Menu

Monthly Archives: November 2019

Type: Vulnerability. Microsoft Windows is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft ActiveX Installer Service is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows JET Database Engine is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP Treasury and Risk Management is prone to an authorization-bypass vulnerability; fixes are available.

Type: Vulnerability. Adobe Illustrator is prone to multiple memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Illustrator is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Adobe Media Encoder is prone to multiple information-disclosure vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Bridge CC is prone to multiple unspecified memory-corruption vulnerabilities; fixes are available.

Type: Vulnerability. Adobe Media Encoder is prone to an unspecified remote code-execution vulnerability; fixes are available.

Type: Vulnerability. SAP BusinessObjects Business Intelligence Platform is prone to an XML External Entity injection vulnerability; fixes are available.

Type: Vulnerability. Adobe Animate is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. SAP Quality Management is prone to an unspecified SQL-injection vulnerability; fixes are available.

Type: Vulnerability. SAP Diagnostics Agent is prone to an unspecified information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP Enable Now is prone to an unspecified cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. SAP Business Objects Business Intelligence Platform is prone to an cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. SAP NetWeaver AS Java is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. SAP UI5 HTTP Handler is prone to an unspecified content-spoofing vulnerability; fixes are available.

DDoS Attacks Target Amazon, SoftLayer and Telecom Infrastructure
BlueKeep freakout had little to no impact on patching, say experts

built version 0.10.5 fix CVE-2019-18837 —- built version 0.10.4 —- built version 0.10.3

**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997

This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.

built version 0.10.5 fix CVE-2019-18837

**MySQL 8.0.18** Release notes: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-18.html CVEs fixed: CVE-2019-2911 CVE-2019-2914 CVE-2019-2938 CVE-2019-2946 CVE-2019-2957 CVE-2019-2960 CVE-2019-2963 CVE-2019-2966 CVE-2019-2967 CVE-2019-2968 CVE-2019-2974 CVE-2019-2982 CVE-2019-2991 CVE-2019-2993 CVE-2019-2997

rebase to 1.16.1

This update brings security updates for OpenJDK 13 and updates it to most current version 13.0.1.9.

security update

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to an integer overflow vulnerability; fixes are available.

Type: Vulnerability. Fortinet FortiClient for macOS is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apache CXF is prone to a denial-of-service vulnerability and an unauthorized access vulnerability; fixes are available.

Type: Vulnerability. Multiple Medtronic Products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Medtronic Products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Philips Tasy EMR is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Philips Tasy EMR is prone to a cross-site scripting vulnerability.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Fuji Electric V-Server is prone to multiple unspecified heap-based buffer overflow vulnerabilities; fixes are available.

ThreatList: Data Breaches Batter Stock Prices at Public Companies, For Months
Back-2-school hacking: Kaspersky blames pesky script kiddies for rash of DDoS cyber hooliganism
First BlueKeep attacks prompt fresh warnings

The infamous vulnerability has been exploited for a cryptocurrency mining campaign, but more damaging attacks may still be in store The post First BlueKeep attacks prompt fresh warnings appeared first on WeLiveSecurity

Microsoft urges us to patch after partially effective BlueKeep attack
If it sounds too good to be true, it most likely is: Nobody can decrypt the Dharma ransomware
Ransomware Attack Downs Hosting Service SmarterASP.NET
BlueKeep: What you need to know

An update that solves two vulnerabilities and has one errata is now available.

Encrypted Emails on macOS Found Stored in Unprotected Way
Adobe fixes SDK weakness affecting mobile apps
AI wordsmith too dangerous to be released… has been released
US military supplier in ‘Made in America’ fraud case
Huge Airbnb scam leads to promise to vet every host, every listing

Several vulnerabilities were discovered in Ampache, a web-based audio file management system.

Bash could be made to crash or execute arbitrary code if it received a specially crafted input.

Hate hub hacked, Cisco bugs squished, Bluekeep attacks begin, and much, much more

In haml, when using user input to perform tasks on the server, characters like ” ‘ must be escaped properly. In this case, the ‘ character was missed. An attacker can manipulate the input to introduce additional

fixed multiple security bugs

Security fix CVE-2019-16275 (AP mode PMF disconnection protection bypass)

Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.

An update that contains security fixes can now be installed.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, cross-site scripting or denial of service.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

fixed multiple security bugs

Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.

– fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that solves three vulnerabilities and has four fixes is now available.

An update that fixes one vulnerability is now available.

GDAL through 3.0.1 had a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold was exceeded.

Platinum APT Shines Up New Titanium Backdoor
Understanding the Ripple Effect: Large Enterprise Data Breaches Threaten Everyone

Type: Vulnerability. Multiple Cisco Products are prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business SPA500 Series IP Phones are prone to a local command-injection vulnerability;fixes are available.

Type: Vulnerability. Multiple Cisco WebEx products are prone to multiple local code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Webex Meetings is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Cisco Managed Services Accelerator is prone to an open-redirection vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business RV Series Routers are prone to an arbitrary command-execution vulnerability; fixes are available.