security update
You may not be able to escape internet trolls, but you have a choice about how you will deal with them – here’s how you can handle trolls without losing your cool The post Don’t feed the trolls and other tips for avoiding online drama appeared first on WeLiveSecurity
Amir Sarabadani and Kunal Mehta discovered that the import functionality of Hyperkitty, the web user interface to access Mailman 3 archives, did not restrict the visibility of private archives during the import, i.e. that during the import of a private Mailman 2 archive the archive was
security update
8u292 update
8u292 update
Security fix for CVE-2021-30465
**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) * bug #41230 [FrameworkBundle][Validator] Fix deprecations from Doctrine Annotations+Cache (derrabus) * bug #41240 Fixed deprecation warnings about passing null as parameter (derrabus) * bug #41241 [Finder] Fix gitignore regex
**Version 3.4.49** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) —- **Version 3.4.48** (2021-05-12) * security **CVE-2021-21424** [Security][Guard] Prevent user enumeration (chalasr)
Luis Merino, Markus Vervier and Eric Sesterhenn discovered an off-by-one in Nginx, a high-performance web and reverse proxy server, which could result in denial of service and potentially the execution of arbitrary code.
The container caasp/v4.5/velero-restic-restore-helper was updated. The following patches have been included in this update:
The container caasp/v4.5/velero-plugin-for-microsoft-azure was updated. The following patches have been included in this update:
The container caasp/v4.5/velero-plugin-for-gcp was updated. The following patches have been included in this update:
The container caasp/v4.5/velero-plugin-for-aws was updated. The following patches have been included in this update:
The container caasp/v4.5/velero was updated. The following patches have been included in this update:
security update
You’ve likely heard of software-as-a-service (SaaS), infrastructure-as-a-service (IaaS), and numerous other “as-a-service” platforms that help support the modern business world. What you may not know is that cybercriminals often use the same business concepts and service models in their own organizations as regular, non-criminal enterprises; i.e., the same practices the majority of their intended victims […]
Here’s how easily your phone number could be stolen, why a successful SIM swap scam is only the beginning of your problems, and how you can avoid becoming a victim of the attack The post I hacked my friend’s website after a SIM swap attack appeared first on WeLiveSecurity
Patch for CVE-2020-24119.
CVE-2021-3480: invalid BIND DN crash
Patch for CVE-2020-24119.
CVE-2021-3480: invalid BIND DN crash
An update that fixes one vulnerability is now available.
Patches to remedy the vulnerabilities should be released over the coming weeks The post Bluetooth bugs could allow attackers to impersonate devices appeared first on WeLiveSecurity
Multiple vulnerabilities have been found in Ceph, the worst of which could result in privilege escalation.
nginx could be made to crash or run programs if it received specially crafted network traffic.
A vulnerability in Nextcloud Desktop Client could allow a remote attacker to execute arbitrary commands.
Multiple vulnerabilities have been found in cURL, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in OpenSSH, the worst of which could allow a remote attacker to execute arbitrary code.
The package thunderbird before version 78.10.2-1 is vulnerable to multiple issues including content spoofing and information disclosure.
The package hivex before version 1.3.20-1 is vulnerable to denial of service.
If you’re an admin, service provider, security executive, or are otherwise affiliated with the world of IT solutions, then you know that one of the biggest challenges to overcome is efficacy. Especially in terms of cybersecurity, efficacy is something of an amorphous term; everyone wants it to be better, but what exactly does that mean? […]
An update that fixes one vulnerability is now available.
Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.
Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.12.
Red Hat OpenShift Container Platform release 4.7.12 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.7.12.
Release of OpenShift Serverless Client kn 1.14.1 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
You would do well to update to macOS Big Sur 11.4 post-haste The post Apple fixes macOS zero‑day bug that let malware take secret screenshots appeared first on WeLiveSecurity
Online dating scams often follow the same script – here’s what senior citizens should watch out for and how their younger relatives can help them avoid falling victim The post Rom‑con: How romance fraud targets older people and how to avoid it appeared first on WeLiveSecurity
An update for openshift-serverless-1-kn-cli-artifacts-rhel8-container, openshift-serverless-1-knative-rhel8-operator-container, and openshift-serverless-1-serverless-operator-bundle-container is now available for Openshift Serveless 1.14.
An update that fixes one vulnerability is now available.
Roman Fiedler found that libX11, the X11 protocol client library, was vulnerable to protocol command injection due to insufficient validation of arguments to some functions.
Roman Fiedler reported that missing length validation in various functions provided by libx11, the X11 client-side library, allow to inject X11 protocol commands on X clients, leading to authentication bypass, denial of service or potentially the
