Menu

Category Archives: Security

Articles about security

Type: Vulnerability. Fortinet FortiClient for macOS is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Apache CXF is prone to a denial-of-service vulnerability and an unauthorized access vulnerability; fixes are available.

Type: Vulnerability. Multiple Medtronic Products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Multiple Medtronic Products are prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Philips Tasy EMR is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Philips Tasy EMR is prone to a cross-site scripting vulnerability.

Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.

Type: Vulnerability. Fuji Electric V-Server is prone to multiple unspecified heap-based buffer overflow vulnerabilities; fixes are available.

ThreatList: Data Breaches Batter Stock Prices at Public Companies, For Months
Back-2-school hacking: Kaspersky blames pesky script kiddies for rash of DDoS cyber hooliganism
First BlueKeep attacks prompt fresh warnings

The infamous vulnerability has been exploited for a cryptocurrency mining campaign, but more damaging attacks may still be in store The post First BlueKeep attacks prompt fresh warnings appeared first on WeLiveSecurity

If it sounds too good to be true, it most likely is: Nobody can decrypt the Dharma ransomware
Ransomware Attack Downs Hosting Service SmarterASP.NET
BlueKeep: What you need to know

An update that solves two vulnerabilities and has one errata is now available.

Encrypted Emails on macOS Found Stored in Unprotected Way

Several vulnerabilities were discovered in Ampache, a web-based audio file management system.

Bash could be made to crash or execute arbitrary code if it received a specially crafted input.

Hate hub hacked, Cisco bugs squished, Bluekeep attacks begin, and much, much more

In haml, when using user input to perform tasks on the server, characters like ” ‘ must be escaped properly. In this case, the ‘ character was missed. An attacker can manipulate the input to introduce additional

fixed multiple security bugs

Security fix CVE-2019-16275 (AP mode PMF disconnection protection bypass)

Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.

An update that contains security fixes can now be installed.

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure, cross-site scripting or denial of service.

An update that fixes two vulnerabilities is now available.

An update that fixes two vulnerabilities is now available.

fixed multiple security bugs

Fix CVE-2019-3463, CVE-2019-3464 and CVE-2019-1000018.

– fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)

Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes

An update that solves two vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves two vulnerabilities and has three fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that fixes 9 vulnerabilities is now available.

An update that solves three vulnerabilities and has four fixes is now available.

An update that fixes one vulnerability is now available.

GDAL through 3.0.1 had a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold was exceeded.

Platinum APT Shines Up New Titanium Backdoor
Understanding the Ripple Effect: Large Enterprise Data Breaches Threaten Everyone

Type: Vulnerability. Multiple Cisco Products are prone to a local security-bypass vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business SPA500 Series IP Phones are prone to a local command-injection vulnerability;fixes are available.

Type: Vulnerability. Multiple Cisco WebEx products are prone to multiple local code-execution vulnerabilities; fixes are available.

Type: Vulnerability. Cisco Webex Meetings is prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Multiple Cisco Products are prone to a remote privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Cisco Managed Services Accelerator is prone to an open-redirection vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business RV Series Routers are prone to an arbitrary command-execution vulnerability; fixes are available.

Type: Vulnerability. Cisco Small Business RV Series Routers are prone to a remote command injection vulnerability; fixes are available.

Type: Vulnerability. Cisco Web Security Appliance is prone to a cross-site scripting vulnerability; fixes are available.

Art Imitates Life: Lessons from the Final Season of Mr. Robot

New kernel packages are available for Slackware 14.2 to fix security issues.

Pwn2Own Tokyo Roundup: Amazon Echo, Routers, Smart TVs Fall to Hackers
Morrisons is to blame for 100k payroll theft and leak, say 9,000 workers
News Wrap: Voice Assistant Laser Hack, Twitter Insider Threats, Data Breach Fine Fails

Reading Time: ~ 2 min. BEC Scam Takes Millions from Nikkei America Officials for Nikkei are working to identify the perpetrators of a recent business email compromise (BEC) scam that took roughly $29 million from the company’s American subsidiary. The illicit transfer took place sometime during the end of September and, though they did make […]

Amazon Fixes Ring Video Doorbell Flaw That Leaked Wi-Fi Credentials

An update that fixes one vulnerability is now available.

Applications using FriBidi could be made to crash or run programs as your login if it displayed specially crafted text.

Surveillance kit slinger accused of slapping ‘Made in America’ on Chinese gear, selling it to the US government
What do you get when you allegedly mix Wireshark, a gumshoe child molester, and a court PC? A judge facing hacking charges

security update

Alex Murray discovered a stack-based buffer overflow vulnerability in fribidi, an implementation of the Unicode Bidirectional Algorithm algorithm, which could result in denial of service or potentially the execution of arbitrary code, when processing a large number of unicode

This may shock you but Adobe is shipping insecure software. No, it’s not Flash this time. Nope, not Acrobat, either

security update

Ex-Twitter Employees Spied on Saudi Dissidents: DoJ

It was discovered that Expat did not properly handle internal entities closing the doctype, potentially resulting in denial of service or information disclosure if a malformed XML file is processed (CVE-2019-15903).

Chromium-browser 78.0.3904.87 fixes security issues: Multiple flaws were found in the way Chromium 77.0.3865.120 processes various types of web content, where loading a web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose

Updated freetds packages fix security vulnerability: Felix Wilhelm discovered that FreeTDS incorrectly handled certain types after a protocol downgrade. A remote attacker could use this issue to cause FreeTDS to crash, resulting in a denial of service, or possibly

Updated python and python3 packages fix security vulnerabilities: It was discovered that Python incorrectly parsed certain email addresses. A remote attacker could possibly use this issue to trick Python applications into accepting email addresses that should be denied (CVE-2019-16056).

Updated unbound packages fix security vulnerability: Versions before 1.9.4 allow accesses to uninitialized memory, which would permit remote attackers to trigger a crash (CVE-2019-16866).

The updated packages fix security issues: Use-after-free when creating index updates in IndexedDB. (CVE-2019-11757)

The updated packages fix several bugs and some security issues: Use-after-free when creating index updates in IndexedDB. (CVE-2019-11757)

Updated proftpd package fixes security vulnerabilities: It was discovered that the mod_copy module of ProFTPD, a FTP/SFTP/FTPS server, performed incomplete permission validation for the CPFR/CPTO commands (CVE-2019-12815).

Communication, communication – and politics: Iowa saga of cuffed infosec pros reveals pentest pitfalls

Type: Vulnerability. Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cisco Web Security Appliance is prone to an unauthorized-access vulnerability; fixes are available

Type: Vulnerability. Multiple Cisco Products are prone to an remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Cisco TelePresence Advanced Media Gateway is prone to a remote denial-of-service vulnerability.

Type: Vulnerability. Cisco Industrial Network Director is prone to a cross-site scripting vulnerability; fixes are available.

Type: Vulnerability. libarchive is prone to an arbitrary code-execution vulnerability; fixes are available.

Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities.

Type: Vulnerability. Google Android is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. Google Android is prone to multiple local privilege-escalation vulnerabilities; fixes are available.

Type: Vulnerability. Joomla! Core is prone to an information-disclosure vulnerability; fixes are available.

Amazon Kindle, Embedded Devices Open to Code-Execution
Gamers Hit with Nvidia GPU Driver, GeForce Flaws
How to Secure Critical Infrastructure When Patching Isn’t Possible
Morrisons tells top court it’s not liable for staffer who nicked payroll data of 100,000 employees

The package linux-hardened before version 5.3.7.b-1 is vulnerable to arbitrary code execution.

Data Breach Fines: Are They Working to Boost Consumer Safety?
Google Enlists Help to Fight Bad Android Apps

An update for cri-o is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which

An update for mediawiki123 is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which

An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,