A view of the Q1 2020 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report appeared first on WeLiveSecurity
It was discovered that there was a integer signedness error in the miniupnpc UPnP client that could allow remote attackers to cause a denial of service attack.
An issue has been found in pound, A request smuggling vulnerability was discovered in pound, a everse proxy, load balancer and HTTPS front-end for Web servers, that may allow
Two issues have been found in w3m, WWW browsable pager with excellent tables/frames support.
An issue has been found in yodl, a pre-document language. Hanno Bock discovered that there was a buffer over-read vulnerability.
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Another in our occasional series demystifying Latin American banking trojans The post Grandoreiro: How engorged can an EXE get? appeared first on WeLiveSecurity
An update that solves 7 vulnerabilities and has 77 fixes is now available.
An update that solves 7 vulnerabilities and has 77 fixes is now available.
An update that solves 13 vulnerabilities and has 157 fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves 6 vulnerabilities and has 8 fixes is now available.
An update that solves 13 vulnerabilities and has 157 fixes is now available.
security update
Reading Time: ~ 3 min. A popular military maxim speaks to the need for redundancy and it goes like this: “Two is one and one is none.” Redundancy is also a key principle when it comes to cyber-resilience. A popular rule in data protection and disaster recovery is called the 3-2-1 backup rule. IT pros […]
re2c could be made to execute arbitrary code if it received a specially crafted file.
An update that solves 15 vulnerabilities and has 8 fixes is now available.
An update that solves 10 vulnerabilities and has 89 fixes is now available.
An update that solves 5 vulnerabilities and has 7 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
security update
Microsoft plugs a security hole that could have enabled attackers to weaponize a GIF in order to hijack Teams accounts and steal data The post Microsoft Teams flaw could let attackers hijack accounts appeared first on WeLiveSecurity
An update that solves 11 vulnerabilities and has 96 fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves 12 vulnerabilities and has 139 fixes is now available.
Several security issues were fixed in OpenEXR.
Update to latest upstream OpenVPN 2.4.9 release. It contains a security fix for CVE-2020-11810. This security issue is quite hard to abuse, requiring a fairly precise timing attack combined with guessing a just assigned peer-id reference. If successful, only a single client just initiating a new connection will experience a denial of service situation. This […]
6.2.6
Three issues have been found in php5, a server-side, HTML-embedded scripting language.
Hanno Boeck discovered that it was possible to create a cross site scripting attack on the webarchives of the Mailman mailing list manager, by sending a special type of attachement.
Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Fix rendering after a cross site navigation with PSON enabled and hardware acceleration forced. * Fix a crash in nested wayland compositor when closing a tab with PSON enabled. * Update Chrome and Firefox versions in user agent quirks. […]
Security fix for CVE-2020-5260 From the upstream [release notes](https://www.kernel.org/pub/software/scm/git/docs/RelNotes/2.17.5.txt): > With a crafted URL that contains a newline or empty host, or lacks > a scheme, the credential helper machinery can be fooled into > providing credential information that is not appropriate for the > protocol in use and host being
Update to WebKitGTK 2.28.1: * Fix position of default option element popup windows under Wayland. * Update Chrome and Firefox versions in user agent quirks. * Fix several crashes and rendering issues. * Security fixes: CVE-2020-11793
Update to version 1.26. Resolves CVE-2017-18640.
security update
It was discovered that python-reportlab, a Python library to create PDF documents, is prone to a code injection vulnerability while parsing a color attribute. An attacker can take advantage of this flaw to execute arbitrary code if a specially crafted document is processed.
security update
This update fixes the following security vulnerabilities: CVE-2018-20536, CVE-2018-20537, CVE-2018-20539, CVE-2018-20540
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid pointer address). (cmb, Nikita) **CURL:** * Fixed bug php#79199 (curl_copy_handle() memory leak). (cmb) **Date:** * Fixed bug php#79396 (DateTime hour incorrect during DST jump forward). (Nate Brunette) **Iconv:**
3.2.3 —- New version 3.2.2 Security fix for CVE-2020-7044, CVE-2020-9428, CVE-2020-9430, CVE-2020-9431
Fix mistakes in Wayland wrapper change —- Fixes Wayland issue when running from terminal —- Update sound touch library, fixes some known security issues.
Security fix for CVE-2015-9541
