Several security issues were fixed in MySQL.
This update ships updated CPU microcode for some types of Intel CPUs and provides mitigations for security vulnerabilities which could result in privilege escalation in combination with VT-d and various side channel attacks.
Several security issues were fixed in the kernel.
An update for thunderbird is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS` command to corrupt the heap and potentially result with remote code execution (CVE-2021-29477). An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt
This affects the package y18n before 3.2.2, 4.0.1 and 5.0.5. PoC by po6ix: const y18n = require(‘y18n’)(); y18n.setLocale(‘__proto__’); y18n.updateLocale({polluted: true}); console.log(polluted); // true (CVE-2020-7774).
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository (CVE-2021-3572). The bundled python-urllib3 was also vulnerable to:
In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream (CVE-2021-21341).
It was discovered that the previous upload of the package rabbitmq-server versioned 3.6.6-1+deb9u1 introduced a regression in function fmt_strip_tags. Big thanks to Christoph Haas for the reporting an issue and for testing the update.
encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method (CVE-2021-27918).
security update
The container suse-sles-15-sp2-chost-byos-v20210722-gen2 was updated. The following patches have been included in this update:
An update that solves one vulnerability and has one errata is now available.
Multiple vulnerabilities have been found in libsdl2, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in libyang, the worst of which could result in a Denial of Service condition.
Multiple vulnerabilities have been found in Leptonica, the worst of which could result in a Denial of Service condition.
At Carbonite + Webroot, we’re always preaching about the importance of layering security solutions. Because here’s the truth: data’s always at risk. Whether from cybercriminals, everyday mishaps or mother nature, businesses can put up all the defenses they want but disaster only has to successfully strike once. The global pandemic means more work is being […]
Security fix for CVE-2021-3602 bump podman to v3.2.3 include podman-machine- cni in podman-plugins subpackage bump crun to 0.20.1 —- Fix `secrets` definition in /usr/share/containers/containers.conf
To mitigate the chances of their Wi-Fi home routers being compromised, users would do well to change the manufacturer’s default access credentials The post Popular Wi‑Fi routers still using default passwords making them susceptible to attacks appeared first on WeLiveSecurity
The container sles-15-sp2-chost-byos-v20210722 was updated. The following patches have been included in this update:
The container suse-sles-15-sp2-chost-byos-v20210722-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
Several vulnerabilities were discovered in lemonldap-ng, a Web-SSO system. The flaws could result in information disclosure, authentication bypass, or could allow an attacker to increase its authentication level or impersonate another user, especially when lemonldap-ng is configured
security update
Multiple vulnerabilities have been found in Apache Velocity, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in IcedTeaWeb, the worst of which could result in the arbitrary execution of code.
– fix TELNET stack contents disclosure again (CVE-2021-22925) – fix bad connection reuse due to flawed path name checks (CVE-2021-22924) – disable metalink support to fix the following vulnerabilities CVE-2021-22923 – metalink download sends credentials CVE-2021-22922 – wrong content via metalink not discarded
The package jre-openjdk before version 16.0.2.u7-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
The package jre-openjdk-headless before version 16.0.2.u7-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
The package lib32-libcurl-gnutls before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
The package libcurl-gnutls before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
The package lib32-libcurl-compat before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
The package libcurl-compat before version 7.78.0-1 is vulnerable to multiple issues including information disclosure and insufficient validation.
security update
security update
Cybercriminals may target the popular event with ransomware, phishing, or DDoS attacks in a bid to increase their notoriety or make money The post Cybercriminals may target 2020 Tokyo Olympics, FBI warns appeared first on WeLiveSecurity
On iOS we have seen link shortener services pushing spam calendar files to victims’ devices. The post Some URL shortener services distribute Android malware, including banking or SMS trojans appeared first on WeLiveSecurity
Several security issues were fixed in Ruby.
An update that solves 13 vulnerabilities and has 5 fixes is now available.
An update that solves one vulnerability, contains one feature and has 5 fixes is now available.
Crash in DNP dissector in Wireshark 3.4.0 to 3.4.6 and 3.2.0 to 3.2.14 allows denial of service via packet injection or crafted capture file (CVE-2021-22235). References:
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input (CVE-2013-7488). References:
An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact
Several security issues were fixed in systemd.
The Qualys Research Labs discovered that an attacker-controlled allocation using the alloca() function could result in memory corruption, allowing to crash systemd and hence the entire operating system.
