Several security issues were fixed in OpenEXR.
Several security issues were fixed in OpenEXR.
Introduction It’s important for a business to be prepared with an exercised business continuity and disaster recovery (BC/DR) plan plan before its hit with ransomware so that it can resume operations as quickly as possible. Key steps and solutions should be followed to prepare and respond to cyber threats or attacks against your organization. It […]
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in Apache HTTP Server.
Several security issues were fixed in Dovecot.
What does the increasingly fuzzy line between traditional cybercrime and attacks attributed to state-backed groups mean for the future of the threat landscape? The post State‑sponsored or financially motivated: Is there any difference anymore? appeared first on WeLiveSecurity
Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613
Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613
Update radare2 to 5.3.1 Also fixes CVS-2021-32613 —- bump to radare2 5.3.0 fixes CVE-2021-32613
Backport fix for CVE-2021-3589 and a heap buffer overflow.
Backport fix for CVE-2021-3589 and a heap buffer overflow.
security update
security update
It was discovered that the previous upload of the package prosody versioned 0.9.12-2+deb9u3 introduced a regression in the mod_auth_internal_hashed module. Big thanks to Andre Bianchi for the reporting an issue and for testing the update.
Update to 1.6.15 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive.
CVE-2021-3560 mitigation
Backport fix for CVE-2021-33503.
2.0.11 Security If an authenticated client connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur. Affects versions 1.6 to 2.0.10 inclusive. Broker Fix possible crash having just upgraded from 1.6 if per_listener_settings true is set, and a SIGHUP is sent to the broker before a client has […]
This updates nettle to the latest upstream release 3.7.3, which contains security fix for RSA decryption: https://lists.lysator.liu.se/pipermail/nettle- bugs/2021/009545.html
Most medical and fitness apps in Google Play have tracking capabilities enabled and their data collection practices aren’t transparent The post Most health apps engage in unhealthy data‑harvesting habits appeared first on WeLiveSecurity
The package connman before version 1.40-1 is vulnerable to arbitrary code execution.
The package grub before version 2:2.06-1 is vulnerable to multiple issues including access restriction bypass and arbitrary code execution.
The package go before version 2:1.16.5-1 is vulnerable to multiple issues including insufficient validation, url request injection and denial of service.
Multiple security vulnerabilities were discovered in Tor, a connection-based low-latency anonymous communication system, which could result in denial of service or spoofing.
By failing to prepare you are preparing to fail – here’s what you can do today to minimize the impact of a potential ransomware attack in the future The post 5 essential things to do before ransomware strikes appeared first on WeLiveSecurity
Several security issues were fixed in GRUB 2.
An update that solves two vulnerabilities and has one errata is now available.
OSINT can be used by anyone, both for good and bad ends – here’s how defenders can use it to keep ahead of attackers The post OSINT 101: What is open source intelligence and how is it used? appeared first on WeLiveSecurity
Several security issues were fixed in libxml2.
The package python-django before version 3.2.4-1 is vulnerable to multiple issues including insufficient validation and directory traversal.
The package radare2 before version 5.3.1-1 is vulnerable to denial of service.
The package thefuck before version 3.31-1 is vulnerable to arbitrary file overwrite.
The package aspnet-runtime-3.1 before version 3.1.16.sdk116-1 is vulnerable to denial of service.
The package aspnet-runtime before version 5.0.7.sdk204-1 is vulnerable to denial of service.
security update
The fraudsters ran their campaigns from the cloud and used phishing and email forwarding rules to steal their targets’ financial information. The post Microsoft takes down large‑scale BEC operation appeared first on WeLiveSecurity
Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140
Upstream details at : https://access.redhat.com/errata/RHSA-2021:1512
Several security issues were fixed in BlueZ.
Several security issues were fixed in BlueZ.
An update for gupnp is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for openvswitch2.11 is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
