An update that fixes two vulnerabilities is now available.
security update
The Federal Reserve looks at ways to counter what is thought to be the fastest-growing type of financial crime in the country The post The Fed shares insight on how to combat synthetic identity fraud appeared first on WeLiveSecurity
Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 firefox-68.10.0-1.el6_10.x86_64.rpm [More…]
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
Mozilla: Memory corruption due to missing sign-extension for ValueTags on ARM64 (CVE-2020-12417) * Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate tr [More…]
An update that fixes one vulnerability is now available.
An update that solves three vulnerabilities and has one errata is now available.
Reading Time: ~ 4 min. “What’s an evasive attack? At a very basic level, it’s exactly what it sounds like; it’s a cyberattack that’s designed to hide from you,” says Grayson Milbourne, Security Intelligence Director at Webroot, an OpenText company. Based on Grayson’s initial explanation, you can imagine that evasive tactics are pretty common throughout […]
security update
An update that solves one vulnerability and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves 13 vulnerabilities and has one errata is now available.
An update for jaeger-all-in-one-rhel7-container and jaeger-query-rhel7-container is now available for Jaeger-1.17. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Security fix for CVE-2020-10753 ceph: radosgw: HTTP header injection via CORS ExposeHeader tag
An update that fixes one vulnerability is now available.
Updated docker packages fix security vulnerability: A flaw was found in Docker when it creates network bridges that accept IPv6 router advertisements by default. This flaw allows an attacker who can execute code in a container to possibly spoof rogue IPv6 router
Multiple security issues were found in PHP, a widely-used open source general purpose scripting language which could result in information disclosure, denial of service or potentially the execution of arbitrary code.
Updated tcpreplay package fixes security vulnerability: tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c (CVE-2020-12740).
Updated tomcat packages fix security vulnerability: When using Apache Tomcat versions 9.0.0.M1 to 9.0.34, if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a
Updated mailman package fixes security vulnerability: Up to mailman 2.1.29 when sending a file without a file extension (or an unknown file extension) then the file is stored in the list archive with the file extension .obj. Most web servers will try to assign a mime type
security update
Update to Samba 4.12.5
Update to Samba 4.12.5
This update fixes CVE-2020-10177, CVE-2020-10994, CVE-2020-10379, CVE-2020-11538 and CVE-2020-10378.
# Python 3.6.11 Python 3.6.11 is the latest security fix release of Python 3.6. – bpo-39073: Disallow CR or LF in email.headerregistry.Address arguments to guard against header injection attacks. – bpo-38576: Disallow control characters in hostnames in http.client, addressing CVE-2019-18348. Such potentially malicious header injection URLs now cause a InvalidURL to be raised. –
3.48.1
Security update for CVE-2020-12695 (CallStranger)
security update
security update
The cybercriminal behind the ransom raids on almost 23,000 databases threatens to leak the data and alert GDPR regulators The post Thousands of MongoDB databases ransacked, held for ransom appeared first on WeLiveSecurity
An update that fixes 19 vulnerabilities is now available.
An update that contains security fixes can now be installed.
An update that solves three vulnerabilities and has three fixes is now available.
2.23 fixes CVE-2020-14929 (#1850048,#1850047) and new version (#1848786)
Update to latest upstream version
Fix CVE-2020-12695 (UPnP SUBSCRIBE misbehavior in hostapd WPS AP)
security update
security update
Reading Time: ~ 2 min. WastedLocker Shuts Down US News Sites Over 30 news sites were compromised in the latest WastedLocker attack that affected many sites under a single parent company. Of the more than 30 companies targeted, eight belong to the Fortune 500 group and were in the early stages of a experiencing a […]
The out-of-band update plugs two remote code execution bugs in the Windows Codecs library, including one rated as critical The post Microsoft releases emergency update to fix two serious Windows flaws appeared first on WeLiveSecurity
An update for rh-nginx116-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
