An update that solves one vulnerability and has one errata is now available.
Two vulnerabilities were discovered in the Nextcloud desktop client, which could result in information disclosure. For the oldstable distribution (buster), these problems have been fixed
The legacy 1.0 version of OpenSSL, a cryptography library for secure communication, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.
Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures.
GnuTLS, a portable cryptography library, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.
Update to 2.2.17
Upstream annoucement: [WordPress 5.8.1 Security and Maintenance Release](https://wordpress.org/news/2021/09/wordpress-5-8-1-security-and- maintenance-release/)
Another race in XENMAPSPACE_grant_table handling [XSA-384, CVE-2021-28701] bugfix for XSA-380
The container caasp/v4.5/kube-scheduler was updated. The following patches have been included in this update:
The container caasp/v4.5/kube-proxy was updated. The following patches have been included in this update:
The container caasp/v4.5/kube-controller-manager was updated. The following patches have been included in this update:
The most recent Patch Tuesday includes a fix for the previously disclosed and actively exploited remote code execution flaw in MSHTML. The post Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws appeared first on WeLiveSecurity
Several security issues were fixed in Python.
Several security issues were fixed in Qt.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Libgcrypt could be made to expose sensitive information.
An update that solves one vulnerability and has three fixes is now available.
The Facebook-owned messaging service plans to roll out the feature to both iOS and Android users in the coming weeks. The post WhatsApp announces end‑to‑end encrypted backups appeared first on WeLiveSecurity
Discover the best ways to mitigate your organization’s attack surface, in order to maximize cybersecurity. The post What is a cyberattack surface and how can you reduce it? appeared first on WeLiveSecurity
Squashfs-Tools could be made to overwrite files.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in curl.
Squashfs-Tools could be made to overwrite files.
The container ses/7/rook/ceph was updated. The following patches have been included in this update:
From cybercriminal evergreens like phishing to the verification badge scam we look at the most common tactics fraudsters use to trick their victims The post Beware of these 5 common scams you can encounter on Instagram appeared first on WeLiveSecurity
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes four vulnerabilities is now available.
The 5.13.15 stable kernel update contains a number of important fixes across the tree.
update to 1.1.1l
This advisory resolves CVE issues filed against XP2 releases that have been fixed in the underlying EAP 7.3.x base. There are no changes to the EAP XP2 code base. NOTE: This advisory is informational only. There are no code changes
This update upgrades Thunderbird to version 78.14.0. * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 (CVE-2021-38493) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – thunderbird-78.14.0-1.el7_9.x86_64.rpm – thunderbird-debuginfo-78.1 [More…]
This update upgrades Firefox to version 78.14.0 ESR. * Mozilla: Memory safety bugs fixed in Firefox 92, Firefox ESR 78.14 and Firefox ESR 91.1 (CVE-2021-38493) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 – firefox-78.14.0-1.el7_9.i686.rpm – firefox-78.14.0-1.el7_9.x86_64.r [More…]
An update that contains security fixes can now be installed.
