
Google has released version 9.0.597.107 of its Chrome browser, which fixes a total of 19 security vulnerabilities, 16 of them rated as high risk. It was, for example, possible to crash the browser using JavaScript dialogues and SVG files, or to use the address bar for URL spoofing. . Also fixed is an integer overflow when handling textareas. As ever, Google is keeping full details of the vulnerabilities under wraps until the bulk of users have switched to the new version. Google's rewards programme pays discoverers of vulnerabilities up to $1,000. Google paid out a total of $14,000 for this particular update. In total, its security bug bounty programme has now paid out more than $100,000. The link for this article located at H Security is no longer available. . Mozilla enhances Firefox 89.0.1, addressing 22 critical vulnerabilities involving memory leaks and security updates.. Chrome Browser Update, High Risk Exploits, Security Fixes, JavaScript Threats. . LinuxSecurity.com Team
Google patched 16 vulnerabilities in Chrome on Thursday, paying one researcher a record $3,133 for reporting a single bug. The flaws fixed in Chrome 8.0.552.334 were in several components, including the browser's support for extensions, its built-in PDF viewer, and CSS (cascade style sheet) processing.. Thirteen of the bugs were labeled as "high" threats, Google's second-most-serious rating, and two were pegged "medium." Only one was tagged as "critical." As it always does, Google locked its bug tracking database to bar outsiders from reading the technical details of the just-patched vulnerabilities. The company usually opens access to a flaw later -- sometimes within weeks, often only after months -- to give users time to update before the information goes public. The link for this article located at IT World is no longer available. . Mozilla fixes 14 vulnerabilities in Firefox, including 10 marked as severe and another deemed critical, prioritizing user safety.. Chrome Security, Patch Management, Threat Assessment, Browser Security. . LinuxSecurity.com Team
Google has released version 8.0.552.224 of Chrome for Windows, Mac OS X and Linux into its Stable and Beta channels. The security update addresses a total of five vulnerabilities in the WebKit-based browser, two of which are rated as "High" priority.. One of the high risk issues affects only 64-bit versions of Linux, while the other relates to stale pointers in cursor handling. Other issues include browser crashes due to bad extensions, CSS parsing problems and a NULL pointer issue in web worker handling. Further details of the vulnerabilities are being withheld until "a majority of users are up-to-date with the fix". As part of its Chromium Security Reward programme, Google rewarded those who reported two of the security vulnerabilities with $1,000. The company has also updated its Development (Dev) channel to version 9.0.597.19 for all platforms to fix a crashing bug related to browser sync. All users are encouraged to update to the latest releases as soon as possible. The link for this article located at H Security is no longer available. . One of the high risk issues affects only 64-bit versions of Linux, while the other relates to stale . google, released, version, chrome, windows, linux, stable. . LinuxSecurity.com Team
First reports of a vulnerability apparently discovered by Microsoft at the start of this year, appeared in mid June. The vulnerability could reportedly be used to carry out man-in-the-middle attacks on HTTPS connections. Mozilla classed the risk as high and released corresponding patches for its browser. It has now become clear that the vulnerability affects many other browsers.. A specially prepared proxy can inject HTML and script code into the context of a secure page. This permits modification of displayed data or, in the case of cookie-based authentication, identity theft. A security advisory from SecurityFocus, modified a few days ago, now cites Chrome, Opera, Safari and Internet Explorer as being affected. The link for this article located at H Security is no longer available. . A specially prepared proxy can inject HTML and script code into the context of a secure page. This p. first, reports, vulnerability, apparently, microsoft, start, appea. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.