Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. (CVE-2022-0561)
An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of the server is neither checked nor displayed. As a result, a user connects to the server without the ability to verify its authenticity. (CVE-2021-36370)
An update that fixes one vulnerability is now available.
An update that fixes 15 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
security update
Multiple security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure.
Press play to hear Aryeh Goretsky, Jean-Ian Boutin and Robert Lipovsky discuss how recent malware attacks in Ukraine tie into years of cyberattacks against the country The post ESET Research Podcast: Ukraine’s past and present cyberwar appeared first on WeLiveSecurity
An update that solves two vulnerabilities, contains two features and has two fixes is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 5 vulnerabilities is now available.
Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences–>Advanced–>HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in […]
Update to 2.34.6: * Fix accessibility not working when the Bubblewrap sandbox is enabled. * Fix rendering of scrollbars when overlay scrollbars are disabled. * Fix several crashes and rendering issues. * Security fixes: CVE-2022-22620 —- Update to 2.34.5: * Improve VP8 codec selection when using GStreamer 1.20. * Fix connecting to the accessiblity bus […]
An update that fixes 12 vulnerabilities is now available.
– Upstream update to 2.4.0 – Fixed CVE-2021-42072 (RHBZ 2022094) – BuildDepends added: gmock-devel, gulrak-filesystem-devel – Address the issue from pull request #1, thanks aekoroglu.
– Upstream update to 2.4.0 – Fixed CVE-2021-42072 (RHBZ 2022094) – BuildDepends added: gmock-devel, gulrak-filesystem-devel – Address the issue from pull request #1, thanks aekoroglu.
Security fix for CVE-2021-4115
containerd would allow unintended access to files over the network.
Several security issues were fixed in PHP.
HAProxy could be made to stop responding if it received specially crafted network traffic.
security update
Security update for php. See changelog for details. References: – https://bugs.mageia.org/show_bug.cgi?id=30056 – https://www.php.net/ChangeLog-8.php#8.0.16
OpenShift Logging bug fix and security update (5.2.8) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for cyrus-sasl is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Update to 6.0.2
If you look back at the long arc of history, it’s clear that one of the most crucial drivers of real progress in society is innovation The post Innovation and the Roots of Progress appeared first on WeLiveSecurity
An update that fixes one vulnerability, contains one feature is now available.
ESET researchers uncover a new wiper that attacks Ukrainian organizations and a worm component that spreads HermeticWiper in local networks The post IsaacWiper and HermeticWizard: New wiper and worm targeting Ukraine appeared first on WeLiveSecurity
Several security issues were fixed in GNU C Library.
An update for kernel is now available for Red Hat Enterprise Linux 7.7 Advanced Update Support, Red Hat Enterprise Linux 7.7 Telco Extended Update Support, and Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions.
An update is now available for Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
OpenShift Logging bug fix and security update (5.3.5) Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for rh-maven36-httpcomponents-client is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Update to 2.53.11 Default version of Firefox for the User-Agent string has now been changed to 68.0 . This should provide better compatibility with modern sites. The value can be changed in Preferences–>Advanced–>HTTP Networking . Besides that, an alternate site-specific override machanism is now activated. (The idea comes from Waterfox-Classic project). The file ua-update.json in […]
Looking to help people in Ukraine? Donate wisely – do your research first so you give without getting scammed The post Beware of charity scams exploiting war in Ukraine appeared first on WeLiveSecurity
As the conflict in Ukraine heightens the risk of cyberattacks globally, what can organizations do to improve their resiliency? The post #ShieldsUp – Now is the time to double‑check cybersecurity processes and operations appeared first on WeLiveSecurity
The container trento/trento-db was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20220222-gen2 was updated. The following patches have been included in this update:
Several security issues were fixed in QEMU.
Several security issues were fixed in WebKitGTK.
Several security issues were fixed in MariaDB.
policykit-1 could be made to crash if it received specially crafted data.
The 5.16.11 stable kernel update contains a number of important fixes across the tree.
One issue have been discovered in ujson: ultra fast JSON encoder and decoder for Python. CVE-2021-45958
