Menu

Monthly Archives: November 2024

Multiple vulnerabilities were discovered in Lemonldap::NG, an OpenID-Connect, CAS and SAML compatible Web-SSO system, which could lead to injection of arbitrary scripts or authorization bypass.

Two issues have been found in editorconfig-core, a coding style indenter for all editors. Both issues are related to buffer overflows in different locations.

Brief introduction CVE-2022-0934

An issue has been found in xfpt, a tool to generate XML from plain tex. The issue is about bad handling of input data, which may result in a stack-based buffer overflow and execution of arbitrary code, when

RansomHub claims to net data hat-trick against Bologna FC

An issue has been found in tgt, Linux SCSI target user-space daemon and tools. The issue was related to using rand() without proper seed, resulting in identical sequences of challenges.

GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations because ‘’ characters at the end of header names are ignored, i.e., a “Transfer-Encoding: chunked” header is treated the same as a “Transfer-Encoding: chunked” header. (CVE-2024-52530) GNOME libsoup before 3.6.1 allows a buffer overflow in applications that

ProFTPD a popular FTP server was affected by multiple vulnerabilities. CVE-2023-48795

Zabbix urges upgrades after critical SQL injection bug disclosure

* bsc#1233447 Cross-References: * CVE-2024-52304

* bsc#1233323 * bsc#1233325 * bsc#1233326 * bsc#1233327

Ransom gang claims attack on NHS Alder Hey Children’s Hospital
UK hospital, hit by cyberattack, resorts to paper and postpones procedures
Fighting cybercrime with actionable knowledge
Python 3.14 is a rational constant
Are we worse at cloud computing than 10 years ago?

Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and

Update the rustls crate to version 0.23.17. Update the zlib-rs crate to version 0.4.0. The update to zlib-rs v0.4.0 also addresses CVE-2024-11249 (stack overflow during decompression with malicious input). This issue had no actual impact in Fedora, because no applications yet use the the zlib-rs feature of rustls and

Deadlock in x86 HVM standard VGA handling [XSA-463, CVE-2024-45818] libxl leaks data to PVH guests via ACPI tables [XSA-464, CVE-2024-45819]

Update to 128.5.0 https://www.thunderbird.net/en-US/thunderbird/128.5.0esr/releasenotes/ https://www.mozilla.org/en-US/security/advisories/mfsa2024-68/

https://security-tracker.debian.org/tracker/DSA-5821-1

https://security-tracker.debian.org/tracker/DSA-5820-1

Exactly what would an AI-centric OS look like?
Mimic ransomware: what you need to know
Uber branches out into AI data labeling
NHS major ‘cyber incident’ forces hospitals to use pen and paper

Multiple security issues were discovered in Thunderbird, which could result in denial of service or the execution of arbitrary code. For Debian 11 bullseye, these problems have been fixed in version

How to use ref structs in C# 13
Copilot Studio Agents get a major upgrade via Microsoft 365 Copilot

* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692

* bsc#1225889 Cross-References: * CVE-2024-1298

* bsc#1209401 Affected Products: * Basesystem Module 15-SP6 * Desktop Applications Module 15-SP6

* jsc#PED-11092 Cross-References: * CVE-2023-31489 * CVE-2023-31490

The only thing worse than being fired is scammers fooling you into thinking you’re fired

1.37 – fix parsing of “use if …” Fixes errors in PAR::Packer test t/90-rt59710.t – add test for _parse_libs() 1.36

Smashing Security podcast #395: Gym hacking, disappearing DNA, and a social lockout
Salt Typhoon’s surge extends far beyond US telcos
Uno Platform unveils visual designer for cross-platform .NET development
T-Mobile US takes a victory lap after stopping cyberattacks: ‘Other providers may be seeing different outcomes’

https://security-tracker.debian.org/tracker/DSA-5819-1

Bolster resilience against 2025 cyber threats
Data broker leaves 600K+ sensitive files exposed online
AWS re:Invent 2024: The future of cloud computing (and where AWS fits in it)
First-ever UEFI bootkit for Linux in the works, experts say
Automating endpoint management

* bsc#1233695 Cross-References: * CVE-2024-11691 * CVE-2024-11692

* bsc#1233434 Cross-References: * CVE-2024-52316

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Python to C: What’s new in Cython 3.1
Kotlin for Java developers: Concurrency with coroutines
A software developer gives thanks
The workplace has become a surveillance state

* bsc#1230366 * bsc#1232542 * bsc#1232622 * bsc#1232624

CrowdStrike still doesn’t know how much its Falcon flame-out will cost
Telco engineer who spied on US employer for Beijing gets four years in the clink

Several security issues were fixed in libsoup.

Kotlin to lose scripting features
Man accused of hilariously bad opsec as alleged cybercrime spree detailed
Anthropic introduces the Model Context Protocol
The AI Fix #26: Would AI kill sentient robots, and is water wet?
US senators propose law to require bare minimum security standards
Data leaks from websites built on Microsoft Power Pages, including 1.1 million NHS records
Fortify your data
Bing Wallpaper app, now in Windows Store, accused of cookie shenanigans

* bsc#1219340 * bsc#1230423 * bsc#1233323 * bsc#1233325 * bsc#1233326

Another ‘major cyber incident’ at a UK hospital, outpatients asked to stay away

USN-7117-1 caused some regression in needrestart.

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

QNAP and Veritas dump 30-plus vulns over the weekend

Multiple vulnerabilities have been fixed in pypy3, an alternative implementation of the Python 3.x language. CVE-2020-10735

Build generative AI pipelines without the infrastructure headache
Are cloud units a good measure of cloud value?

* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853

Britain Putin up stronger AI defences to counter growing cyber threats
USPTO petitioned to cancel Oracle’s JavaScript trademark
Supply chain management vendor Blue Yonder succumbs to ransomware
PHP updates DOM API
Security? We’ve heard of it: How Microsoft plans to better defend Windows
FlipaClip animation app data breach exposes details of almost 900,000 users

Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks.

A microcode update has been released for Intel processors, addressing multiple vulnerabilties which potentially could cause information disclosue or local DoS.

China has utterly pwned ‘thousands and thousands’ of devices at US telcos
3 data engineering trends riding Kafka, Flink, and Iceberg
GitHub Copilot: Everything you need to know
Speed is the killer app
Google blocked 1,000-plus pro-China fake news websites from its search results
Imagine a land in which Big Tech can’t send you down online rabbit holes or use algorithms to overcharge you
Russian spies may have moved in next door to target your network

Several security issues were fixed in OpenJDK 23.

Multiple vulnerabilities have been fixed in the PostScript/PDF interpreter Ghostscript. CVE-2024-46951

Volunteer DEF CON hackers dive into America’s leaky water infrastructure

Ansible is a command-line IT automation software application. It can configure systems, deploy software, and orchestrate advanced workflows to support application deployment, system updates, …

https://security-tracker.debian.org/tracker/DSA-5818-1

A buffer overflow with long SOCKS4a proxy hostname and username has been fixed in the GNOME Input/Output library (GIO). For Debian 11 bullseye, this problem has been fixed in version

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Trump taps border hawk to head DHS. Will Noem’s ‘enthusiasm’ extend to digital domain?

PHP version 8.3.14 (21 Nov 2024) CLI: Fixed bug GH-16373 (Shebang is not skipped for router script in cli-server started through shebang). (ilutov) Fixed bug GHSA-4w77-75f9-2c8w (Heap-Use-After-Free in sapi_read_post_data

This is the .NET 9.0 GA release. It contains security fixes for CVE-2024-43498 and CVE-2024-43499 Announcement: https://devblogs.microsoft.com/dotnet/announcing-dotnet-9/ Release Notes: https://github.com/dotnet/core/blob/main/release- notes/9.0/9.0.0/9.0.0.md