security update
– New upstream version (86.0)
Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157
The container suse/sle15 was updated. The following patches have been included in this update:
An update that fixes two vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2021:0661
Upstream details at : https://access.redhat.com/errata/RHSA-2021:0656
Upstream details at : https://access.redhat.com/errata/RHSA-2021:0024
Upstream details at : https://access.redhat.com/errata/RHSA-2020:5408
Upstream details at : https://access.redhat.com/errata/RHSA-2020:5402
Beast Glatisant and Jelmer Vernooij reported that python-aiohttp, a async HTTP client/server framework, is prone to an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website.
security update
An update that fixes one vulnerability is now available.
A snapshot of some of the ways ESET makes an impact supporting the well-being of people, communities and the environment The post Championing worthy causes: How ESET gives a helping hand appeared first on WeLiveSecurity
Several issues have been found in python-pysaml2, a pure python implementation of SAML Version 2 Standard. CVE-2017-1000433
The container suse/sles12sp5 was updated. The following patches have been included in this update:
security update
security update
Update postgresql and libpq to the new upstream release.
Update postgresql and libpq to the new upstream release.
Linux: display frontend “be-alloc” mode is unsupported (comment only) [XSA-363, CVE-2021-26934] (#1929549) arm: The cache may not be cleaned for newly allocated scrubbed pages [XSA-364, CVE-2021-26933] (#1929547)
Two new tools will warn users about the risks of searching for and sharing content that exploits children, including the potential legal consequences of doing so The post Facebook ramps up fight against child abuse content appeared first on WeLiveSecurity
People who use devices running Android 9 or newer will be alerted if their login credentials have been stolen The post Google’s Password Checkup tool rolling out to Android devices appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code or information disclosure.
The package mumble before version 1.3.4-1 is vulnerable to arbitrary code execution.
The package postgresql before version 13.2-1 is vulnerable to information disclosure.
The package ansible-base before version 2.10.6-1 is vulnerable to information disclosure.
The package keycloak before version 12.0.3-1 is vulnerable to cross- site scripting.
An update for ansible is now available for Ansible Engine 2 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for ansible is now available for Ansible Engine 2.9 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Red Hat OpenShift Container Platform release 4.7.0 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
The incident raises concerns about the privacy and security of conversations taking place on the platform The post Clubhouse chats streamed to third‑party website appeared first on WeLiveSecurity
An update that solves two vulnerabilities and has two fixes is now available.
security update
security update
security update
A bug in the ad blocking component of Brave’s Tor feature caused the browser to leak users’ DNS queries The post Brave browser’s Tor mode exposed users’ dark web activity appeared first on WeLiveSecurity
gdk-pixbuf2 2.42.2 release, fixing CVE-2021-20240 and CVE-2020-29385. This update also includes new gdk-pixbuf2-xlib package that was split out from gdk- pixbuf2 to its own source rpm. The gdk-pixbuf2-xlib and gdk-pixbuf2-xlib-devel binary package names are identical to what they were before the split.
gdk-pixbuf2 2.42.2 release, fixing CVE-2021-20240 and CVE-2020-29385. This update also includes new gdk-pixbuf2-xlib package that was split out from gdk- pixbuf2 to its own source rpm. The gdk-pixbuf2-xlib and gdk-pixbuf2-xlib-devel binary package names are identical to what they were before the split.
An update that fixes one vulnerability is now available.
The package python-django before version 3.1.7-1 is vulnerable to url request injection.
