The OpenSLP package had two open security issues: CVE-2017-17833
phpMyAdmin before 4.9.2 does not escape certain Git information, related to libraries/display_git_revision.lib.php and libraries/Footer.class.php.
This update addresses a number of bugs affecting processing of CRLs in mod_tls, including possible null pointer dereferences and missing some checks. Thanks to Lionel Debroux for reporting them.
This update addresses a number of bugs affecting processing of CRLs in mod_tls, including possible null pointer dereferences and missing some checks. Thanks to Lionel Debroux for reporting them.
Address CVE-2019-19204 CVE-2019-19203 CVE-2019-19012. Fixes are backported.
Type: Vulnerability. Multiple Linux Distributions are prone to a security-bypass vulnerability.
Type: Vulnerability. Xen is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. CZ.NIC Knot Resolver is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. OpenBSD is prone to multiple privilege-escalation and authentication-bypass vulnerabilities; fixes are available.
Type: Vulnerability. Redhat KeyCloak is prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Apache Olingo is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. An AMD ATI driver is prone to denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Wireshark is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Embedthis GoAhead is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Embedthis GoAhead Web Server is prone to a remote code execution vulnerability; fixes are available.
Reading Time: ~ 2 min. ZeroCleare Malware Wiping Systems IBM researchers have been tracking the steady rise in ZeroCleare deployments throughout the last year, culminating in a significant rise in 2019. This malware is deployed on both 32 and 64-bit systems in highly targeted attacks, with the capability to completely wipe the system by exploiting […]
The updated packages fix a security vulnerability: ImageMagick 7.0.8-35 has a memory leak in coders/dps.c, as demonstrated by XCreateImage. (CVE-2019-16709)
Updated sysstat package fixes security vulnerability: Memory corruption due to an integer overflow (CVE-2019-16167). References:
Updated python-psutil packages fix security vulnerability: Riccardo Schirone discovered that psutil incorrectly handled certain reference counting operations. An attacker could use this issue to cause psutil to crash, resulting in a denial of service, or possibly execute
Updated libvpx packages fix security vulnerabilities: It was discovered that libvpx did not properly handle certain malformed WebM media files. If an application using libvpx opened a specially crafted WebM file, a remote attacker could cause a denial of service, or possibly
Updated libvncserver packages fix security vulnerability: LibVNC contained a memory leak in VNC server code, which allowed an attacker to read stack memory and could be abused for information disclosure. Combined with another vulnerability, it could be used to
Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim’s .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based
Type: Vulnerability. Redhat KeyCloak is prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a denial-of-service vulnerability.
Type: Vulnerability. VMware Harbor Container Registry for PCF is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.
Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.
Type: Vulnerability. Linux Kernel is prone to multiple local denial-of-service vulnerabilities; fixes are available.
Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Moxa AWK-3121 Series is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Linux Kernel is prone to multiple local denial-of-service vulnerabilities; fixes are available.
Type: Vulnerability. Dell Command Update is prone to multiple arbitrary-file-deletion vulnerabilities; a fix is available.
Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.
Type: Vulnerability. Linux Kernel is prone to a local denial-of-service vulnerability.
Type: Vulnerability. Reliable Controls LicenseManager is prone to a local code execution vulnerability; fixes are available.
Type: Vulnerability. Dell EMC RSA Authentication Manager is prone to an HTML-injection vulnerability; fixes are available.
Google keeps pushing in its mission for broader encryption adoption The post 80% of all Android apps encrypt traffic by default appeared first on WeLiveSecurity
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
RabbitMQ could be made to execute arbitrary code if it received a specially crafted input.
What issues would face scanning attached to a mobile device resolve and, if used correctly, would it make the incursion into my privacy acceptable? The post Face scanning – privacy concern or identity protection? appeared first on WeLiveSecurity
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Type: Vulnerability. Symantec Norton Password Manager is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Symantec Norton Password Manager is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Symantec Norton Password Manager is prone to a security bypass vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.
