An update for kernel is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
The package dovecot before version 2.3.13-1 is vulnerable to multiple issues including information disclosure and denial of service.
The package poppler before version 21.01.0-1 is vulnerable to arbitrary code execution.
The package roundcubemail before version 1.4.10-1 is vulnerable to cross-site scripting.
The package rsync before version 3.2.3-2 is vulnerable to man-in-the- middle.
The container harbor/harbor-trivy-adapter was updated. The following patches have been included in this update:
The scam starts with a text warning victims of suspicious activity on their accounts The post PayPal users targeted in new SMS phishing campaign appeared first on WeLiveSecurity
It was discovered that there was an issue in the gssproxy privilege separation caused by gssproxy not unlocking cond_mutex prior to calling pthread_exit.
It was discovered that csync2, a cluster synchronization tool, did not correctly check for the return value from GnuTLS security routines. It neglected to repeatedly call this function as required by the design of the API.
The vlc package has been updated to version 3.0.12.1, which includes security enhancements in the web interface, as well as other fixes and enhancements. See the upstream NEWS file for details.
There is a floating point exception in dcraw_common.cpp of libRAW. It will lead to remote denial of service attack. This code is embedded in rawtherapee (CVE-2017-13735). References:
Kevin Backhouse discovered that GDM incorrectly launched the initial setup tool when the accountsservice daemon was not reachable. A local attacker able to cause accountsservice to crash or stop responding could trick GDM into launching the initial setup tool and create a privileged user (CVE-2020-16125).
libxml2 v2.9.10 and earlier has a global Buffer Overflow vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c (CVE-2020-24977). References: – https://bugs.mageia.org/show_bug.cgi?id=27300
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there (CVE-2020-11867).
security update
security update
ceph 15.2.8 GA Security fix for CVE-2020-27781
Multiple security issues were discovered in the Chromium web browser, which could result in the execution of arbitrary code, denial of service or information disclosure.
It was discovered that incorrect validation of JWT tokens in InfluxDB, a time series, metrics, and analytics database, could result in authentication bypass.
An update that contains security fixes can now be installed.
Is the message real or fake? Take our Phishing Derby quiz to find out how much you know about phishing. The post Would you take the bait? Take our phishing quiz to find out! appeared first on WeLiveSecurity
David Cook reported several memory safety issues affecting the RPC protocol in p11-kit, a library providing a way to load and enumerate PKCS#11 modules.
security update
