Isaac Boukris and Andrew Bartlett discovered that the S4U2Self Kerberos extension used in Samba’s Active Directory support was susceptible to man-in-the-middle attacks caused by incomplete checksum validation.
Multiple issues have been addressed in Qt4. CVE-2018-15518
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
security update
Risk Level: Very Low. Type: Trojan.
What are some of the most interesting takeaways from Verizon’s latest annual security report? The post Verizon’s data breach report: What the numbers say appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 16 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 7 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 9 vulnerabilities is now available.
The PostgreSQL project has release a new minor release of the 9.4 branch. For Debian 8 “Jessie”, this has been uploaded as version
An update for python-jinja2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Updated openssh packages fix security vulnerabilities: Due to missing character encoding in the progress display, the object name can be used to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred (CVE-2019-6109).
Updated cronie packages fix security vulnerabilities: Cronie before 1.5.3 allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked (CVE-2019-9704).
Updated tcpreplay package fixes security vulnerabilities: An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary.
A vulnerability was found in the svgsalamander library. If the library is being used in a web application for processing user supplied SVG files then the app is vulnerable to SSRF (CVE-2017-5617). References:
Updated mxml packages fix security vulnerabilities: An issue has been found in Mini-XML (aka mxml) 2.12. It is a stack-based buffer overflow in mxml_write_node in mxml-file.c via vectors involving a double-precision floating point number and the ”
The updated packages fix security vulnerabilities: A vulnerability in the Portable Document Format (PDF) scanning functionality of Clam AntiVirus (ClamAV) Software versions 0.101.1 and prior could allow an unauthenticated, remote attacker to cause a denial of service (DoS)
Updated qt4 packages fix security vulnerability: A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp (CVE-2018-19872).
Updated bash package fixes security vulnerability: A vulnerability in which shell did not prevent user BASH_CMDS, allowing the user to execute any command with the permissions of the shell (CVE-2019-9924).
pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended headers (CVE-2019-9923). References:
Updated openexr package fixes security vulnerabilities: It was discovered that makeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified other impact (CVE-2018-18444).
Updated python packages fix security vulnerability: A ‘file:’ blacklist bypass in URIs by using the ‘local-file:’ scheme instead (CVE-2019-9948).
Updated sysstat package fix security vulnerabilities: Out-of-bounds read during a memmove call inside the remap_struct function (CVE-2018-19416).
Update to April 2019 CPU. See: http://mail.openjdk.java.net/pipermail/jdk- updates-dev/2019-April/000951.html
security update
security update
An update that contains security fixes can now be installed.
An update that solves one vulnerability and has one errata is now available.
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, sandbox bypass, information disclosure or the execution of arbitrary code.
Reading Time: ~2 min. Dharma Ransomware Employs Diversion Tactics Researchers recently discovered a new ransomware variant that displays an ESET AV removal screen once launched in order to divert the a victim’s attention from the silent encryption taking place. Initially dropped by an email spam campaign, the payload comes as a password protected zip archive, […]
Multiple vulnerabilities were discovered in the Symfony PHP framework which could lead to cache bypass, authentication bypass, information disclosure, open redirect, cross-site request forgery, deletion of arbitrary files, or arbitrary code execution.
security update
Security, Performance updates, fiexes blocker with crashing httpd BZ 1708248
Security, Performance updates, fiexes blocker with crashing httpd BZ 1708248
The 5.0.13 update contains a number of important fixes across the tree. There is no kernel-headers build this time. The tools version is 5.0.12 because originally it was built with the 5.0.12 kernel version but 5.0.13 was built before 5.0.12 could be filed in bodhi.
The 5.0.13 update contains a number of important fixes across the tree. There is no kernel-headers build this time. The tools version is 5.0.12 because originally it was built with the 5.0.12 kernel version but 5.0.13 was built before 5.0.12 could be filed in bodhi.
Security, Performance updates, fiexes blocker with crashing httpd BZ 1708248
Update Ruby on Rails to 5.2.3. Fixes CVE-2019-5418 CVE-2019-5419 CVE-2019-5420.
Update Ruby on Rails to 5.2.3. Fixes CVE-2019-5418 CVE-2019-5419 CVE-2019-5420.
Update Ruby on Rails to 5.2.3. Fixes CVE-2019-5418 CVE-2019-5419 CVE-2019-5420.
