Menu

Monthly Archives: September 2019

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

Bug fixes and security fixes. Better threading compile time option set. See: https://src.fedoraproject.org/rpms/ImageMagick/pull-request/2 Additional formats enabled.

Bug fixes and security fixes. Better threading compile time option set. See: https://src.fedoraproject.org/rpms/ImageMagick/pull-request/2 Additional formats enabled.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– Update jackson-databind to version 2.9.9.3. – Update jackson-core to version 2.9.9. – Update jackson-annotations to version 2.9.9. – Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.

– rebase to latest upstream version 9.27 – security fixes added for: – CVE-2019-14811 (bug #1747908) – CVE-2019-14812 (bug #1747907) – CVE-2019-14813 (bug #1747906) – CVE-2019-14817 (bug #1747909)

This kernel update is based on the upstream 5.2.16 and fixes atleast the following security issues: There is heap-based buffer overflow in the marvell wifi chip driver that allows local users to cause a denial of service(system crash) or possibly

This kernel update is based on the upstream 4.14.145 and fixes atleast the following security issues: There is heap-based buffer overflow in the marvell wifi chip driver that allows local users to cause a denial of service(system crash) or possibly

Updated samba packages fix security vulnerabilities: A combination of parameters and permissions in smb.conf can allow user to escape from the share path definition (CVE-2019-10197).

An update for kpatch-patch is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

The updated thunderbird packages fix security issues: Covert Content Attack on S/MIME encryption using a crafted multipart/ alternative message. (CVE-2019-11739)

It was discovered that any unprivileged user could monitor and send method calls to the ibus bus of another user, due to a misconfiguration during the setup of the DBus server. When ibus is in use, a local attacker, who discovers the UNIX socket used by another user connected on a graphical environment, could use […]

Multiple flaws were found in the way Chromium 73.0.3683.103 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information. (CVE-2019-5805, CVE-2019-5806, CVE-2019-5807, CVE-2019-5808, CVE-2019-5809, CVE-2019-5810,

Disgraced ex-Kaspersky guy made me do it, says bloke in Russian court on hacking charges
Poor security: 15,000 private webcams exposed to creeps

security update

security update

security update

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes two vulnerabilities is now available.

– Updated to new upstream (69.0.1) – Wayland rendering fixes —- – The update to 69.0.1 – Fix flickering issues – Fix disappearing webrtc dialogs —- – Fixed rendering artifacts on Wayland backend

Update to Samba 4.11.0 —- Update to Samba 4.11.0rc4 —- Update to Samba 4.11.0rc3 – Security fixes for CVE-2019-10197

Facebook Removed Tens of Thousands of Apps Post-Cambridge Analytica
How To Keep Your Data Safe When Traveling With A Laptop
Forcepoint VPN Client is Vulnerable to Privilege Escalation Attacks
Bulgarian phishing gang member who lived with his parents jailed for part in £40m fraud ring

Reading Time: ~ 2 min. TFlower Ransomware Exploiting RDP  Ransomware attacks seem to be earning larger payouts by focusing on big businesses and governments, and a new variant dubbed TFlower might be no exception. TFlower has been proliferating by hacking into compromised networks through various remote desktop services. Attackers can reportedly execute the malware and begin encrypting most file types and removing all local backups. It is still unclear how much the demanded ransom is, but […]

Supply chain actors agree that everyone’s a security risk – except themselves, of course

Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: Missing sanitising in the EXIF extension and the iconv_mime_decode_headers() function could result in information disclosure or denial of service.

News Wrap: Emotet’s Return, U.S. Vs. Snowden, Physical Pen Testers Arrested

An update that fixes 35 vulnerabilities is now available.

An update that fixes 35 vulnerabilities is now available.

Mattress Company Leaks Data Records of 387K Customers
Server-squashing zero-day published for phpMyAdmin tool
IBM’s new 53-qubit quantum ‘mainframe’ is live in the cloud
Report: Use of AI surveillance is growing around the world

dovecot: improper NULL byte handling in IMAP and ManageSieve protocol parsers leads to out of bounds writes (CVE-2019-11500) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. SL7 x86_64 dovecot-2.2.36-3.el7_7.1.i686.rpm [More…]

A buffer overflow flaw was found in the way Linux kernel’s vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could use this flaw to increase their privileges on the host. (CVE-2019-14835) […]

Facebook Libra rejected by France as “dangerous”

An update for kernel-alt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for qpid-proton is now available for Satellite Tools 6.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for qpid-proton is now available for Satellite Tools 6.4. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several vulnerabilities were found in QEMU, a fast processor emulator (notably used in KVM and Xen HVM virtualization).

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for jenkins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for dovecot is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Nice work if you can grift it: Two blokes accused of swindling $10m from the elderly with bogus virus infection alerts

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

15,000 private webcams left open to snooping, no password required
If you’re using Harbor as your container registry, bear in mind it can be hijacked with has_admin_role = True
FedEx execs: We had no idea cyberattack would be so bad. Investors: Is that why you sold $40m+ of your own shares?

security update

Payment Card Breach Hits 8 Cities Using Vulnerable Bill Portal
Microsoft Silent Update Torpedoes Windows Defender
These Hacks Require Literally Sneaking in the Backdoor
How to spot online dating scam and its never ending fakery
Universities warned to brace for cyberattacks

The UK’s cybersecurity agency also outlines precautions that academia should take to mitigate risks The post Universities warned to brace for cyberattacks appeared first on WeLiveSecurity

Air Force to offer up a satellite to hackers at Defcon 2020
Chinese students in UK ripe target for scammers exploiting visa concerns
Researchers find 737 million medical images exposed on the internet
US files suit against Snowden to keep book profits out of his hands
Belgian F-16 pilot rescued from power line after emergency ejection
Smart TVs, Subscription Services Leak Data to Facebook, Google

This update upgrades Thunderbird to version 60.9.0. * Mozilla: Covert Content Attack on S/MIME encryption using a crafted multipart/alternative message (CVE-2019-11739) * Mozilla: Memory safety bugs fixed in Firefox 69, Firefox ESR 68.1, and Firefox ESR 60.9 (CVE-2019-11740) * Mozilla: Same-origin policy violation with SVG filters and canvas to steal cross-origin images (CVE-2019-11742) * Mo […]

WannaCry is still the smallpox of infosec. But the latest strain (sort of) immunises its victims
No surprises in the top 25 most dangerous software errors

An update that fixes 35 vulnerabilities is now available.

An update that fixes 35 vulnerabilities is now available.

IT now stands for Intermediate Targets: Tech providers pwned by snoops eyeing up customers – report

An update for the nginx:1.14 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for thunderbird is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for systemd is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

An update for ruby is now available for Red Hat Enterprise Linux 7.3 Advanced Update Support, Red Hat Enterprise Linux 7.3 Telco Extended Update Support, and Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions.

Remember that security probe that ended with a sheriff cuffing the pen testers? The contract is now public so you can decide who screwed up

An update for kernel is now available for Red Hat Enterprise Linux 5 Extended Lifecycle Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for patch is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Smashing Security #146: Password secrets and baking brownies

An update for skydive is now available for Red Hat OpenStack Platform 14.0 (Rocky). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Update to 4.1.7

Marc Rogers: Success of Anonymous Bug Submission Program ‘Takes A Village’
IRS Emails Promise a Refund But Deliver Botnet Recruitment
Scotiabank slammed for ‘muppet-grade security’ after internal source code and credentials spill onto open internet
Every Ecuadorian has been compromised in massive data breach
GitHub gobbles biz used by NASA, Google, etc to search code for bugs and security holes in Mars rovers, apps…
Uni sysadmins, don’t relax. Cybercrooks are still after your crown jewels, warns NCSC
Rethinking Responsibilities and Remedies in Social-Engineering Attacks

Risk Level: Very Low. Type: Trojan.

Remote access flaws found in popular routers, NAS devices

In almost all tested units, the researchers achieved their goal of obtaining remote root-level access The post Remote access flaws found in popular routers, NAS devices appeared first on WeLiveSecurity

Analytics exec nicked as Ecuador tries to rush through privacy laws after massive data leak
Emotet Returns from Summer Vacation, Ramps Up Stolen Email Tactic

An update that fixes one vulnerability is now available.

An update that fixes three vulnerabilities is now available.

Edward Snowden Sued by U.S. Over New Memoir
CookieMiner malware targets Macs, steals passwords and SMS messages, mines for cryptocurrency