An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that fixes four vulnerabilities is now available.
An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Samba could be made to crash if it received specially crafted network traffic.
An update for libvncserver is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Reading Time: ~ 2 min. Multiple Individuals Charged for Twitter Hack Three people were charged with last month’s Twitter hack, which generated over $100,000 in bitcoin by hijacking high-profile accounts. Of the 130 accounts used to spread the Bitcoin scam, major names included Elon Musk and Bill Gates, who have been portrayed in similar past […]
xrdp-sesman service in xrdp can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them
ruby-kramdown processes the template option inside Kramdown documents by default, which allows unintended read access (such as template=”/etc/passwd”) or unintended embedded Ruby code execution (such as a string that begins with template=”string://
An update that fixes 26 vulnerabilities is now available.
Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt
# rpki-client 6.7p1 * Security fix: Incorrect use of `EVP_PKEY_cmp` allowed an authentication bypass
The following CVE(s) have been reported against src:wpa. CVE-2019-10064
An update that fixes 7 vulnerabilities is now available.
An update that fixes 7 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
A use-after-free was found in iproute2, possibly allowing a Denial of Service condition.
A buffer overflow in gThumb might allow remote attacker(s) to execute arbitrary code.
Multiple vulnerabilities have been found in Apache, the worst of which could result in the arbitrary execution of code.
security update
Here’s what to be aware of if your personal data was compromised in the breach at the cloud software provider The post Blackbaud data breach: What you should know appeared first on WeLiveSecurity
An update that contains security fixes can now be installed.
An update that fixes 12 vulnerabilities is now available.
An update that fixes 6 vulnerabilities is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3253
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3344
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3233
security update
At Black Hat USA 2020, ESET researchers delved into details about the KrØØk vulnerability in Wi-Fi chips and revealed that similar bugs affect more chip brands than previously thought The post Beyond KrØØk: Even more Wi‑Fi chips vulnerable to eavesdropping appeared first on WeLiveSecurity
The intelligence agency warns of location tracking risks and offers tips for how to reduce the amount of data shared The post NSA shares advice on how to limit location tracking appeared first on WeLiveSecurity
Yunus ‘ad±rc± found an issue in the SUBSCRIBE method of UPnP, a network protocol for devices to automatically discover and communicate with each other. Insuficient checks on this method allowed attackers to use vulnerable UPnP services for DoS attacks or possibly to bypass
An update that solves one vulnerability and has two fixes is now available.
An update that fixes 10 vulnerabilities is now available.
An update that solves 19 vulnerabilities and has 92 fixes is now available.
ppp could be made to load arbitrary kernel modules and possibly run programs.
An update that solves one vulnerability and has one errata is now available.
In one scheme, shoppers ordering gadgets or gym equipment are in for a rude surprise – they receive disposable face masks instead The post FBI warns of surge in online shopping scams appeared first on WeLiveSecurity
An update that fixes 10 vulnerabilities is now available.
An update that fixes 26 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Red Hat Ansible Tower 3.7.2-1 – RHEL7 Container 2. Description: * Updated Named URLs to allow for testing the presence or absence of objects (CVE-2020-14337)
Red Hat Ansible Tower 3.6.5-1 – RHEL7 Container 2. Description: * Removed reports option for Satellite inventory script * Fixed Tower Server Side Request Forgery on Credentials (CVE-2020-14327)
USN-4441-1 introduced a regression in MySQL
security update
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
