– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html
Several security issues were fixed in LibreOffice.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that solves two vulnerabilities and has three fixes is now available.
Tracking the malicious activities of the elusive Ke3chang APT group, ESET researchers have discovered new versions of malware families linked to the group, and a previously unreported backdoor The post Okrum: Ke3chang group targets diplomatic missions appeared first on WeLiveSecurity
security update
Several security issues were fixed in Thunderbird.
Keeping up with BlueKeep; or how many internet-facing systems, and in which countries and industries, remain ripe for exploitation? The post BlueKeep patching isn’t progressing fast enough appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
An update that fixes three vulnerabilities is now available.
An update that fixes 12 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 10 vulnerabilities is now available.
An update that solves 7 vulnerabilities and has three fixes is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1775
The package chromium before version 75.0.3770.142-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
The package squid before version 4.8-1 is vulnerable to arbitrary code execution.
The package firefox before version 68.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site request forgery, sandbox escape, arbitrary filesystem access, content spoofing, cross-site scripting, denial of service, information disclosure, insufficient validation and silent downgrade.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1774
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1777
A use-after-free in onig_new_deluxe() in regext.c allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
A researcher found that it was possible to subvert the platform’s password recovery mechanism and take control of user accounts The post How your Instagram account could have been hijacked appeared first on WeLiveSecurity
An update that solves one vulnerability and has two fixes is now available.
Several security issues were fixed in NSS.
An update is now available for Red Hat JBoss BPM Suite. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several security issues were fixed in Redis.
An update for vim is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for keepalived is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for libssh2 is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for perl is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for 389-ds-base is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Several security issues were fixed in NSS.
Risk Level: Very Low. Type: Trojan.
This update includes a fix for a security vulnerability, CVE-2018-20843: > Fix extraction of namespace prefixes from XML names; XML names with multiple colons could end up in the wrong namespace, and take a high amount of RAM and CPU resources while processing, opening the door to use for denial-of-service attacks For more information on […]
Rebase to radare2 3.6.0 and fixes CVE-2019-12790 and CVE-2019-12802
security update
An update that fixes 5 vulnerabilities is now available.
