Menu

Monthly Archives: November 2019

updated to 3.04 (CVE-2019-19035)

An update that fixes one vulnerability is now available.

The updated packages fix a security vulnerability: file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used. (CVE-2019-12450)

Updated httpie packages fix security vulnerability: HTTPie is vulnerable to Open Redirect that allows an attacker to write an arbitrary file with supplied filename and content to the current directory, by redirecting a request from HTTP to a crafted URL pointing

Updated python-sqlalchemy packages fix security vulnerabilities: SQL Injection via the order_by parameter (CVE-2019-7164). SQL Injection via the group_by parameter (CVE-2019-7548).

Updated glibc packages fixes the following security issue: On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local

gnupg2 is updated to 2.2.18 and fix security vulnerability: Web of Trust forgeries using collisions in SHA-1 signatures (CVE-2019-14855) * Note that this change removes all SHA-1 based key signature newer than 2019-01-19 from the web-of-trust. This includes all key signature created

With KENT CamEye Travelling in a Cab Just Got a Lot Safer!

security update

Private details of Palo Alto Networks employees leaked online

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IP APM is prone to an unauthorized file-access vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. HAProxy is prone to a CRLF-injection vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IP is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IP is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. F5 SSL Orchestrator is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. FreeIPA is prone to a denial-of-service vulnerability; fixes are available.

480.1 million mobile VPN downloaded worldwide in 12 months
Netflix account freeze – don’t click, it’s a scam!
Customers complain after alarms go offline, as security firm hit by ransomware attack
Amazon Plans Ring Facial Recognition-Based ‘Watch List:’ Report

An update that fixes four vulnerabilities is now available.

How Will Blockchain Technology Revolutionize Logistics?

Several vulnerabilities have been identified in the VNC code of ssvnc, an encryption-capable VNC client..

Handling of Netscape Certificate Sequences in CERT_DecodeCertPackage() may haved crash with a NULL deref leading to a Denial-of-Service.

US tightens rules on drone use in policy update
Adobe’s Magento Marketplace suffers data breach
Pressure mounts for federal privacy law with second bill
Master Go player retires citing AI supremacy
Palo Alto Networks employee data breach highlights risks posed by third party vendors

Several vulnerabilities have been identified in the VNC code of vino, a desktop sharing utility for the GNOME desktop environment.

React Prereleases-Preparing for the Future

Fix a grub hidden-menu regression and a bug in blscfg variable expansion —- Security fix for CVE-2019-14865

Updates the nss package to upstream NSS 3.47.1. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47.1_release_notes

Type: Vulnerability. F5 BIG-IP AFM is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Ghostscript is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. FreeIPA is prone to a information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 Products are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Kaspersky Protection extension for Google Chrome is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Pivotal Ops Manager is prone to local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. IBM Spectrum Protect is prone to a clickjacking vulnerability; fixes are available.

Type: Vulnerability. Multiple Kaspersky Products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. ABB Relion 670 Series is prone to a directory-traversal vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to an information-disclosure vulnerability; fixes are available.

Sextortion with a twist of Litecoin
Botnet found using YouTube to illegally mine cryptocurrency
Stay safe on Black Friday – and the rest of the year, too!
UPbit cryptocurrency exchange hacked; Ether worth $50 million stolen
Google caught a Russian state hacker crew uploading badness to the Play Store
Small businesses also need protection from cyber attacks
ThreatList: Healthcare Breaches Spike in October
Kids’ smartwatch security tracker can be hacked by anyone
Ransomware attack freezes health records access at 110 nursing homes
HPE warns of impending SSD disk doom
Twitter says it won’t delete tweets from those who have died
5 scams to watch out for this shopping season

Black Friday and Cyber Monday are just around the corner and scammers are gearing up to flood you with bogus offers The post 5 scams to watch out for this shopping season appeared first on WeLiveSecurity

An update that fixes two vulnerabilities is now available.

An update that contains security fixes can now be installed.

An update that contains security fixes can now be installed.

psutil could be made to crash or run programs.

Cloudy biz Datrix locks down phishing attack in 15 mins after fat thumb triggers email badness

Tim Düsterhus discovered that haproxy, a TCP/HTTP reverse proxy, did not properly sanitize HTTP headers when converting from HTTP/2 to HTTP/1. This would allow a remote user to perform CRLF injections.

This week, we give thanks to Fortinet for reminding us what awful crypto with hardcoded keys looks like

security update

How To Stop Someone From Spying On Your Cell Phone

Fixes a CVE: CVE-2019-13038 mod_auth_mellon: an Open Redirect via the login?ReturnTo= substring which could facilitate information theft

NSO Group President Defends Controversial Tactics

Type: Vulnerability. Ruby is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. ABB Relion 650 and 670 Series are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Squid is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Ansible Tower is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Dell EMC Storage Monitoring and Reporting (SMR) is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. PuTTY is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. OpenAFS is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Redhat Undertow is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. ZmartZone mod_auth_openidc Module is prone to an open-redirection vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. DotNetNuke is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. OpenAFS is prone to an information-disclosure vulnerability; fixes are available.

Ginp Android trojan targets banking apps & threatens 2FA/SMS
SDKs Misused to Scrape Twitter, Facebook Account Info
Smashing Security #156: Better safe than Sony
Facebook & Twitter suffer data breach via third-party developers
Cryptocurrency exchange loses US$50 million in apparent hack

UPbit has announced that, as a precaution, all transactions will remain suspended for at least two weeks The post Cryptocurrency exchange loses US$50 million in apparent hack appeared first on WeLiveSecurity

IoT Smartwatch Exposes Kids’ Personal, GPS Data
Federal Data Privacy Bill Takes Aim at Tech Giants
Dexphot Malware Hijacked 80K+ Devices to Mine Cryptocurrency

An update that fixes four vulnerabilities is now available.

An update that fixes 18 vulnerabilities is now available.

An update that fixes 16 vulnerabilities is now available.

Facebook, Twitter profiles slurped by mobile apps using malicious SDKs

NSS could be made to crash or run programs if it received specially crafted input.

Splunk customers should update now to dodge Y2K-style bug
EU raises eyebrows at possible US encryption ban
‘Ethical’ hackers say: It’s just hacker. To be one is no longer a bad thing