Two remotely exploitable security flaws involving incorrect handling of certain malformed PDF files were discovered in the Poppler PDF rendering library ( CVE-2020-36023 and CVE-2020-36024 ). These vulnerabilities could result in crashes leading to denial of service (DoS). . Updates for Poppler that mitigate these issues are now available. We strongly recommend that all impacted users apply the updates issued by Debian LTS , Mageia , and Ubuntu as soon as possible to protect against loss of access to critical systems. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . New patches for Poppler have been issued to mitigate severe vulnerabilities leading to system crashes and downtime. Ensure your environments are updated immediately.. Poppler Update, DoS Mitigation, Security Flaws, PDF Rendering, Open Source. . Brittany Day
Web sites serviced by DNS and hosting provider Go Daddy were down for most of today, but were back up later this afternoon. A hacker using the "Anonymous Own3r" Twitter account claimed credit for the outage. . "Things are restored," Go Daddy spokeswoman Elizabeth Driscoll told CNET just before 5 p.m. PT today. She said she did not have many details and was hoping to be able to give an update with more information in the next 24 hours. The link for this article located at CNET is no longer available. . XYZ Hosting faced a significant disruption allegedly caused by a cybercriminal, with operations gradually returning within hours, prompting worries among clients.. Go Daddy Hosting, Anonymous Own3r Hack, DNS Service Attack. . LinuxSecurity.com Team
Buy.com, Amazon and EBay are the latest sites to be hit with a distributed denial of service attack. These attacks are coordinated typically between many people and web sites, all sending "junk traffic" to a site at the same . . .. Buy.com, Amazon and EBay are the latest sites to be hit with a distributed denial of service attack. These attacks are coordinated typically between many people and web sites, all sending "junk traffic" to a site at the same time, restricting access by legitimate customers. The companies are working with service providers and vendors to address the problem. The link for this article located at Bloomberg News is no longer available. . Various e-commerce platforms encounter difficulties as distributed denial of service attacks impede user access to their websites.. DDoS Attacks, Online Retail Security, Cybersecurity Threats. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.