Menu

Monthly Archives: December 2021

The 5..15..12 stable kernel update contains a number of important fixes across the tree.

security update

The 5..15..12 stable kernel update contains a number of important fixes across the tree.

https://lib.openmpt.org/libopenmpt/2021/12/23/security- update-0.5.15-releases-0.4.27-0.3.36/

22 cybersecurity statistics to know for 2022

As we usher in the New Year, let’s take a look at some statistics that will help you stay up-to-date on recent cybersecurity trends The post 22 cybersecurity statistics to know for 2022 appeared first on WeLiveSecurity

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes four vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Patch for CVE-2021-39359. —- Update to 5.2.10

xwayland 21.1.4 Security fix for CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011 Store EGLcontext to avoid superfluous eglMakeCurrent() calls Prefer EGLStream with NVIDIA proprietary driver if both GBM and EGLstream are available

What the Rise in Cyber-Recon Means for Your Security Strategy
APT ‘Aquatic Panda’ Targets Universities with Log4Shell Exploit Tools
Instagram copyright infringment scams – don’t get sucked in!
5 Cybersecurity Trends to Watch in 2022

stack-based buffer overflow in handle_request() in DHT.c (CVE-2021-44847) References: – https://bugs.mageia.org/show_bug.cgi?id=29821 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/S7EBS3NIRYJ7V3PTNINP3PJSVUHGZTGA/

HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818) References: – https://bugs.mageia.org/show_bug.cgi?id=29817

e2guardian did not validate TLS hostnames (CVE-2021-44273) References: – https://bugs.mageia.org/show_bug.cgi?id=29811 – https://www.openwall.com/lists/oss-security/2021/12/23/2

ReDoS vulnerability in html_preprocess_rules in ebooks/conversion/preprocess.py References: – https://bugs.mageia.org/show_bug.cgi?id=29803

HTTP Request Smuggling due to spaces in headers. The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). (CVE-2021-22959) HTTP Request Smuggling when parsing the body. The parse ignores chunk extensions when parsing the body of chunked requests. This leads […]

Authenticate active help requests to the local help web server (CVE-2020-27225) References: – https://bugs.mageia.org/show_bug.cgi?id=29048

security update

Threat Advisory: E-commerce Bots Use Domain Registration Services for Mass Account Fraud
Log4Shell vulnerability Number Four: “Much ado about something”
Cryptomining Attack Exploits Docker API Misconfiguration Since 2019

Two vulnerabilities were fixed in the reSIProcate SIP stack. CVE-2017-11521

An update that fixes 33 vulnerabilities is now available.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

New wpa_supplicant packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.

2021 in review: The biggest cybersecurity stories of the year

As we close out another year like no other, let’s look back at some of the most notable cybersecurity stories that shaped 2021 The post 2021 in review: The biggest cybersecurity stories of the year appeared first on WeLiveSecurity

That Toy You Got for Christmas Could Be Spying on You

A couple of vulnerabilites were found in paramiko, an implementation of SSHv2 protocol in Python. CVE-2018-1000805

An XSS vulnerability was discovered in noVNC, a HTML5 VNC client, in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.

A cookie prefix spoofing vulnerability in CGI::Cookie.parse and a regular expression denial of service vulnerability (ReDoS) on date parsing methods were discovered in src:ruby2.1, the Ruby interpreter.

2021 Wants Another Chance (A Lighter-Side Year in Review)
What most cloud-using CIOs want in 2022

Several vulnerabilities were discovered in djvulibre, a library and set of tools to handle documents in the DjVu format. An attacker could crash document viewers and possibly execute arbitrary code through

The python-rdflib-tools package (tools for converting to and from RDF) had wrappers that could load Python modules from the current working directory, allowing code injection.

An update that contains security fixes can now be installed.

Global Cyberattacks from Nation-State Actors Posing Greater Threats
The 5 Most-Wanted Threatpost Stories of 2021

Several security vulnerabilities were found in Apache Log4j2, a Logging Framework for Java, which could lead to a denial of service or information disclosure.

Invalid read for malformed DVI files was fixed in GNU libextractor, a library that extracts meta-data from files of arbitrary type. For Debian 9 stretch, this problem has been fixed in version

What app developers need to do now to fight Log4j exploits

Update log4j to 2.17.0 for CVE-2021-45105 Denial of Service attack

Backport fix for CVE-2021-45078

Update log4j to 2.17.0 for CVE-2021-45105 Denial of Service attack

Backport fix for CVE-2021-45078

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The 5.15.11 stable kernel update contains a number of important fixes across the tree.

Updat eto 4.6.5 to fix CVE-2021-43818.

Update to 2.53.10.1 Backport fixes to improve compatibility of some sites

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

The container ses/7/ceph/ceph was updated. The following patches have been included in this update:

The container ses/7/ceph/grafana was updated. The following patches have been included in this update:

The container ses/7/cephcsi/cephcsi was updated. The following patches have been included in this update:

security update

security update

https://lib.openmpt.org/libopenmpt/2021/12/23/security- update-0.5.15-releases-0.4.27-0.3.36/

The following vulnerabilities have been discovered in the wpewebkit web engine: CVE-2021-30887

The following vulnerabilities have been discovered in the webkit2gtk web engine: CVE-2021-30887

OpenPGP signature status doesn’t consider additional message content. (CVE-2021-4126) Matrix chat library libolm bundled with Thunderbird vulnerable to a buffer overflow. (CVE-2021-44538)

SFW! The Top N Cyber­security Stories of 2021 (for small positive integer values of N)
Four years: that’s how long Azure’s App Service had a source code leak bug

security update

security update

Security fix for CVE-2021-44224, CVE-2021-44790

Rebuild 3.8.5 using golang-1.16.12

Rebuild 3.8.5 using golang-1.16.12

4-Year-Old Microsoft Azure Zero-Day Exposes Web App Source Code
The cool retro phone with a REAL DIAL… plus plenty of IoT problems
This holiday season, give your children the gift of cybersecurity awareness

Don’t leave your kids to their own devices – give them a head start with staying safe online instead The post This holiday season, give your children the gift of cybersecurity awareness appeared first on WeLiveSecurity

Telegram Abused to Steal Crypto-Wallet Credentials
‘Spider-Man: No Way Home’ Download Installs Cryptominer
Time to Ditch Big-Brother Accounts for Network Scanning

An update that fixes four vulnerabilities is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

Fisher Price’s Bluetooth reboot of pre-school play phone has adult privacy flaw
Alibaba Cloud slapped by Chinese ministry for mishandling Log4j

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

security update

PYSA Emerges as Top Ransomware Actor in November
All in One SEO Plugin Bug Threatens 3M Websites with Takeovers
Critical Apache HTTPD Server Bugs Could Lead to RCE, DoS
Plundered bitcoins recovered by FBI – all 3,879-and-one-sixth of them!
Four Bugs in Microsoft Teams Left Platform Vulnerable Since March

An update that fixes 33 vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

It was discovered that missing SAML signature validation in the SOGo groupware could result in impersonation attacks. For the oldstable distribution (buster), this problem has been fixed

An update that fixes three vulnerabilities is now available.

An update that solves one vulnerability and has one errata is now available.