Menu

Category Archives: Security

Articles about security

An update that fixes 15 vulnerabilities is now available.

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1650

Upstream details at : https://access.redhat.com/errata/RHSA-2019:1652

You lost US Customs Border data? You’re losing your government contracts…
US Cyber Command warns nation-state hackers are exploiting old Microsoft Outlook bug. Make sure you’re patched!

Two vulnerabilities have been discovered in pdns, an authoritative DNS server which may result in denial of service via malformed zone records and excessive NOTIFY packets in a master/slave setup.

An update that solves two vulnerabilities and has two fixes is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

Russian ‘Silence’ hacking crew turns up the volume – with $3m-plus cyber-raid on bank’s cash machines

An update for jenkins-2-plugins is now available for Red Hat OpenShift Container Platform 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,

Here’s a great idea: Why don’t we hardcode the same private key into all our smart home hubs?
$30/month email upstart Superhuman brought low with a blast of privacy Kryptonite
Cloudflare’s recent 502 Bad Gateway outage blamed on bad software

Update to v5.1.15 —- Update to v5.1.14

Update to v5.1.15 —- Update to v5.1.14

Security Camera Firm Arlo Zaps High-Severity Bugs

security update

security update

IBM Patches Critical, High-Severity Flaws in Spectrum Protect
We are shocked to learn oppressive authoritarian surveillance state China injects spyware into foreigners’ smartphones
Google July Android Security Bulletin Fixes 3 Critical RCE Bugs
Two billion user logs leaked by smart home vendor

The leak, which apparently has yet to be plugged, exposes a range of very specific data about users The post Two billion user logs leaked by smart home vendor appeared first on WeLiveSecurity

Mobile app building is simple and affordable – the Appy Pie way!
Mac Malware Pushed via Google Search Results, Masquerades as Flash Installer

A specially crafted URL in can potentially cause cgit to excessively use CPU and network resources, resulting in a Denial-of-Service. This update resolves that issue

Several security issues were fixed in Thunderbird.

Updated firefox packages fix a security vulnerability thats being exploited in the wild: sandbox escape using Prompt:Open. (CVE-2019-11708)

An update that fixes one vulnerability is now available.

An update that solves three vulnerabilities and has one errata is now available.

An update that fixes one vulnerability is now available.

libssh2: Integer overflow in transport read resulting in out of bounds write (CVE-2019-3855) * libssh2: Integer overflow in keyboard interactive handling resulting in out of bounds write (CVE-2019-3856) * libssh2: Integer overflow in SSH packet processing channel resulting in out of bounds write (CVE-2019-3857) * libssh2: Integer overflow in user authenticate keyboard interactive allows out […]

An update that fixes one vulnerability is now available.

QEMU: Slirp: information leakage in tcp_emu() due to uninitialized stack variables (CVE-2019-9824) SL6 x86_64 qemu-guest-agent-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-img-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-debuginfo-0.12.1.2-2.506.el6_10.4.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.506.el6_10.4.x86_64.rpm i386 qemu-gue [More…]

An update that solves one vulnerability and has one errata is now available.

Updated thunderbird packages fix security vulnerabilities: Type confusion in Array.pop. (CVE-2019-11707) Sandbox escape using Prompt:Open. (CVE-2019-11708)

An update for spacewalk-backend is now available for Red Hat Satellite 5.8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from

July is here – and so are the latest Android security fixes. Plenty of critical updates for all
Cop a load of this: 1TB of police body camera videos found lounging around public databases
Is Your VPN Provider in a 14 Eyes Country? (What is 14 Eyes?)
Facebook staff sarin for a bad day: Suspected chemical weapon parcel sent to Silicon Valley HQ
Finding Beauty in the IT Architecture
Facebook Removes Accounts Used to Infect Thousands With Malware
Hacker deletes entire student newspaper website of University of Ottawa
Ex-Equifax CIO, who knew about huge data breach, jailed for insider trading
Ex-Equifax executive sent to jail for insider trading after breach

“Sounds bad”, the former Equifax CIO wrote in a text after learning of the breach that ended up affecting almost half the US population The post Ex-Equifax executive sent to jail for insider trading after breach appeared first on WeLiveSecurity

Dating App Jack’d Fined After Leaking Users’ Nude Pics
Don’t tell Alice and Bob: Security maven Bruce Schneier is leaving IBM

An update that fixes two vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

An update that solves 9 vulnerabilities and has two fixes is now available.

An update that solves one vulnerability and has one errata is now available.

An update that fixes four vulnerabilities is now available.

openSUSE: openSUSE Leap 42.3 has reached end of SUSE support

Malware makes an exhibition of itself

vim/neovim: ‘:source!’ command allows arbitrary command execution via modelines (CVE-2019-12735) SL7 x86_64 vim-X11-7.4.160-6.el7_6.x86_64.rpm vim-common-7.4.160-6.el7_6.x86_64.rpm vim-debuginfo-7.4.160-6.el7_6.x86_64.rpm vim-enhanced-7.4.160-6.el7_6.x86_64.rpm vim-filesystem-7.4.160-6.el7_6.x86_64.rpm vim-minimal-7.4.160-6.el7_6.x86_64.rpm – Scientific Linux Develo [More…]

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalu [More…]

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) SL7 x86_64 firefox-60.7.2-1.el7_6.x86_64.rpm firefox-debuginfo-60.7.2-1.el7_6.x86_64.rpm firefox-60.7.2-1.el7_6.i686.rpm firefox-debuginfo-60.7.2-1.el7_6.i686.rpm – Scientific Linux Development Team

Several security issues were fixed in Django.

Yuge U-turn: Prez Trump walks back on Huawei ban… at least the tech sector seems to think so
White House mulls just banning strong end-to-end crypto. Plus: More bad stuff in infosec land
Worried about hacker-infested waters? Fret not. Sophos Security SOS Week will come to the rescue this month

It was discovered that Expat, an XML parsing C library, did not properly handle XML input including XML names that contain a large number of colons, potentially resulting in denial of service.

An update that solves one vulnerability and has one errata is now available.

An update that fixes one vulnerability is now available.

An update that contains security fixes can now be installed.

– Update to 4.1.10 Release notes: https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10 Security Advisory: https://doc.powerdns.com/authoritative/security- advisories/powerdns-advisory-2019-04.html https://doc.powerdns.com/authoritative/security-advisories/powerdns-

– Update to 4.1.10 Release notes: https://doc.powerdns.com/authoritative/changelog/4.1.html#change-4.1.10 Security Advisory: https://doc.powerdns.com/authoritative/security- advisories/powerdns-advisory-2019-04.html https://doc.powerdns.com/authoritative/security-advisories/powerdns-

New bug and security fix release, see http://www.graphicsmagick.org/NEWS.html#june-15-2019

security update

New irssi packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.

Popular Android Zombie game phish users to steal Gmail credentials

Several security issues were fixed in the Linux kernel.

Several security issues were fixed in the Linux kernel.

Scumbags can program vulnerable MedTronic insulin pumps over the air to murder diabetics – insecure kit recalled
New Dridex Variant Slips By Anti-Virus Detection
MongoDB Leak Exposed Millions of Medical Insurance Records
Iran’s blame-it-on-Bitcoin ‘leccy shortage probably isn’t a US hack cover story… yet
Crooks steal $28M in crypto using Google Adwords & spoofed domains

Reading Time: ~ 2 min. Second Florida City Pays Ransom Following the news that Riviera Beach, FL would pay the ransom demanded by cyberattackers, the mayor of Lake City, FL has announced that the city will be paying the demanded ransom of $460,000 to restore access to their email and internal system servers. While law […]

Mozilla’s ‘Track This’ lets you choose fake identity to deceive advertisers
FDA Warns of Potentially Fatal Flaws in Medtronic Insulin Pumps
Fortune 100 passwords, email archives, and corporate secrets left exposed on unsecured Amazon S3 servers

An update that fixes 53 vulnerabilities is now available.

An update that fixes 53 vulnerabilities is now available.

Death of the VPN: Enterprise Security Needs New Foundations

Update to v5.1.15 —- Update to v5.1.14

Update to v5.1.15 —- Update to v5.1.14

Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in

An update that fixes 22 vulnerabilities is now available.

Mozilla: Type confusion in Array.pop (CVE-2019-11707) * thunderbird: Stack buffer overflow in icalrecur_add_bydayrules in icalrecur.c (CVE-2019-11705) * Mozilla: Sandbox escape using Prompt:Open (CVE-2019-11708) * thunderbird: Heap buffer over read in icalparser.c parser_get_next_char (CVE-2019-11703) * thunderbird: Heap buffer overflow in icalmemory_strdup_and_dequote function in icalvalu [More…]

Several minor issues have been fixed in mupdf, a lightweight PDF viewer tailored for display of high quality anti-aliased graphics.

It was discovered that Expat, an XML parsing C library, did not properly handled XML input including XML names that contain a large number of colons, potentially resulting in denial of service.

– https://www.drupal.org/project/uuid/releases/7.x-1.3 – https://www.drupal.org/sa-contrib-2019-052

## php-typo3-phar-stream-wrapper2 ### v2.1.2 Handling mime-type & Windows paths #### Resolved Issues – #34: Normalize resolved Windows path to Unix-style – #42: Avoid analysing non-phar files on alias resolving – #40: Add Windows tests using AppVeyor – #33: Add alternative mime-type resolving (without ext- fileinfo) ### v2.1.1 Phar Alias Handling & Performance Releases v3.1.1 and

## php-typo3-phar-stream-wrapper2 ### v2.1.2 Handling mime-type & Windows paths #### Resolved Issues – #34: Normalize resolved Windows path to Unix-style – #42: Avoid analysing non-phar files on alias resolving – #40: Add Windows tests using AppVeyor – #33: Add alternative mime-type resolving (without ext- fileinfo) ### v2.1.1 Phar Alias Handling & Performance Releases v3.1.1 and