The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Gollem, as used in Horde Groupware Webmail Edition and other products, had been affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting
The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
An update that solves one vulnerability and has one errata is now available.
New upstream release with bug and security fixes. Also, consolidates duplicate pakages marked and nodejs-marked. I tested upgrades from both, but may have missed some wonky situation.
New version 3.2.4, enabled build with androiddump.
Two memory management issues were found in the asfdemux element of the GStreamer “ugly” plugin collection, which can be triggered via a maliciously crafted file.
Two memory handling issues were found in gst-plugins-good0.10, a collection of GStreamer plugins from the “good” set:
It was discovered that there was both an invalid memory and heap overflow vulnerability in dosfstools, a collection of utilities for making and checking MS-DOS FAT filesystems.
Several vulnerabilities were discovered in package salt, a configuration management and infrastructure automation software.
New version 3.2.4, enabled build with androiddump.
An update that fixes one vulnerability is now available.
And most people don’t change their password even after hearing about a breach, a survey finds The post People know reusing passwords is risky – then do it anyway appeared first on WeLiveSecurity
An update that solves one vulnerability and has two fixes is now available.
git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008) SL7 x86_64 git-1.8.3.1-23.el7_8.x86_64.rpm git-daemon-1.8.3.1-23.el7_8.x86_64.rpm git-debuginfo-1.8.3.1-23.el7_8.x86_64.rpm git-gnome-keyring-1.8.3.1-23.el7_8.x86_64.rpm git-svn-1.8.3.1-23.el7_8.x86_64.rpm noarch emacs-git-1.8.3.1-23.el7_8.noarch.rpm [More…]
## Python 3.8.3 This is the third maintenance release of Python 3.8. See [the c hangelog](https://docs.python.org/release/3.8.3/whatsnew/changelog.html#changelo g) for details. Contains the security fix for CVE-2020-8492.
An update that fixes three vulnerabilities is now available.
USN-4369-1 introduced a regression in the Linux kernel.
USN-4367-1 introduced a regression in the Linux kernel.
Left unpatched, the vulnerability could expose almost all Android users to the risk of having their personal data intercepted by attackers The post Critical Android flaw lets attackers hijack almost any app, steal data appeared first on WeLiveSecurity
Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.
An update for freerdp is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for freerdp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Various minor vulnerabilities have been addredd in libexif, a library to parse EXIF metadata files.
This is a security update for JBoss EAP Continuous Delivery 19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes 5 vulnerabilities is now available.
security update
security update
Turla has updated its ComRAT backdoor and now uses the Gmail web interface for Command and Control The post From Agent.BTZ to ComRAT v4: A ten‑year journey appeared first on WeLiveSecurity
An update that fixes three vulnerabilities is now available.
Several security issues were fixed in Unbound.
Updated transmission packages fix security vulnerability: Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent
Updated sleuthkit packages fix security vulnerabilities: An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532).
Updated log4net packages fix security vulnerability This patch fixes a security vulnerabiliy reported by Karthik Balasundaram. The security vulnerability was found in the way how log4net parses xml configuration files where it allowed to process XML External Entity Processing. An attacker could use
Advisory text to describe the update. Wrap lines at ~75 chars. Updated dojo package fixes security vulnerabilities: In affected versions of dojo, the deepCopy method is vulnerable to
A hack-and-extort campaign takes aim at poorly secured databases replete with customer information that can be exploited for further attacks The post Crooks threaten to leak customer data stolen from e‑commerce sites appeared first on WeLiveSecurity
Has the landmark law helped build a culture of privacy in organizations and have consumers become more wary of sharing their personal data? The post Two years later, has GDPR fulfilled its promise? appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
