Release of OpenShift Serverless Client kn 1.16.0 Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes one vulnerability is now available.
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
A security update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
XStream: remote command execution attack by manipulating the processed input stream (CVE-2021-29505) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 noarch – xstream-1.3.1-14.el7_9.noarch.rpm – xstream-javadoc-1.3.1-14.el7_9.noarch.rpm – Scientific Linux Development Team
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Red Hat AMQ Broker 7.8.2 is now available from the Red Hat Customer Portal. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability, contains three features and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves 14 vulnerabilities and has three fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that solves 9 vulnerabilities and has two fixes is now available.
Updated htmldoc packages fix security vulnerabilities: Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of service that is similar to CVE-2017-9181 (CVE-2021-20308).
Updated connman packages fix security vulnerability. ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA) (CVE-2021-33833).
Updated php packages provides upstream 8.0.8 and fixes the following security vulnerabilities: – PDO_Firebird: * Fix Stack buffer overflow in firebird_info_cb (CVE-2021-21704).
Updated botan2 packages fix security vulnerability: In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex) (CVE-2021-24115).
security update
The out-of-band update fixes a remote code execution flaw affecting the Windows Print Spooler service The post Microsoft issues patch to fix PrintNightmare zero‑day bug appeared first on WeLiveSecurity
Caught between a rock and a hard place, many ransomware victims cave in to extortion demands. Here’s what might change the calculus. The post Ransomware: To pay or not to pay? Legal or illegal? These are the questions … appeared first on WeLiveSecurity
The package ruby-addressable before version 2.8.0-1 is vulnerable to denial of service.
The package gitlab before version 14.0.3-1 is vulnerable to multiple issues including cross-site request forgery, access restriction bypass, arbitrary code execution, arbitrary command execution, cross-site scripting, information disclosure, content spoofing and denial of service.
The package rabbitmq before version 3.8.19-1 is vulnerable to cross- site scripting.
The package php7 before version 7.4.21-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package php before version 8.0.8-1 is vulnerable to multiple issues including denial of service and insufficient validation.
The package openexr before version 3.0.5-1 is vulnerable to arbitrary code execution.
Cybersecurity analysts are charting both a rise in ransomware incidents and in amounts cybercriminals are demanding from businesses to restore their data. That’s bad news in itself, but what’s often overlooked are the additional ways – beyond payments victims may or may not choose to make– victims pay for these attacks. Our latest threat report […]
ESET Research uncovers an active malicious campaign that uses new versions of old malware, Bandook, to spy on its victims The post Bandidos at large: A spying campaign in Latin America appeared first on WeLiveSecurity
Several vulnerabilities have been found in the Apache HTTP server, which could result in denial of service. In addition the implementation of the MergeSlashes option could result in unexpected behaviour.
The container ses/7/rook/ceph was updated. The following patches have been included in this update:
An inefficient regular expression could be exploited to cause a Denial of Service condition.
A buffer overflow in BladeEnc might allow arbitrary code execution.
A file named by an attacker being utilized by Mechanize could result in arbitrary code execution.
Multiple vulnerabilities have been found in Privoxy, the worst of which could result in Denial of Service.
