The group used phishing, BEC and other types of attacks to swindle victims out of millions The post European police dismantle cybercrime ring with ties to Italian Mafia appeared first on WeLiveSecurity
A security vulnerability has been found in Kaminari, a pagination engine plugin for Rails 3+ and other modern frameworks, that would allow an attacker to inject arbitrary code into pages with pagination links.
Several security issues were fixed in WebKitGTK.
SQL parse could be made to denial of service if it received a specially crafted regular expression.
IBM s390x systems could be made to crash or run programs as an administrator.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sles12sp5 was updated. The following patches have been included in this update:
security update
Update to 2.32.4: * Do not append .asc extension to downloaded text/plain files. * Fix several crashes and rendering issues. * Fix CVE-2021-30858
– CVE-2021-22947 – STARTTLS protocol injection via MITM – CVE-2021-22946 – protocol downgrade required TLS bypassed – CVE-2021-22945 – use-after-free and double-free in MQTT sending
Backport patch for CVE-2021-23437.
Backport patch for CVE-2021-23437.
Backport patch for CVE-2021-23437.
Backport patch for CVE-2021-23437.
security update
Rebase with Security fix for CVE-2021-3781
Rebuild for dovecot 2.3.16 —- Rebuild for dovecot 2.3.16
– fix disclosure of HTTP auth credentials via SNI data (CVE-2021-38165)
An update for rh-ruby27-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that solves one vulnerability and has one errata is now available.
Two vulnerabilities were discovered in the Nextcloud desktop client, which could result in information disclosure. For the oldstable distribution (buster), these problems have been fixed
The legacy 1.0 version of OpenSSL, a cryptography library for secure communication, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.
Multiple vulnerabilities were discovered in nettle, a low level cryptographic library, which could result in denial of service (remote crash in RSA decryption via specially crafted ciphertext, crash on ECDSA signature verification) or incorrect verification of ECDSA signatures.
GnuTLS, a portable cryptography library, fails to validate alternate trust chains in some conditions. In particular this breaks connecting to servers that use Let’s Encrypt certificates, starting 2021-10-01.
Update to 2.2.17
Upstream annoucement: [WordPress 5.8.1 Security and Maintenance Release](https://wordpress.org/news/2021/09/wordpress-5-8-1-security-and- maintenance-release/)
Another race in XENMAPSPACE_grant_table handling [XSA-384, CVE-2021-28701] bugfix for XSA-380
The container caasp/v4.5/kube-scheduler was updated. The following patches have been included in this update:
The container caasp/v4.5/kube-proxy was updated. The following patches have been included in this update:
The container caasp/v4.5/kube-controller-manager was updated. The following patches have been included in this update:
The most recent Patch Tuesday includes a fix for the previously disclosed and actively exploited remote code execution flaw in MSHTML. The post Microsoft Patch Tuesday fixes actively exploited zero‑day and 85 other flaws appeared first on WeLiveSecurity
Several security issues were fixed in Python.
Several security issues were fixed in Qt.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Libgcrypt could be made to expose sensitive information.
An update that solves one vulnerability and has three fixes is now available.
