Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132
Emil Lerner, beched and d90pwn found a buffer underflow in php5-fpm, a Fast Process Manager for the PHP language, which can lead to remote code execution.
security update
Type: Vulnerability. NixOS Nix is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. GNU Guix is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Elasticsearch is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Multiple VMware products are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cloud Foundry UAA is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Istio is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Qt QtBase module is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. PHP is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Cloud Foundry SMB Volume is prone to an information disclosure vulnerability; fixes are available.
Type: Vulnerability. OpenSSH is prone to an integer overflow vulnerability; fixes are available.
Type: Vulnerability. SLUB Event Registration Extension is prone to an arbitrary-file-upload vulnerability; fixes are available.
Type: Vulnerability. vBulletin is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. PHP is prone to a heap-based buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Nessus is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Adobe Creative Cloud Desktop Application is prone to an unspecified security-bypass vulnerability; fixes are available.
Type: Vulnerability. vBulletin is prone to multiple SQL-injection vulnerabilities.
Type: Vulnerability. Dnsmasq is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to information-disclosure vulnerability; fixes are available.
Reading Time: ~ 2 min. MedusaLocker Ransomware Spotted Worldwide While it’s still unclear how MedusaLocker is spreading, the victims have been confirmed around the world in just the last month. By starting with a preparation phase, this variant can ensure that local networking functionality is active and maintain access to network drives. After shutting down […]
Reading Time: ~ 3 min. Certain types of cybercrime targets always make headlines. In this two-part series, we’ll get into a pretty serious one: your health, and why hackers are targeting the healthcare industry for profit. The Short Answer: Medical Data is Worth a Lot Stolen medical data is valuable, plain and simple. In a […]
Type: Vulnerability. Golang Go is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. file is prone to a heap-based buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Direct Mail Extension for TYPO3 is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. F5 BIG-IQ Centralized Management is prone to a remote security-bypass vulnerability; fixes are available.
Type: Vulnerability. Multiple D-Link products are prone to a command-injection vulnerability.
Type: Vulnerability. ISC BIND is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. F5 BIG-IQ Centralized Management is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Linux kernel is prone to a local memory-corruption vulnerability; fixes are available.
Type: Vulnerability. Python is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Multiple Dell EMC products are prone to a remote security-bypass vulnerability; fixes are available.
Type: Vulnerability. Juniper Junos is prone to a local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. libxslt is prone to an arbitrary code-execution vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan, Virus, Worm.
Risk Level: Very Low. Type: Trojan.
How is the social network preparing to curtail the spread of misinformation as the election season heats up? The post Facebook lays out plan to protect elections appeared first on WeLiveSecurity
An update that fixes 13 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes 16 vulnerabilities is now available.
The 5.3.7 update contains a number of important fixes across the tree. The update also includes a fix for the [CVE-2019-17666](https://access.redhat.com/security/cve/CVE-2019-17666) security vulnerability regarding a buffer overflow in a Realtek wireless driver.
The 5.3.7 update contains a number of important fixes across the tree. The update also includes a fix for the [CVE-2019-17666](https://access.redhat.com/security/cve/CVE-2019-17666) security vulnerability regarding a buffer overflow in a Realtek wireless driver.
sudo: Privilege escalation via ‘Runas’ specification with ‘ALL’ keyword (CVE-2019-14287) SL7 x86_64 sudo-1.8.23-4.el7_7.1.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.1.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.1.i686.rpm sudo-devel-1.8.23-4.el7_7.1.i686.rpm sudo-devel-1.8.23-4.el7_7.1.x86_64.rpm – Scientific Linux Development Team
An update is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for sudo is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for sudo is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
ESET researchers discovered a year-long adware campaign on Google Play and tracked down its operator. The apps involved, installed eight million times, use several tricks for stealth and persistence. The post Tracking down the developer of Android adware affecting millions of users appeared first on WeLiveSecurity
An update is now available for Ansible Engine 2.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Type: Vulnerability. Ansible is prone to multiple information-disclosure vulnerabilities; fixes are available.
Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Fortinet FortiOS is prone to an insufficient entropy vulnerability; fixes are available.
Type: Vulnerability. McAfee Endpoint Security is prone to a vulnerability that lets attackers inject and execute arbitrary code; fixes are available.
Type: Vulnerability. URL redirect extension for TYPO3 is prone to an SQL-injection vulnerability; fixes are available.
Type: Vulnerability. Citrix NetScaler ADC and NetScaler Gateway are prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Libexpat Expat is prone to a heap-based buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Google Chrome is prone to multiple vulnerabilities; fixes are available.
Type: Vulnerability. Mozilla Firefox and Firefox ESR are prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Mozilla Firefox is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Juniper Junos is prone to a local directory-traversal vulnerability; fixes are available.
Type: Vulnerability. Mozilla Firefox ESR is prone to a memory-corruption vulnerability; fixes are available.
Type: Vulnerability. The Booking and Availability Management Tools module for Drupal is prone to an access-bypass vulnerability; fixes are available.
Type: Vulnerability. ISC BIND is prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Schneider Electric ProClima is prone to multiple remote code-execution vulnerabilities; fixes are available.
