security update
The container ses/7/ceph/ceph was updated. The following patches have been included in this update:
The package vivaldi before version 4.1.2369.11-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, content spoofing, incorrect calculation, information disclosure and insufficient validation.
The package powerdns before version 4.5.1-1 is vulnerable to denial of service.
The package 389-ds-base before version 2.0.7-1 is vulnerable to multiple issues including authentication bypass and denial of service.
The package geckodriver before version 0.29.1-1 is vulnerable to cross- site request forgery.
The package containerd before version 1.5.4-1 is vulnerable to directory traversal.
security update
A security update is now available for Red Hat Single Sign-On 7.4 from the Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Now that organizations are set to evolve a hybrid blend of home and office-based work for most employees, it is more important then ever to address the risks that insider threat can – willingly or unwitingly – pose. The post Tackling the insider threat to the new hybrid workplace appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
Update to 2.53.8.1 Includes fixes for mailnews archiving, as well as account creation after news subscribing. Show just an icon (instead of a big image etc.) when moving in drag-and-drop operations to make sure the target is visible. (You can change it back by toggling boolean preference “nglayout.enable_drag_images” in about:config).
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
security update
An issue has been found in libsndfile, a library for reading/writing audio files. A crafted WAV file can trigger a heap buffer overflow and might allow exectution of arbitrary code.
There are 30 vulnerabilities listed in total; organizations would do well to patch their systems if they haven’t done so yet The post Leading cybersecurity agencies reveal list of most exploited vulnerabilities of the past 2 years appeared first on WeLiveSecurity
With vacations in full swing, cybercriminals will be looking to scam vacationers looking for that perfect accommodation. The post Booking your next holiday? Watch out for these Airbnb scams appeared first on WeLiveSecurity
PEAR could be made to overwrite files as the administrator.
Several security issues were fixed in QPDF.
libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.
An update that solves one vulnerability, contains two features and has two fixes is now available.
libsndfile could be made to crash or run programs as your login if it opened a specially crafted file.
* Properly set the cookies settings after a network process crash. * Fix accessibility tree after a cross site navigation with PSON enabled. * Ensure WebKitScriptWorld::window-object-cleared signal is always emitted. * Fix several crashes and rendering issues. * Security fixes: CVE-2021-21775, CVE-2021-21779, CVE-2021-30663, CVE-2021-30665, CVE-2021-30689, CVE-2021-30720,
Twitter’s transparency report revealed that users aren’t quick to adopt 2FA and once they do enable it, they choose the least secure option The post Most Twitter users haven’t enabled 2FA yet, report reveals appeared first on WeLiveSecurity
Several security issues were fixed in WebKitGTK.
An update for rh-nodejs14-nodejs and rh-nodejs14-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for rh-nodejs12-nodejs and rh-nodejs12-nodejs-nodemon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
* Update to go1.16.6 * Security fix for CVE-2021-34558
Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.8.
Red Hat OpenShift Container Platform release 4.8.2 is now available with updates to packages and images that fix several bugs. This release includes a security update for Red Hat OpenShift Container Platform 4.8.
OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]
OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the [More…]
The vulnerability is under active exploitation by unknown attackers and affects a wide range of Apple’s products. The post Apple releases patch for zero‑day flaw in iOS, iPadOS and macOS appeared first on WeLiveSecurity
An update that fixes 8 vulnerabilities is now available.
An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
* Update to upstream 20210716 release * update NXP 8897/8997 firmware images * rtlwifi: de-dupe rtl8723b/rtl8192e SDIO/USB WiFi firmware * Mediatek: update WiFi/bluetooth chip (MT7921) * Mediatek: update MT7915 firmware to 20201105 * Mellanox: Add new mlxsw_spectrum firmware xx.2008.2946 * cxgb4: Update firmware to revision 1.26.0.0 * firmware/i915/guc: Add HuC v7.9.3 for TGL & DG1 […]
This update upgrades Thunderbird to version 78.12.0. * Mozilla: IMAP server responses sent by a MITM prior to STARTTLS could be processed (CVE-2021-29969) * Mozilla: Use-after-free in accessibility features of a document (CVE-2021-29970) * Mozilla: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 (CVE-2021-29976) * chromium-browser: Out of bounds write in ANGLE […]
Aspell could be made to execute arbitrary code or cause a crash if it received a specially crafted input.
An update is now available for Red Hat OpenShift Container Platform 4.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
