Multiple vulnerabilities have been found in Keepalived, the worst of which could allow an attacker to cause Denial of Service condition.
Several security vulnerabilities have been discovered in symfony, a PHP web application framework. Numerous symfony components are affected: Security, bundle readers, session handling, SecurityBundle,
security update
An update that fixes one vulnerability is now available.
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language: The EXIF extension had multiple cases of invalid memory access and rename() was implemented insecurely.
Security fix for CVE-2018-15587
An update that solves one vulnerability and has 5 fixes is now available.
An update that fixes two vulnerabilities is now available.
New ntp packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
An update that solves 5 vulnerabilities and has 6 fixes is now available.
Reading Time: ~2 min. Ransomware as-a-Service Offers Tiered Membership Benefits Jokeroo is the latest ransomware-as-a-service (RaaS) to begin spreading through hacker forums, though it’s differentiating itself by requiring a membership fee with various package offerings. For just $90, a buyer obtains access to a ransomware variant that they can fully customize in exchange for a […]
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0230
The vulnerabilities, which resided in associated smartphone apps, were both easy to find and easy to fix The post Flaws in smart car alarms exposed 3 million cars to hijack appeared first on WeLiveSecurity
An update that solves three vulnerabilities and has one errata is now available.
An update that fixes 9 vulnerabilities is now available.
An update that fixes 15 vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
A bright tomorrow of technical delight, or a dismal future of digital dysfunction? The post RSA conference, USA 2019: Keynotes and key words appeared first on WeLiveSecurity
Protecting your privacy is no longer just an option but a legal requirement in many parts of the world The post RSA 2019: Protecting your privacy in a NIST and GDPR world appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Risk Level: Very Low. Type: Trojan.
## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –
## drupal8 Upstream: – https://www.drupal.org/project/drupal/releases/8.6.10 – https://www.drupal.org/SA-CORE-2019-003 – https://www.drupal.org/project/drupal/releases/8.6.9 – https://www.drupal.org/project/drupal/releases/8.6.8 – https://www.drupal.org/project/drupal/releases/8.6.7 –
A flaw was found in Nagios Core version 4.4.1 and earlier. The qh_help function is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket (CVE-2018-13441).
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. […]
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a […]
When symmetric encryption is used, data can be injected through the passphrase property of the gnupg.GPG.encrypt() and gnupg.GPG.decrypt() methods. The supplied passphrase is not validated for newlines, and the library passes –passphrase-fd=0 to the gpg executable, which expects the passphrase on the first line of stdin, and the ciphertext to be decrypted
NVIDIA graphics drivers could be made to expose sensitive information.
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update for java-1.7.1-ibm is now available for Red Hat Enterprise Linux 7 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
Users should waste no time in updating to the browser’s latest version The post Latest Chrome update plugs a zero-day hole appeared first on WeLiveSecurity
An update for java-1.8.0-ibm is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which
An update that solves two vulnerabilities and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves four vulnerabilities and has four fixes is now available.
security update
Several security issues were fixed in PHP.
Fixes: CVE-2018-6358, CVE-2018-7867, CVE-2018-7868, CVE-2018-7870, CVE-2018-7871, CVE-2018-7872, CVE-2018-7875, CVE-2018-9165.
– https://www.drupal.org/project/link/releases/7.x-1.6 – https://www.drupal.org/sa-contrib-2019-020 – https://www.drupal.org/sa- core-2019-003 – https://www.drupal.org/project/link/releases/7.x-1.5 – https://www.drupal.org/project/link/releases/7.x-1.5-beta3
## 1.7.1 – #475: “Loose” lists will now contain paragraphs in all items, not just some. – #433: Links will no longer be double nested – #525: The info- string when beginning a code block may now contain non-word characters (e.g. `c++`) – #561: The `mbstring` extension (which we already depend on) has been added […]
– bugfix {foreach} using new style property access like {$item@property} on Smarty 2 style named foreach loop could produce errors https://github.com/smarty-php/smarty/issues/484 31.08.2018 – bugfix some custom left and right delimiters like ‘{^’ ‘^}’ did not work
Bump to ignition-dracut 2c69925 * support platform configs and user configs in /boot ^ https://github.com/coreos/ignition-dracut/pull/43 * Add ability to parse config.ign file on boot ^ https://github.com/coreos/ignition-dracut/pull/42
