LinuxSecurity.com: Harry Sintonen discovered that wget, a network utility to retrieve files from the web, does not properly handle ‘rn’ from continuation lines while parsing the Set-Cookie HTTP header. A malicious web server could use this flaw to inject arbitrary cookies to the cookie jar file, adding
security update
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer and Edge are prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft ChakraCore is prone to a remote memory-corruption vulnerability; fixes are available.
LinuxSecurity.com: An update that solves four vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
LinuxSecurity.com: Several security issues were fixed in the kernel.
Reading Time: ~3 min.As the EU’s General Data Protection Regulation (GDPR) edges closer, we’re looking back on the five most significant stories during the lead up to its implementation. Read about GDPR’s impact on data security and find out how to get prepared with five steps to compliance. What aspect of GDPR will have the […]
The importance of providing the best possible after-sales service to customers The post Tech support scams and the call of the void appeared first on WeLiveSecurity
security update
LinuxSecurity.com: An XML external entity expansion vulnerability was discovered in the DataImportHandler of Solr, a search server based on Lucene, which could result in information disclosure.
LinuxSecurity.com: – fix stack-based buffer overflow in utils.c:checkmailpath() (CVE-2018-1100) – fix stack-based buffer overflow in gen_matches_files() (CVE-2018-1083) – fix stack-based buffer overflow in exec.c:hashcmd() (CVE-2018-1071)
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: Several vulnerabilities were discovered in wordpress, a web blogging tool, which could allow remote attackers to compromise a site via cross-site scripting, bypass restrictions or unsafe redirects. More information can be found in the upstream advisory at
security update
LinuxSecurity.com: – https://www.drupal.org/project/drupal/releases/7.59 – https://www.drupal.org/SA-CORE-2018-004
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: Update to 2.0.0 release. * Fixes CVE-2017-17528.
LinuxSecurity.com: Red Hat Single Sign-On 7.2.2 is now available for download from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
LinuxSecurity.com: It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code.
LinuxSecurity.com: This update includes the changes in tzdata 2018e for the Perl bindings. For the list of changes, see DLA-1371-1. For Debian 7 “Wheezy”, these problems have been fixed in version
LinuxSecurity.com: This update includes the changes in tzdata 2018e. Notable changes are: – North Korea switches back to +09 on 2018-05-05.
LinuxSecurity.com: Several vulnerabilities were discovered in MAD, an MPEG audio decoder library, which could result in denial of service if a malformed audio file is processed.
LinuxSecurity.com: New python packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
A bug exposed the passwords of an undisclosed number of users in plain text within Twitter’s internal systems The post Twitter advises all users to change passwords after glitch appeared first on WeLiveSecurity
The move is part of the company’s HTTPS-everywhere vision for the internet The post Google rolls out .app domains with built-in HTTPS appeared first on WeLiveSecurity
Reading Time: ~2 min.The Cyber News Rundown brings you the latest happenings in cybersecurity news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst and a guy with a passion for all things security. Any questions? Just ask. Cyberattack Shuts Down Mexico Central Bank Within the past week, several payment systems associated […]
Reading Time: ~1 min.Our most recent release of the DNS Protection agent provided customers with added features and enhancements designed to improve the overall product experience and its capabilities delivered to end users. We revamped the network detection functionality to improve accuracy and speed for roaming and off-site clients who frequently change networks. We also […]
security update
