Menu

Category Archives: Security

Articles about security

Update to 2.46.3

Update to b3561

Backport fix for CVE-2024-50602.

CVE fix for CVE-2024-9632

Reminder: China-backed crews compromised ‘multiple’ US telcos in ‘significant cyber espionage campaign’

Update to 2.46.3

ShrinkLocker ransomware scrambled your files? Free decryption tool to the rescue
Smashing Security podcast #393: Who needs a laptop to hack when you have a Firestick?
Data broker amasses 100M+ records on people – then someone snatches, sells it
Ransomware fiends boast they’ve stolen 1.4TB from US pharmacy network

giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB Function. (CVE-2023-48161) Array indexing integer overflow. (CVE-2024-21210) HTTP client improper handling of maxHeaderSize. (CVE-2024-21208) Unbounded allocation leads to out-of-memory error. (CVE-2024-21217)

Microsoft slips Task Manager and processor count fixes into Patch Tuesday
Visual Studio 17.12 brings C++, Copilot enhancements
The Agile Manifesto was ahead of its time
Kotlin for Java developers
Docker tutorial: Get started with Docker volumes

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Update to 130.0.6723.116

Update to 1.16.2 Fixes CVE-2024-0132 or GHSA-mjjw-553x-87pq, and CVE-2024-0133 or GHSA-f748-7hpg-88ch

Admins can give thanks this November for dollops of Microsoft patches
China’s Volt Typhoon crew and its botnet surge back with a vengeance
Air National Guardsman gets 15 years after splashing classified docs on Discord

Several security issues were fixed in .NET.

Microsoft’s .NET 9 arrives, emphasizing performance, cloud, and AI
Here’s what we know about the suspected Snowflake data extortionists

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

https://security-tracker.debian.org/tracker/DSA-5811-1

https://security-tracker.debian.org/tracker/DSA-5810-1

Red Hat OpenShift AI unveils model registry, data drift detection
‘Cybersecurity issue’ at Food Lion parent blamed for US grocery mayhem
Go language rises in Tiobe popularity index
The AI Fix #24: Where are the alien AIs, and are we being softened up for superintelligence?
HTTP your way into Citrix’s Virtual Apps and Desktops with fresh exploit code
Managing third-party risks in complex IT environments
Red Hat Developer Hub adds AI templates
Snowflake bares its agentic AI plans by showcasing its Intelligence platform
Amazon confirms employee data exposed in leak linked to MOVEit vulnerability
Winter Fuel Payment scam targets UK citizens via SMS
Why your AI models stumble before the finish line

* bsc#1186511 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Fixes CVE-2024-9341, CVE-2024-9407, CVE-2024-9675 and CVE-2024-9676.

Multiple vulnerabilities have been fixed in libarchive, a multi-format archive and compression library. CVE-2021-36976

New wget packages are available for Slackware 15.0 and -current to fix a security issue.

An out-of-bounds write vulnerability when handling crafted streams was discovered in mpg123, a real time MPEG 1.0/2.0/2.5 audio player/decoder for layers 1, 2 and 3, which could result in the execution of arbitrary code.

Containerizing WordPress: Best Practices for Robust Security and Management
FBI issues warning as crooks ramp up emergency data request scams
200,000 SelectBlinds customers have their card details skimmed in malware attack
Dark web crypto laundering kingpin sentenced to 12.5 years in prison

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

Breaking down digital silos
Can Wasm replace containers?
Is your software architecture as clean as your code?

* bsc#1216423 Cross-References: * CVE-2023-45802

* bsc#1216423 Cross-References: * CVE-2023-45802

Alleged Snowflake attacker gets busted by Canadians – politely, we assume

https://security-tracker.debian.org/tracker/DSA-5808-1

https://security-tracker.debian.org/tracker/DSA-5809-1

https://security-tracker.debian.org/tracker/DSA-5807-1

https://security-tracker.debian.org/tracker/DSA-5805-1

A heap-based out-of-bounds write vulnerability was discovered in libarchive, a multi-format archive and compression library, which may result in the execution of arbitrary code if a specially crafted RAR archive is processed.

Invalid low-level GF(2^m) parameters can lead to an OOB memory access. (CVE-2024-9143) References: – https://bugs.mageia.org/show_bug.cgi?id=33736

HTMLDOC before 1.9.19 has an out-of-bounds write in parse_paragraph in ps-pdf.cxx because of an attempt to strip leading whitespace from a whitespace-only node. (CVE-2024-45508) HTMLDOC v1.9.18 contains a buffer overflow in parse_pre function,ps-pdf.cxx:5681. (CVE-2024-46478)

In Libheif, insufficient checks in ImageOverlay::parse() while decoding a HEIF file containing an overlay image with forged offsets can lead to an out-of-bounds read and write. (CVE-2024-41311) References:

Werkzeug is a Web Server Gateway Interface web application library. Applications using `werkzeug.formparser.MultiPartParser` corresponding to a version of Werkzeug prior to 3.0.6 to parsing `multipart/form-data` requests (e.g. all flask applications) are vulnerable to a relatively simple but effective resource exhaustion (denial of service) attack. A

Permission leak via embed or object elements. (CVE-2024-10458) Use-after-free in layout with accessibility. (CVE-2024-10459) Confusing display of origin for external protocol handler prompt. (CVE-2024-10460) XSS due to Content-Disposition being ignored in

https://security-tracker.debian.org/tracker/DSA-5806-1

https://security-tracker.debian.org/tracker/DSA-5804-1

Scattered Spider, BlackCat claw their way back from criminal underground
Secure cloud bursting: Leveraging confidential computing for peace of mind
Recent improvements in Red Hat Enterprise Linux CoreOS security data
Strengthening security of the software supply chain for LLVM

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Java app security would get a boost through quantum resistance
Serverless computing’s second act
Winos4.0 abuses gaming apps to infect, control Windows machines
Don’t open that ‘copyright infringement’ email attachment – it’s an infostealer
IBM: APIs getting AI boost
Jane Goodall: Reasons for hope | Starmus highlights

The trailblazing scientist shares her reasons for hope in the fight against climate change and how we can tackle seemingly impossible problems and keep going in the face of adversity

Cisco scores a perfect CVSS 10 with critical flaw in its wireless system

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Officials warn of Russia’s tech-for-troops deal with North Korea amid Ukraine conflict

New upstream build (132.0)

Smashing Security podcast #392: Pasta spies and private eyes, and are you applying for a ghost job?

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Cybercrooks are targeting Bengal cat lovers in Australia for some reason
Operation Synergia II sees Interpol swoop on global cyber crims
Cyberattackers stole Microlise staff data following DHL, Serco disruption