Menu

Category Archives: Security

Articles about security

Happy 20th birthday Gmail, you’re mostly grown up – now fix the spam
Avoiding the dangers of AI-generated code

* bsc#1222045 Cross-References: * CVE-2024-29025

* bsc#1221815 Cross-References: * CVE-2024-2494

Apple’s GoFetch silicon security fail was down to an obsession with speed

The 6.7.11 stable kernel update contains a number of important fixes across the tree.

Upgrade to 2.44.0: Make the DOM accessibility tree reachable from UI process with GTK4. Removed the X11 and WPE renderers in favor of DMA-BUF. Improved vblank synchronization when rendering. Removed key event reinjection in GTK4 to make keyboard shortcuts work in web

The 6.7.11 stable kernel update contains a number of important fixes across the tree.

Six banks share customer info to help Singapore fight money laundering

https://security-tracker.debian.org/tracker/DSA-5652-1

US House of Reps tells staff: No Microsoft Copilot for you!
Malicious xz backdoor reveals fragility of open source
Nearly 3M people hit in Harvard Pilgrim healthcare data theft
Ex-White House CIO tells The Reg: TikTok ban may be diplomatic disaster
AT&T admits massive 70M+ mid-March customer data dump is real though old

Multiple vulnerabilities were found in libvirt, a C toolkit to interact with the virtualization capabilities of Linux, which could lead to denial of service or information disclosure.

* bsc#1041090 * bsc#1084627 * bsc#1133158 * bsc#1172267 * bsc#1191783

Update to 2.53.18.2

Update to 2.53.18.2

Update to 2.53.18.2

Two security issues were discovered in MediaWiki, a website engine for collaborative work, which could result in cross-site scripting or denial of service.

Rust developers at Google are twice as productive as C++ teams

Skyler Ferrante discovered that the wall tool from util-linux does not properly handle escape sequences from command line arguments. A local attacker can take advantage of this flaw for information disclosure.

Urgent security alert for Fedora Linux 40 and Fedora Rawhide users

In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23. (CVE-2024-30202) In Emacs before 29.3, Gnus treats inline MIME contents as trusted. (CVE-2024-30203)

Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. (CVE-2023-22655) Information exposure through microarchitectural state after transient

Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `–with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a

These are bug fix and security releases including MODERATE, HIGH, and CRITICAL issues.

release v1.11.0 release v1.10.1 release v1.10.0

https://security-tracker.debian.org/tracker/DSA-5650-1

https://security-tracker.debian.org/tracker/DSA-5651-1

podman-tui release v1.0.0 Security fix for [CVE-2024-28180]

x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]

Automatic update for cockpit-314-1.fc39.

This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.

Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary

Security fix for CVE-2023-35936 and CVE-2023-38745 pandoc: backport fixes for CVE-2023-35936 and CVE-2023-38745 pandoc-cli: new package for pandoc binary

Malicious SSH backdoor sneaks into xz, Linux world’s data compression library
Easy-to-use make-me-root exploit lands for recent Linux kernels. Get patching

https://security-tracker.debian.org/tracker/DSA-5648-1

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

podman-tui release v1.0.0

Version 6.7.4 (2024-03-21) Upgrade tcpdf tag encryption algorithm. Version 6.7.3 (2024-03-20) Fix regression issue #699. Version 6.7.2 (2024-03-18)

This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.

CVE-2024-2004: Usage of disabled protocol If all protocols are disabled at run-time with none being added, curl/libcurl would still allow communication with the default set of allowed protocols, including some that are unencrypted. CVE-2024-2398: HTTP/2 push headers memory-leak

update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-2887: Type Confusion in WebAssembly

https://security-tracker.debian.org/tracker/DSA-5649-1

JetBrains keeps mum on 26 ‘security problems’ fixed after Rapid7 spat
FTX crypto-crook Sam Bankman-Fried gets 25 years in prison
Nvidia’s newborn ChatRTX bot patched for security bugs
Sellafield nuclear waste dump faces prosecution over cybersecurity failures
US critical infrastructure cyberattack reporting rules inch closer to reality

* bsc#1218610 Cross-References: * CVE-2023-51779

* bsc#1218487 * bsc#1218610 Cross-References: * CVE-2023-51779

* bsc#1218487 Cross-References: * CVE-2023-6531

* bsc#1208911 * bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

Canonical cracks down on crypto cons following Snap Store scam spree
INC Ransom claims responsibility for attack on NHS Scotland
These 17,000 unpatched Microsoft Exchange servers are a ticking time bomb
AI hallucinates software packages and devs download them – even if potentially poisoned with malware
Execs in Japan busted for winning dev bids then outsourcing to North Koreans
China encouraged armed offensive against Myanmar government to protest proliferation of online scams
Smashing Security podcast #365: Hacking hotels, Google’s AI goof, and cyberflashing
Apple fans deluged with phony password reset requests
Majority of Americans now use ad blockers
‘Thousands’ of businesses at mercy of miscreants thanks to unpatched Ray AI flaw
Ransomware hits The Big Issue. Qilin group leaks confidential data
Meta accused of snarfing people’s Snapchat data via traffic decryption
Miscreants are exploiting enterprise tech zero days more and more, Google warns

Several security issues were fixed in curl.

* bsc#1221237 * bsc#1221468 Cross-References: * CVE-2024-1441

* bsc#1220770 * bsc#1220771 Cross-References: * CVE-2024-26458

* bsc#1144060 * bsc#1176006 * bsc#1188307 * bsc#1203823 * bsc#1205502

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Street newspaper appears to have Big Issue with Qilin ransomware gang
Trezor’s Twitter account hijacked by cryptocurrency scammers via bogus Calendly invite
The easy road to pervasive DLP
Uncle Sam’s had it up to here with ‘unforgivable’ SQL injection flaws
Ransomware can mean life or death at hospitals, but DEF CON hackers have a plan

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

Several security issues were fixed in Thunderbird.

FreeBSD Foundation hands out Beacon gongs for safer software

PAM could be made to stop responding if it opened a specially crafted file.

UK elections are unaffected by China’s cyber-interference, says deputy PM

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

Row breaks out over true severity of two DNSSEC flaws
New Zealand to world: China attacked us, too!
US charges Chinese nationals with cyber-spying on pretty much everyone for Beijing

https://security-tracker.debian.org/tracker/DSA-5647-1

https://security-tracker.debian.org/tracker/DSA-5646-1

Over 170K users hit by poisoned Python package ruse
AceCryptor attacks surge in Europe – Week in security with Tony Anscombe

The second half of 2023 saw massive growth in AceCryptor-packed malware spreading in the wild, including courtesy of multiple spam campaigns where AceCryptor packed the Rescoms RAT

Notorious Nemesis Market zapped by video game-loving German police
Tech trade union confirms cyberattack behind IT, email outage
Puppet’s devops report plumbs the benefits of platform engineering