Menu

Category Archives: Security

Articles about security

Updated dia package fixes security vulnerability: An endless loop on filenames with invalid encoding (CVE-2019-19451). References:

Updated mediawiki packages fix security vulnerability: MediaWiki through 1.33.1 allows attackers to bypass the Title_blacklist protection mechanism by starting with an arbitrary title, establishing a non-resolvable redirect for the associated page, and using redirect=1

The updated packages fix a security vulnerability: xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. (CVE-2019-19956)

The updated packages fix security vulnerabilities: When FreeImage 3.18.0 reads a tiff file, it will be handed to the Load function of the PluginTIFF.cpp file, but a memcpy occurs in which the destination address and the size of the copied data are not considered,

Updated jss packages fix security vulnerability: A flaw was found in the “Leaf and Chain” OCSP policy implementation in JSS CryptoManager, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly

Authorities lost track of suspect after WhatsApp hacking warning

Update to NetHack 3.6.4 – fixes security issue with privilege escalation: http://nethack.org/security/index.html

**PHP version 7.3.13** (18 Dec 2019) **Bcmath:** * Fixed bug php#78878 (Buffer underflow in bc_shift_addsub). (**CVE-2019-11046**). (cmb) **Core:** * Fixed bug php#78862 (link() silently truncates after a null byte on Windows). (**CVE-2019-11044**). (cmb) * Fixed bug php#78863 (DirectoryIterator class silently truncates after a null byte). (**CVE-2019-11045**). (cmb) * Fixed bug

denial of service in find_next_bit() [XSA-307, CVE-2019-19581, CVE-2019-19582] (#1782211) denial of service in HVM/PVH guest userspace code [XSA-308, CVE-2019-19583] (#1782206) privilege escalation due to malicious PV guest [XSA-309, CVE-2019-19578] (#1782210) Further issues with restartable PV type change operations [XSA-310, CVE-2019-19580] (#1782207) vulnerability in dynamic

Update to version 0.9.3 to address CVE-2019-14889

Update to Samba 4.10.11, Security fixes for CVE-2019-14861 and CVE-2019-14870

IT exec sets up fake biz, uses it to bill his bosses $6m for phantom gear, gets caught by Microsoft Word metadata
New year, new critical Cisco patches to install – this time for a dirty dozen of bugs that can be exploited to sidestep auth, inject commands, etc
BusKill USB cable switches off your laptop in the event of theft
Ransomware Attack Topples Telemarketing Firm, Leaving Hundreds Jobless

Reading Time: ~ 2 min. US Coast Guard Facility Hit with Ransomware During the last week of December a US Coast Guard facility was the target of a Ryuk ransomware attack that shut down operations for over 30 hours. Though the Coast Guard has implemented multiple cybersecurity regulations in just the last six months or […]

3 Critical Bugs Allow Remote Attacks on Cisco NX-OS and Switches
TikTok boom: US Army bans squaddies from using trendy app on govt-issued phones
Cybercriminals Fill Up on Gas Pump Transaction Scams Ahead of Oct. Deadline
Travelex Knocked Offline by System-Wide Malware Attack
Brit banking sector hasn’t gone a single day of 2020 without something breaking
Google Boots Security Camera Maker From Nest Hub After Private Images Go Public
Don’t Xiaomi pics of other people’s places! Chinese kitmaker fingers dodgy Boxing Day cache update after Google banishes it from Home

It was reported that Netty, a Java NIO client/server framework, is prone to a HTTP request smuggling vulnerability due to mishandling whitespace before the colon in HTTP headers.

This page is currency unavailable… Travelex scrubs UK homepage, kills services, knackers other sites amid ‘software virus’ infection
And we now go live to Apple v Corellium, where the iTitan is still lobbing copyright fireballs at the virtual iPhone upstart

security update

Travelex exchange suffers malware attack; affects Tesco Bank service
Data Breach Affects 63 Landry’s Restaurants
Oddly specific ‘cyber attack’ hits Alaskan airline RavnAir and one plane type
US Military Bans TikTok over privacy concerns
TikTok boom: US Army bans squaddies from using platform on government-issued phones
California Adopts Strictest Privacy Law in U.S.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

TikTok Banned By U.S. Army Over China Security Concerns
Cambridge Analytica scandal: Facebook hit with $1.6 million fine
Mitigating the risks of AI transparency in the next decade
Simple steps to protect yourself against identity theft

As we enter the New Year, be sure to keep up, or adopt, these good data security habits to avoid identity theft The post Simple steps to protect yourself against identity theft appeared first on WeLiveSecurity

An update that fixes 16 vulnerabilities is now available.

An update that solves one vulnerability and has three fixes is now available.

An update for java-1.8.0-ibm is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Multiple buffer overflows have been fixed in jhead, a program to manipulate the non-image part of Exif compliant JPEG files. For Debian 8 “Jessie”, these problems have been fixed in version

An issue has been found in igraph, a library for creating and manipulating graphs. A NULL pointer dereference vulneribility was detected in

Online Privacy: What to Expect in 2020

It was discovered that there was a HTTP request smuggling vulnerability in waitress, pure-Python WSGI server. If a proxy server is used in front of waitress, an invalid request

It was discovered that the fix to address an ECDSA timing attack in the libgcrypt20 cryptographic library was incomplete. For Debian 8 “Jessie”, this issue has been fixed in libgcrypt20

An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, which are in the queue where attacker doesn’t have permissions.

Why Web Hosting Security is important?
Microsoft pwns domains used by hackers for large-scale cyber attacks
4 uses for programmable logic controllers in industrial settings
7 Tips for Maximizing Your SOC

The updated packages fix a security vulnerability: Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor. (CVE-2019-17064)

Updated hunspell packages fix security vulnerability: Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx (CVE-2019-16707).

The updated package fixes a security vulnerability: Roundcube Webmail through 1.3.9 mishandles Punycode xn-- domain names, leading to homograph attacks. (CVE-2019-15237)

Updated pdfresurrect package fixes security vulnerabilities: A vulnerability was found in PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled (CVE-2019-14267).

The updated packages fix an issue: Wrong permissions on /etc/freshclam.conf prevent freshclam usage with authenticated proxy. (rhbz#1733112)

Updated filezilla packages fix bugs and a security vulnerability: Filenames containing double-quotation marks were not escaped correctly when selected for opening/editing. Depending on the associated program, parts of the filename could be interpreted as commands.

2020 Cybersecurity Trends to Watch
20 tips for 2020: Be smarter with your smartphone

In the second blogpost of the two-part series we’ll suggest handy tips to help enhance the security of your mobile devices The post 20 tips for 2020: Be smarter with your smartphone appeared first on WeLiveSecurity

Most popular tech stories of 2019
Most second-hand phones contain previous owner’s data
Smart TVs make screenshots every second & send them to the server
IoT Company Wyze Leaks Emails, Device Data of 2.4M
Mean Time to Hardening: The Next-Gen Security Metric
Top Mobile Security Stories of 2019

An update that solves one vulnerability and has one errata is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes three vulnerabilities is now available.

20 tips for 2020: Mistakes to avoid

In this first instalment of the two-article series we will be looking at cybersecurity habits to avoid when using your computing devices The post 20 tips for 2020: Mistakes to avoid appeared first on WeLiveSecurity

Several security bugs have been identified and fixed in php5, a server-side, HTML-embedded scripting language. The affected components include the exif module and handling of filenames

It was discovered that there was a potential denial of service vulnerability in libxml2, the GNOME XML parsing library. For Debian 8 “Jessie”, this issue has been fixed in libxml2 version

Multiple vulnerabilities have been found in imagemagick, an image processing toolkit. CVE-2019-19948

security update

security update

security update

security update

security update

Several issues were discovered in the Tomcat servlet and JSP engine, which could result in session fixation attacks, information disclosure, cross- site scripting, denial of service via resource exhaustion and insecure redirects.

It was discovered that debian-lan-config, a FAI config space for the Debian-LAN system, configured too permissive ACLs for the Kerberos admin server, which allowed password changes for other user principals.

Guido Vranken discovered an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. For the oldstable distribution (stretch), this problem has been fixed

It was found that freeimage, a graphics library, was affected by the following two security issues: CVE-2019-12211

What Brings The Essence Of Secured Web Hosting
Google Chrome Affected By Magellan 2.0 Flaws
Prison surveillance footage posted on YouTube

It’s not a stretch to surmise that the incident was enabled by poor security settings The post Prison surveillance footage posted on YouTube appeared first on WeLiveSecurity

Facebook Security Debacles: 2019 Year in Review
Podcast: The Roadblocks and Opportunities For Women in Cybersecurity

An update that fixes one vulnerability is now available.

An update that solves 24 vulnerabilities and has 75 fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves 24 vulnerabilities and has 75 fixes is now available.

An update that fixes one vulnerability is now available.

How to get rid of your old devices safely

Disposing of old tech isn’t a one-click solution; there are multiple things you have to consider before moving on to greener pastures The post How to get rid of your old devices safely appeared first on WeLiveSecurity

Beware the three-finger-salute, or ‘How I Got The Keys To The Kingdom’
Critical Citrix Bug Puts 80,000 Corporate LANs at Risk

Updated php packages fix security vulnerabilities: DirectoryIterator class silently truncates after a null byte (CVE-2019-11045).

he updated packages fix security vulnerabilities and a packaging problem: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make