Menu

Category Archives: Security

Articles about security

WhatsApp Remote Code Execution Triggered by Videos

Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code execution via unserialization.

The Unhappiest Subscribers on Earth? Disney+ Accounts Hacked & Hijacked

security update

security update

Type: Vulnerability. Teamviewer is prone to a remote security vulnerability; fixes are available.

Type: Vulnerability. Intel Ethernet 700 Series Controllers are prone to a buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. McAfee Advanced Threat Defense is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Siemens Products are prone to an unspecified denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Siemens Products are prone to a security vulnerability; fixes are available.

Type: Vulnerability. Multiple ABB products are prone to an authentication-bypass vulnerability; fixes are available.

Type: Vulnerability. McAfee Data Loss Prevention is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. FriBidi is prone to a stack-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Siemens SIMATIC S7-1200 is prone to a local unauthorized-access vulnerability.

Type: Vulnerability. Fortinet FortiOS is prone to an local information-disclosure vulnerability; fixes are available.

Office 365 Admins Targeted in Ongoing Phishing Scam
Interpol: Strong encryption helps paedos. Build backdoors
Disney+ accounts hijacked – How to protect yourself

As users are losing access to their accounts by the dozens, we offer a few tips to help keep your streaming subscriptions safe The post Disney+ accounts hijacked – How to protect yourself appeared first on WeLiveSecurity

Pack your bags, you’re going to America, Lord Chief Justice tells accused Brit hacker
NextCry Ransomware Targets NextCloud Linux Servers and Remains Undetected>
Pipka Card Skimmer Removes Itself After Infecting eCommerce Sites

Earlier versions of this package package were vulnerable to Cross-site Scripting (XSS) due to no proper sanitization of xlink:href attributes.

An update that solves one vulnerability and has 22 fixes is now available.

Multiple security issues have been found in Thunderbird which could potentially result in the execution of arbitrary code or denial of service. Debian follows the Thunderbird upstream releases. Support for the 60.x series

Tianfu Cup Round-Up: Safari, Chrome, D-Link Routers and Office 365 Successfully Hacked

An update is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

A security vulnerability was found in libapache2-mod-auth-openidc, the OpenID Connect authentication module for the Apache HTTP server. Insufficient validation of URLs leads to an Open Redirect

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability

Several security issues were fixed in python-ecdsa.

Several security issues were fixed in MySQL.

An update for libcomps is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

Pemex hit by ransomware, US Postal Service gets a copycat and new WhatsApp bugs

New kernel packages are available for Slackware 14.2 to fix security issues.

A vulnerability was discovered in mosquitto, a MQTT version 3.1/3.1.1 compatible message broker, allowing a malicious MQTT client to cause a denial of service (stack overflow and daemon crash), by sending a specially crafted SUBSCRIBE packet containing a topic with a extremely

VCPUOP_initialise DoS [XSA-296, CVE-2019-18420] missing descriptor table limit checking in x86 PV emulation [XSA-298, CVE-2019-18425] Issues with restartable PV type change operations [XSA-299, CVE-2019-18421] (#1767726) add-to-physmap can be abused to DoS Arm hosts [XSA-301, CVE-2019-18423] passed through PCI devices may corrupt host memory after deassignment [XSA-302, CVE-2019-18424]

8u232 update

Security fix for CVE-2019-15142, CVE-2019-15143, CVE-2019-15144 and CVE-2019-15145.

Update to 1.1.20

Security fix for CVE-2019-16275

Rich Mirch discovered that the pg_ctlcluster script didn’t drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation.

An update that fixes 11 vulnerabilities is now available.

Holiday Shoppers Beware: 100K Malicious Sites Found Posing as Well-Known Retailers
GitHub makes CodeQL free for research and open source

security update

security update

Security fix for CVE-2019-14664, CVE-2019-12269 and compatibility with Thunderbird 68

Update to Samba 4.10.10 – Security fixes for CVE-2019-10218, CVE-2019-14833, CVE-2019-14847

Denial of service kingpin hit with 13 months denial of freedom and a massive bill to pay

Type: Vulnerability. Philips IntelliBridge EC40 and EC80 is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. Multiple Veritas products are prone to an arbitrary command-injection vulnerability; fixes are available.

Type: Vulnerability. Multiple Siemens Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Siemens Desigo PX is prone to denial of service vulnerability; fixes are available.

Type: Vulnerability. Redhat Syndesis is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. McAfee Threat Intelligence Exchange Server is prone to an unauthorized-access vulnerability; fixes are available.

Type: Vulnerability. OpenStack Mistral is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. McAfee Total Protection is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Exim is prone to an arbitrary code-execution vulnerability; fixes are available.

Update to latest stable (78.0.3904.97). This build contains a number of bug fixes and security updates. Changes can be viewed here: https://chromium.googles ource.com/chromium/src/+log/78.0.3904.86..78.0.3904.92?n=10000

James Clapper: Lessons Learned in a Post-Snowden World
1Password hopes to cross some items off its todo list with help from $200m in venture capital
Lizard Squad Threatens UK’s Labour Leader with Cyberattacks Against His Family
Stealthy Malware Flies Under AV Radar with Advanced Obfuscation

An update that solves one vulnerability and has two fixes is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

An update that solves two vulnerabilities and has one errata is now available.

Reading Time: ~ 2 min. Orvis Internal Credentials Leaked A database containing login credentials for numerous internal systems belonging to Orvis, one of America’s oldest retailers, was found to be publicly available for an unknown amount of time. Why the database was publicly accessible at all is still unclear, but the retailer has determined that […]

An update that contains security fixes can now be installed.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 49 vulnerabilities and has two fixes is now available.

Tim Brown discovered a shared memory permissions vulnerability in the Mesa 3D graphics library. Some Mesa X11 drivers use shared-memory XImages to implement back buffers for improved performance, but Mesa

An update that fixes one vulnerability is now available.

An update that fixes 11 vulnerabilities is now available.

Try as they might, ransomware crooks can’t hide their tells when playing hands
Double Vision: Stealthy Malware Dropper Delivers Dual RATs
What a pair of Massholes! New England duo cuffed over SIM-swapping cryptocoin charges

Type: Vulnerability. Google Pixel is prone to a privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Magento CMS is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Lenovo ThinkPad is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Drupal Open Social is prone to a session-fixation vulnerability; fixes are available.

Type: Vulnerability. IBM Spectrum Protect Plus is prone to insecure file-permission vulnerability; fixes are available.

Type: Vulnerability. systemd is prone to an security-bypass vulnerability; fixes are available.

Type: Vulnerability. Lenovo is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. IBM QRadar SIEM is prone to an unspecified cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. TIBCO EBX Add-on is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. TIBCO EBX is prone to multiple unspecified cross-site scripting vulnerabilities; fixes are available.

Type: Vulnerability. Intel Xeon Scalable Processors are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Envoy is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. TIBCO EBX Add-on is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. Istio is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Multiple Intel Processors are prone to a denial of service vulnerability; fixes are available.

Type: Vulnerability. VMware Workstation and Fusion are prone to multiple security vulnerabilities; fixes are available

Type: Vulnerability. Trusted Platform Module is prone to an unspecified security vulnerability; fixes are available.

Type: Vulnerability. Multiple Intel Products are prone to a denial-of-service vulnerability; fixes are available.