Several security issues were fixed in etcd.
Several security issues were fixed in the Linux kernel.
Several security vulnerabilities were discovered in mediawiki, a website engine for collaborative work. Insufficiently escaped input text may allow a malicious user to perform cross-site-scripting (XSS) attacks.
An update that fixes three vulnerabilities is now available.
PCRE could be made to expose sensitive information.
Several vulnerabilities were discovered in BIND, a DNS server implementation. CVE-2022-2795
Several security issues were fixed in Bind.
It was discovered that the wordexp() function of tinygltf, a library to load/save glTF (GL Transmission Format) files was susceptible to command execution when processing untrusted files.
Mako could be made to denial of service if it received a specially crafted regular expression.
Several security issues were fixed in Bind.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Here are some of the most common ways that an iPhone can be compromised with malware, how to tell it’s happened to you, and how to remove a hacker from your device The post Can your iPhone be hacked? What to know about iOS security appeared first on WeLiveSecurity
The news seems awash this week with reports of both Microsoft and Apple scrambling to patch security flaws in their products The post Rising to the challenges of secure coding – Week in security with Tony Anscombe appeared first on WeLiveSecurity
Several security issues were fixed in LibTIFF.
Red Hat OpenShift Container Platform release 4.11.5 is now available with updates to packages and images that fix several bugs and add enhancements. This release includes a security update for Red Hat OpenShift Container Platform 4.11.
The container bci/python was updated. The following patches have been included in this update:
The container suse/pcp was updated. The following patches have been included in this update:
The container bci/dotnet-aspnet was updated. The following patches have been included in this update:
An update that fixes one vulnerability is now available.
security update
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update for redhat-release-virtualization-host, redhat-virtualization-host, and redhat-virtualization-host-productimg is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact
Maher Azzouzi found a local root escalation vulnerability in Enlightenment, an X11 window manager. For Debian 10 buster, this problem has been fixed in version
– control code in cookie denial of service (CVE-2022-35252)
6.0.8, fixes CVE-2022-40626
An update that fixes one vulnerability is now available.
Security fix for CVE-2022-2309
Update to latest upstream release
An update that fixes two vulnerabilities is now available.
Several vulnerabilities were discovered in ConnMan, a network manager for embedded devices, which could result in denial of service or the execution of arbitrary code.
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/rust was updated. The following patches have been included in this update:
The container bci/bci-minimal was updated. The following patches have been included in this update:
The container bci/bci-init was updated. The following patches have been included in this update:
security update
An update that solves 25 vulnerabilities, contains four features and has 91 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Several security issues were fixed in the Linux kernel.
Multiple file parsing vulnerabilities have been fixed in libraw. They are concerned with the dng and x3f formats. CVE-2020-35530
An update that solves one vulnerability and has one errata is now available.
ESET researchers have uncovered another tool in the already extensive arsenal of the SparklingGoblin APT group: a Linux variant of the SideWalk backdoor The post You never walk alone: The SideWalk backdoor gets a Linux variant appeared first on WeLiveSecurity
It was found that GLib, a general-purpose portable utility library, could be used to print partial contents from arbitrary files. This could be exploited from setuid binaries linking to GLib for information disclosure of files with a specific format.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Cross-site tracking cookies have a bleak future but can still cause privacy woes to unwary users The post Third‑party cookies: How they work and how to stop them from tracking you across the web appeared first on WeLiveSecurity
ESET Research first spotted this variant of the SideWalk backdoor in the network of a Hong Kong university in February 2021 The post SparklingGoblin deploys new Linux backdoor – Week in security, special edition appeared first on WeLiveSecurity
security update
