Menu

Monthly Archives: November 2022

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

It was discovered that there was a information disclosure utility in sudo, a tool used to provide limited superuser privileges to specific users.

China is likely stockpiling and deploying vulnerabilities, says Microsoft
Red Cross seeks digital equivalent of its emblems to mark some tech as off-limits in war
Breached health insurer won’t pay ransom to protect customers, warns of more attacks

security update

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. CVE-2022-40303

Several vulnerabilities were discovered in libxml2, a library providing support to read, modify and write XML and HTML files. CVE-2022-40303

New sudo packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.

The container suse/sle15 was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

security update

Ransomware rages on – Week in security with Tony Anscombe

This week’s news offered fresh reminders of the threat that ransomware poses for businesses and critical infrastructure worldwide The post Ransomware rages on – Week in security with Tony Anscombe appeared first on WeLiveSecurity

updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

# New in release OpenJDK 19.0.1 (2022-10-18) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-19.0.1.html) * This update depends on [FEDORA-2022- 10bb6f119e](https://bodhi.fedoraproject.org/updates/FEDORA-2022-10bb6f119e) ## CVEs Fixed – CVE-2022-21618 – CVE-2022-21619 – CVE-2022-21624 –

Security fix for CVE-2022-3705 2139842 – vim upgrade broke :! for displaying terminal output

Security fix for CVE-2022-3705 2139842 – vim upgrade broke :! for displaying terminal output

updates the C library to 0.29.0.gfm.6 which fixes CVE-2022-39209

SolarWinds reaches $26m settlement with shareholders, expects SEC action
Qualys previews TotalCloud FlexScan for multicloud security management
Double-check demand payment emails from law firms: Convincing fakes surface
Twitter Blue Badge email scams – Don’t fall for them!
Reducing the risk of cloud attack

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Several vulnerabilities have been discovered in the FFmpeg multimedia framework, which could result in denial of service or potentially the execution of arbitrary code if malformed files/streams are processed.

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Crime in the metaverse – police face new challenges in a virtual world

– Updated to 106.0.3 —- – New upstream version (106.0.1)

– Updated to 106.0.3 —- – New upstream version (106.0.1)

French-speaking voleurs stole $30m in 15-country bank, telecoms cyber-heist spree
Multi-factor auth fatigue is real – and it’s why you may be in the headlines next

security update

S3 Ep107: Eight months to kick out the crooks and you think that’s GOOD? [Audio + Text]
International summit agrees crack down on crypto to combat ransomware
Verified users beware! Scammers are exploiting Twitter turmoil caused by Elon Musk’s takeover

**PHP version 8.1.12** (27 Oct 2022) **Core:** * Fixes segfault with Fiber on FreeBSD i386 architecture. (David Carlier) **Fileinfo:** * Fixed bug [GH-8805](https://github.com/php/php-src/issues/8805) (finfo returns wrong mime type for woff/woff2 files). (Anatol) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**)

**PHP version 8.1.12** (27 Oct 2022) **Core:** * Fixes segfault with Fiber on FreeBSD i386 architecture. (David Carlier) **Fileinfo:** * Fixed bug [GH-8805](https://github.com/php/php-src/issues/8805) (finfo returns wrong mime type for woff/woff2 files). (Anatol) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**)

# New in release OpenJDK 11.0.17 (2022-10-18) * [Release announcement](https://bit.ly/openjdk11017) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-11.0.7.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider

# New in release OpenJDK 17.0.5 (2022-10-18) * [Release announcement](https://bit.ly/openjdk1705) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-17.0.5.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider

# New in release OpenJDK 17.0.5 (2022-10-18) * [Release announcement](https://bit.ly/openjdk1705) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes-17.0.5.html) ## Security Fixes – JDK-8282252: Improve BigInteger/Decimal validation – JDK-8285662: Better permission resolution – JDK-8286077, CVE-2022-21618: Wider

# New in release OpenJDK 8u352 (2022-10-18) * [Release announcement](https://bit.ly/openjdk8u352) * [Full release notes](https://builds.shipilev.net/backports-monitor/release-notes- openjdk8u352.html) ## Security Fixes * JDK-8282252: Improve BigInteger/Decimal validation * JDK-8285662: Better permission resolution * JDK-8286511: Improve

Using daysofrisk.pl with the Red Hat Security Data API
The future starts now: 10 major challenges facing cybersecurity

To mark Antimalware Day, we’ve rounded up some of the most pressing issues for cybersecurity now and in the future The post The future starts now: 10 major challenges facing cybersecurity appeared first on WeLiveSecurity

Royal Mail customer data leak shutters online Click and Drop
Smashing Security podcast #296: Twitter turmoil, AI animal chatters, and metaverse at work
The OpenSSL security update story – how can you tell what needs fixing?
US Treasury thwarts DDoS attack from Russian Killnet group

security update

security update

The spy who rented to me? Throwing the spotlight on hidden cameras in Airbnbs

Do you find reports of spy cams found in vacation rentals unsettling? Try these tips for spotting hidden cameras and put your worries to rest. The post The spy who rented to me? Throwing the spotlight on hidden cameras in Airbnbs appeared first on WeLiveSecurity

Ransomware cost US banks $1.2 billion last year

Upstream update including security & bug fixes as well as feature enhancements. From the upstream [release notes](https://github.com/git/git/raw/v2.38.1/Documen tation/RelNotes/2.30.6.txt): CVE-2022-39253 ————– When relying on the `–local` clone optimization, Git dereferences symbolic links in the source repository before creating hardlinks (or copies) of the dereferenced link in the

Azul detects Java vulnerabilities in production apps

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Ritz cracker giant settles bust-up with insurer over $100m+ NotPetya cleanup
Dropbox admits 130 of its private GitHub repos were copied after phishing attack
OpenSSL downgrades horror bug after week of panic, hype
3 primo cloud computing jobs in 2023
OpenSSL patches are out – CRITICAL bug downgraded to HIGH, but patch anyway!
Trick or treat? Stay so cyber‑safe it’s scary – not just on Halloween

Gather around, folks, to learn about some of the ghastliest tricks used by criminals online and how you can avoid security horrors this Halloween and beyond The post Trick or treat? Stay so cyber‑safe it’s scary – not just on Halloween appeared first on WeLiveSecurity

Government by Gmail catches up with UK minister… who is reappointed anyway
SHA-3 code execution bug patched in PHP – check your version!

Several security issues were fixed in OpenSSL.

Several security issues were fixed in OpenSSL.

**PHP version 8.0.25** (27 Oct 2022) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**) (cmb) **Hash:** * Fixed bug php#81738: buffer overflow in hash_update() on long parameter. (**CVE-2022-37454**) (nicky at mouha dot be) **Session:** * Fixed bug [GH-9583](https://github.com/php/php-src/issues/9583)

**PHP version 8.0.25** (27 Oct 2022) **GD:** * Fixed bug php#81739: OOB read due to insufficient input validation in imageloadfont(). (**CVE-2022-31630**) (cmb) **Hash:** * Fixed bug php#81738: buffer overflow in hash_update() on long parameter. (**CVE-2022-37454**) (nicky at mouha dot be) **Session:** * Fixed bug [GH-9583](https://github.com/php/php-src/issues/9583)

New upstream release fixing CVE-2022-3515

New upstream release fixing CVE-2022-3515

Kioxia warns Uncle Sam: Be careful what you wish for with China sanctions
German cops arrest student suspected of running infamous dark-web souk
Unofficial fix emerges for Windows bug abused to infect home PCs with ransomware
India’s Home Ministry cracks down on predatory lending apps following suicides