Evgeny Vereshchagin discovered multiple vulnerabilities in D-Bus, a simple interprocess messaging system, which may result in denial of service by an authenticated user.
Several security vulnerabilities were discovered in WordPress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XSS) attacks may facilitate the bypass of access controls or the injection of client-side scripts.
A security issue was fixed in nginx’s lua module.
Security fix for CVE-2022-38784
There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src/cd-profile-db.c separately. They exist because the ‘err_msg’ of ‘sqlite3_exec’ is not releasing after use, while libxml2 emphasizes that the caller needs to release it. (CVE-2021-42523)
A syntactically invalid type signature with incorrectly nested parentheses and curly brackets would cause an assertion failure in debug builds. Similar messages could potentially result in a crash or incorrect message processing in a production build, although we are not aware of a practical example. (CVE-2022-42010)
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. (CVE-2022-41322)
libvncclient v0.9.13 was discovered to contain a memory leak via the function rfbClientCleanup(). (CVE-2020-29260) References: – https://bugs.mageia.org/show_bug.cgi?id=30917
Core Fixed bug GH-9323 (Crash in ZEND_RETURN/GC/zend_call_function) Fixed bug GH-9361 (Segmentation fault on script exit #9379). Fixed bug GH-9407 (LSP error in eval’d code refers to wrong class for static type).
Non-Responsive Delegation Attack. (CVE-2022-3204) Improves performance when under load, by cutting promiscuous queries for nameserver discovery and limiting the number of times a delegation point can look in the cache for missing records.
A look back on the key trends and developments that shaped the cyberthreat landscape from May to August of this year The post Key takeaways from ESET Threat Report T2 2022 – Week in security with Tony Anscombe appeared first on WeLiveSecurity
Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013
Security fix for CVE-2022-21797
Update to the September 2022 update release of .NET Core 3.1 Release Notes: https://github.com/dotnet/core/blob/main/release-notes/3.1/3.1.29/3.1.29.md This includes a fix for CVE-2022-38013
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
security update
security update
security update
Healthy habits that are instilled and nurtured at an early age bring lifelong benefits – the same applies to good cybersecurity habits The post The need to change cybersecurity for the next generation appeared first on WeLiveSecurity
A view of the T2 2022 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2022 appeared first on WeLiveSecurity
Security fix for CVE-2022-38784
Some stability fixes. —- Update to 2.53.14 Note that besides the ordinary builds for the current Fedora and EPEL branches, there is an additional distro- independed build available at https://buc.fedorapeople.org/seamonkey . So if you have friends who use other Linux distro, but that distro does not provide SeaMonkey yet, you can recommend it for them.
Rebase to 2.4.9
**Version 3.4.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)
**Version 2.15.3** (2022-09-28) * Fix a security issue on filesystem loader (possibility to load a template outside a configured directory)
Updated to version 0.10.2 with CVE fix.
expat: a use-after-free in the doContent function in xmlparse.c (CVE-2022-40674) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 expat-2.1.0-15.el7_9.i686.rpm expat-2.1.0-15.el7_9.x86_64.rpm expat-debuginfo-2.1.0-15.el7_9.i686.rpm expat-debuginfo-2.1.0-15.el7_9.x86_ [More…]
squid: buffer-over-read in SSPI and SMB authentication (CVE-2022-41318) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 squid-3.5.20-17.el7_9.8.x86_64.rpm squid-debuginfo-3.5.20-17.el7_9.8.x86_64.rpm squid-migration-script-3.5.20-17.el7_9.8.x86_64.rpm squid-sysvinit [More…]
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
security update
security update
security update
Several security issues were fixed in DHCP.
Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2022-2795
Multiple vulnerabilities were discovered in Node.js, a JavaScript runtime environment, which could result in memory corruption, invalid certificate validation, prototype pollution or command injection.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update is now available for Red Hat Process Automation Manager. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
As each new smart home device may pose a privacy and security risk, do you know what to look out for before inviting a security camera into your home? The post 8 questions to ask yourself before getting a home security camera appeared first on WeLiveSecurity
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that solves three vulnerabilities and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
security update
