This kernel update is based on upstream 5.10.78 and fixes atleast the following security issues: A use-after-free vulnerability in the NFC stack can lead to a threat to confidentiality, integrity, and system availability (CVE-2021-3760).
An update that solves 13 vulnerabilities and has 43 fixes is now available.
An update for freerdp is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
The tech giant wins an appeal against a claim that it unlawfully collected personal data of millions of iPhone users The post Google scores big win as court blocks iPhone tracking lawsuit appeared first on WeLiveSecurity
An update for gcc-toolset-10-annobin is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for gcc-toolset-10-gcc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for gcc-toolset-11-gcc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for gcc is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for the rust-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for gcc-toolset-11-annobin is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An attacker gained access to some of Robinhood’s customer support systems and stole the personal data of around a third of the app’s userbase The post Robinhood data breach affects 7 million people appeared first on WeLiveSecurity
Are the days numbered for ‘123456’? As Microsoft further nudges the world away from passwords, here’s what your organization should consider before going password-free. The post Passwordless authentication: Is your company ready to move beyond passwords? appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
The package grafana before version 8.2.3-1 is vulnerable to cross-site scripting.
The package opera before version 81.0.4196.31-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure and insufficient validation.
The package thunderbird before version 91.3.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, same-origin policy bypass and sandbox escape.
The package firefox before version 94.0-1 is vulnerable to multiple issues including arbitrary code execution, content spoofing, same- origin policy bypass and sandbox escape.
The package jenkins before version 2.319-1 is vulnerable to multiple issues including arbitrary filesystem access and sandbox escape.
Discover how cybercriminals find their targets on the dark web: For the average internet user, the dark web is something you only hear about in news broadcasts talking about the latest cyberattacks. But while you won’t find yourself in the dark web by accident, it’s important to know what it is and how you can […]
An update that solves 15 vulnerabilities and has 40 fixes is now available.
An update that solves two vulnerabilities and has two fixes is now available.
security update
rpki-client 7.4 Public Keys. * Fix issues with chunked transfer encoding in the RRDP HTTP client. * Cleanup and improvement of how IO is handled. * Improvements in the way X509 certificates are verified. * Make rpki-client more resilient regarding untrusted input: – Limit the allowed character set for filename
rpki-client 7.4 Public Keys. * Fix issues with chunked transfer encoding in the RRDP HTTP client. * Cleanup and improvement of how IO is handled. * Improvements in the way X509 certificates are verified. * Make rpki-client more resilient regarding untrusted input: – Limit the allowed character set for filename
rpki-client 7.4 Public Keys. * Fix issues with chunked transfer encoding in the RRDP HTTP client. * Cleanup and improvement of how IO is handled. * Improvements in the way X509 certificates are verified. * Make rpki-client more resilient regarding untrusted input: – Limit the allowed character set for filename
An update that fixes 12 vulnerabilities is now available.
A flaw was discovered in containerd, an open and reliable container runtime. Insufficiently restricted permissions on container root and plugin directories could result in privilege escalation.
Update to WebKitGTK 2.34: * Add support for CSS Scroll Snap. * Add support for date and datetime-local input elements. * Add support for display capture. * Add support for ICC color management. * Add support color-schemes CSS property. * Add multi-track support to MSE media backend. * Add new API to handle web process […]
Update to WebKitGTK 2.34: * Add support for CSS Scroll Snap. * Add support for date and datetime-local input elements. * Add support for display capture. * Add support for ICC color management. * Add support color-schemes CSS property. * Add multi-track support to MSE media backend. * Add new API to handle web process […]
security update
Two SQL injection vulnerabilities were discovered in SQLAlchemy, a SQL toolkit and Object Relational Mapper for Python, when the order_by or group_by parameters can be controlled by an attacker.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes 15 vulnerabilities is now available.
The 5.14.16 stable kernel update contains a number of important fixes across the tree.
The 5.14.16 stable kernel update contains a number of important fixes across the tree.
The binary got built with Fedora mandatory compiler flags.
Cybercriminals have made headlines by forcing Fortune 500 companies to pay million-dollar ransom payments to retrieve their data and unlock their systems. But despite the headlines, most ransomware targets families as well as small and medium sized businesses. In fact, the average ransom payment is closer to $50,000. And it makes sense – just like […]
An update that fixes 15 vulnerabilities is now available.
Beyond the vulnerability in the Android kernel, the monthly round of security patches plugs another 38 security loopholes The post Google squashes Android zero‑day bug exploited in targeted attacks appeared first on WeLiveSecurity
There were a couple of vulnerabilites found in src:python3.5, the Python interpreter v3.5, and are as follows: CVE-2021-3733
This update upgrades Thunderbird to version 91.3.0. * Mozilla: Use-after-free in HTTP2 Session object * Mozilla: Memory safety bugs fixed in Firefox 94 and Firefox ESR 91.3 * Mozilla: iframe sandbox rules did not apply to XSLT stylesheets (CVE-2021-38503) * Mozilla: Use-after-free in file picker dialog (CVE-2021-38504) * Mozilla: Firefox could be coaxed into going […]
Stefan Walter found that udisks2, a service to access and manipulate storage devices, could cause denial of service via system crash if a corrupted or specially crafted ext2/3/4 device or image was mounted, which could happen automatically on certain environments.
The container suse/sles12sp5 was updated. The following patches have been included in this update:
Rust 1.56.1 adds a mitigation for CVE-2021-42574, the “trojan source” attack that obfuscates code with BiDi control characters. The compiler will now error on such characters in code comments and string/char literals. For more details, see the upstream [security advisory](https://blog.rust- lang.org/2021/11/01/cve-2021-42574.html).
