A sea of sensors will soon influence almost everything in your world The post CES 2022: More sensors than people appeared first on WeLiveSecurity
From social engineering to looking over your shoulder, here are some of the most common tricks that bad guys use to steal passwords The post 5 ways hackers steal passwords (and how to stop them) appeared first on WeLiveSecurity
Several security issues were fixed in WebKitGTK.
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in the kernel.
The container bci/openjdk was updated. The following patches have been included in this update:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
The container bci/minimal was updated. The following patches have been included in this update:
Each year, as online shopping ramps up in the weeks before the holidays, so do online scams targeting the elderly. This season – in many ways unprecedented – is no different in this regard. In fact, COVID-19, Zoom meetings, vaccination recommendations and travel warnings all provide ample and unique precedent for social engineering attacks. Not […]
security update
The following updated rpms for Oracle Linux 7 have been uploaded to the Unb= reakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
How can you help your kids navigate Instagram safely? Here are a few tips to help you protect their privacy on the app. The post Instagram and teens: A quick guide for parents to keep their kids safe appeared first on WeLiveSecurity
Several security issues were fixed in Django.
The container sles-15-sp3-chost-byos-v20220103 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20220103-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20220103-gen2 was updated. The following patches have been included in this update:
Be alert, be proactive and break these 10 bad habits to improve your cyber-hygiene in 2022 The post Breaking the habit: Top 10 bad cybersecurity habits to shed in 2022 appeared first on WeLiveSecurity
Two vulnerabilities have been discovered in the Apache HTTP server: CVE-2021-44224
An update for the idm:DL1 module is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for samba is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for telnet is now available for Red Hat Enterprise Linux 7.6 Advanced Update Support, Red Hat Enterprise Linux 7.6 Telco Extended Update Support, and Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions.
xorg-x11-server: SProcRenderCompositeGlyphs out-of-bounds access (CVE-2021-4008) * xorg-x11-server: SProcXFixesCreatePointerBarrier out-of-bounds access (CVE-2021-4009) * xorg-x11-server: SProcScreenSaverSuspend out-of-bounds access (CVE-2021-4010) * xorg-x11-server: SwapCreateRegister out-of-bounds access (CVE-2021-4011) For more details about the security issue(s), including the impact, [More…]
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code, spoofing, information disclosure, downgrade attacks on SMTP STARTTLS connections or misleading display of OpenPGP/MIME signatures.
security update
An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for grafana is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for grafana is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Fix missing TLS certificate verification. (CVE-2021-39359) References: – https://bugs.mageia.org/show_bug.cgi?id=29834 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/HRPPP47WRCAPAEJGRMEKYYJZBQCYXTLQ/
Several wireshark vulnerabilities have been fixed. See the release notes for details. References: – https://bugs.mageia.org/show_bug.cgi?id=29832
Fix shell expansion via crafted pathname in the ImageMagick convert fallback References: – https://bugs.mageia.org/show_bug.cgi?id=29829
Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code, spoofing, information disclosure, downgrade attacks on SMTP STARTTLS connections or misleading display of OpenPGP/MIME signatures.
Security fix for CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011
The 5..15..12 stable kernel update contains a number of important fixes across the tree.
security update
The 5..15..12 stable kernel update contains a number of important fixes across the tree.
https://lib.openmpt.org/libopenmpt/2021/12/23/security- update-0.5.15-releases-0.4.27-0.3.36/
As we usher in the New Year, let’s take a look at some statistics that will help you stay up-to-date on recent cybersecurity trends The post 22 cybersecurity statistics to know for 2022 appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Patch for CVE-2021-39359. —- Update to 5.2.10
xwayland 21.1.4 Security fix for CVE-2021-4008, CVE-2021-4009, CVE-2021-4010, CVE-2021-4011 Store EGLcontext to avoid superfluous eglMakeCurrent() calls Prefer EGLStream with NVIDIA proprietary driver if both GBM and EGLstream are available
stack-based buffer overflow in handle_request() in DHT.c (CVE-2021-44847) References: – https://bugs.mageia.org/show_bug.cgi?id=29821 – https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/S7EBS3NIRYJ7V3PTNINP3PJSVUHGZTGA/
HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818) References: – https://bugs.mageia.org/show_bug.cgi?id=29817
e2guardian did not validate TLS hostnames (CVE-2021-44273) References: – https://bugs.mageia.org/show_bug.cgi?id=29811 – https://www.openwall.com/lists/oss-security/2021/12/23/2
ReDoS vulnerability in html_preprocess_rules in ebooks/conversion/preprocess.py References: – https://bugs.mageia.org/show_bug.cgi?id=29803
HTTP Request Smuggling due to spaces in headers. The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). (CVE-2021-22959) HTTP Request Smuggling when parsing the body. The parse ignores chunk extensions when parsing the body of chunked requests. This leads […]
Authenticate active help requests to the local help web server (CVE-2020-27225) References: – https://bugs.mageia.org/show_bug.cgi?id=29048
security update
Two vulnerabilities were fixed in the reSIProcate SIP stack. CVE-2017-11521
An update that fixes 33 vulnerabilities is now available.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
New wpa_supplicant packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
As we close out another year like no other, let’s look back at some of the most notable cybersecurity stories that shaped 2021 The post 2021 in review: The biggest cybersecurity stories of the year appeared first on WeLiveSecurity
A couple of vulnerabilites were found in paramiko, an implementation of SSHv2 protocol in Python. CVE-2018-1000805
An XSS vulnerability was discovered in noVNC, a HTML5 VNC client, in which the remote VNC server could inject arbitrary HTML into the noVNC web page via the messages propagated to the status field, such as the VNC server name.
A cookie prefix spoofing vulnerability in CGI::Cookie.parse and a regular expression denial of service vulnerability (ReDoS) on date parsing methods were discovered in src:ruby2.1, the Ruby interpreter.
Several vulnerabilities were discovered in djvulibre, a library and set of tools to handle documents in the DjVu format. An attacker could crash document viewers and possibly execute arbitrary code through
The python-rdflib-tools package (tools for converting to and from RDF) had wrappers that could load Python modules from the current working directory, allowing code injection.
An update that contains security fixes can now be installed.
