This update applies a proposed fix for CVE-2018-12983.
This update applies a proposed fix for CVE-2018-12983.
Backport patches for CVE-2020-15306, CVE-2020-15305, CVE-2020-15304
Security fix
This update applies a proposed fix for CVE-2018-12983.
This update applies a proposed fix for CVE-2018-12983.
Reading Time: ~ 2 min. Ragnar locker Attacks Portuguese Energy Producer It was recently confirmed that Energias de Portugal (EDP), one of the largest energy producers in the world, has fallen victim to the Ragnar Locker ransomware variant. The original attack took place in April but was only discovered in May after nearly three weeks […]
While logins to music and video streaming services sell for less than ten dollars each, domain admin access is being offered for US$120,000 The post Billions of stolen passwords for sale on the dark web appeared first on WeLiveSecurity
ESET research gives a detailed picture of the operations of the Evilnum group and its toolkit deployed in attacks against carefully chosen targets in the fintech sector The post More evil: A deep look at Evilnum and its toolset appeared first on WeLiveSecurity
Updated mbedtls packages fix security vulnerabilities Fix a side channel vulnerability in modular exponentiation that could reveal an RSA private key used in a secure enclave.
Updated mediawiki packages fix security vulnerability: In MediaWiki before 1.31.8, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This
Advisory text to describe the update. Wrap lines at ~75 chars. A stack-based buffer over-read exists in FoFiTrueType::dumpString in fofi/FoFiTrueType.cc in Xpdf 4.01.01. It can, for example, be triggered by sending crafted TrueType data in a PDF document to the pdftops tool.
Updated ffmpeg packages fix security vulnerabilities: This update provides ffmpeg version 4.1.6, which fixes several security vulnerabilities and other bugs which were corrected upstream.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
security update
security update
A study paints a dim picture of router security, as none of the 127 devices tested was free of severe vulnerabilities The post Popular home routers plagued by critical security flaws appeared first on WeLiveSecurity
Several security issues were fixed in OpenSSL.
FIx CVE-2019-20454
This is a security fix release that includes fixes for the following local buffer overflow vulnerability. – CVE-2022-4044: Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it This update is recommended for all xrdp users.
Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs
Remmina 1.4.7 and FreeRDP 2.1.2 to fix many bugs and CVEs
Security update for CVE-2020-12695 (CallStranger)
security update
The vulnerability, which received the highest possible severity score, leaves thousands of devices at risk of being taken over by remote attackers. A patch is available. The post Attackers target critical flaw in popular networking gear appeared first on WeLiveSecurity
How (over)sharing your children’s triumphs and antics with the world may impact their immediate and distant future – and how to reduce the risks of ‘sharenting’ The post Raising children in the social media limelight? Pause before you post appeared first on WeLiveSecurity
Several security issues were fixed in Thunderbird.
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2824
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2827
Several vulnerabilities have been discovered in the interpreter for the Ruby language. CVE-2020-10663
An update that fixes four vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
security update
The Federal Reserve looks at ways to counter what is thought to be the fastest-growing type of financial crime in the country The post The Fed shares insight on how to combat synthetic identity fraud appeared first on WeLiveSecurity
Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 firefox-68.10.0-1.el6_10.x86_64.rpm [More…]
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Mozilla: Memory corruption due to missing sign-extension for ValueTags on ARM64 (CVE-2020-12417) * Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate tr [More…]
An update that fixes one vulnerability is now available.
An update that solves three vulnerabilities and has one errata is now available.
Reading Time: ~ 4 min. “What’s an evasive attack? At a very basic level, it’s exactly what it sounds like; it’s a cyberattack that’s designed to hide from you,” says Grayson Milbourne, Security Intelligence Director at Webroot, an OpenText company. Based on Grayson’s initial explanation, you can imagine that evasive tactics are pretty common throughout […]
security update
