Menu

Category Archives: Security

Articles about security

An update that fixes one vulnerability is now available.

An update that solves 24 vulnerabilities and has 75 fixes is now available.

An update that solves one vulnerability and has two fixes is now available.

An update that solves 24 vulnerabilities and has 75 fixes is now available.

An update that fixes one vulnerability is now available.

How to get rid of your old devices safely

Disposing of old tech isn’t a one-click solution; there are multiple things you have to consider before moving on to greener pastures The post How to get rid of your old devices safely appeared first on WeLiveSecurity

Beware the three-finger-salute, or ‘How I Got The Keys To The Kingdom’
Critical Citrix Bug Puts 80,000 Corporate LANs at Risk

Updated php packages fix security vulnerabilities: DirectoryIterator class silently truncates after a null byte (CVE-2019-11045).

he updated packages fix security vulnerabilities and a packaging problem: An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make

The updated package fixes a security vulnerability: A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with trailing slashes similar to CVE-2019-3877 in mod_auth_mellon. (CVE-2019-14857)

Updated libofx packages fix security vulnerability: There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump (CVE-2019-9656).

Combining AI and Playbooks to Predict Cyberattacks
Top 10 Breaches and Leaky Server Screw Ups of 2019
Top 7 PDF Tools to Edit, Merge/Split and Protect PDF

An issue was discovered in libopensc/card-setcos.c in OpenSC, which has an incorrect read operation during parsing of a SETCOS file attribute.

Type: Vulnerability. ImageMagick is prone to multiple heap-based buffer-overflow vulnerabilities; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. IBM Cognos Analytics is prone to a cross-site scripting vulnerability and a cross-site request-forgery vulnerability; fixes are available.

Type: Vulnerability. FasterXML Jackson-databind is prone to a remote code-execution vulnerability; fixes are available.

This update is based on upstream 5.4.6 and fixes various potential security issues related to buffer overflows, double frees, NUll pointer dereferences, improper / missing input validations and so on. It also adds other bugfixes all over the kernel.

Man accused of hiring hitman on dark web to kill ex-girlfriend

Type: Vulnerability. Trend Micro Apex Central is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. TYPO3 is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. IBM Spectrum Scale is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Samba is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a denial-of-service vulnerability.

Type: Vulnerability. Redis is prone to a buffer overflow vulnerability; fixes are available.

Type: Vulnerability. Multiple Trend Micro Products are prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Apple iOS/iPadOS/watchOS/macOS are prone to a security vulnerability; fixes are available.

Type: Vulnerability. Wecon PLC Editor is prone to multiple stack-based buffer-overflow vulnerabilities.

Type: Vulnerability. Multiple Moxa Products are prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Broadcom CA Client Automation is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Sudo is prone to multiple security-bypass vulnerabilities; fixes are available.

Biggest Malware Threats of 2019
Londoner who tried to blackmail Apple with 300m+ iCloud account resets was reusing stale old creds
The Case for Cyber-Risk Prospectuses
Here is a list of top 25 worst passwords of 2019

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4107

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4148

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4240

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4326

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4190

Upstream details at : https://access.redhat.com/errata/RHSA-2019:4190

To protect data and code in the age of hybrid cloud, you can always turn to Intel SGX
Twitter Fixes Bug that Enabled Takeover of Android App Accounts

Type: Vulnerability. RedHat Ceph is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Redis is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Kubernetes API Server is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache Log4j is prone to remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Multiple VMware products are prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Kubernetes is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Equinox Control Expert is prone to an SQL-injection vulnerability.

Type: Vulnerability. Philips Veradius Unity, Pulsera, and Endura are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry Cloud Controller API is prone to a security-bypass vulnerability; fixes are available.

Apple Bug bounty: Earn big backs for hacking iPhone & other products

A change introduced in libssh 0.6.3-4+deb8u4 (which got released as DLA 2038-1) has broken x2goclient’s way of scp’ing session setup files from client to server, resulting in an error message shown in a GUI error dialog box during session startup (and session resuming).

An update that fixes two vulnerabilities is now available.

ToTok app caught spying on millions of Android & iPhone users
Patch now: Published Citrix applications leave networks of ‘potentially 80,000’ firms at risk from attackers
Top 10 IoT Disasters of 2019
Podcast: What We’ve Learned from the Year of the Breach
Emirati ‘surveillance app’ ToTok promoted by Huawei as Apple punts it from store
Say GDP-aaaR: UK’s Information Commissioner pours £275k fine into London pharmacy’s teaspoon
How to secure your digital Christmas presents

What are some of the key things you should do with your shiny new device as soon as you unbox it? The post How to secure your digital Christmas presents appeared first on WeLiveSecurity

An update for fribidi is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for libyang is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An issue has been found in cups, the Common UNIX Printing System(tm). An incorrect bounds check could lead to a possible out-of-bounds read and

An update that fixes 7 vulnerabilities is now available.

security update

Fake streaming sites using Star Wars as bait to spread malware
Tracking President Trump with cellphone location data, Greta-Thunberg-themed malware, SharePoint patch, and more

Several vulnerabilities have recently been discovered in TightVNC 1.x, an X11 based VNC server/viewer application for Windows and Unix.

An update that solves 26 vulnerabilities and has 14 fixes is now available.

How to check for websites hacked to run web skimming, magecart attack

security update

New tigervnc packages are available for Slackware 14.2 and -current to fix security issues.

New openssl packages are available for Slackware 14.2 and -current to fix a security issue.

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

– Update to 1.2.8 Release notes: https://www.cacti.net/release_notes.php?version=1.2.8

Type: Vulnerability. Palo Alto Networks PAN-OS is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Telos AMHS is prone to multiple cross-site scripting vulnerabilities and an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple Apple Products are prone to an arbitrary code execution vulnerability; fixes are available.

Type: Vulnerability. Atlassian Confluence Server and Data Center are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Django is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. D-Link DIR-615 is prone to a privilege-escalation vulnerability.

Type: Vulnerability. ABB PB610 Panel Builder 600 is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. TYPO3 is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Multiple Dell products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Drupal Core is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Apache Xerces-C is prone to a remote code-execution vulnerability.

Type: Vulnerability. Sysstat is prone to a memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Apache Tomcat is prone to a session-fixation vulnerability; fixes are available.

Type: Vulnerability. Drupal is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Apache Tomcat is prone to local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Drupal is prone to an access-bypass vulnerability; fixes are available.

It’s cool for Brit snoops to break the law, says secretive spy court. Just hold on while we pull off some legal jujitsu to let MI5 off the hook…
Top Zero Days, Data Breaches and Security Stories of 2019: News Wrap
Greta Thunberg: Emotet’s Person of the Year