A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
This update upgrades Thunderbird to version 78.5.0. * Mozilla: Parsing mismatches could confuse and bypass security sanitizer for chrome privileged code (CVE-2020-26951) * Mozilla: Memory safety bugs fixed in Firefox 83 and Firefox ESR 78.5 (CVE-2020-26968) * Mozilla: Variable time processing of cross-origin images during drawImage calls (CVE-2020-16012) * Mozilla: Fullscreen could be enable [More…]
An update for faq is now available for Red Hat OpenShift Container Platform 4.6. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
Red Hat Ansible Tower 3.7.4-1 – RHEL7 Container 2. Description: * Fixed two jQuery vulnerabilities (CVE-2020-11022, CVE-2020-11023) * Improved Ansible Tower’s web service configuration to allow for
An update for rh-mariadb103-mariadb and rh-mariadb103-galera is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
The package swtpm before version 0.5.1-1 is vulnerable to privilege escalation.
The package rclone before version 1.53.3-1 is vulnerable to private key recovery.
An update that fixes two vulnerabilities is now available.
Some issues have been found in qemu, a fast processor emulator. All issues are related to assertion failures, out-of-bounds access
Update to WebKitGTK 2.30.3: * Fix backdrop filters with rounded borders. * Fix scrolling iframes when async scrolling is enabled. * Allow applications to handle drag and drop on the web view again. * Update Outlook user agent quirk. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-9983, CVE-2020-13584
An update that fixes one vulnerability is now available.
An update that fixes 5 vulnerabilities is now available.
Guenal Davalan reported a flaw in x11vnc, a VNC server to allow remote access to an existing X session. x11vnc creates shared memory segments with 0777 mode. A local attacker can take advantage of this flaw for information disclosure, denial of service or interfering with the VNC
security update
Fix for multiple CVEs
fix CVE-2020-27780: authentication bypass when the user doesn’t exist
Update to upstream 17.9.0 for bug and security fixes
The U.S. law enforcement agency shares a sampling of more than 90 spoofed FBI-related domains registered recently The post FBI warns of threat actors spoofing Bureau domains, email accounts appeared first on WeLiveSecurity
Here’s what to know about attacks where a fraudster has your number, literally and otherwise The post SIM swap scam: What it is and how to protect yourself appeared first on WeLiveSecurity
An update that fixes 10 vulnerabilities, contains one feature is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes 12 vulnerabilities is now available.
security update
An update that solves 26 vulnerabilities and has 32 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves 26 vulnerabilities and has 32 fixes is now available.
security update
This won’t be music to your ears – researchers spot an unsecured database replete with records used for an account hijacking spree The post Up to 350,000 Spotify accounts hacked in credential stuffing attacks appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that solves three vulnerabilities and has one errata is now available.
An update that solves 12 vulnerabilities and has 103 fixes is now available.
An update that fixes one vulnerability is now available.
This November 28 may be the most important Small Business Saturday since the occasion was founded by American Express in 2010. As early as July, nearly half (43 percent) of small businesses had closed at least temporarily, according to a study published in the Proceedings of the National Academy of Sciences. Research also suggests that […]
An update that solves 21 vulnerabilities and has 21 fixes is now available.
An update that solves 17 vulnerabilities and has 15 fixes is now available.
An update that fixes 5 vulnerabilities is now available.
net-snmp: Improper Privilege Management in EXTEND MIB may lead to privileged commands execution (CVE-2020-15862) SL6 x86_64 net-snmp-5.5-60.el6_10.2.x86_64.rpm net-snmp-debuginfo-5.5-60.el6_10.2.i686.rpm net-snmp-debuginfo-5.5-60.el6_10.2.x86_64.rpm net-snmp-libs-5.5-60.el6_10.2.i686.rpm net-snmp-libs-5.5-60.el6_10.2.x86_64.rpm net-snmp-devel-5.5-60.el6_10.2.i686.rpm [More…]
This update upgrades Thunderbird to version 78.4.3. * Mozilla: Write side effects in MCallGetProperty opcode not accounted for (CVE-2020-26950) SL6 x86_64 thunderbird-78.4.3-1.el6_10.x86_64.rpm thunderbird-debuginfo-78.4.3-1.el6_10.x86_64.rpm i386 thunderbird-78.4.3-1.el6_10.i686.rpm – Scientific Linux Development Team
An update that fixes 5 vulnerabilities is now available.
REvil Ransomware Strikes Hosting Provider In recent days the web hosting provider Managed.com has been working to recover from a ransomware attack targeting many of their core systems. While the company was able to stop the spread of the attack by shutting down their systems and client websites, it remains unclear what information may have […]
The peace of mind that comes with connected home security gadgets may be false – your smart doorbell may make an inviting target for unwanted visitors The post Security flaws in smart doorbells may open the door to hackers appeared first on WeLiveSecurity
