Menu

Monthly Archives: March 2024

upstream security release 122.0.6261.128 High CVE-2024-2400: Use after free in Performance Manager

Security fix for CVE-2007-4559.

New upstream release with security fixes for CVE-2023-5992 and CVE-2024-1454

Path traversal in moment.locale. (CVE-2022-24785) Inefficient parsing algorithim resulting in DoS. (CVE-2022-31129) References: – https://bugs.mageia.org/show_bug.cgi?id=30664

Security fix for CVE-2007-4559.

Update to 3.2.2 It indirectly fix CVE-2023-3966 and CVE-2023-5366

As if working at Helldesk weren’t bad enough, IT helpers now targeted by cybercrims
How to share sensitive files securely online

Here are a few tips for secure file transfers and what else to consider when sharing sensitive documents so that your data remains safe

Scareware scam: Restoro and Reimage fined $26 million by FTC

* bsc#1219836 Cross-References: * CVE-2024-1062

Cop shop rapped for ‘completely avoidable’ web form blunder

It was discovered that composer, a dependency manager for the PHP language, processed files in the local working directory. This could lead to local privilege escalation or malicious code execution. Due to a technical issue this email was not sent on 2024-02-26 like it should

* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

* jsc#PED-2362 * jsc#SLE-5514 Cross-References: * CVE-2023-20593

* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465

* bsc#1221134 * bsc#1221151 Cross-References: * CVE-2023-42465

Forget TikTok – Chinese spies want to steal IP by backdooring digital locks
FTC goes undercover to probe suspected antivirus scam, scores $26M settlement
LockBit ransomware kingpin gets 4 years behind bars
Google gooses Safe Browsing with real-time protection that doesn’t leak to ad giant
Record breach of French government exposes up to 43 million people’s data
International effort to disrupt cybercrime moves into operational phase
US to probe Change Healthcare’s data protection standards as lawsuits mount

Expat could be made to crash if it received specially crafted input.

Several security issues were fixed in TeX Live.

Two vulnerabilities were discovered in Open vSwitch, a software-based Ethernet virtual switch, which could result in a bypass of OpenFlow rules or denial of service.

python-cryptography could be made to expose sensitive information over the network.

Open source is not insecure
US Congress goes bang, bang, on TikTok sale-or-ban plan

Update to 115.8.1 https://www.mozilla.org/en-US/security/advisories/mfsa2024-11/ read that if you have mails with encrypted email subjects https://www.thunderbird.net/en-US/thunderbird/115.8.1/releasenotes/

python-multipart 0.0.7 (2024-02-03) Refactor header option parser to use the standard library instead of a custom RegEx #75. Fixes a denial of service vulnerability, GHSA-qf9m-vfgh-m389, initially reported in FastAPI but applicable to other libraries and applications.

Nissan to let 100,000 Aussies and Kiwis know their data was stolen in cyberattack
Smashing Security podcast #363: Stuck streaming sticks, TikTok conspiracies, and spying cars

https://security-tracker.debian.org/tracker/DSA-5640-1

Feds seek attestation on secure software
JetBrains releases security fixes for TeamCity CI/CD system
Poking holes in Google tech bagged bug hunters $10M
Leak of Acer Philippines employee database appears on hacking forum
Microsoft Copilot for Security prepares for April liftoff

* bsc#1219775 Cross-References: * CVE-2024-22119

* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081

* bsc#1220404 * bsc#1220405 Cross-References: * CVE-2024-25081

Stanford University failed to detect ransomware intruders for 4 months
Hackers target Roku: 15,000 accounts compromised in data breach
Incognito Market: The not-so-secure dark web drug marketplace

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Reducing the cloud security overhead

Add implicit rejection in PKCS#1 v1.5 in OpenSSL.

Whizkids jimmy OpenAI, Google’s closed models
March Patch Tuesday sees Hyper-V join the guest-host escape club

https://security-tracker.debian.org/tracker/DSA-5639-1

Meta sues ex infra VP for allegedly stealing top-secret datacenter blueprints
Biden’s budget proposal boosts CISA funding to $3B
JetBrains is still mad at Rapid7 for the ransomware attacks on its customers

Rack could be made do denial of service if it received a specially crafted header.

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

Several security issues were fixed in Open vSwitch.

UK council yanks IT systems and phone lines offline following cyber ambush
French government sites disrupted by très grande DDoS
White House and lawmakers increase pressure on UnitedHealth to ease providers’ pain

An update that fixes one vulnerability is now available.

Kremlin accuses America of plotting cyberattack on Russian voting systems
British Library pushes the cloud button, says legacy IT estate cause of hefty rebuild

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Two vulnerabilities were discovered in tiff, Tag Image File Format library. CVE-2023-3576

* bsc#1027519 * bsc#1218851 * bsc#1219080 * bsc#1219885

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

How do you lot feel about Pay or say OK to ads model, asks ICO
Microsoft waited 6 months to patch actively exploited admin-to-kernel vulnerability
APT attacks taking aim at Tibetans – Week in security with Tony Anscombe

Evasive Panda has been spotted targeting Tibetans in several countries and territories with payloads that included a previously undocumented backdoor ESET has named Nightdoor

It was discovered that the uv_getaddrinfo() function in libuv, an asynchronous event notification library, incorrectly truncated certain hostnames, which may result in bypass of security measures on internal APIs or SSRF attacks.

2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]

backport fix for PEAP client (CVE-2023-52160)

2267205 – CVE-2024-24246 qpdf – Heap Buffer Overflow vulnerability in qpdf [fedora-all]

Update to latest version Security fix for CVE-2023-39325

https://security-tracker.debian.org/tracker/DSA-5638-1

Incorrect handling of extension attributes in PAX archives has been fixed in the GNU tar archiving utility. For Debian 10 buster, this problem has been fixed in version

Several security vulnerabilities have been discovered in Squid, a full featured web proxy cache. Due to programming errors in Squid’s HTTP request parsing, remote attackers may be able to execute a denial of service attack by sending large X-Forwarded-For header or trigger a stack buffer overflow while

Confidential Containers for Financial Services on Public Cloud

upstream security release 122.0.6261.111 – High CVE-2024-2173: Out of bounds memory access in V8 – High CVE-2024-2174: Inappropriate implementation in V8 – High CVE-2024-2176: Use after free in FedCM

Cybercrime crew Magnet Goblin bursts onto the scene exploiting Ivanti holes

* bsc#1218571 * bsc#1219238 Cross-References: * CVE-2023-7207

* bsc#1218571 * bsc#1219238 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5

Top 10 scams targeting seniors – and how to keep your money safe

The internet can be a wonderful place. But it’s also awash with fraudsters targeting people who are susceptible to fraud.

Microsoft confirms Russian spies stole source code, accessed internal systems
Change Healthcare registers pulse after crippling ransomware attack

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219243 Cross-References: * CVE-2024-0727

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

* bsc#1219026 * bsc#1220389 Cross-References: * CVE-2023-42465

Swiss cheese security? Play ransomware gang milks government of 65,000 files
Font security ‘still a Helvetica of a problem’ says Australian graphics outfit Canva
Securing open source software: Whose job is it, anyway?