Menu

Category Archives: Security

Articles about security

Mozilla fixes $100,000 Firefox zero-days following two-day hackathon
GoFetch security exploit can’t be disabled on M1 and M2 Apple chips

Stack-based buffer overflow has been fixed in gross, a server for greylisting emails. For Debian 10 buster, this problem has been fixed in version

QPDF could be made to crash or run programs if it opened a specially crafted file.

Net::CIDR::Lite could allow unintended access to network services.

It was discovered that there was a command-line injection issue in the FreeIPA identity, authentication and audit framework. A specially crafted HTTP request could have lead to a Denial of Service (DoS) attack and/or data exposure.

Insights Advisor for OpenShift – How to react to Advisor recommendations
Charting the Course of Cybersecurity Education for Linux Admins
Ransomware: lessons all companies can learn from the British Library attack
Time to examine the anatomy of the British Library ransomware nightmare
10 cloud development gotchas to watch out for
That Asian meal you eat on holidays could launder money for North Korea

Several security issues were fixed in Firefox.

Microsoft confirms memory leak in March Windows Server security update

New upstream version (124.0.1)

https://security-tracker.debian.org/tracker/DSA-5645-1

Some 300,000 IPs vulnerable to this Loop DoS attack

Multiple security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in cross-site scripting, SQL injection, or command injection.

Vans claims cyber crooks didn’t run off with its customers’ financial info

Buffer Overflow vulnerability in FreeImage_AllocateBitmap. (CVE-2023-47995) Infinite loop exits in Load in PluginTIFF.cpp. (CVE-2023-47997) References:

The updated package fixes security vulnerabilities: pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. (CVE-2023-30570) An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA

Patch CVE-2023-4256 and CVE-2023-43279

Updates google.golang.org/protobuf to v1.33.0 to resolve CVE-2024-24786. Kubernetes is now built with go 1.21.8.

Security fix for CVE-2024-22871 Update to upstream release 1.11.2

Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or leaks of encrypted email subjects.

Russia’s Cozy Bear caught phishing German politicos with phony dinner invites

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could […]

Update to version 2.13.1 Fix CVE-2024-28054

update to xen-4.18.1 rebase xen.gcc12.fixes.patch remove patches now included or superceded upstream x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]

Updated to 124.0 Updated to latest upstream (123.0.1)

Added upstream patch to fix out-of-bounds access due to multiple backspaces to address incomplete fix for CVE-2022-38223 (#2222775, #2222780, #2255207)

Chinese snoops use F5, ConnectWise bugs to sell access into top US, UK networks

https://security-tracker.debian.org/tracker/DSA-5644-1

Java 22 brings security enhancements
3 million doors open to uninvited guests in keycard exploit
Hardware-level Apple Silicon vulnerability can leak cryptographic keys
NVD slowdown leaves thousands of vulnerabilities without analysis data

Graphviz could be made to crash if it opened a specially crafted config6a file.

* bsc#1221323 Cross-References: * CVE-2023-22655 * CVE-2023-28746

* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773

* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773

* bsc#1219465 Cross-References: * CVE-2023-3966

* bsc#1050549 * bsc#1186484 * bsc#1200599 * bsc#1212514 * bsc#1213456

Truck-to-truck worm could infect – and disrupt – entire US commercial fleet
FBI v the bots: Feds urge denial-of-service defense after critical infrastructure alert
Microsoft faces bipartisan criticism for alleged censorship on Bing in China
Congress votes unanimously to ban brokers selling American data to enemies
AI used extensively for security but not for coding, JFrog survey finds
Yacht dealer to the stars attacked by Rhysida ransomware gang
UK council won’t say whether two-week ‘cyber incident’ impacted resident data
Exposed: Chinese smartphone farms that run thousands of barebones mobes to do crime
It’s 2024 and North Korea’s Kimsuky gang is exploiting Windows Help files

A security flaw was found on rubygem-yard that documents generated by yard may be vulnerable to XSS attack. This issue is now assigned as CVE-2024-27285 . This new rpm is supposed to fix this issue.

Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

Security fix for CVE-2024-1048

Update to 115.9.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-14/ https://www.thunderbird.net/en-US/thunderbird/115.9.0/releasenotes/

Update to 4.14 for CVE-2024-2357, v6 SAN name and TFC padding fix for AEAD

Smashing Security podcast #364: Bing pop-up wars, and the British Library ransomware scandal

https://security-tracker.debian.org/tracker/DSA-5643-1

Several security issues were fixed in the Linux kernel.

https://security-tracker.debian.org/tracker/DSA-5641-1

It’s tax season, and scammers are a step ahead of filers, Microsoft says
US task force aims to plug security leaks in water sector
GitHub previews AI-powered code scanning autofix
AI used extensively for security but not coding, JFrog survey finds
A prescription for privacy protection: Exercise caution when using a mobile health app

Given the unhealthy data-collection habits of some mHealth apps, you’re well advised to tread carefully when choosing with whom you share some of your most sensitive data

London Clinic probes claim staffer tried to peek at Princess Kate’s records
Fraudsters are posing as the FTC to scam consumers
Serial extortionist of medical facilities pleads guilty to cybercrime charges
Gotta Hack ‘Em All: Pokémon passwords reset after attack
Stalkerware usage surging, despite data privacy concerns
Introducing OpenShift Service Mesh 2.5
Red Hat Advanced Cluster Security 4.4: What’s included
Five Eyes tell critical infra orgs: take these actions now to protect against China’s Volt Typhoon

A memory leak was found in imagemagick a popular software suite for displaying, creating, converting, modifying, and editing raster images. For Debian 10 buster, this problem has been fixed in version

How to deploy software to Linux-based IoT devices at scale

Several security issues were fixed in Firefox.

The updated packages fix security vulnerabilities: Heap buffer overflow in sqlite. (CVE-2023-2137) A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler.

Updated to 124.0

Updated to 124.0

Australian techie jailed for accessing museum’s accounting system and buying himself stuff

New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.

Red Hat Quay 3.11: Smarter permissions, lifecycle, and AWS integration

https://security-tracker.debian.org/tracker/DSA-5642-1

https://security-tracker.debian.org/tracker/DSA-5626-2

Beijing-backed cyberspies attacked 70+ orgs across 23 countries
Crypto scams more costly to the US than ransomware, Feds say
Crypto wallet providers urged to rethink security as criminals drain them of millions

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Atos says Airbus flew off, no longer interested in infosec and big data biz

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Update to 2.6.1, backport fix for CVE-2024-28757.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Add downstream fixes for CVE-2023-47995 and CVE-2023-47997.

Don’t be like these 900+ websites and expose millions of passwords via Firebase
Fujitsu reveals malware installed on internal systems, risk of customer data spill
More than 133,000 Fortinet appliances still vulnerable to month-old critical bug
Cyber baddies leak 70M+ files online, claim they’re from AT&T
C++ creator rebuts White House warning