Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -1 articles for you...
210

VLC Media Player: No Significant Vulnerabilities Detected in Software

There has been a lot of confusion over the last few days after news spread of a supposedvulnerability in the media player VLC. Despite being labelled as "critical", VLC's developers, VideoLAN, denied there was a problem at all. . And they were right. While there is a vulnerability, it was in a third-party library, not VLC itself. On top of this, it is nowhere near as severe as first suggested. Oh -- and it was fixed over a year ago. An older version of Ubuntu Linux was to blame for the confusion. The problem actually exists in a third-party library called libebml, and the issue was addressed some time ago. The upshot is that if you have updated VLC within the last year, there is no risk whatsoever. VLC's developers are understandably upset at the suggestion that their software was insecure. The link for this article located at BetaNews is no longer available. . Despite confusion over a critical flaw, VLC developers confirmed no vulnerabilities exist in their software, only in a library.. VLC Media Player, Libebml Library, Security Patch, Open Source Software. . Brittany Day

Calendar%202 Jul 26, 2019 User Avatar Brittany Day Security Vulnerabilities
83

RealNetworks RealPlayer 10.0.5 Critical Advisory: Remote Attack Risk

Users who run the media players on Linux or Unix are at risk of attack, security experts claim Popular media players RealPlayer and Helix Player are at risk of a security vulnerability that could let malicious attackers launch remote attacks on a user's system, security experts say. . A flaw has been discovered in RealNetworks' RealPlayer version 10.0.5.756 Gold and Helix Player 1.0.5.757 Gold running on Linux or Unix operating systems, according to a report released Tuesday by the French Security Incident Response Team, or FrSIRT. Attack code that takes advantage of the flaw, a so-called exploit, has been posted on the Internet, increasing the security risk to users. The link for this article located at ZDNet.co.uk is no longer available. . A vulnerability has been identified in RealNetworks' RealPlayer 10.0.5.756 Gold and Helix Player 1.0, presenting potential security threats.. RealNetworks Security, Remote Attack Threat, Media Player Risks, Helix Player Vulnerability. . LinuxSecurity.com Team

Calendar%202 Sep 28, 2005 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Examining Flash Player Privacy Risks: Data Tracking and User Info

Macromedia's Flash media player is raising concerns among privacy advocates for its little-known ability to store computer users' personal information and assign a unique identifier to their machines. "A lot of media players come with identifiers embedded in them to track content usage and digital rights management," Chris Hoofnagle, director of the Electronic Privacy Information Center's West Coast office, said. "With respect to Windows Media Player and now the Macromedia player, we're realizing that the media players themselves are creating privacy risks." . Flash, popular for its ability to play animation and video clips, employs a technology known as local shared objects to save up to 100KB of information on users' hard drives. By assigning a unique identifier to a computer and preserving it in the space for the local shared object, a website can recognize that someone has already visited the site, and advertisers can use the information to determine that a visitor has previously viewed an ad. Websites that require users to fill out personal information can also associate that data with the identifier. Macromedia does not view its software as a threat to user privacy. "The Flash player by its nature doesn't by default gather any information," Jeff Whatcott, vice president of product management at Macromedia, said. " We designed that technology from the beginning to make sure that (computer) users are always in control of their key information." Macromedia provides instructions on its website for how to disable local shared objects on an individual site or all sites, delete data that is already stored locally, and set the maximum space allowed for storage. Unfortunately, most Flash users are unaware that the player is storing any information about them at all and are unlikely to see these instructions or understand how to follow them. The link for this article located at Security Pipeline is no longer available. . Flash, popular for its ability to play animation and video clips,employs a technology known as loca. macromedia's, flash, media, player, raising, concerns, among, privacy, advocates, little-known. . LinuxSecurity.com Team

Calendar%202 Apr 21, 2005 User Avatar LinuxSecurity.com Team Privacy
81

Windows XP Media Player Data Logging Risk Highlighted By Privacy Advocate

A prominent Internet privacy advocate says Microsoft Corp. should have warned consumers that the media player that ships with its new Windows XP operating system connects to a server operated by the software giant and reports what DVDs customers insert into their PCs.. . .. A prominent Internet privacy advocate says Microsoft Corp. should have warned consumers that the media player that ships with its new Windows XP operating system connects to a server operated by the software giant and reports what DVDs customers insert into their PCs. Richard M. Smith said in a posting to Internet security mailing lists Wednesday that the Windows Media Player version 8 installed by default along with millions of copies of XP automatically contacts a Microsoft Web server to look up information about DVDs played by users. Smith, who one month ago complained that earlier - and more ubiquitous - versions of the Windows Media Player can give up a uniquely identifying digital fingerprint when communicating across the Internet, said that a similar ID number is transmitted when the version 8 player looks up DVD "chapter" information at a Microsoft Web site. The link for this article located at Newsbytes is no longer available. . An information rights activist condemns Google for failing to inform users regarding data tracking by Android's default settings.. Privacy Awareness, Microsoft Concerns, Data Logging, Windows XP Issues, Consumer Protection. . LinuxSecurity.com Team

Calendar%202 Feb 21, 2002 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200