Two vulnerabilities were discovered in spamassassin, a Perl-based spam filter using text analysis. CVE-2018-11805
Multiple cross-site scripting and cross-site request forgery issues were discovered in the DAViCal CalDAV Server.
A vulnerability has been found in php-horde, the Horde Application Framework, which may result in information disclosure via cross-site scripting.
This update provides an update to 5.4 series kernels, currently based on upstream 5.4.2, adding support for new hardware and features, and fixing atleast the following security issue: KVM: x86: fix out-of-bounds write in KVM_GET_EMULATED_CPUID
Updated ncurses packages fix security vulnerabilities: Heap-based buffer over-read in the _nc_find_entry function (CVE-2019-17594).
Updated signing-party package fixes security vulnerability: The gpg-key2ps tool in signing-party contained an unsafe shell call enabling shell injection via a User ID (CVE-2019-11627).
Reading Time: ~ 4 min. The holiday shopping season is prime time for digital purchases and cybercriminals are cashing in on the merriment. With online shopping officially becoming more popular than traditional in-store visits this year, all signs point to an increase in cyberattacks. It’s more important than ever to be mindful of potential dangers […]
Type: Vulnerability. OpenBSD is prone to a local privilege escalation vulnerability; fixes are available.
Type: Vulnerability. Atlassian FishEye and Crucible are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Redhat 3scale API Management is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. McAfee TechCheck is prone to an arbitrary code-execution vulnerability; fixes are available.
Type: Vulnerability. IBM Cloud Pak System is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Linux Kernel is prone to an information disclosure vulnerability.
Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. IBM Spectrum Scale is prone to a cross-site scripting vulnerability; fixes are available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Risk Level: Very Low. Type: Trojan.
Reading Time: ~ 2 min. Zeppelin Ransomware Spreading Over the last month, researchers have been monitoring the spread of a new ransomware variant, Zeppelin. This is the latest version of the ransomware-as-a-service that started life as VegaLocker/Buran and has differentiated itself by focusing on healthcare and IT organizations in both the U.S. and Europe. This […]
Type: Vulnerability. Atlassian FishEye and Crucible are prone to an unauthorized-access vulnerability; fixes are available.
– update to upstream version 4.3.0 – fixes CVE-2019-19331 – root.keys is moved to /var/lib/knot-resolver – knot-resolver no longer requires write permission to /etc/knot-resolver/
Device quarantine for alternate pci assignment methods [XSA-306]
– update to upstream version 4.3.0 – fixes CVE-2019-19331 – root.keys is moved to /var/lib/knot-resolver – knot-resolver no longer requires write permission to /etc/knot-resolver/
Type: Vulnerability. Webform Module of Drupal is prone to multiple vulnerabilities; fixes are available.
Type: Vulnerability. OpenStack Keystone is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Siemens SCALANCE W700 and W1700 is prone to an information disclosure vulnerability; fixes are available.
An update is now available for CloudForms Management Engine 5.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
This update upgrades Thunderbird to version 68.3.0. * Mozilla: Use-after-free in worker destruction (CVE-2019-17008) * Mozilla: Memory safety bugs fixed in Firefox 71 and Firefox ESR 68.3 (CVE-2019-17012) * Mozilla: Buffer overflow in plain text serializer (CVE-2019-17005) * Mozilla: Use-after-free when performing device orientation checks (CVE-2019-17010) * Mozilla: Use-after-free when ret [More…]
Red Hat OpenShift Service Mesh 1.0.3. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes 118 vulnerabilities is now available.
RabbitMQ could be made to execute arbitrary code if it received a specially crafted input.
The browser’s latest version also aims to up the ante in phishing protection The post Chrome now warns you if your password has been stolen appeared first on WeLiveSecurity
Update to Samba 4.11.3 – Security fixes for CVE-2019-14861, CVE-2019-14870 —- Restart winbindd on samba-winbind package upgrade
security update
Type: Vulnerability. WebKit is prone to an arbitrary-code execution vulnerability; fixes are available.
Type: Vulnerability. Broadcom CA Nolio is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Apple iOS and iPadOS are prone to a security bypass vulnerability; fixes are available.
Type: Vulnerability. Apple iOS and iPadOS are prone to an arbitrary code execution vulnerability; fixes are available.
Type: Vulnerability. Apple Xcode is prone to an arbitrary code-execution vulnerability; fixes are available.
Risk Level: Very Low. Type: Virus.
Risk Level: Very Low. Type: Trojan.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4152
Upstream details at : https://access.redhat.com/errata/RHSA-2019:4108
Several security issues were fixed in Samba.
