Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Visual Studio is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft ASP.NET is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Microsoft ASP.NET Core is prone to an information disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Word is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows Subsystem for Linux is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Visual Studio is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.
LinuxSecurity.com: Several security issues were fixed in NSS.
LinuxSecurity.com: Django could be made to expose spoofed information over the network.
What’s in store for automotive security once cars morph into mobile living rooms and working spaces? And how about transportation at large? The post CES – singularity and securing the car appeared first on WeLiveSecurity
LinuxSecurity.com: Updates for rh-dotnet21-dotnet and rh-dotnet22-dotnet are now available for .NET Core on Red Hat Enterprise Linux. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
LinuxSecurity.com: The avidemux package has been updated to version 2.7.1. Avidemux includes a bundled copy of the ffmpeg libraries, which have been updated from version 3.3.3 to version 3.3.9, fixing several security issues and other bugs.
LinuxSecurity.com: Double free in QXmlStreamReader (CVE-2018-15518). Denial of Service on malformed BMP file in QBmpHandler (CVE-2018-19873). References:
LinuxSecurity.com: A flaw was found in GNU Coreutils through 8.29 in chown-core.c. The functions chown and chgrp do not prevent replacement of a plain file with a symlink during use of the POSIX “-R -L” options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition (CVE-2017-18018).
LinuxSecurity.com: A leaky data conversion exposing a manager oracle (CVE-2018-16869). References: – https://bugs.mageia.org/show_bug.cgi?id=24080 – https://lists.opensuse.org/opensuse-updates/2018-12/msg00120.html
LinuxSecurity.com: It was found that when a retry task in ansible run with -vvv fails, it will log the raw return code, stdout and stderr from ssh which could have contained sensitive data (CVE-2018-16876). References:
LinuxSecurity.com: Jeffrey Altman reported that the backup tape controller (butc) process does accept incoming RPCs but does not require (or allow for) authentication of those RPCs, allowing an unauthenticated attacker to perform volume operations with administrator credentials (CVE-2018-16947).
LinuxSecurity.com: Several buffer overflows when handling responses from a Muscle Card in muscle_list_files in libopensc/card-muscle.c in OpenSC before 0.19.0-rc1 could be used by attackers able to supply crafted smartcards to cause a denial of service (application crash) or possibly have unspecified other impact (CVE-2018-16391).
LinuxSecurity.com: The __mkd_trim_line function in mkdio.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file (CVE-2018-11468). DISCOUNT through version 2.2.3a is vulnerable to a Heap-based
LinuxSecurity.com: It was discovered that ruby-loofah, a general library for manipulating and transforming HTML/XML documents and fragments, performed insufficient sanitising of SVG elements.
LinuxSecurity.com: It was discovered that malformed URLs could spoof the content of the default 404 page of Django, a Python web development framework. For the stable distribution (stretch), this problem has been fixed in
LinuxSecurity.com: The package elfutils before version 0.175-1 is vulnerable to denial of service.
Risk Level: Very Low.
In case there are some blank entries in your laundry list of New Year’s resolutions, we have a few tips for a bit of cybersecurity ‘soul searching’. Here’s the first batch, looking at how you can fix your good ol’ passwords. The post New Year’s resolutions: Get your passwords shipshape appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
