Menu

Category Archives: Security

Articles about security

xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]

xorg-x11-server: buffer overflow in _GetCountedString() in xkb/xkb.c (CVE-2022-3550) * xorg-x11-server: memory leak in ProcXkbGetKbdByName() in xkb/xkb.c (CVE-2022-3551) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 xorg-x11-server-Xephyr-1.20.4-19.el7_9.x86_64.rpm xorg- [More…]

An update that fixes one vulnerability is now available.

Swiss bankers warn: Three quarters of retail Bitcoin investors are in the red
Boosting telcos’ 5G cyber resilience
It’s time. Delete your Twitter DMs
Eggheads show how network flaw could lead to NASA crew pod loss. Key word: Could
Shocker: EV charging infrastructure is seriously insecure
Healthcare sector warned of Venus ransomware attacks
Securing the mail

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.

Several vulnerabilities were discovered in WordPress, a web blogging tool. They allowed remote attackers to perform SQL injection, create open redirects, bypass authorization access, or perform Cross-Site Request Forgery (CSRF) or Cross-Site Scripting (XSS) attacks.

Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.

Several bugs were discovered in PostgreSQL, a relational database server system. This new LTS minor version update fixes over 25 bugs that were reported in the last several months. The complete and detailed list of issues could be found at: https://www.postgresql.org/docs/release/11.18.

An update that fixes two vulnerabilities is now available.

An update that fixes one vulnerability is now available.

Country that still uses fax machines wants to lead the world on data standards at G7
Data sovereignty and compliance need help
Russia-based Pushwoosh tricks US Army and others into running its code – for a while
GitHub sets up private vulnerability reports for public repos to avoid ‘naming and shaming’

security update

security update

Another crypto shocker: Major player actually corrects $400m mistake instead of cratering
Complete Guide to Ethical Hacking on Linux
ESET APT Activity Report T2 2022

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in T2 2022 The post ESET APT Activity Report T2 2022 appeared first on WeLiveSecurity

An update that fixes 6 vulnerabilities is now available.

An update for libksba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for device-mapper-multipath is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Australia to ‘stand up and punch back’ against cyber crims

An issue was discovered in Dropbear, a relatively small SSH server and client. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it was possible for an SSH server to change the login process in its favor. This attack can bypass

There were a couple of secuity issues found in sysstat, system performance tools for Linux, which are as follows: CVE-2019-16167

Update to 4.19.0, fixes CVE-2021-46848.

libiberty: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c (CVE-2021-3826) binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcopy.c via a crafted file (CVE-2022-38533)

libiberty: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c (CVE-2021-3826) binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcopy.c via a crafted file (CVE-2022-38533)

LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-3599) LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in

LibTIFF 4.4.0 has an out-of-bounds read in writeSingleSection in tools/tiffcrop.c:7345, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-3599) LibTIFF 4.4.0 has an out-of-bounds write in _TIFFmemset in

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. (CVE-2022-44638) References:

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y. (CVE-2022-44638) References:

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

Security challenges facing SMBs – Week in security with Tony Anscombe

New ESET report shows how ever-growing threats impact SMB sentiment and why many SMBs are underprepared to defend against attacks The post Security challenges facing SMBs – Week in security with Tony Anscombe appeared first on WeLiveSecurity

FIFA World Cup 2022 scams: Beware of fake lotteries, ticket fraud and other cons

When in doubt, kick it out, plus other tips for hardening your cyber-defenses against World Cup-themed phishing and other scams The post FIFA World Cup 2022 scams: Beware of fake lotteries, ticket fraud and other cons appeared first on WeLiveSecurity

LockBit suspect cuffed after ransomware forces emergency services to use pen and paper

Maddie Stone reported a heap-based buffer overflow flaw in pixman, a pixel-manipulation library for X and cairo, which could result in denial of service or potentially the execution of arbitrary code.

The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

The container bci/golang was updated. The following patches have been included in this update:

security update

security update

World Cup apps pose a data security and privacy nightmare
Toward the cutting edge: SMBs contemplating enterprise security

Survey finds SMBs, weary of security failures, curious about detection and response The post Toward the cutting edge: SMBs contemplating enterprise security appeared first on WeLiveSecurity

Alleged LockBit ransomware operator arrested in Canada
NSA urges orgs to use memory-safe programming languages
What observability means for cloud operations

The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-squid was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:

The container suse/sle15 was updated. The following patches have been included in this update:

Europe calls for joint cyber defense to ward off Russia
Australia blames Russia for harboring health insurance hackers
Instagram star gets 11 years for $300m email scam plot
Husband and wife nuclear warship ‘spy’ team get 20 years each
10 common security mistakes and how to avoid them

Do you make these security mistakes and put yourself at greater risk for successful attacks? The post 10 common security mistakes and how to avoid them appeared first on WeLiveSecurity

Twitter Chief Information Security Officer flies the coop
Update your Lenovo laptop’s firmware now! Flaws could help malware survive a hard disk wipe

A vulnerability has been found in lesspipe which could result in arbitrary code execution.

A vulnerability has been found in lesspipe which could result in arbitrary code execution.

This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032

This is the October 2022 monthly update for .NET 6. It updates the SDK to 6.0.110 and the Runtime to 6.0.10. This update includes a fix for CVE 2022-41032

– url: use IDN decoded names for HSTS checks (CVE-2022-42916) – http_proxy: restore the protocol pointer on error (CVE-2022-42915) – netrc: replace fgets with Curl_get_line (CVE-2022-35260) – fix POST following PUT confusion (CVE-2022-32221)

– url: use IDN decoded names for HSTS checks (CVE-2022-42916) – http_proxy: restore the protocol pointer on error (CVE-2022-42915) – netrc: replace fgets with Curl_get_line (CVE-2022-35260) – fix POST following PUT confusion (CVE-2022-32221)

A roadmap to better cyber security training
Windows breaks under upgraded IceXLoader malware
Smashing Security podcast #297: Mastodon 101, and the Hushpuppi saga
Wells Fargo, Zelle slammed by Liz Warren over rampant online banking fraud

security update

security update

Having refused to pay ransom, health insurer Medibank sees customer data posted online by hackers
Authoritative Guide on Linux Disk Encryption
OpenSSL: Email address buffer overflow security flaws

Several security issues were fixed in OpenJDK.

Zstandard could be made to expose sensitive information

Zstandard could be made to expose sensitive information

An update for kpatch-patch is now available for Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for linux-firmware is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

An update for linux-firmware is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.

VMware warns of three critical holes in remote-control tool
Microsoft squashes six security bugs already exploited in the wild
Swiss Re wants government bail out as cybercrime insurance costs spike
Robin Banks crooks back at the table with fresh phish from Russia
Experian, T-Mobile US settle data spills for mere $16m
Hacking baby monitors can be child’s play: Here’s how to stay safe

Make sure that the device that’s supposed to help you keep tabs on your little one isn’t itself a privacy and security risk The post Hacking baby monitors can be child’s play: Here’s how to stay safe appeared first on WeLiveSecurity

Mastodon: What you need to know for your security and privacy
Cloud architects are afraid of automation

For Debian 10 buster, these problems have been fixed in version 2:8.1.0875-5+deb10u3. We recommend that you upgrade your vim packages.

An update that fixes 7 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 7 vulnerabilities is now available.