Menu

Monthly Archives: December 2019

The OpenSLP package had two open security issues: CVE-2017-17833

phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/display_git_revision.lib.php and libraries/Footer.class.php.

This update addresses a number of bugs affecting processing of CRLs in mod_tls, including possible null pointer dereferences and missing some checks. Thanks to Lionel Debroux for reporting them.

This update addresses a number of bugs affecting processing of CRLs in mod_tls, including possible null pointer dereferences and missing some checks. Thanks to Lionel Debroux for reporting them.

Address CVE-2019-19204 CVE-2019-19203 CVE-2019-19012. Fixes are backported.

Amazon battles leaky S3 buckets with a new security tool
OpenBSD bugs, Microsoft’s bad update, a new Nork hacking crew, and more
New privacy tool exposes which website leaves your data unprotected
Email Voted a Weak Link for Election Security, with DMARC Lagging
China fires up ‘Great Cannon’ denial-of-service blaster, points it toward Hong Kong
Feds Crack Down on Money Mules, Warn of BEC Scams

Type: Vulnerability. Multiple Linux Distributions are prone to a security-bypass vulnerability.

Type: Vulnerability. Xen is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. CZ.NIC Knot Resolver is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. OpenBSD is prone to multiple privilege-escalation and authentication-bypass vulnerabilities; fixes are available.

Type: Vulnerability. Redhat KeyCloak is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Apache Olingo is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. An AMD ATI driver is prone to denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Wireshark is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Embedthis GoAhead is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Embedthis GoAhead Web Server is prone to a remote code execution vulnerability; fixes are available.

News Wrap: Authorities Target Evil Corp., Imminent Monitor, Money Mules
New Linux vulnerability puts VPN connections at risk of hijacking
Linux Bug Opens Most VPNs to Hijacking
Facebook Alleges Company Infiltrated Thousands for Ad Fraud
Stealthy MacOS Malware Tied to Lazarus APT
Mac users targetted by Lazarus ‘fileless’ Trojan

Reading Time: ~ 2 min. ZeroCleare Malware Wiping Systems IBM researchers have been tracking the steady rise in ZeroCleare deployments throughout the last year, culminating in a significant rise in 2019. This malware is deployed on both 32 and 64-bit systems in highly targeted attacks, with the capability to completely wipe the system by exploiting […]

US parents file class action against TikTok over children’s privacy
Reasons to be fearful 2020: Smishing, public Wi-Fi, deepfakes… and all the usual suspects
Instagram trying to protect kids by getting dates of birth from new users
OpenBSD devs patch authentication bypass bug
5 things you should never do when using anonymous operating systems

The updated packages fix a security vulnerability: ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. (CVE-2019-16709)

Updated sysstat package fixes security vulnerability: Memory corruption due to an integer overflow (CVE-2019-16167). References:

Updated python-psutil packages fix security vulnerability: Riccardo Schirone discovered that psutil incorrectly handled certain reference counting operations. An attacker could use this issue to cause psutil to crash, resulting in a denial of service, or possibly execute

Updated libvpx packages fix security vulnerabilities: It was discovered that libvpx did not properly handle certain malformed WebM media files. If an application using libvpx opened a specially crafted WebM file, a remote attacker could cause a denial of service, or possibly

Updated libvncserver packages fix security vulnerability: LibVNC contained a memory leak in VNC server code, which allowed an attacker to read stack memory and could be abused for information disclosure. Combined with another vulnerability, it could be used to

Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim’s .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based

SANS Announces 13th Holiday Hack Challenge and 2nd KringleCon infosec conference
Tricky VPN-busting bug lurks in iOS, Android, Linux distros, macOS, FreeBSD, OpenBSD, say university eggheads
VCs find exciting new way to blow $1m: Wire it directly to hackers after getting spoofed
If there’s somethin’ stored in a secure enclave, who ya gonna call? Membuster!
Ransomware Attack Hits Data Center Provider CyrusOne: Report
Israeli firm buys Private Internet Access (PIA) VPN raising privacy concerns

Type: Vulnerability. Redhat KeyCloak is prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability.

Type: Vulnerability. VMware Harbor Container Registry for PCF is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple local denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Moxa AWK-3121 Series is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple local denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Dell Command Update is prone to multiple arbitrary-file-deletion vulnerabilities; a fix is available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.

Type: Vulnerability. Reliable Controls LicenseManager is prone to a local code execution vulnerability; fixes are available.

Type: Vulnerability. Dell EMC RSA Authentication Manager is prone to an HTML-injection vulnerability; fixes are available.

AT&T, Verizon Subscribers Exposed as Mobile Bills Turn Up on the Open Web
Scammy and spammy harassers are chasing veteran pros off crypto-collab platform Keybase
Feds Offer $5M Reward to Nab ‘Evil Corp’ Dridex Hacker
Cookie-stealing malware wants to know your Facebook ad budget
Chinese DDoS tool Great Cannon resurfaces to target Hong Kong protestors
iCloud-hacking politician to be sentenced on Christmas eve
Machine-raiding Python libraries squashed by community
Feds slap $5m bounty on ‘Evil Corp’ Russian duo accused of running ZeuS, Dridex banking trojans
HackerOne Breach Leads to $20,000 Bounty Reward
Critical DoS messaging flaw fixed in December Android update
Microsoft readies new language for safe programming
OpenBSD Hit with Authentication, LPE Bugs
How to fool infosec wonks into pinning a cyber attack on China, Russia, Iran, whomever
Yodel parcel tracking app blabs about other people’s parcels
80% of all Android apps encrypt traffic by default

Google keeps pushing in its mission for broader encryption adoption The post 80% of all Android apps encrypt traffic by default appeared first on WeLiveSecurity

Major data center provider hit by ransomware attack, claims report
Oil be damned: Iran-based crooks flinging malware at Middle Eastern energy plants again – research
‘Ultimate’ MiTM Attack Steals $1M from Israeli Startup

An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

Snake bites: Beware malicious Python libraries

RabbitMQ could be made to execute arbitrary code if it received a specially crafted input.

Face scanning – privacy concern or identity protection?

What issues would face scanning attached to a mobile device resolve and, if used correctly, would it make the incursion into my privacy acceptable? The post Face scanning – privacy concern or identity protection? appeared first on WeLiveSecurity

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Atlassian scrambles to fix zero-day security hole accidentally disclosed on Twitter
Lazarus group goes back to the Apple orchard with new macOS trojan
Smashing Security #157: A biometric knuckle duster

Type: Vulnerability. Symantec Norton Password Manager is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Symantec Norton Password Manager is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Symantec Norton Password Manager is prone to a security bypass vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

ThreatList: 1 in 9 SMBs Believe Nation-State Actors Are Targeting Them
Cut-and-paste goof reveals HackerOne session cookie, and earns bug hunter $20,000
Flawed Implementation of RCS Standard putting data of millions at risk
Nebraska Medicine Breached By Rogue Employee
‘Highly Competitive’ Buer Loader Emerges in Underground Markets
Iran Targets Mideast Oil with ZeroCleare Wiper Malware
3 arrested, 30,000+ piracy sites shut down in global operation IOSX