Update to latest upstream version.
security update
– Fix CVE-2020-28196 (DoS in ASN.1 parsing due to missing recursion depth checks) – fc32 + fc33 only: pull-up to rawhide
Add correct fix for CVE-2020-24977 (RHBZ#1877788), thanks: Jan de Groot.
CVE-2020-0181, CVE-2020-0198, and CVE-2020-0452
USN-4607-1 introduced a regression in OpenJDK.
The last three weeks have seen a bumper crop of patches for zero-day bugs across software from Google, Apple and Microsoft The post Google patches two new zero‑day flaws in Chrome appeared first on WeLiveSecurity
Backdoor authors show deep knowledge of the targeted POS software, decrypting database passwords from Windows registry values The post Hungry for data, ModPipe backdoor hits POS software used in hospitality sector appeared first on WeLiveSecurity
Reading Time: ~ 2 min. Phony IRS Emails Flooding Inboxes Upwards of 70,000 inboxes have been receiving spam claiming to be from the IRS threatening legal action for late or missing payments. Most recipients are Microsoft Office 365 users and have been receiving threats of lawsuits to, wage garnishment and even arrest. These spoofing scams […]
Li Fei found that libproxy, a library for automatic proxy configuration management, was vulnerable to a buffer overflow vulnerability when receiving a large PAC file from a server without a Content-Length header in the response.
A use-after-free was found in Thunderbird, which could potentially result in the execution of arbitrary code. For Debian 9 stretch, this problem has been fixed in version
Ken Gaillot discovered a vulnerability in the Pacemaker cluster resource manager: If ACLs were configured for users in the “haclient” group, the ACL restrictions could be bypassed via unrestricted IPC communication, resulting in cluster-wide arbitrary code execution with
security update
Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes
Updates the nss package to upstream NSS 3.58 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.57_release_notes
Reading Time: ~ 3 min. Webroot is a dynamic team of hard-working individuals with diverse backgrounds. One of those hard-working individuals is Ben Jackson, Senior Manager of Software Development, Engineering. Ben started off building pages in HTML. Now he leads high-performing teams and helps develop architectures from his home in the UK. We sat down […]
The second Tuesday of the month brings another fresh batch of fixes for security vulnerabilities in various Microsoft products The post Microsoft Patch Tuesday fixes 17 critical flaws, Windows zero‑day appeared first on WeLiveSecurity
Sharing is caring – except when it isn’t. Here’s why you shouldn’t share your password for online media services with other people. The post Why you should keep your Netflix password to yourself appeared first on WeLiveSecurity
An update that solves 53 vulnerabilities, contains 14 features and has 5 fixes is now available.
libmaxminddb could be made to crash if it received specially crafted data.
USN-4171-1 introduced a regression in Apport.
An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for firefox is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
security update
security update
Several security issues were fixed in Intel Microcode.
raptor2 could be made to crash or run programs as your login if it opened a specially crafted file.
An update that fixes four vulnerabilities is now available.
An update that solves 18 vulnerabilities and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes 18 vulnerabilities is now available.
Reading Time: ~ 4 min. A few years back, cryptojacking and cryptomining emerged as relatively low-effort ways to profit by hijacking another’s computing resources. Today, cloudjacking and cloud mining capitalize on similar principles, only by targeting the near infinite resources of the cloud to generate revenue for attackers. Knowing this growing threat is key to […]
security update
The cache of data sitting wide open on a server included full names, national ID numbers and credit card data The post Data on millions of hotel guests exposed in cloud storage leak appeared first on WeLiveSecurity
The ppp de-capsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. The buffer should be big enough to hold the captured data, but it
It was discovered that ZeroMQ, a lightweight messaging kernel library does not properly handle connecting peers before a handshake is completed. A remote, unauthenticated client connecting to an application using the libzmq library, running with a socket
Firefox could be made to crash or run programs as your login if it opened a malicious website.
Fabian Vogt discovered a flaw in sddm before 0.19.0. A local attacker can take advantage of a race condition when creating the Xauthority file to escalate privileges (CVE-2020-28049). References:
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. (CVE-2019-19917) Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. (CVE-2019-19918)
ACL restrictions bypass. (CVE-2020-25654) References: – https://bugs.mageia.org/show_bug.cgi?id=27472 – https://www.openwall.com/lists/oss-security/2020/10/27/1
security update
