The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837). The fetch module was susceptible to path traversal (CVE-2019-3828).
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c. (CVE-2019-7397) References: – https://bugs.mageia.org/show_bug.cgi?id=24396
Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506). Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788).
Several security issues were fixed in Ghostscript.
An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.
Our penchant for plugging in random memory sticks isn’t the only trouble with our USB hygiene, a study shows The post Most second-hand thumb drives contain data from past owners appeared first on WeLiveSecurity
More advice for detecting and avoiding sextortion scams The post I Still Didn’t See What You Did appeared first on WeLiveSecurity
Reading Time: ~4 min. Since the dawn of IT, there’s been a very consistent theme among admins: end users are the weakest link in your network, organization, security strategy, fill-in-the-blank. We’ve all heard the stories, and even experienced them first-hand. An employee falls for a phishing scam and the whole network is down. Another colleague […]
An update that fixes three vulnerabilities is now available.
Risk Level: Very Low. Type: Trojan.
An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes two vulnerabilities is now available.
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that solves 9 vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
The third penalty that Europe has levied on the tech giant in less than two years brings the total to €8.25 billion The post Google hit with €1.49 billion antitrust fine by EU appeared first on WeLiveSecurity
The package wordpress before version 5.1-1 is vulnerable to directory traversal.
The package libelf before version 0.176-1 is vulnerable to denial of service.
Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to gain unauthorized access.
ESET researchers detail the latest tricks and techniques OceanLotus uses to deliver its backdoor while staying under the radar The post Fake or Fake: Keeping up with OceanLotus decoys appeared first on WeLiveSecurity
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0597
An update that fixes three vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
security update
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
cloud-init: extra ssh keys added to authorized_keys on the Azure platform (CVE-2019-0816) SL7 x86_64 cloud-init-18.2-1.el7_6.2.x86_64.rpm – Scientific Linux Development Team
It’s prudent to get a security solution for your device, but a test by AV-Comparatives shows why you need to choose judiciously The post You should pick your Android security app wisely, test shows appeared first on WeLiveSecurity
An update that fixes 9 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0482
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0485
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0483
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0512
It has been discovered that OTRS (Open source Ticket Request System) is susceptible to code injection vulnerability. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully
Cyberblackmail/sextortion again raises its not-so-pretty little head The post I didn’t see what you did, redux appeared first on WeLiveSecurity
An update is now available for CloudForms Management Engine 5.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
security update
The CLI tools in python-rdflib-tools can load python modules found in the current directory. This happens because “python -m” appends the current directory in the python path.
The ikiwiki maintainers discovered that the aggregate plugin did not use LWPx::ParanoidAgent. On sites where the aggregate plugin is enabled, authorized wiki editors could tell ikiwiki to fetch potentially undesired URIs even if LWPx::ParanoidAgent was installed:
