Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office SharePoint is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office Access Connectivity Engine is prone to a remote code-execution vulnerability; fixes are available.
Several security vulnerabilities were discovered in Zabbix, a server/client network monitoring solution. CVE-2016-10742
The package pacman before version 5.1.3-1 is vulnerable to arbitrary code execution.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0462
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
The repository of email addresses and other records would offer a gold mine of data for scammers The post Over 2 billion records exposed by email marketing firm appeared first on WeLiveSecurity
poppler could be made to crash if it opened a specially craftedfile.
Asian game developers again targeted in supply-chain attacks distributing malware in legitimately signed software The post Gaming industry still in the scope of attackers in Asia appeared first on WeLiveSecurity
A vulnerability in GNU Wget which could allow an attacker to obtain sensitive information.
Multiple vulnerabilities have been found in systemd, the worst of which may allow execution of arbitrary code.
Multiple vulnerabilities have been discovered in rdesktop, the worst of which could result in the remote execution of arbitrary code.
security update
A vulnerability in Tar could led to a Denial of Service condition.
Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which may allow execution of arbitrary code.
Multiple vulnerabilities have been found in cURL, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been discovered in openjpeg2, the open-source JPEG 2000 codec, that could be leveraged to cause a denial of service or possibly remote code execution.
Clement Lecigne discovered a use-after-free issue in chromium’s file reader implementation. A maliciously crafted file could be used to remotely execute arbitrary code because of this problem.
Input validation errors in Zsh could result in arbitrary code execution.
Multiple vulnerabilities have been found in Keepalived, the worst of which could allow an attacker to cause Denial of Service condition.
Several security vulnerabilities have been discovered in symfony, a PHP web application framework. Numerous symfony components are affected: Security, bundle readers, session handling, SecurityBundle,
security update
An update that fixes one vulnerability is now available.
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF extension had multiple cases of invalid memory access and rename() was implemented insecurely.
Security fix for CVE-2018-15587
An update that solves one vulnerability and has 5 fixes is now available.
An update that fixes two vulnerabilities is now available.
New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
An update that solves 5 vulnerabilities and has 6 fixes is now available.
Reading Time: ~2 min. Ransomware as-a-Service Offers Tiered Membership Benefits Jokeroo is the latest ransomware-as-a-service (RaaS) to begin spreading through hacker forums, though it’s differentiating itself by requiring a membership fee with various package offerings. For just $90, a buyer obtains access to a ransomware variant that they can fully customize in exchange for a […]
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0230
The vulnerabilities, which resided in associated smartphone apps, were both easy to find and easy to fix The post Flaws in smart car alarms exposed 3 million cars to hijack appeared first on WeLiveSecurity
An update that solves three vulnerabilities and has one errata is now available.
An update that fixes 9 vulnerabilities is now available.
An update that fixes 15 vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
A bright tomorrow of technical delight, or a dismal future of digital dysfunction? The post RSA conference, USA 2019: Keynotes and key words appeared first on WeLiveSecurity
Protecting your privacy is no longer just an option but a legal requirement in many parts of the world The post RSA 2019: Protecting your privacy in a NIST and GDPR world appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Risk Level: Very Low. Type: Trojan.
## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –
## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –
When symmetric encryption is used, data can be injected through the passphrase property of the gnupg.GPG.encrypt() and gnupg.GPG.decrypt() methods. The supplied passphrase is not validated for newlines, and the library passes –passphrase-fd=0 to the gpg executable, which expects the passphrase on the first line of stdin, and the ciphertext to be decrypted
