security update
security update
ESET researchers analyzed Android and Windows clippers that can tamper with instant messages and use OCR to steal cryptocurrency funds The post Not‑so‑private messaging: Trojanized WhatsApp and Telegram apps go after cryptocurrency wallets appeared first on WeLiveSecurity
The container suse/sles/15.5/virt-operator was updated. The following patches have been included in this update:
The container suse/sles/15.5/libguestfs-tools was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-launcher was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-handler was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-exportserver was updated. The following patches have been included in this update:
The container suse/sles/15.5/virt-exportproxy was updated. The following patches have been included in this update:
Several buffer overflows were found which allow an attacker to make tcpdump crash.
Sebastian Krahmer found a problem in the modprobe utility that could beexploited by local users to run arbitrary commands as root if themachine is running a kernel with kmod enabled.
Proton reported on bugtraq that tcsh did not handle in-here documentscorrectly. The version of tcsh that is distributed with Debian GNU/Linux2.2r0 also suffered from this problem.
The version of gnupg that was distributed in Debian GNU/Linux 2.2 hada logic error in the code that checks for valid signatures which couldcause false positive results:
ESET Research uncovered a campaign by APT group Tick against a data-loss prevention company in East Asia and found a previously unreported tool used by the group The post The slow Tick‑ing time bomb: Tick APT group compromise of a DLP software developer in East Asia appeared first on WeLiveSecurity
Emacs could be made to crash or run programs as your login if it opened a specially crafted file.
Several security issues were fixed in OpenJPEG.
No matter how old you are, it is important to learn how to stay safe online! According to a study conducted by Learning Innovation, more than 93% of students have access to smartphones and laptops. Cyber threats show no sign of slowing down, which is why it is important to stay up to date on […]
security update
Here’s how to know you have fallen victim to a scam – and what to do in order to undo or mitigate the damage. The post 5 signs you’ve fallen for a scam – and what to do next appeared first on WeLiveSecurity
The container sles-15-sp4-chost-byos-v20230310-arm64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp4-chost-byos-v20230310-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp4-chost-byos-v20230310-x86_64-gen2 was updated. The following patches have been included in this update:
It was discovered that there was a potential remote denial of service vulnerability in redis, a popular key-value database. Authenticated users could have used string matching commands (like
Security fix for CVE-2023-25193 Update of HarfBuzz to 7.0.1 version (#2169172) Update of freetype to 2.13.0 version (#2168496) —- Security fix for CVE-2023-25193, Update to 7.0.1 version (#2169172)
Security fix for CVE-2023-25193 Update of HarfBuzz to 7.0.1 version (#2169172) Update of freetype to 2.13.0 version (#2168496) —- Security fix for CVE-2023-25193, Update to 7.0.1 version (#2169172)
Several security issues were fixed in XStream.
The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:
The container ses/7.1/ceph/ceph was updated. The following patches have been included in this update:
The container ses/7.1/cephcsi/cephcsi was updated. The following patches have been included in this update:
Several security issues were fixed in Twig.
Several security issues were fixed in Protocol Buffers.
update to 111.0.5563.64. Fixes the following security issues: CVE-2023-0927 CVE-2023-0928 CVE-2023-0929 CVE-2023-0930 CVE-2023-0931 CVE-2023-0932 CVE-2023-0933 CVE-2023-0941 CVE-2023-1213 CVE-2023-1214 CVE-2023-1215 CVE-2023-1216 CVE-2023-1217 CVE-2023-1218 CVE-2023-1219 CVE-2023-1220 CVE-2023-1221 CVE-2023-1222 CVE-2023-1223 CVE-2023-1224 CVE-2023-1225
An issue has been found in mpv, a video player based on MPlayer/mplayer2. Due to a use after free an attacker coudl execute arbitrary code or crash the program via the ao_c parameter.
Several vulnerabilities have been discovered in imagemagick that may lead to a privilege escalation, denial of service or information leaks. CVE-2020-19667
High CVE-2023-1213: Use after free in Swiftshader. Reported by Jaehun Jeong(@n3sk) of Theori on 2023-01-30 High CVE-2023-1214: Type Confusion in V8. Reported by Man Yue Mo of GitHub Security Lab on 2023-02-03
A change in the libreswan 4.2 Traffic Selector parsing code introduced a missing check that would reject palformed Traffic Selector payloads. As such, in such case the code stumbles on to hit a double free, leading to a crash and restart of the pluto daemon. No remote code execution. (CVE-2023-23009)
This kernel-linus update is based on upstream 5.15.98 and fixes atleast the following security issues: A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution attacks. L2 can carry out Spectre v2 attacks on L1
A request to move an online conversation to a supposedly more secure platform may not be as well-meaning as it sounds The post APT hackers set a honeytrap to ensnare victims – Week in security with Tony Anscombe appeared first on WeLiveSecurity
Here’s a roundup of some of the most common tricks that fraudsters use to dupe their victims on WhatsApp – and what you can do to protect yourself against them. The post Common WhatsApp scams and how to avoid them appeared first on WeLiveSecurity
Update to 5.9.10 for CVE-2023-26463
Security fix for CVE-2022-43272
Apply upstream libtiff fix for CVE-2022-4645
Release of stargz snapshotter v0.14.2 https://github.com/containerd/stargz- snapshotter/releases/tag/v0.14.2 This release uses containerd v1.7.0-rc.1 so this release fixes GHSA-hmfx-3pcx-653p (CVE-2023-25173) and GHSA-259w-8hf6-59c2 (CVE-2023-25153). This release uses Go 1.20.1 so this release fixes CVE-2022-41717 .
Update to python-werkzeug-2.2.3.
Backport patch for CVE-2023-25587.
security update
Several security issues were fixed in SnakeYAML.
The container bci/openjdk-devel was updated. The following patches have been included in this update:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
**Redis 6.2.11** – Released Tue Feb 28 12:00:00 IST 2023 Upgrade urgency: SECURITY, contains fixes to security issues. Security Fixes: * (**CVE-2023-25155**) Specially crafted SRANDMEMBER, ZRANDMEMBER, and HRANDFIELD commands can trigger an integer overflow, resulting in a runtime assertion and termination of the Redis server process. * (**CVE-2022-36021**) String matching
Backport of upstream fix for CVE-2022-29718.
Security fix for CVE-2023-23931 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. In affected versions `Cipher.update_into` would accept Python objects which implement the buffer protocol, but provide only immutable buffers. This would allow immutable objects (such as `bytes`) to be mutated, thus violating fundamental rules of Python and
An astrobiologist, analog astronaut, author and speaker, Dr. Michaela Musilova shares her experience as a woman at the forefront of space exploration and from her quest for scientific and personal excellence The post ‘A woman from Mars’: Life in the pursuit of space exploration appeared first on WeLiveSecurity
The container bci/bci-init was updated. The following patches have been included in this update:
