security update
A security issue was fixed in MariaDB
Upstream details at : https://access.redhat.com/errata/RHSA-2021:4904
libmodbus could be made to crash if it received specially crafted input.
Several security issues were fixed in uriparser.
Several security issues were fixed in Long Range ZIP.
USN-5142-1 introduced regressions in Samba.
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks.
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sles12sp3 was updated. The following patches have been included in this update:
The container sles-15-sp3-chost-byos-v20211202 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20211202-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20211202-gen2 was updated. The following patches have been included in this update:
NSS rebase to 3.73, includes fix for CVE-2021-43527
Press play for the first episode as host Aryeh Goretsky is joined by Zuzana Hromcová to discuss native IIS malware The post Launching ESET Research Podcast: A peek behind the scenes of ESET discoveries appeared first on WeLiveSecurity
An update that contains security fixes can now be installed.
Several vulnerabilities were discovered in LibreCAD, an application for computer aided design (CAD) in two dimensions. An attacker could trigger code execution through malicious .dwg and .dxf files.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sles12sp5 was updated. The following patches have been included in this update:
The container suse/sles12sp4 was updated. The following patches have been included in this update:
security update
ESET researchers studied all the malicious frameworks ever reported publicly that have been used to attack air-gapped networks and are releasing a side-by-side comparison of their most important TTPs The post Jumping the air gap: 15 years of nation‑state effort appeared first on WeLiveSecurity
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS #7, or PKCS #12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP […]
A NULL pointer dereference in Busybox’s hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input. (CVE-2021-42376)
BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which allocates memory which will always be hung in the singly linked list of cstates and will not be freed. This will cause a memory leak over time. The data can be a very large object, which can be […]
The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could be
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. References:
Thunderbird could be made to crash or run programs if it verified a specially crafted signature.
NSS could be made to crash or run programs if it verified a specially crafted signature.
Red Hat OpenShift Container Platform release 4.7.38 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
