Reading Time: ~ 3 min. Mobile devices have become an indispensable part of our lives. By the time we’re teenagers, we’re already tethered to technology that lives in our pockets and connects us to a network far larger than we ever imagined possible. Because of the way we interact with our phones, it knows our […]
An update for xorg-x11-server is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for Red Hat Enterprise Linux 6, 7, and 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that fixes two vulnerabilities is now available.
An update that fixes 16 vulnerabilities is now available.
The updates come on the heels of news of attacks exploiting another zero-day in Chrome in tandem with a previously-unknown Windows flaw The post Google squashes two more Chrome bugs under active attacks appeared first on WeLiveSecurity
The security hole isn’t expected to be plugged until the forthcoming Patch Tuesday bundle of security fixes The post Google discloses Windows zero‑day bug exploited in the wild appeared first on WeLiveSecurity
python-cryptography could be made to expose sensitive information over the network.
Several security issues were fixed in AccountsService.
GDM could be made to create privileged users.
Vaisha Bernard discovered that Blueman, a graphical bluetooth manager performed insufficient validation on a D-Bus interface, which could result in denial of service or privilege escalation.
There were several vulnerabilites reported against wordpress, as follows: CVE-2020-28032
An update that solves one vulnerability and has two fixes is now available.
Several security issues were fixed in Samba.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
In junit4 the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system’s temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system. Both the SPICE client (spice-gtk) and server are affected by
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that solves 5 vulnerabilities and has one errata is now available.
An update that solves 8 vulnerabilities and has 5 fixes is now available.
security update
An update that fixes one vulnerability is now available.
An update that fixes 7 vulnerabilities is now available.
An update that solves 8 vulnerabilities and has 5 fixes is now available.
This update corrects a regression in some Xen virtual machine environments. For reference the original advisory text follows. Several vulnerabilities have been discovered in the Linux kernel that
An update that fixes 6 vulnerabilities is now available.
An update that solves one vulnerability and has three fixes is now available.
Better IoT security and data protection are long overdue. Will they go from an afterthought to everyone’s priority any time soon? The post IoT security: Are we finally turning the corner? appeared first on WeLiveSecurity
A vulnerability in the handling of normalization with modrdn was discovered in OpenLDAP, a free implementation of the Lightweight Directory Access Protocol. An unauthenticated remote attacker can use this flaw to cause a denial of service (slapd daemon crash) via a
An update that fixes two vulnerabilities is now available.
Several issues have been found in cimg, a powerful image processing library.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Several vulnerabilities have been discovered in the Linux kernel that may lead to the execution of arbitrary code, privilege escalation, denial of service or information leaks.
Reading Time: ~ 4 min. Nurul Mohd-Reza knows how to empathize with the customers she serves. Her work with marginalized groups as a college student, she says, helped prepare her for when the pandemic turned many of her customers’ businesses upside down last March. Here she discusses what she’s learned after just 10 months in […]
The patch for the critical flaw that allows malware to spread across machines without any user interaction was released months ago The post Over 100,000 machines remain vulnerable to SMBGhost exploitation appeared first on WeLiveSecurity
A view of the Q3 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report Q3 2020 appeared first on WeLiveSecurity
