Menu

Monthly Archives: April 2024

Cyber-bastard jailed for stealing psychotherapy files, blackmailing patients

Gerbv could be made to crash if it opened a specially crafted input file.

Several issues have been found in qtbase-opensource-src, a collection of several Qt modules/libraries. The issues are related to buffer overflows, infinite loops or application

A bug that could allow an attacker with access to the machine to potentially access data in a temporary directory created by the Guava. (CVE-2020-8908) Predictable temporary files and directories used in FileBackedOutputStream. (CVE-2023-2976)

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c. (CVE-2024-26458) Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. (CVE-2024-26461)

This release is a security release and addresses multiple issues: [Low] OutOfBound Read in zgfx_decompress_segment. [Moderate] Integer overflow & OutOfBound Write in clear_decompress_residual_data. [Low] integer underflow in nsc_rle_decode.

cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. (CVE-2023-50471) cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. (CVE-2023-50472)

UnitedHealth CEO: ‘Decision to pay ransom was mine’
NSA guy who tried and failed to spy for Russia gets 262 months in the slammer
European Commission starts formal probe of Meta over election misinformation

* bsc#1222518 Cross-References: * CVE-2024-31948

JSON5 could allow unintended access to network services or have other unspecified impact.

Multiple problems were discovered in Org-mode, a GNU Emacs major mode for keeping notes, authoring documents, and maintaining to-do lists. CVE-2024-30203 & CVE-2024-30204

Anope could be made to bypass authentication checks for suspended accounts.

Apple’s ‘incredibly private’ Safari is not so private in Europe

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

AT&T, Verizon, Sprint, T-Mobile US fined $200M for selling off people’s location info
Google blocked 2.3M apps from Play Store last year for breaking the G law
Why space exploration is important for Earth and its future: Q&A with David Eicher

We caught up with Astronomy magazine editor-in-chief David Eicher to talk about key challenges facing our planet, the benefits of space exploration, and the possibility of life beyond Earth

London Drugs closes all of its pharmacies following ‘cybersecurity incident’

Multiple problems were discovered in GNU Emacs, the extensible, customisable, self-documenting display editor. CVE-2024-30203 & CVE-2024-30204

Pillow could be made to crash or run programs as an administrator if it opened a specially crafted file.

France willing to buy key Atos assets to keep them French

Several security issues were fixed in libvirt.

Several security issues were fixed in GnuTLS.

Several security issues were fixed in curl.

Several security issues were fixed in Apache HTTP Server.

UK lays down fresh legislation banning crummy default device passwords
Watchdog reveals lingering Google Privacy Sandbox worries
The next step up for high-impact identity authorization
Discord dismantles Spy.pet site that snooped on millions of users

Security vulnerabilities were found in mediawiki, a website engine for collaborative work, that could lead to information disclosure, privilege escalation, or denial of service.

Several vulnerabilities have been found in frr, the FRRouting suite of internet protocols. An attacker could craft packages to trigger buffer overflows with the possibility to gain remote code execution, buffer overreads, crashes or trick the software to enter an infinite loop.

Release 4.2.0

update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn

Release 4.2.0

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986

* bsc#1213470 * bsc#1222979 * bsc#1222983 * bsc#1222984 * bsc#1222986

Major phishing-as-a-service platform disrupted – Week in security with Tony Anscombe

The investigation uncovered at least 40,000 phishing domains that were linked to LabHost and tricked victims into handing over their sensitive details

CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in

update to 124.0.6367.78 * Critical CVE-2024-4058: Type Confusion in ANGLE * High CVE-2024-4059: Out of bounds read in V8 API * High CVE-2024-4060: Use after free in Dawn

CVE-2024-3852: GetBoundName in the JIT returned the wrong object CVE-2024-3854: Out-of-bounds-read after mis-optimized switch statement CVE-2024-3857: Incorrect JITting of arguments led to use-after-free during garbage collection CVE-2024-2609: Permission prompt input delay could expire when not in

The chromium-browser-stable package has been updated to the 124.0.6367.60 release. It includes 23 security fixes. Please, do note, only x86_64 is supported from now on. i586 support for linux was stopped some years ago and the community is not able to provide patches anymore for the latest Chromium code.

https://security-tracker.debian.org/tracker/DSA-5674-1

Kaiser Permanente shared 13.4M people’s data with Microsoft Bing, Google, others
What makes Starmus unique? – A Q&A with award-winning filmmaker Todd Miller

The director of the Apollo 11 movie shares his views about the role of technology in addressing pressing global challenges as well as why he became involved with Starmus.

Second time lucky for Thoma Bravo, which scoops up Darktrace for $5.3B

* bsc#1219217 * jsc#PED-3360 * jsc#PED-3361 Cross-References:

UK’s Investigatory Powers Bill to become law despite tech world opposition

* bsc#1213269 * bsc#1218889 * bsc#1222843 * bsc#1222845

* bsc#1222842 Cross-References: * CVE-2024-3651

* bsc#1222950 Cross-References: * CVE-2024-1135

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756

* bsc#1222857 * bsc#1222858 Cross-References: * CVE-2024-2756

Four trends to top the CISO’s packed agenda
Flaws in Chinese keyboard apps leave 750 million users open to snooping, researchers claim

https://security-tracker.debian.org/tracker/DSA-5675-1

Cops cuff man for allegedly framing colleague with AI-generated hate speech clip
Ring dinged for $5.6M after, among other claims, rogue insider spied on ‘pretty girls’
Hacker’s Corner: Complete Guide to Keylogging in Linux – Part 1
How technology drives progress – A Q&A with Nobel laureate Michel Mayor

We spoke to Michel Mayor about the importance of public engagement with science and fostering responsibility among the youth for the preservation of our changing planet

The vision behind Starmus – A Q&A with the festival’s co-founder Garik Israelian

Dr. Israelian talks about Starmus’s vision and mission, the importance of inspiring and engaging audiences, and the strong sense of community within the Starmus universe

Two cuffed in Samourai Wallet crypto dirty money sting
“Junk gun” ransomware: the cheap new threat to small businesses
Russia, Iran pose most aggressive threat to 2024 elections, say infoseccers
Hacker posts fake news story about Ukrainians trying to kill Slovak President
What to do in the age of the critical breach
Indian bank’s IT is so shabby it’s been banned from opening new accounts

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Several security issues were fixed in Thunderbird.

Fix for CVE-2024-31497

Fix for CVE-2024-31497

Australia’s spies and cops want ‘accountable encryption’ – aka access to backdoors
Governments issue alerts after ‘sophisticated’ state-backed actor found exploiting flaws in Cisco security boxes
Smashing Security podcast #369: Keeping the lights on after a ransomware attack
Shouldn’t Teams, Zoom, Slack all interoperate securely for the Feds? Wyden is asking
Microsoft cannot keep its own security in order, so what hope for its add-ons customers?
Management company settles for $18.4M after nuclear weapons plant staff fudged their timesheets
Google cools on cookie phase-out while regulators chew on plans
US charges Iranians with cyber snooping on government, companies

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

* bsc#1217325 Cross-References: * CVE-2023-26364

* bsc#1217325 Cross-References: * CVE-2023-26364

* bsc#1118590 * bsc#874743 Cross-References: * CVE-2014-2913

* bsc#1219887 * bsc#1219912 * bsc#1220371 * jsc#MSQA-759 * jsc#PED-7893

City street lights “misbehave” after ransomware attack
If Britain is so bothered by China, why do these .gov.uk sites use Chinese ad brokers?
Mandiant: Orgs are detecting cybercriminals faster than ever

Google Guest Agent and OS Config Agent could be made to crash if it open a specially crafted JSON.

* bsc#1213269 * bsc#1218889 * bsc#1220134 * bsc#1222843 * bsc#1222845

UnitedHealth admits IT security breach could ‘cover substantial proportion of people in America’

* bsc#1190011 * bsc#1198038 * bsc#1207205 * bsc#1212850 * bsc#1213925

* bsc#1223155 Cross-References: * CVE-2024-31744

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Leicester streetlights take ransomware attack personally, shine on 24/7