Menu

Monthly Archives: December 2020

An update that fixes one vulnerability is now available.

The 5 Most-Wanted Threatpost Stories of 2020
What’s Next for Ransomware in 2021?
Get back into the cybersecurity groove for 2021

Several security vulnerabilities were discovered in XStream, a Java library to serialize objects to XML and back again. CVE-2020-26258

It was discovered that minidlna does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue (CVE-2020-12695).

Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. (CVE-2020-8231). A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way

The package qemu before version 5.2.0-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.

The package firefox before version 84.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing and information disclosure.

The package openssl before version 1.1.1.i-1 is vulnerable to denial of service.

New warning issued over COVID‑19 vaccine fraud, cyberattacks

Cybercriminals look to cash in on the vaccine rollout, including by falsely offering to help people jump the line The post New warning issued over COVID‑19 vaccine fraud, cyberattacks appeared first on WeLiveSecurity

FBI Warn Hackers are Using Hijacked Home Security Devices for ‘Swatting’

An update that fixes 6 vulnerabilities is now available.

An update that fixes 6 vulnerabilities is now available.

This update includes the changes in tzdata 2020e for the Perl bindings. For the list of changes, see DLA-2510-1. For Debian 9 stretch, this problem has been fixed in version

This update includes the changes in tzdata 2020e. Notable changes are: – – Volgograd switched to Moscow time on 2020-12-27 at 02:00.

21 arrested after allegedly using stolen logins to commit fraud

UK police also give some food for thought to those on the verge of breaking the law The post 21 arrested after allegedly using stolen logins to commit fraud appeared first on WeLiveSecurity

Taking a Neighborhood Watch Approach to Retail Cybersecurity
The curse of knowing a bit about IT: ‘Could you just…?’ and ‘No I haven’t changed anything’
Lawsuit Claims Flawed Facial Recognition Led to Man’s Wrongful Arrest

An update that contains security fixes can now be installed.

6 Questions Attackers Ask Before Choosing an Asset to Exploit
Japanese Aerospace Firm Kawasaki Warns of Data Breach
2020 Work-for-Home Shift: What We Learned

Fixes stored cross-site scripting (XSS) vulnerability via HTML or plain text messages with malicious content. (CVE-2020-35730). References: – https://bugs.mageia.org/show_bug.cgi?id=27957

In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation (CVE-2020-0499).

Multiple buffer overflow flaws were found in pngcheck 2.4.0 and older (rhbz#1902806). References: – https://bugs.mageia.org/show_bug.cgi?id=27922

There’s a flaw in openjpeg in src/lib/openjp2/pi.c. When an attacker is able to provide crafted input to be processed by the openjpeg encoder, this could cause an out-of-bounds read. The greatest impact from this flaw is to application availability (CVE-2020-27841).

In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP (CVE-2020-27619). References: – https://bugs.mageia.org/show_bug.cgi?id=27868

posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 has a “double file descriptor close” issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the […]

security update

How Reverse Engineering Can Help Secure Your Linux Systems Against Malware>
Hackers Amp Up COVID-19 IP Theft Attacks
Ransomware in 2020: A Banner Year for Extortion

An issue was discovered in roundcube where in a cross-site scripting (XSS) via HTML or plain text messages with malicious content was possible.

Alex Birnberg discovered that roundcube, a skinnable AJAX based webmail solution for IMAP servers, is prone to a cross-site scripting vulnerability in handling HTML or Plain text messages with malicious content.

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

security update

security update

An update that fixes three vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

The update for python-apt released as DSA 4809-1 introduced a regression when passing a file descriptor to apt_inst.ArFile or apt_inst.DebFile causing a segmentation fault. Updated python-apt packages are now available to correct this issue.

https://lists.wikimedia.org/pipermail/mediawiki- announce/2020-December/000268.html

Backport patches for CVE-2020-16592 and CVE-2020-16598

Backport patches for CVE-2020-16592 and CVE-2020-16598

Update to latest upstream version.

An update that fixes one vulnerability is now available.

Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification (CVE-2020-13802). References: – https://bugs.mageia.org/show_bug.cgi?id=27511

Smart tech gifts: How to keep your kids and family safe

Cyberthreats can take the fun out of connected gadgets – here’s how to make sure your children enjoy the tech without putting themselves or their family at risk The post Smart tech gifts: How to keep your kids and family safe appeared first on WeLiveSecurity

The update for python-apt released as 2488-1 introduced a regression by causing a segmentation fault, which is now fixed with this update. For Debian 9 stretch, this problem has been fixed in version

An update that solves 7 vulnerabilities and has two fixes is now available.

New version 1.4.3. Security fix for CVE-2020-28241.

New version 1.4.3. Security fix for CVE-2020-28241.

An update that fixes 8 vulnerabilities is now available.

An update that fixes 8 vulnerabilities is now available.

security update

xenstore watch notifications lacking permission checks [XSA-115, CVE-2020-29480] (#1908091) Xenstore: new domains inheriting existing node permissions [XSA-322, CVE-2020-29481] (#1908095) Xenstore: wrong path length check [XSA-323, CVE-2020-29482] (#1908096) Xenstore: guests can crash xenstored via watchs [XSA-324, CVE-2020-29484] (#1908088) Xenstore: guests can disturb domain cleanup

xenstore watch notifications lacking permission checks [XSA-115, CVE-2020-29480] (#1908091) Xenstore: new domains inheriting existing node permissions [XSA-322, CVE-2020-29481] (#1908095) Xenstore: wrong path length check [XSA-323, CVE-2020-29482] (#1908096) Xenstore: guests can crash xenstored via watchs [XSA-324, CVE-2020-29484] (#1908088) Xenstore: guests can disturb domain cleanup

Several vulnerabilities were discovered in Sympa, a mailing list manager, which could result in local privilege escalation, denial of service or unauthorized access via the SOAP API.

A vulnerability in NSS might allow remote attackers to cause a Denial of Service condition.

7 ways malware can get into your device

You know that malware is bad, but are you also aware of the various common ways in which it can infiltrate your devices? The post 7 ways malware can get into your device appeared first on WeLiveSecurity

Windows Zero-Day Still Circulating After Faulty Fix

Multiple vulnerabilities have been found in Samba, the worst of which could result in a Denial of Service condition.

A vulnerability has been discovered in Apache Tomcat that allows for the disclosure of sensitive information.

A buffer overflow in HAProxy might allow an attacker to execute arbitrary code.

Lazarus Group Hits COVID-19 Vaccine-Maker in Espionage Attack

It was found that spip, a website engine for publishing, did not correctly validate its input (couleur, display, display_navigation, display_outils, imessage, and spip_ecran) allowing authenticated users to execute arbitrary code.

Third-Party APIs: How to Prevent Enumeration Attacks
Hey Alexa, Who Am I Messaging?
Emotet Returns to Hit 100K Mailboxes Per Day
Police bring down “bulletproof” VPN services beloved by cybercriminals

It was discovered that Awstats, a web server log analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution. The previous fix did not fully address the issue when the default

How to bring zero-trust security to microservices

The container ses/7/ceph/ceph was updated. The following patches have been included in this update:

US Department of Homeland Security warns American business not to use Chinese tech or let data behind the Great Firewall
Holiday Puppy Swindle Has Consumers Howling

Previous fix for buffer overrun printing the contents of the sPLT chunk in certain malformed inputs (RHBZ#1905775) was incomplete; it should be properly fixed now. —- Security fix for multiple buffer overflows from crafted file input (RHBZ#1902786,1902806,1902810: no CVE yet assigned), and for buffer overrun printing the contents of the sPLT chunk in certain malformed […]

Update to 2.16.9 Release notes: https://github.com/ARMmbed/mbedtls/releases/tag/v2.16.9

Previous fix for buffer overrun printing the contents of the sPLT chunk in certain malformed inputs (RHBZ#1905775) was incomplete; it should be properly fixed now. —- Security fix for multiple buffer overflows from crafted file input (RHBZ#1902786,1902806,1902810: no CVE yet assigned), and for buffer overrun printing the contents of the sPLT chunk in certain malformed […]

An update that fixes 8 vulnerabilities is now available.

Does a friend “need money urgently”? Check your facts before paying out…
Cybersecurity Advent calendar: Stay aware, stay safe!

When it comes to holiday gifts, surprise and wonder are always welcome. When it comes to protecting your security, however, you don’t want to leave anything to chance. The post Cybersecurity Advent calendar: Stay aware, stay safe! appeared first on WeLiveSecurity

Tech Giants Lend WhatsApp Support in Spyware Case Against NSO Group
UK cryptocurrency exchange EXMO suffers breach, funds stolen
Joker’s Stash Carding Site Taken Down
Patrick Wardle on Hackers Leveraging ‘Powerful’ iOS Bugs in High-Level Attacks
UK firm NOW: Pensions tells some customers a ‘service partner’ leaked their data all over ‘public software forum’

Security awareness training is one of the most straightforward ways to improve a business’ overall resilience against cyberattacks. That is, when you get it just right. Thanks to the disruptions to “normal” work routines that COVID-19 has brought, launching a company-wide training program to teach end users how to avoid phishing scams and online risks […]

An update that fixes one vulnerability is now available.

An update that solves 7 vulnerabilities and has two fixes is now available.

A few issues have been found in the OpenJDK 8u272 update, including LDAP connection failures and application crash. For Debian 9 stretch, this problem has been fixed in version

An update for kernel is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for the postgresql:10 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for mariadb-connector-c is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Nosy Ex-Partners Armed with Instagram Passwords Pose a Serious Threat
Smart Doorbell Disaster: Many Brands Vulnerable to Attack
Defending Against State and State-Sponsored Threat Actors
Zero-Click Apple Zero-Day Uncovered in Pegasus Spy Attack