The last Patch Tuesday of the year brings another fresh batch of fixes for Microsoft products and while the number may be lower the patches are no less important. The post Microsoft Patch Tuesday fixes 58 flaws appeared first on WeLiveSecurity
The updated packages fix some problems found in version 86 and security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=27630
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves 8 vulnerabilities, contains one feature and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
security update
security update
U.S. tax-payers will be able to enroll in the Identity Protection PIN program that was previously available only to certain users starting mid-January. The post The Internal Revenue Service expands identity protection to all tax‑payers appeared first on WeLiveSecurity
David Benjamin discovered a flaw in the GENERAL_NAME_cmp() function which could cause a NULL dereference, resulting in denial of service. Additional details can be found in the upstream advisory:
An update that solves 6 vulnerabilities and has one errata is now available.
An update for mariadb-galera is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of High. A Common Vulnerability Scoring System (CVSS) base score, which
The new release patches a total of eight vulnerabilities affecting the desktop versions of the popular browser. The post Google patches four high‑severity flaws in Chrome appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that contains security fixes can now be installed.
When reading SMTP server status codes, Thunderbird writes an integer value to a position on the stack that is intended to contain just one byte. Depending on processor architecture and stack layout, this leads to stack corruption that may be exploitable (CVE-2020-26970).
In PDFResurrect before 0.20, lack of header validation checks causes a heap-buffer-overflow in pdf_get_version() (CVE-2020-20740). References: – https://bugs.mageia.org/show_bug.cgi?id=27704
Mutt before 2.0.2 did not ensure that $ssl_force_tls was processed if an IMAP server’s initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in authentication credentials being exposed on an unencrypted connection, or to a machine-in-the-middle (CVE-2020-28896).
Security fix for CVE-2020-8037
security update
security update
Santa will soon come down the chimney, but there are potential entry points into your home and digital life that you should never leave open The post Cybersecurity Advent Calendar: Let Santa in, keep hackers out! appeared first on WeLiveSecurity
The package musl before version 1.2.1-2 is vulnerable to arbitrary code execution.
The package webkit2gtk before version 2.30.3-1 is vulnerable to arbitrary code execution.
The package gitea before version 1.12.6-1 is vulnerable to insufficient validation.
The package neomutt before version 20201120-1 is vulnerable to silent downgrade.
The package matrix-synapse before version 1.20.1-1 is vulnerable to denial of service.
Biological Worries Over Malware Attacks Researchers have recently unveiled the latest potential victim for malware authors: biological laboratories. By illicitly accessing these facilities, hackers may be able to digitally replace sections of DNA strings, causing unexpected results when biologists go to create or experiment with these compounds. While it is fortunate that this specific targeted […]
security update
Two vulnerabilities in the certificate list syntax verification and in the handling of CSN normalization were discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can take advantage of these
Several vulnerabilities were discovered in salt. CVE-2020-16846
According to data from a recent report, only 60% of office workers worldwide believe their company is resilient against cyberattacks. Nearly one in four (23%) admit to not knowing, while nearly one in five (18%) flat-out think it isn’t. In the anonymous, write-in responses to the survey, many workers agreed that their employers could be […]
ESET experts look back at some of the key themes that defined the cybersecurity landscape in the year that’s ending and give their takes on what to expect in 2021 The post Cybersecurity Trends 2021: Staying secure in uncertain times appeared first on WeLiveSecurity
An update that fixes 5 vulnerabilities, contains one feature is now available.
An update that fixes 10 vulnerabilities is now available.
Chiaki Ishikawa discovered a stack overflow in SMTP server status handling which could potentially result in the execution of arbitrary code.
