An update is now available for Red Hat Ceph Storage 4.2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for kernel is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update that fixes 13 vulnerabilities is now available.
An update that fixes 13 vulnerabilities is now available.
This update upgrades Firefox to version 78.6.1 ESR. * Mozilla: Use-after-free write when handling a malicious COOKIE-ECHO SCTP chunk (CVE-2020-16044) SL7 x86_64 firefox-78.6.1-1.el7_9.x86_64.rpm firefox-debuginfo-78.6.1-1.el7_9.x86_64.rpm firefox-78.6.1-1.el7_9.i686.rpm – Scientific Linux Development Team
An update that solves 6 vulnerabilities and has 58 fixes is now available.
A flaw was discovered in coturn, a TURN and STUN server for VoIP. By default coturn does not allow peers on the loopback addresses (127.x.x.x and ::1). A remote attacker can bypass the protection via a specially crafted request using a peer address of ‘0.0.0.0’ and trick
An update that contains security fixes can now be installed.
security update
An update that fixes 13 vulnerabilities is now available.
An update that fixes 13 vulnerabilities is now available.
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.
A use-after-free in Mozilla Firefox’s SCTP handling may allow remote code execution.
A buffer overflow in ipmitool might allow remote attacker(s) to execute arbitrary code.
Multiple vulnerabilities have been found in Firejail, the worst of which could result in the arbitrary execution of code.
security update
security update
New Firefox version (84.0.2) which fixes security / stability issues.
A malicious peer could have modified a COOKIE-ECHO chunk in a SCTP packet in a way that potentially resulted in a use-after-free. We presume that with enough effort it could have been exploited to run arbitrary code. (CVE-2020-16044).
It was discovered that mingw-binutils and binutils suffered from two vulnerabilites which might lead to DoS. Null Pointer Dereference in debug_get_real_type could result in DoS (CVE-2020-16598).
XSS was discovered in SquirrelMail through 1.4.22. Due to improper handling of RCDATA and RAWTEXT type elements, the built-in sanitization mechanism can be bypassed. Malicious script content from HTML e-mail can be executed within the application context via crafted use of (for example) a NOEMBED, NOFRAMES, NOSCRIPT, or TEXTAREA element ().
Busybox contains a Missing SSL certificate validation vulnerability in The “busybox wget” applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using “busybox wget https://compromised-domain.com/important-file”. ().
The container suse/sle15 was updated. The following patches have been included in this update:
It was discovered that Dovecot incorrectly handled certain imap hibernation commands. A remote authenticated attacker could possibly use this issue to access other users’ email (CVE-2020-24386). Innokentii Sennovskiy discovered that Dovecot incorrectly handled MIME
security update
Many users have until February 8 to accept the new rules – or else lose access to the app The post WhatsApp updates privacy policy to enable sharing more data with Facebook appeared first on WeLiveSecurity
An update is now available for Red Hat support for Spring Boot. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each
There was an integer overflow vulnerability concerning the length of websocket frames received via a websocket connection. An attacker could use this flaw to cause a denial of service attack on an HTTP Server allowing websocket connections.
Security fix for CVE-2020-13482
Backport patches for CVE-2020-35493, CVE-2020-35494, CVE-2020-35495, CVE-2020-35496.
Security fix for CVE-2020-13482.
Several security vulnerabilities were addressed in pacemaker, a cluster resource manager. CVE-2018-16877
The update for minidlna released as DSA 4806-1 introduced a regression when purging the package. Updated minidlna packages are now available to correct this issue.
ImageMagick: Shell injection via PDF password could result in arbitrary code execution (CVE-2020-29599) SL7 x86_64 ImageMagick-6.9.10.68-5.el7_9.i686.rpm ImageMagick-6.9.10.68-5.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-5.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-5.el7_9.x86_64.rpm ImageMagick-debuginfo-6.9.10.68-5.el7_9.i686.rpm ImageMagick-debuginfo-6.9.10.68-5.el7 [More…]
An update for openvswitch2.11, ovn2.11, redhat-release-virtualization-host, and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 and Red Hat Virtualization Engine 4.3. Red Hat Product Security has rated this update as having a security impact
security update
It’s hardly fun and games for top gaming companies and their customers as half a million employee credentials turn up for sale on the dark web The post Stolen employee credentials put leading gaming firms at risk appeared first on WeLiveSecurity
LibreOffice slideshow aborts with stack smashing in cairo’s composite_boxes. For Debian 9 stretch, this problem has been fixed in version
