Several security issues were fixed in WebKitGTK+.
An update that fixes 9 vulnerabilities is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
An update for openstack-octavia is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 13.0 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
security update
Type: Vulnerability. Joomla! is prone to a cross-site request-forgery vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to multiple information-disclosure vulnerabilities; fixes are available.
Type: Vulnerability. MantisBT is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Google Android is prone to a remote code execution vulnerability; fixes are available.
Type: Vulnerability. Red Hat ‘389-ds-base’ is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Sonatype Nexus Repository Manager is prone to an OS command-injection vulnerability; fixes are available.
security update
Type: Vulnerability. Multiple F5 BIG-IP Products are prone to a cross-site scripting vulnerability.
The virtual keyboard app ai.type, which has racked up 40 million downloads, has been found to sign up users to premium services without their consent The post Android keyboard app caught red‑handed trying to make sneaky purchases appeared first on WeLiveSecurity
How can organizations foster a workplace environment that enables employees to acquire the skills needed to keep cyber-threats at bay? The post Five ways to strengthen employee cybersecurity awareness appeared first on WeLiveSecurity
Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a security vulnerability; fixes are available.
Type: Vulnerability. OpenAFS is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Microsoft Office for Mac is prone to a remote code-execution vulnerability.
Type: Vulnerability. Apple Xcode is prone to multiple memory corruption vulnerabilities; fixes are available.
Type: Vulnerability. Honeywell equIP and Performance Series IP Cameras and Recorders is prone to a remote authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Multiple Honeywell Products are prone to an unauthorized-access vulnerability; fixes are available.
Type: Vulnerability. Advantech WISE-PaaS/RMM is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Multiple IBM Products are prone to an unauthorized-access vulnerability; fixes are available.
Type: Vulnerability. Apache Commons Beanutils is prone to a remote security vulnerability; fixes are available.
Type: Vulnerability. LibGD is prone to a heap-based buffer-overflow vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low.
The package qt5-webengine before version 5.13.2-2 is vulnerable to arbitrary code execution.
The introduction to a series of articles marking this year’s Antimalware Day and highlighting the importance of cyber-readiness The post Antimalware Day 2019: Building a culture of cybersecurity awareness appeared first on WeLiveSecurity
An update that fixes 21 vulnerabilities is now available.
An update that fixes 21 vulnerabilities is now available.
Rebasing to 2.26.x For release info please see https://www.webkitgtk.org/2019/09/09/webkitgtk2.26.0-released.html and https://www.webkitgtk.org/2019/09/23/webkitgtk2.26.1-released.html CVE fixes: CVE-2019-8625, CVE-2019-8720, CVE-2019-8769, CVE-2019-8771
An update that fixes two vulnerabilities is now available.
– fix heap-based buffer overflow in cdf_read_property_info() (CVE-2019-18218)
Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes
Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes
**PHP version 7.3.11** (24 Oct 2019) **Core:** * Fixed bug php#78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) * Fixed bug php#78620 (Out of memory error). (cmb, Nikita) **Exif :** * Fixed bug php#78442 (‘Illegal component’ on exif_read_data since PHP7) (Kalle) **FPM:** * Fixed bug php#78599 (env_path_info underflow in fpm_main.c can lead to RCE).
Updated libxslt package fixes security vulnerabilities: * In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains
Updated libsoup package fixes security vulnerability: It was discovered that libsoup incorrectly handled parsing certain NTLM messages. If a user or automated system were tricked into connecting to a malicious server, a remote attacker could possibly use this issue to
Updated aspell packages fix security vulnerability: libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated character (CVE-2019-17544).
Updated golang packages fix security vulnerability: Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service (CVE-2019-17596).
Updated ansible package fixes security vulnerabilities: ansible-playbook -k and ansible cli tools prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them
An update that fixes 21 vulnerabilities is now available.
Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes
Updates the nspr and nss packages to upstream NSPR 4.23 and NSS 3.47 respectively. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes – https://developer.mozilla.org/en- US/docs/Mozilla/Projects/NSS/NSS_3.47_release_notes
**PHP version 7.2.24** (24 Oct 2019) **Core:** * Fixed bug php#78535 (auto_detect_line_endings value not parsed as bool). (bugreportuser) * Fixed bug php#78620 (Out of memory error). (cmb, Nikita) **Exif:** * Fixed bug php#78442 (‘Illegal component’ on exif_read_data since PHP7) (Kalle) **FPM:** * Fixed bug php#78599 (env_path_info underflow in fpm_main.c can lead to RCE).
security update
security update
Type: Vulnerability. Xen is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Honeywell equIP Series IP Cameras is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Xen is prone to a denial-of-service vulnerability; fixes are available.
