Type: Vulnerability. Cisco TelePresence Collaboration Endpoint Software is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks GlobalProtect Agent is prone to a local privilege-escalation vulnerability; fixes are available.
Notorious cyberespionage group debases MSSQL The post Winnti Group’s skip‑2.0: A Microsoft SQL Server backdoor appeared first on WeLiveSecurity
It was discovered that Aspell, the GNU spell checker, incorrectly handled certain inputs which leads to a stack-based buffer over-read. An attacker could potentially access sensitive information.
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability and has two fixes is now available.
security update
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update for logging-elasticsearch5-container is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
It was discovered that the Special:Redirect functionality of MediaWiki, a website engine for collaborative work, could expose suppressed user names, resulting in an information leak.
New build after fixing BuildRequires —- – Rebase to upstream version 3.9.0 – fix CVE-2019-14745
In the nfs-utils package, providing support files for Network File System (NFS) including the rpc.statd daemon, the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files
* Rebase to 1.8.28 * Fixed CVE-2019-14287
Type: Vulnerability. Horner Automation Cscape is prone to multiple arbitrary code-execution vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Aironet Access Points is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Wireless LAN Controller is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Palo Alto Networks GlobalProtect Agent is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. ISC Kea is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Aironet Access Points is prone to an unauthorized access vulnerability; fixes are available.
Type: Vulnerability. Jenkins is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Pulse Connect Secure and Policy Secure are prone to an access-bypass vulnerability; fixes are available.
Type: Vulnerability. Pulse Connect Secure and Pulse Policy Secure are prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapter is prone to multiple arbitrary code-execution vulnerabilities; fixes are available.
Type: Vulnerability. Multiple Cisco Products are prone to a cross-site request-forgery vulnerability; fixes are available.
Type: Vulnerability. VMware SD-WAN by VeloCloud is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.
Type: Vulnerability. Npmjs ‘csv-parse’ module is prone to a denial-of-service vulnerability; fixes are available.
The fix for CVE-2019-10871 broke xpdf. This change has been reverted until a better fix can be developed.
The 5.3.6 update contains a number of important fixes across the tree.
The 5.3.6 update contains a number of important fixes across the tree.
The 5.3.6 update contains a number of important fixes across the tree.
== Security fixes == * (T230402, CVE-2019-16738) SECURITY: Add permission check for suppressed account to Special:Redirect. == Links to all mentioned tasks == * https://phabricator.wikimedia.org/T230402 * https://phabricator.wikimedia.org/T227662
Reading Time: ~ 2 min. Cryptominers Found in Audio Files Researchers have recently found that both cryptominers and backdoors are being deployed within WAV audio files on targeted systems. Using steganography, attackers can include components for both loading and executing malicious scripts, while still allowing some audio files to play normally. Along with the malicious […]
kernel: Use-after-free in __blk_drain_queue() function in block/blk-core.c (CVE-2018-20856) * kernel: Heap overflow in mwifiex_update_bss_desc_with_ie function in marvell/mwifiex/scan.c (CVE-2019-3846) * hardware: bluetooth: BR/EDR encryption key negotiation attacks (KNOB) (CVE-2019-9506) * kernel: Heap overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ [More…]
Two buffer allocation issues were identified in poppler. CVE-2019-9959
An update for jenkins is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for mediawiki is now available for Red Hat OpenShift Container Platform 3.11. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which
Type: Vulnerability. Eclipse Jetty is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.
Type: Vulnerability. Apache Axis is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to multiple arbitrary code-execution vulnerabilities; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Adobe Download Manager is prone to an insecure file-permission vulnerability; fixes are available.
Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Juniper Junos is prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Eclipse Jetty is prone to a security vulnerability; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to an arbitrary code-execution vulnerability; fixes are available.
Type: Vulnerability. Adobe Acrobat and Reader are prone to a cross-site scripting vulnerability; fixes are available.
Several cross-site scripting (XSS) vulnerabilities were discovered in WordPress, a popular content management framework. An attacker can use these flaws to send malicious scripts to an unsuspecting user.
In sudo, a program that provides limited super user privileges to specific users, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can
Reading Time: ~ 3 min. In May of 2018, the General Data Protection Regulation (GDPR) came into effect in the EU. Seemingly overnight, websites everywhere started throwing pop-ups to inform us about their use of cookies and our privacy rights. While the presence of the pop-ups may be reassuring to some (and annoying to others), […]
OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302) (CVE-2019-2949) * OpenJDK: Unexpected exception thrown during regular expression processing in Nashorn (Scripting, 8223518) (CVE-2019-2975) * OpenJDK: Out of bounds access in optimized String indexof implementation (Hotspot, 8224062) (CVE-2019-2977) * OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handl [More…]
OpenJDK: Improper handling of Kerberos proxy credentials (Kerberos, 8220302) (CVE-2019-2949) * OpenJDK: Unexpected exception thrown during regular expression processing in Nashorn (Scripting, 8223518) (CVE-2019-2975) * OpenJDK: Incorrect handling of nested jar: URLs in Jar URL handler (Networking, 8223892) (CVE-2019-2978) * OpenJDK: Incorrect handling of HTTP proxy responses in HttpURLConne [More…]
An update that fixes one vulnerability is now available.
An update is now available for Red Hat JBoss Data Virtualization. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
ESET Smart Home Research Team uncovers Echo, Kindle versions vulnerable to 2017 Wi-Fi vulnerabilities The post What was wrong with Alexa? How Amazon Echo and Kindle got KRACKed appeared first on WeLiveSecurity
ESET researchers describe recent activity of the infamous espionage group, the Dukes, including three new malware families The post Operation Ghost: The Dukes aren’t back – they never left appeared first on WeLiveSecurity
Several security issues were fixed in LibTIFF.
