The updated packages fix a security vulnerability: Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor. (CVE-2019-17064)
Updated hunspell packages fix security vulnerability: Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx (CVE-2019-16707).
The updated package fixes a security vulnerability: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. (CVE-2019-15237)
Updated pdfresurrect package fixes security vulnerabilities: A vulnerability was found in PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled (CVE-2019-14267).
The updated packages fix an issue: Wrong permissions on /etc/freshclam.conf prevent freshclam usage with authenticated proxy. (rhbz#1733112)
Updated filezilla packages fix bugs and a security vulnerability: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.
In the second blogpost of the two-part series we’ll suggest handy tips to help enhance the security of your mobile devices The post 20 tips for 2020: Be smarter with your smartphone appeared first on WeLiveSecurity
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes three vulnerabilities is now available.
In this first instalment of the two-article series we will be looking at cybersecurity habits to avoid when using your computing devices The post 20 tips for 2020: Mistakes to avoid appeared first on WeLiveSecurity
Several security bugs have been identified and fixed in php5, a server-side, HTML-embedded scripting language. The affected components include the exif module and handling of filenames
It was discovered that there was a potential denial of service vulnerability in libxml2, the GNOME XML parsing library. For Debian 8 “Jessie”, this issue has been fixed in libxml2 version
Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-19948
security update
security update
security update
security update
security update
Several issues were discovered in the Tomcat servlet and JSP engine, which could result in session fixation attacks, information disclosure, cross- site scripting, denial of service via resource exhaustion and insecure redirects.
It was discovered that debian-lan-config, a FAI config space for the Debian-LAN system, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other user principals.
Guido Vranken discovered an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. For the oldstable distribution (stretch), this problem has been fixed
It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211
It’s not a stretch to surmise that the incident was enabled by poor security settings The post Prison surveillance footage posted on YouTube appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that solves 24 vulnerabilities and has 75 fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that solves 24 vulnerabilities and has 75 fixes is now available.
An update that fixes one vulnerability is now available.
Disposing of old tech isn’t a one-click solution; there are multiple things you have to consider before moving on to greener pastures The post How to get rid of your old devices safely appeared first on WeLiveSecurity
Updated php packages fix security vulnerabilities: DirectoryIterator class silently truncates after a null byte (CVE-2019-11045).
he updated packages fix security vulnerabilities and a packaging problem: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make
The updated package fixes a security vulnerability: A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon. (CVE-2019-14857)
Updated libofx packages fix security vulnerability: There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump (CVE-2019-9656).
An issue was discovered in libopensc/card-setcos.c in OpenSC, which has an incorrect read operation during parsing of a SETCOS file attribute.
Type: Vulnerability. ImageMagick is prone to multiple heap-based buffer-overflow vulnerabilities; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. IBM Cognos Analytics is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability; fixes are available.
Type: Vulnerability. FasterXML Jackson-databind is prone to a remote code-execution vulnerability; fixes are available.
This update is based on upstream 5.4.6 and fixes various potential security issues related to buffer overflows, double frees, NUll pointer dereferences, improper / missing input validations and so on. It also adds other bugfixes all over the kernel.
Type: Vulnerability. Trend Micro Apex Central is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. TYPO3 is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. IBM Spectrum Scale is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Samba is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.
Type: Vulnerability. Redis is prone to a buffer overflow vulnerability; fixes are available.
Type: Vulnerability. Multiple Trend Micro Products are prone to a local security-bypass vulnerability; fixes are available.
Type: Vulnerability. Apple iOS/iPadOS/watchOS/macOS are prone to a security vulnerability; fixes are available.
Type: Vulnerability. Wecon PLC Editor is prone to multiple stack-based buffer-overflow vulnerabilities.
Type: Vulnerability. Multiple Moxa Products are prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Broadcom CA Client Automation is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Sudo is prone to multiple security-bypass vulnerabilities; fixes are available.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4107
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4148
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4240
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4326
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4190
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4190
Type: Vulnerability. RedHat Ceph is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Redis is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Kubernetes API Server is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Apache Log4j is prone to remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Multiple VMware products are prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Kubernetes is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Equinox Control Expert is prone to an SQL-injection vulnerability.
