Menu

Monthly Archives: November 2024

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Will passkeys ever replace passwords? Can they?

Multiple vulnerabilties were discovered for smarty3, a widely-used PHP templating engine, which potentially allows an attacker to perform an XSS (e.g JavaScript or PHP code injection).

A vulnerability has been discovered in the Xorg Server and XWayland, the worst of which can result in privilege escalation.

A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution.

CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325238) 2325241 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws [fedora-41]

DoS due to resource exhaustion has been fixed in waitress, a Python Web Server Gateway Interface. For Debian 11 bullseye, this problem has been fixed in version

https://security-tracker.debian.org/tracker/DSA-5814-1

https://security-tracker.debian.org/tracker/DSA-5813-1

https://security-tracker.debian.org/tracker/DSA-5812-1

Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For Debian 11 bullseye, these problems have been fixed in version

Rust haters, unite! Fil-C aims to Make C Great Again
Swiss cheesed off as postal service used to spread malware

Update to upstream 2.1-47. 20241112 Update of 06-8f-04/0x87 (SPR-SP E0/S1) microcode (in intel-ucode/06-8f-05) from revision 0x2b0005c0 up to 0x2b000603; Update of 06-8f-05/0x87 (SPR-SP E2) microcode from revision 0x2b0005c0 up to 0x2b000603;

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

Update to version 3.0.1, which resolves CVE-2024-49768 and CVE-2024-49769.

CVE-2024-46951 ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space (fedora#2325237) 2325240 – CVE-2024-46952 CVE-2024-46953 CVE-2024-46954 CVE-2024-46955 CVE-2024-46956 ghostscript: various flaws

bartlett/php-compatinfo-db 6.12.0 – 2024-10-29 Added db:show command is now able to display deprecations on all components PHP 8.2.25 support PHP 8.3.13 support

Bloke behind Helix Bitcoin launderette jailed for three years, hands over $400M
Go language evolving for future hardware, AI workloads
Letting chatbots run robots ends as badly as you’d expect
Mystery Palo Alto Networks hijack-my-firewall zero-day now officially under exploit
Keyboard robbers steal 171K customers’ data from AnnieMac mortgage house
The Dual Edge of Open Source: Examining Key Benefits and Security Challenges
Simplifying endpoint security
Bitfinex burglar bags 5 years behind bars for Bitcoin heist

* bsc#1233313 Cross-References: * CVE-2024-21820 * CVE-2024-21853

* bsc#1232590 Cross-References: * CVE-2024-50602

* bsc#1233282 Cross-References: * CVE-2024-52533

AI meets security: POC to run workloads in confidential containers using NVIDIA accelerated computing

Several security issues were fixed in the Linux kernel.

Microsoft Power Pages misconfigurations exposing sensitive data

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Security: CVE-2024-3596: Fix for BlastRADIUS vulnerability in libkrad (support for Message-Authenticator attribute) Marvin attack: Removal of the “RSA” method for PKINIT Fix of miscellaneous mistakes in the code

Fortinet patches VPN app flaw that could give rogue users, malware a privilege boost
Cybercriminal devoid of boundaries gets 10-year prison sentence
ShrinkLocker ransomware: what you need to know
IT specialist Jack Teixeira jailed for 15 years after leaking classified military documents on Discord
Kids’ shoemaker Start-Rite trips over security again, spilling customer card info
OpenSSL in Red Hat Enterprise Linux 10: From engines to providers
NatWest blocks bevy of apps in clampdown on unmonitorable comms
Asda security chief replaced, retailer sheds jobs during Walmart tech divorce
How to use DispatchProxy for AOP in .NET Core
Understanding Hyperlight, Microsoft’s minimal VM manager
Five Eyes infosec agencies list 2024’s most exploited software flaws

Update to 2.46.3

Update to b3561

Backport fix for CVE-2024-50602.

CVE fix for CVE-2024-9632

Reminder: China-backed crews compromised ‘multiple’ US telcos in ‘significant cyber espionage campaign’

Update to 2.46.3

ShrinkLocker ransomware scrambled your files? Free decryption tool to the rescue
Smashing Security podcast #393: Who needs a laptop to hack when you have a Firestick?
Data broker amasses 100M+ records on people – then someone snatches, sells it
Ransomware fiends boast they’ve stolen 1.4TB from US pharmacy network

giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function. (CVE-2023-48161) Array indexing integer overflow. (CVE-2024-21210) HTTP client improper handling of maxHeaderSize. (CVE-2024-21208) Unbounded allocation leads to out-of-memory error. (CVE-2024-21217)

Microsoft slips Task Manager and processor count fixes into Patch Tuesday
Docker tutorial: Get started with Docker volumes
Kotlin for Java developers
The Agile Manifesto was ahead of its time
Visual Studio 17.12 brings C++, Copilot enhancements

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Admins can give thanks this November for dollops of Microsoft patches
China’s Volt Typhoon crew and its botnet surge back with a vengeance
Air National Guardsman gets 15 years after splashing classified docs on Discord

Several security issues were fixed in .NET.

Microsoft’s .NET 9 arrives, emphasizing performance, cloud, and AI
Here’s what we know about the suspected Snowflake data extortionists

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5811-1

https://security-tracker.debian.org/tracker/DSA-5810-1

Red Hat OpenShift AI unveils model registry, data drift detection
‘Cybersecurity issue’ at Food Lion parent blamed for US grocery mayhem
Go language rises in Tiobe popularity index
The AI Fix #24: Where are the alien AIs, and are we being softened up for superintelligence?
HTTP your way into Citrix’s Virtual Apps and Desktops with fresh exploit code
Managing third-party risks in complex IT environments
Red Hat Developer Hub adds AI templates
Snowflake bares its agentic AI plans by showcasing its Intelligence platform
Amazon confirms employee data exposed in leak linked to MOVEit vulnerability
Winter Fuel Payment scam targets UK citizens via SMS
Why your AI models stumble before the finish line

* bsc#1186511 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Multiple vulnerabilities have been fixed in libarchive, a multi-format archive and compression library. CVE-2021-36976

New wget packages are available for Slackware 15.0 and -current to fix a security issue.

An out-of-bounds write vulnerability when handling crafted streams was discovered in mpg123, a real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3, which could result in the execution of arbitrary code.

Containerizing WordPress: Best Practices for Robust Security and Management
FBI issues warning as crooks ramp up emergency data request scams
200,000 SelectBlinds customers have their card details skimmed in malware attack
Dark web crypto laundering kingpin sentenced to 12.5 years in prison

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: