The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The landmark regulation changed everyone’s mindset on how companies worldwide collect and use the personal data of EU citizens The post 5 reasons why GDPR was a milestone for data protection appeared first on WeLiveSecurity
This update upgrades Firefox to version 91.9.1 ESR. * Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution (CVE-2022-1529) * Mozilla: Prototype pollution in Top-Level Await implementation (CVE-2022-1802) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 [More…]
Multiple security vulnerabilities were discovered in Puma, a HTTP server for Ruby/Rack applications, which could result in HTTP request smuggling or information disclosure.
Multiple vulnerabilities have been discovered in the lrzip compression program which could result in denial of service or potentially the execution of arbitrary code.
An update that solves one vulnerability, contains one feature and has two fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
security update
security update
security update
Several security issues were fixed in libpng.
Several security issues were fixed in Thunderbird.
Firefox could be made to execute JavaScript in a privileged context if it opened a malicious website.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
As NFTs exploded in popularity, scammers also jumped on the hype. Watch out for counterfeit NFTs, rug pulls, pump-and-dumps and other common scams plaguing the industry. The post Common NFT scams and how to avoid them appeared first on WeLiveSecurity
The updated postgresql packages fix a security vulnerability: Autovacuum, REINDEX, and others omit “security restricted operation” sandbox (CVE-2022-1552).
Manfred Paul discovered two security issues in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed
Nokogiri did not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a ‘String’ by calling ‘#to_s’ or equivalent.
This update provides ffmpeg version 4.3.4, which fixes several security vulnerabilities and other bugs which were corrected upstream. References: – https://bugs.mageia.org/show_bug.cgi?id=30444
Updated nvidia-current packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead
Updated nvidia390 packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead
This kernel-linus update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem
This kernel update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem
Updated microcodes for Intel processors, fixing various functional issues, and at least the following security issues: Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to
A bug was found in runc where runc exec –cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set
The container bci/dotnet-aspnet was updated. The following patches have been included in this update:
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
security update
security update
When you hear the term ‘cryptocurrency’, does ‘secure’ also spring to mind? Here are some implications of the lack of sound security practices in the world of crypto. The post Cryptocurrency: secure or not? – Week in security with Tony Anscombe appeared first on WeLiveSecurity
ESET researchers spot an updated version of the malware loader used in the Industroyer2 and CaddyWiper attacks The post Sandworm uses a new version of ArguePatch to attack targets in Ukraine appeared first on WeLiveSecurity
Fabian Vogt and Dominik Penner discovered that the Ark archive manager did not sanitize extraction paths, which could result in maliciously crafted archives with symlinks writing outside the extraction directory.
An update that contains security fixes can now be installed.
An update that solves one vulnerability and has one errata is now available.
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/ruby was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
Webroot Console 6.5 is here To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To improve […]
OpenLDAP could be made to perform arbitrary modifications to the database.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes 6 vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2022:4642
Cybercriminals continue to mine for opportunities in the crypto space – here’s what you should know about coin-mining hacks and crypto theft The post The flip side of the coin: Why crypto is catnip for criminals appeared first on WeLiveSecurity
security update
security update
