ESET experts share their insights on the cyber-elements of the first year of the war in Ukraine and how a growing number of destructive malware variants tried to rip through critical Ukrainian systems The post ESET Research Podcast: A year of fighting rockets, soldiers, and wipers in Ukraine appeared first on WeLiveSecurity
Several security issues were fixed in the Linux kernel.
By failing to prepare you are preparing to fail. Make sure you’re able to bounce back if, or when, a data disaster strikes. The post World Backup Day: Avoiding a data disaster is a forever topic appeared first on WeLiveSecurity
Multiple vulnerabilities were found in Json-smart library. Json-smart is a performance focused, JSON processor lib written in Java. CVE-2021-31684
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
The container bci/bci-minimal was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
How fraudsters groom their marks and move in for the kill using tricks from the playbooks of romance and investment scammers The post Pig butchering scams: The anatomy of a fast‑growing threat appeared first on WeLiveSecurity
Several out of bounds memory access and buffer overflows were fixed in xrdp, an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP)
The container bci/bci-init was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
security update
How content creators and subscribers can embrace the social media platform without (overly) exposing themselves to the potentially toxic brew of NSFW content and privacy threats The post Staying safe on OnlyFans: The naked truth appeared first on WeLiveSecurity
Jan-Niklas Sohn discovered that a user-after-free flaw in the Composite extension of the X.org X server may result in privilege escalation if the X server is running under the root user.
Several security vulnerabilities have been discovered in unbound, a validating, recursive, caching DNS resolver. CVE-2022-3204
The container bci/rust was updated. The following patches have been included in this update:
The container suse/pcp was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
security update
The container bci/bci-init was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/ruby was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:
The container ses/7.1/ceph/ceph was updated. The following patches have been included in this update:
The container ses/7.1/ceph/grafana was updated. The following patches have been included in this update:
The container ses/7.1/cephcsi/cephcsi was updated. The following patches have been included in this update:
An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for kernel is now available for Red Hat Enterprise Linux 9.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in privilege escalation, denial of service or information leaks.
3 security issues (#2180425) x86 shadow plus log-dirty mode use-after-free [XSA-427, CVE-2022-42332] x86/HVM pinned cache attributes mis-handling [XSA-428, CVE-2022-42333, CVE-2022-42334] x86: speculative vulnerability in 32bit SYSCALL path [XSA-429, CVE-2022-42331]
3 security issues (#2180425) x86 shadow plus log-dirty mode use-after-free [XSA-427, CVE-2022-42332] x86/HVM pinned cache attributes mis-handling [XSA-428, CVE-2022-42333, CVE-2022-42334] x86: speculative vulnerability in 32bit SYSCALL path [XSA-429, CVE-2022-42331]
Fix for CVE-2022-48303
This update upgrades Thunderbird to version 102.9.0. * Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751) * Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176) * Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752) * Mozilla: Invalid downcast in Worklets (CVE-2023-28162) * Mozilla: URL being dragged fr [More…]
Here are some of the key moments from the five hours of Shou Zi Chew’s testimony and other interesting news on the data privacy front The post Highlights from TikTok CEO’s Congress grilling – Week in security with Tony Anscombe appeared first on WeLiveSecurity
As TikTok CEO attempts to placate U.S. lawmakers, it’s time for us all to think about the wealth of personal information that TikTok and other social media giants collect about us The post What TikTok knows about you – and what you should know about TikTok appeared first on WeLiveSecurity
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
update to 111.0.5563.110. Fixes the following security issues: CVE-2023-1528 CVE-2023-1529 CVE-2023-1530 CVE-2023-1531 CVE-2023-1532 CVE-2023-1533 CVE-2023-1534
Rebuild for CVE-20220-{3064,41717,41723}
security update
security update
New tar packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.
This update includes the changes in tzdata 2023b for the Perl bindings. For the list of changes, see DLA-3366-1. For Debian 10 buster, this problem has been fixed in version
This update includes the changes in tzdata 2023b. Notable changes are: – – Egypt uses DST again, starting on April.
Incorrect code generation during JIT compilation. (CVE-2023-25751) Potential out-of-bounds when accessing throttled streams. (CVE-20223-25752) Invalid downcast in Worklets. (CVE-2023-28162) URL being dragged from a removed cross-origin iframe into the same tab triggered navigation. (CVE-2023-28164)
If a malicious Flatpak app is run on a Linux virtual console such as /dev/tty1, it can copy text from the virtual console and paste it back into the virtual console’s input buffer, from which the command might be run by the user’s shell after the Flatpak app has exited. This is similar to CVE-2017-5226, […]
In the MHD_PostProcessor, malformed inputs can be used to crash the server (for denial-of-service). References: – https://bugs.mageia.org/show_bug.cgi?id=31670
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-4645) References:
