The Qualys Research Labs discovered a heap-based buffer overflow vulnerability in sudo, a program designed to provide limited super user privileges to specific users. Any local user (sudoers and non-sudoers) can exploit this flaw for root privilege escalation.
XStream: remote code execution due to insecure XML deserialization when relying on blocklists (CVE-2020-26217) SL7 noarch xstream-1.3.1-12.el7_9.noarch.rpm xstream-javadoc-1.3.1-12.el7_9.noarch.rpm – Scientific Linux Development Team
An update that fixes 26 vulnerabilities is now available.
An update for cryptsetup is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for gnome-settings-daemon is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for net-snmp is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.
Skyrocketing Bitcoin prices prompt resurgence in mining malware As the price of the cryptocurrency Bitcoin pushes record highs, there’s been a corresponding resurgence in cryptomining malware. Illicit miners had slipped off the radar as Bitcoin’s value plummeted in recent years, but now authors are hoping to profit off the latest price increase. Researchers have identified […]
security update
An update that contains security fixes can now be installed.
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest() (CVE-2020-26137). References:
It was discovered that pip did not properly sanitize the filename during pip install. A remote attacker could possible use this issue to read and write arbitrary files on the host filesystem as root, resulting in a directory traversal attack (CVE-2019-20916).
The update for gst-plugins-bad1.0 released as DSA 4833-1 choosed a package version incompatible with binNMUs and prevented upgrades to the fixed packages. Updated gst-plugins-bad1.0 packages are now available to correct this issue.
Several vulnerabilities were discovered in salt, a powerful remote execution manager. The flaws could result in authentication bypass and invocation of Salt SSH, creation of certificates with weak file permissions via the TLS execution module or shell injections with the
An update that fixes 35 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Security fixes: – fix buffer overrun in EUC-KR conversion module [bz #2497] (CVE-2019-25013) – arm: CVE-2020-6096: Fix multiarch memcpy for negative length [BZ #25620] – arm: CVE-2020-6096: fix memcpy and memmove for negative length [BZ #25620] – iconv: Fix incorrect UCS4 inner loop bounds [BZ #26923] (CVE-2020-29562)
Rebase SDDM to 0.19.0
security update
security update
security update
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
The container suse/sle15 was updated. The following patches have been included in this update:
Update to 87.0.4280.141. Fixes: CVE-2021-21106 CVE-2021-21107 CVE-2021-21108 CVE-2021-21109 CVE-2021-21110 CVE-2021-21111 CVE-2021-21112 CVE-2021-21113 CVE-2020-16043 CVE-2021-21114 CVE-2020-15995 CVE-2021-21115 CVE-2021-21116
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling (CVE-2020-10719). References:
A heap-based buffer overflow vulnerability was found in the blosc library. Depending on how the library is used, if there is a lack of space to write compressed data, an attacker might exploit this flaw to crash the program or potentially execute arbitrary code (CVE-2020-29367).
Another in our occasional series demystifying Latin American banking trojans The post Vadokrist: A wolf in sheep’s clothing appeared first on WeLiveSecurity
An update that fixes 13 vulnerabilities is now available.
An update that fixes 13 vulnerabilities is now available.
A vulnerability in KDE Connect could lead to a Denial of Service condition.
Multiple vulnerabilities have been found in VirtualBox, the worst of which could result in privilege escalation.
Multiple vulnerabilities have been found in Mozilla Thunderbird, the worst of which could result in the arbitrary execution of code.
Multiple vulnerabilities have been found in Chromium and Google Chrome, the worst of which could result in the arbitrary execution of code.
An update that fixes one vulnerability is now available.
Webroot BrightCloud® Threat Intelligence relies on the collective power of millions of devices working together. But what sometimes gets lost is the actual humans behind bringing this technology to market. In this Employee Spotlight, we talk to Account Development Executive, Jordan Gray, who works with C-level executives to integrate threat intelligence solutions within their environments. […]
Security flaws in a widely used DNS software package could allow attackers to send users to malicious websites or to remotely hijack their devices The post DNSpooq bugs expose millions of devices to DNS cache poisoning appeared first on WeLiveSecurity
Backport fixes for CVE-2020-35653, CVE-2020-35654, CVE-2020-35655.
Backport fixes for CVE-2020-35653, CVE-2020-35654, CVE-2020-35655.
Update to security fix 1.6 version. Fixes CVE-2019-17455
rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups).
Rebase to 1.9.5p1 – updated sudo url Resolves: rhbz#1902758 – enabled python plugin as a subpackage Resolves: rhbz#1909299 – fixed double free in sss_to_sudoers Resolves: rhbz#1885874 – fixed CVE-2021-23239 sudo: possible directory existence test due to race condition in sudoedit Resolves: rhbz#1915055 – fixed CVE-2021-23240 sudo: symbolic link attack in SELinux-
Red Hat OpenShift Container Platform release 3.11.374 is now available with updates to packages and images that fix several bugs. This release also includes a security update for Red Hat OpenShift Container Platform 3.11.
An update that fixes 7 vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
