The container trento/trento-db was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
The US military knows it needs to speed up technology adoption through optimization, something at the heart of Silicon Valley culture The post US military vs. Silicon Valley – a cultural divide appeared first on WeLiveSecurity
This is a maintenance release of OpenVPN 2.5 with a security fix when used in server mode ([CVE-2022-0547](https://community.openvpn.net/openvpn/wiki/CVE-2022-0547)). The other changes are available in [Changes.rst](https://github.com/OpenVPN/openvpn/blob/release/2.5/Changes.rst).
Update to 91.7.0
Update to version 1.5.5. This includes a fix for a denial-of-service vulnerability ([RUSTSEC-2022-0013](https://rustsec.org/advisories/RUSTSEC-2022-0013.html) / [CVE-2022-24713](https://cve.mitre.org/cgi- bin/cvename.cgi?name=CVE-2022-24713)).
Fix potential DoS in pesign daemon
An update that fixes one vulnerability, contains one feature is now available.
An update that fixes one vulnerability, contains one feature is now available.
security update
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Update to 3.24: fix CVE-2022-26495, CVE-2022-26496
Update to 3.24: fix CVE-2022-26495, CVE-2022-26496
An update that contains security fixes and contains one feature can now be installed.
An update that solves 13 vulnerabilities and has three fixes is now available.
An update that contains security fixes and contains one feature can now be installed.
An overview of some of the most popular open-source tools for threat intelligence and threat hunting The post A first look at threat intelligence and threat hunting tools appeared first on WeLiveSecurity
OpenSSL could be made to stop responding if it opened a specially crafted certificate.
Tavis Ormandy discovered that the BN_mod_sqrt() function of OpenSSL could be tricked into an infinite loop. This could result in denial of service via malformed certificates.
rsh would allow unintended modification of target directory permissions.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
This is the third time in as many weeks that ESET researchers have spotted previously unknown data wiping malware taking aim at Ukrainian organizations The post CaddyWiper: New wiper malware discovered in Ukraine appeared first on WeLiveSecurity
security update
security update
security update
Command injection in ruby bundler. (CVE-2021-43809) References: – https://bugs.mageia.org/show_bug.cgi?id=30162 – https://blog.sonarsource.com/securing-developer-tools-package-managers
This kernel-linus update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially
This kernel update is based on upstream 5.15.28 and fixes at least the following security issues: Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially
The chromium-browser-stable package has been updated to the 99.0.4844.51 version that fixes multiples security vulnerabilities. References: – https://bugs.mageia.org/show_bug.cgi?id=29988
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
A flaw was discovered in the way HAProxy, a fast and reliable load balancing reverse proxy, processes HTTP responses containing the “Set-Cookie2” header, which can result in an unbounded loop, causing a denial of service.
The update for expat released as DSA 5085-1 introduced regressions for applications using URI characters (‘:’ in particular) for a namespace separator (while the HTML API docs of function XML_ParserCreateNS have been advising against their use). Updated expat packages are now
Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer library, allows to inject values into a PostgreSQL connection string. Depending on how the library is used this flaw can result in authentication bypass, reveal a server IP address or have other
Two vulnerabilities were discovered in the server for the Network Block Device (NBD), which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed
The container sles-15-sp3-chost-byos-v20220310 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20220310-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20220310-gen2 was updated. The following patches have been included in this update:
Null pointer dereference in MD_UPDATE. (CVE-2021-4209) References: – https://bugs.mageia.org/show_bug.cgi?id=30112 – https://lists.suse.com/pipermail/sle-security-updates/2022-March/010333.html
security update
security update
Multiple security vulnerabilities have been discovered in vim, an enhanced vi editor. Buffer overflows, out-of-bounds reads and Null pointer dereferences may lead to a denial of service (application crash) or other unspecified impact.
