createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
createrepo_c 0.16.1 – Update to 0.16.1 – Add the section number to the manual pages – Parse xml snippet in smaller parts (RhBug:1859689) – Add module metadata support to createrepo_c (RhBug:1795936) librepo 1.12.1 – Update to 1.12.1 – Validate path read from repomd.xml (RhBug:1868639) libdnf 0.54.2 – Update to 0.54.2 – history: Fix dnf history […]
security update
An update that solves four vulnerabilities and has 9 fixes is now available.
New version 3.2.7 Security fix for CVE-2020-25862, CVE-2020-25863, CVE-2020-25866
New version 3.2.7 Security fix for CVE-2020-25862, CVE-2020-25863, CVE-2020-25866
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that contains security fixes can now be installed.
Reading Time: ~ 2 min. Backdoor Found in Children’s Smartwatch Researchers have discovered that the X4, made by Norwegian smartwatch seller Xplora, contains a backdoor that could allow for information to be stolen. The X4 watch is designed specifically for children with a limited number of capabilities, mostly for children’s security. The backdoor, however, could […]
The videoconferencing platform is making the feature available to users of both free and paid tiers The post Zoom to begin rolling out end‑to‑end encryption appeared first on WeLiveSecurity
An update that fixes two vulnerabilities is now available.
An issue has been found in PowerDNS Authoritative Server allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up […]
NULL Pointer Dereference that leads to arbitrary code execution’¯in the context of the current user. (CVE-2020-9746) References: – https://bugs.mageia.org/show_bug.cgi?id=27432
The TCP dissector could crash (CVE-2020-25862). The MIME Multipart dissector could crash (CVE-2020-25863). The BLIP dissector could crash (CVE-2020-25866).
A vulnerability was discovered where an attacker can cause an XSS attack through the transformation feature. If an attacker sends a crafted link to the victim with the malicious JavaScript, when the victim clicks on the link, the JavaScript will run and complete the instructions made by the attacker. (CVE-2020-26934)
CVE-2020-26116: HTTP request method CRLF injection in httplib
security update
Priyank Nigam discovered that HttpComponents Client, a Java HTTP agent implementation, could misinterpret malformed authority component in a request URI and pick the wrong target host for request execution.
Some footage has already appeared on adult sites, with cybercriminals offering lifetime access to the entire loot for US$150 The post 50,000 home cameras reportedly hacked, footage posted online appeared first on WeLiveSecurity
An update that contains security fixes can now be installed.
An update that contains security fixes can now be installed.
Update to 3.17.7 — https://www.claws-mail.org/news.php
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in Vim.
The package chromium before version 86.0.4240.75-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, information disclosure and insufficient validation.
Red Hat Ansible Tower 3.6 runner release (CVE-2019-18874) 2. Description: * Updated python-psutil version to 5.6.6 inside ansible-runner container (CVE-2019-18874)
Bad actors have accessed US elections support systems, although there’s no evidence to suggest that election data has been compromised, say FBI and CISA The post Attackers chain Windows, VPN flaws to target US government agencies appeared first on WeLiveSecurity
Throughout its monitoring, ESET analyzed thousands of malicious samples every month to help this effort The post ESET takes part in global operation to disrupt Trickbot appeared first on WeLiveSecurity
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update is now available for Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
