– digiKam-8.0.0 – enabled MediaPlayer – Security fix for CVE-2023-1729 https://www.digikam.org/news/2023-04-16-8.0.0_release_announcement/
The container suse/registry was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sles12sp5 was updated. The following patches have been included in this update:
The container suse/sles12sp4 was updated. The following patches have been included in this update:
The container ses/7.1/rook/ceph was updated. The following patches have been included in this update:
The recent compromise of the networks of several companies via the abuse of a remote access tool used by MSPs exemplifies why state-aligned threat actors should be on the radars of IT service providers The post APTs target MSP access to customer networks – Week in security with Tony Anscombe appeared first on WeLiveSecurity
The container bci/bci-minimal was updated. The following patches have been included in this update:
The container bci/bci-micro was updated. The following patches have been included in this update:
The container bci/bci-minimal was updated. The following patches have been included in this update:
The container bci/bci-micro was updated. The following patches have been included in this update:
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:
security update
Several vulnerabilities were discovered in odoo, a suite of web based open source business apps. CVE-2021-44775, CVE-2021-26947, CVE-2021-45071, CVE-2021-26263:
The system could be made to run programs as an administrator.
Several security issues were fixed in the Linux kernel.
The guest VM system could be made to crash or expose sensitive information.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
security update
An update is now available for Red Hat Satellite 6.13. The release contains a new version of Satellite and important security fixes for various components.
Red Hat Integration Camel for Spring Boot 3.20.1 release and security update is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
It’s all fun and games until someone gets hacked – here’s what to know about, and how to avoid, threats lurking on the social media juggernaut The post Using Discord? Don’t play down its privacy and security risks appeared first on WeLiveSecurity
A quick dive into the murky world of cyberespionage and other growing threats facing managed service providers – and their customers The post APT groups muddying the waters for MSPs appeared first on WeLiveSecurity
Don’t torture people with exceedingly complex password composition rules but do blacklist commonly used passwords, plus other ways to help people help themselves – and your entire organization The post Creating strong, yet user‑friendly passwords: Tips for your business password policy appeared first on WeLiveSecurity
Several security issues were fixed in Ruby.
The Migration Toolkit for Containers (MTC) 1.7.9 is now available. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Update to 1.21.1 (resolve rhbz#2182365)
Red Hat Advanced Cluster Management for Kubernetes 2.5.8 General Availability release images, which fix bugs and security updates container images. Red Hat Product Security has rated this update as having a security impact
security update
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service, or information leak.
Multiple vulnerabilities have been discovered in Lua, the worst of which could result in arbitrary code execution.
Multiple vulnerabilities have been discovered in ISC DHCP, the worst of which could result in denial of service.
A buffer overflow vulnerability has been discovered in libapreq2 which could result in denial of service.
A vulnerability has been discovered in Firejail which could result in local root privilege escalation.
Multiple vulnerabilities have been found in libsdl2, the worst of which could result in arbitrary code execution.
security update
security update
An untrusted search path vulnerability was discovered in Node.js, which could result in unexpected searching or loading ICU data when running with elevated privileges.
An update that fixes one vulnerability is now available.
This update includes the changes in tzdata 2023c for the Perl bindings. For the list of changes, see DLA-3412-1. For Debian 10 buster, this problem has been fixed in version
This update includes the changes in tzdata 2023c. Notable changes are: – – Revert Lebanon DST changes.
An update for libwebp is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for libwebp is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.
security update
The system could be made to run programs as an administrator.
Several security issues were fixed in the Linux kernel.
ZenLib could be made to crash if it received specially crafted input.
Several security issues were fixed in Git.
This is a routine update of the distro-info-data database for Debian LTS users. It includes the expected release date for Debian 12, adds Debian 14,
update to 2.40.1 (CVE-2023-25652, CVE-2023-25815, CVE-2023-29007) Refer to the release notes for 2.30.9 for details of each CVE as well as the following security advisories from the git project: https://github.com/git/git/security/advisories/GHSA-2hvf-7c8p-28fx (CVE-2023-25652)
