RHEL (Red Hat Enterprise Linux) and CentOS Linux 7 users have received a new Linux kernel security update fixing several vulnerabilities affecting the Intel graphics drivers. . The new Linux kernel security update comes exactly two months after the previous one and it’s here to fix three security vulnerabilities discovered by various security researchers in the Intel graphics drivers (i915), as well as three other security flaws. The three security vulnerabilities affecting the Intel graphics drivers are CVE-2020-12362 , an integer overflow that could allow a privileged user to escalate his/her privileges via local access, CVE-2020-12363 , an input validation flaw, and CVE-2020-12364 , a null pointer reference, both of which allowing a privileged user to initiate a denial-of-service (DoS) attack via local access The link for this article located at 9 to 5 Linux is no longer available. . The latest Linux kernel upgrade for RHEL and CentOS 7 addresses Intel graphics performance concerns, enhancing overall system security significantly.. kernel update, RHEL security, CentOS security, graphics flaw, local privilege escalation. . Brittany Day
Intel last night made public two more data leakage disclosures, which tie back to Zombieload and November's TAA issue. . Here are the new disclosures: CVEID: CVE-2020-0548 Description: Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVSS Base Score: 2.8 Low CVE-2020-0549 Description: Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. CVSS Base Score: 6.5 Medium The link for this article located at Phoronix is no longer available. . Intel reveals two fresh security concerns tied to CPU termination flaws and access loopholes.. Data Leakage, Intel Processors, Information Disclosure. . Brittany Day
Two separate teams of security researchers and academics from universities in Australia and Switzerland have revealed today vulnerabilities in the e-voting system that the Swiss voting commission plans to roll out for future elections. . Among the reported vulnerabilities there is one that security researchers said it could allow an attacker with local access to a voting machine --or the voting machine vendor itself-- to tamper with cast votes. The vulnerability resides in the cryptographic system that verifies that the cast votes are the same ones that are being reported, however, researchers say this cryptographic scheme is weak and allows someone to swap votes. The link for this article located at ZDNet is no longer available. . An in-depth examination of weaknesses present in Switzerland's electronic voting framework that could potentially enable manipulation of ballots.. Swiss E-Voting,Cryptographic Vulnerability,Vote Tampering,Security Research,Local Access. . Brittany Day
A serious vulnerability in a popular Belkin router could be exploited by a local, unauthenticated attacker to gain full control over affected devices.. The good news is that the bug has already been patched by Belkin. The bad news is that approximately nobody installs router firmware updates. The link for this article located at ThreatPost is no longer available. . The good news is that the bug has already been patched by Belkin. The bad news is that approximately. serious, vulnerability, popular, belkin, router, exploited, local, unauthenticated. . LinuxSecurity.com Team
A security researcher has uncovered a security bug in the FreeBSD operating system that allows users with limited privileges to take full control of underlying systems.. The bug in FreeBSD's kqueue notification interface makes it trivial for those with local access to a vulnerable system to gain full root privileges, Przemyslaw Frasunek, an independent security consultant in Poland, told The Register. It affects versions 6.0 through 6.4 of the operating system, the last two versions of which enjoy wide use and continue to be supported by the FreeBSD Foundation. Versions 7.1 and and beyond are not vulnerable. The link for this article located at The Register is no longer available. . A vulnerability in OpenBSD permits unauthorized users to escalate privileges through a flaw in the PF firewall subsystem.. FreeBSD Access Control Bug, Local Root Exploit, kqueue Notification Issue. . LinuxSecurity.com Team
Security experts and vendors of Linux and other Unix-like operating systems are urging network administrators to replace some versions of popular e-mail server software known as Sendmail, because the most recent open-source versions can provide a doorway for local hackers.. . .. Security experts and vendors of Linux and other Unix-like operating systems are urging network administrators to replace some versions of popular e-mail server software known as Sendmail, because the most recent open-source versions can provide a doorway for local hackers. Since malicious individuals would need to gain command-line access to a server in order to exploit the vulnerability, the problem is greatest for organizations such as Internet service providers or universities that regularly provide shell access to users. Cade Cairns, a member of the Security Focus Threat Analysis Team, reported late last week that hackers with access to run Sendmail from the command line of vulnerable systems could possibly gain administrator access to the server by supplying specially crafted commands. The link for this article located at Newsbytes is no longer available. . Specialists strongly recommend that system administrators enhance their Sendmail versions to mitigate the possibility of unauthorized local access by hackers.. Sendmail Security Update, Unix-Like Systems, Mail Server Vulnerability. . LinuxSecurity.com Team
Roman Drahtmüller send this message to the suse-security-announce mailing list in regards to an April Fools joke that some people are taking a little bit too seriously. . .. Roman Drahtmüller send this message to the suse-security-announce mailing list in regards to an April Fools joke that some people are taking a little bit too seriously : Date: Thu, 29 Mar 2001 15:48:18 +0200 (MEST) From: Roman Drahtmueller To:
A serious bug has been discovered in the Linux kernel that can be used by local users to gain root access. The problem, a vulnerability in the Linux kernel capability model, exists in kernel versions up to and including version 2.2.15. According to Alan Cox, a key member of the Linux developer community, "It will affect programs that drop setuid state and rely on losing saved setuid, even those that check that the setuid call succeeded." To ensure that this vulnerability cannot be exploited by programs running on Linux, Linux users are advised to update to kernel version 2.2.16 immediately. Information on "capabilities" are discussed in the Capabilities FAQ We also recently ran a story on a capabilities-based operating system that is worth reading. . A serious bug has been discovered in the Linux kernel that can be used by local users to gain root access. The problem, a vulnerability in the Linux kernel capability model, exists in kernel versions up to and including version 2.2.15. According to Alan Cox, a key member of the Linux developer community, "It will affect programs that drop setuid state and rely on losing saved setuid, even those that check that the setuid call succeeded." To ensure that this vulnerability cannot be exploited by programs running on Linux, Linux users are advised to update to kernel version 2.2.16 immediately. Information on "capabilities" are discussed in the Capabilities FAQ We also recently ran a story on a capabilities-based operating system that is worth reading. The link for this article located at Sendmail.net --Â Â is no longer available. . A serious bug has been discovered in the Linux kernel that can be used by local users to gain root a. serious, linux, kernel, local, users. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.