Menu

Monthly Archives: August 2019

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 6 vulnerabilities is now available.

NASA astronaut accused of accessing ex-wife’s bank account from space

An update that solves 5 vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Time to spin the wheel of pwnage! This week, malware can infect your…. Android set-top box!

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Romance scams – 80 people charged with ripping off millions of dollars
Android 10 coming soon, with important privacy upgrades
Report: 53% of social media logins are fraudulent
Dixons hits back at McAfee’s £30m antivirus sueball: Your AV didn’t work on Windows 10S
Android PDF app with just 100m downloads caught sneaking malware into mobes

security update

Employers Beware: Microsoft Word ‘Resume’ Phish Delivers Quasar RAT

An update that solves 7 vulnerabilities and has three fixes is now available.

Several vulnerabilities have been found in the Apache HTTPD server. CVE-2019-9517

ghostscript: -dSAFER escape via .buildfont1 (701394) (CVE-2019-10216) SL7 x86_64 ghostscript-9.25-2.el7_7.1.i686.rpm ghostscript-9.25-2.el7_7.1.x86_64.rpm ghostscript-cups-9.25-2.el7_7.1.x86_64.rpm ghostscript-debuginfo-9.25-2.el7_7.1.i686.rpm ghostscript-debuginfo-9.25-2.el7_7.1.x86_64.rpm libgs-9.25-2.el7_7.1.i686.rpm libgs-9.25-2.el7_7.1.x86_64.rpm ghostsc [More…]

zziplib: Bus error caused by loading of a misaligned address inzzip/zip.c (CVE-2018-6541) * zziplib: Memory leak triggered in the function __zzip_parse_root_directory in zip.c (CVE-2018-16548) SL7 x86_64 zziplib-0.13.62-11.el7.i686.rpm zziplib-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62-11.el7.x86_64.rpm zziplib-utils-0.13.62-11.el7.x86_64.rpm zziplib-devel-0.13.62- [More…]

opensc: Buffer overflows handling responses from Muscle Cards in card- muscle.c:muscle_list_files() (CVE-2018-16391) * opensc: Buffer overflows handling responses from TCOS Cards in card- tcos.c:tcos_select_file() (CVE-2018-16392) * opensc: Buffer overflows handling responses from Gemsafe V1 Smartcards in pkcs15-gemsafeV1.c:gemsafe_get_cert_len() (CVE-2018-16393) * opensc: Buffer overflow h [More…]

gvfs: Incorrect authorization in admin backend allows privileged users to read and modify arbitrary files without prompting for password (CVE-2019-3827) SL7 x86_64 gvfs-1.36.2-3.el7.i686.rpm gvfs-smb-1.36.2-3.el7.x86_64.rpm gvfs-afp-1.36.2-3.el7.x86_64.rpm gvfs-mtp-1.36.2-3.el7.x86_64.rpm gvfs-devel-1.36.2-3.el7.x86_64.rpm gvfs-client-1.36.2-3.el7.x86_64.rpm gvfs [More…]

Malicious App on Google Play Tallies 100 Million Downloads
Imperva Firewall Breach Exposes Customer API Keys, SSL Certificates
We will hack back if you tamper with our shiz, NATO declares to world’s black hats
Why is learning Python important in Data Science?
Oil and Gas Firms Targeted By New LYCEUM Threat Group

Security fix for CVE-2019-13509

An update that fixes three vulnerabilities is now available.

GitHub joins WebAuthn club
Hostinger upgrades password security after 14m accounts breached
Court squeezes $1 million back from convicted phisher
Weekly review – the hot 21 stories of the week
Yes, TfL asked people to write down their Oyster passwords – but don’t worry, they didn’t inhale

An update for ruby is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for kernel is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Can’t bear to part with that well-worn copy of Windows 7? Microsoft might let you keep it updated an extra year
Breaking news: Apple un-breaks break on jailbreak break

security update

Fraught ‘naut who sought consort’s report says: I was up to naught, I will thwart fault tort

An update that contains security fixes can now be installed.

New kernel packages are available for Slackware 14.2 to fix a security issue.

Apple Fixes iOS Flaw That Opened iPhones to Jailbreaks

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

IRS Impersonation Attacks Spread Malware Nationwide
ThreatList: Half of All Social Media Logins Are Fraud
Hostinger Data Breach: 14M Customer Passwords, Personal Data at Risk
Company that was laughed off-stage sues Black Hat

Multiple vulnerabilities have been found in xymon, the network monitoring application. Remote attackers might leverage these vulnerabilities in the CGI parsing code (including buffer overflows and XSS) to cause denial of service, or any other unspecified impact.

Hacktivist skids nip at Mounties’ ankles, Emotet ransomware rides again, and more
Biz forked out $115k to tout ‘Time AI’ crypto at Black Hat. Now it sues organizers because hackers heckled it
Hostinger resets passwords following security breach

Update to v1.15.2 + carry upstream #81330

Even Rouault found an issue in tiff, a library providing support for the Tag Image File Format. Wrong handling off integer overflow checks, that are based on undefined

Solving the Cyber Security Problem: Mission Impossible

Addresses CVE-2019-14462 and CVE-2019-14463

Addresses CVE-2019-14462 and CVE-2019-14463

Update to Node.js 10.6.13

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has two fixes is now available.

Security gone in 600 seconds: Make-me-admin hole found in Lenovo Windows laptop crapware. Delete it now

An update that solves three vulnerabilities and has two fixes is now available.

It was discovered that there was a remote arbitrary code vulnerability in commons-beanutils, a set of utilities for manipulating JavaBeans code.

The package nginx before version 1.16.1-1 is vulnerable to denial of service.

The package nginx-mainline before version 1.17.3-1 is vulnerable to denial of service.

The package firefox before version 68.0.2-1 is vulnerable to information disclosure.

The package subversion before version 1.12.2-1 is vulnerable to denial of service.

The package libreoffice-still before version 6.2.6-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure.

An update that fixes one vulnerability is now available.

Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in

Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting

Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or bypass of ACLs.

security update

2019-08-14 – Fix compile issues – Fix output buffer size for lzo1x_decompress_safe() 2019-08-07 – Fix VerifyExtensionMap #179 2019-08-06 – Fix compile errors 2019-08-05 – Fix nfdump.1 man page. #175 – Fix off by 1 array. #173 – Fix use after free in ModifyCompressFile – Add bound checks in AddExporterStat #174 – Add bound checks in […]

security update

WordPress Plugins Exploited in Ongoing Attack, Researchers Warn

Three vulnerabilities were discovered in the HTTP/2 code of Nginx, a high-performance web and reverse proxy server, which could result in denial of service.

Someone find a make-me-admin hole in your laptop crapware? Don’t want fix the bug? Just move the EOL date – right, Lenovo?
Authorities arrest culprits for crypto mining at Ukraine nuclear plant

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.