Menu

Category Archives: Security

Articles about security

An update that contains security fixes can now be installed.

An update that solves one vulnerability and has two fixes is now available.

Security gone in 600 seconds: Make-me-admin hole found in Lenovo Windows laptop crapware. Delete it now

An update that solves three vulnerabilities and has two fixes is now available.

It was discovered that there was a remote arbitrary code vulnerability in commons-beanutils, a set of utilities for manipulating JavaBeans code.

The package nginx before version 1.16.1-1 is vulnerable to denial of service.

The package nginx-mainline before version 1.17.3-1 is vulnerable to denial of service.

The package firefox before version 68.0.2-1 is vulnerable to information disclosure.

The package subversion before version 1.12.2-1 is vulnerable to denial of service.

The package libreoffice-still before version 6.2.6-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure.

An update that fixes one vulnerability is now available.

Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in

Several vulnerabilities were discovered in Squid, a fully featured web proxy cache. The flaws in the HTTP Digest Authentication processing, the HTTP Basic Authentication processing and in the cachemgr.cgi allowed remote attackers to perform denial of service and cross-site scripting

Multiple security issues were discovered in QEMU, a fast processor emulator, which could result in denial of service, the execution of arbitrary code or bypass of ACLs.

security update

2019-08-14 – Fix compile issues – Fix output buffer size for lzo1x_decompress_safe() 2019-08-07 – Fix VerifyExtensionMap #179 2019-08-06 – Fix compile errors 2019-08-05 – Fix nfdump.1 man page. #175 – Fix off by 1 array. #173 – Fix use after free in ModifyCompressFile – Add bound checks in AddExporterStat #174 – Add bound checks in […]

security update

WordPress Plugins Exploited in Ongoing Attack, Researchers Warn

Three vulnerabilities were discovered in the HTTP/2 code of Nginx, a high-performance web and reverse proxy server, which could result in denial of service.

Someone find a make-me-admin hole in your laptop crapware? Don’t want fix the bug? Just move the EOL date – right, Lenovo?
Authorities arrest culprits for crypto mining at Ukraine nuclear plant

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Reading Time: ~ 2 min. Android Apps Riddled with Adware Another 85 photo and gaming apps have been removed from the Google Play store after they were discovered to have been distributing adware to the roughly 8 million users who had downloaded the fake apps. The adware itself is rather tricky: by sitting dormant on […]

News Wrap: Linux Utility Backdoor, Steam Zero Day Disclosure Drama
Lenovo High-Severity Bug Found in Pre-Installed Software
Cybercrook hands cops £923k in Bitcoin made from selling phished deets on the dark web

An update that fixes one vulnerability is now available.

YouTube joins Facebook and Twitter, disabling accounts targeting Hong Kong protests
GitHub upgrades two-factor authentication with WebAuthn support
Steam cleaned of zero-day security holes after Valve turned off by bug bounty snub outrage

This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of

This update includes the latest release of the Apache HTTP Server, version `2.4.41`, fixing various security issues. Several major enhancements are also included in this update: * `mod_md` is now packaged from upstream *github* releases, adding support for ACMEv2. * `mod_cgid` stderr handling has been improved See http://www.apache.org/dist/httpd/CHANGES_2.4.41 for a full list of

– update to the latest upstream release (fixes CVE-2019-9511 and CVE-2019-9513)

– Security fix for CVE-2019-13636 – Security fix for CVE-2019-13638

As browser rivals block third-party tracking, Google pitches ‘Privacy Sandbox’ peace plan

The latest security update of openjdk-7 caused a regression when applications relied on elliptic curve algorithms to establish SSL connections. Several duplicate classes were removed from rt.jar by the upstream developers of OpenJDK because they were also present in

Google Launches Open-Source Browser Extension for Ad Transparency

Two issues have been found in cups, the Common UNIX Printing System(tm). Basically both CVEs (CVE-2019-8675 and CVE-2019-8696) are about

An update that fixes two vulnerabilities is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that solves four vulnerabilities and has 7 fixes is now available.

An update that contains security fixes can now be installed.

Microsoft, PayPal & Facebook most targeted brands in phishing scams: Report
Contacts-slurping Android malware sneaked onto Google Play store – twice

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Risk Level: Very Low. Type: Trojan.

Building a Mobile Defense: 5 Key Questions to Ask
Spyware App on Google Play Gets Boot, Returns Days Later
Meet Utopia; a privacy focused decentralized P2P ecosystem
Block newly-registered domains to reduce security threats in your organisation
Shhh! Microsoft, Intel, Google and more sign up to the Confidential Computing Consortium
Security flaws caused by compiler optimizations