Type: Vulnerability. Microsoft ASP.NET Core is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft MSR JavaScript Cryptography Library is prone to a remote security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft .NET Framework is prone to a remote code-execution vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan.
Type: Vulnerability. Microsoft Office is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Visual Studio is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft .NET Framework is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Macro Assembler is prone to a security bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote denial of service vulnerability; fixes are available.
Type: Vulnerability. Microsoft .NET Framework is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Wireless Display Adapter is prone to a command-injection vulnerability; fixes are available.
Type: Vulnerability. Microsoft SharePoint Server is prone to a remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft WordPad is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Microsoft Web Customization for ADFS is prone to a cross-site scripting vulnerability; fixes are available.
LinuxSecurity.com: Orange Tsai discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker can take advantage of this flaw to read arbitrary files outside an application’s root directory via specially crafted requests, when the Sprockets server is
Risk Level: Very Low. Type: Trojan.
D-Link and Changing Information Technologies code-signing certificates stolen and abused by highly skilled cyberespionage group focused on East Asia, particularly Taiwan The post Certificates stolen from Taiwanese tech-companies misused in Plead malware campaign appeared first on WeLiveSecurity
LinuxSecurity.com: Fix CVE-2018-13054 cinnamon: privilege escalation in cinnamon-settings-users.py GUI
LinuxSecurity.com: Several security vulnerabilities were found in Bouncy Castle, a Java implementation of cryptographic algorithms. CVE-2016-1000338
LinuxSecurity.com: New upstream version
LinuxSecurity.com: ## 3.3.17 (2018-05-25) * security #cve-2018-11407 [Ldap] cast to string when checking empty passwords * security #cve-2018-11408 [SecurityBundle] Fail if security.http_utils cannot be configured * security #cve-2018-11406 clear CSRF tokens when the user is logged out * security #cve-2018-11385 migrating session for UsernamePasswordJsonAuthenticationListener * security #cve-2018-11386
LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.
LinuxSecurity.com: Latest upstream release, omits some mounting code found to be insecure and not well tested.
LinuxSecurity.com: There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered “valid” or otherwise should be trusted.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that solves one vulnerability and has two fixes is now available.
LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.
LinuxSecurity.com: An update that fixes 11 vulnerabilities is now available.
LinuxSecurity.com: An update that solves two vulnerabilities and has one errata is now available.
security update
security update
The attack, called “Thermanator”, could use your body heat against you in order to steal your credentials or any other short string of text that you have typed on a computer keyboard The post Attackers could use heat traces left on keyboard to steal passwords appeared first on WeLiveSecurity
LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.
LinuxSecurity.com: Several vulnerabilities were found in phpMyAdmin, the web-based MySQL administration interface, including SQL injection attacks, denial of service, arbitrary code execution, cross-site scripting, server-side request forgery, authentication bypass, and file system traversal.
Reading Time: ~2 min.Canadian college breach targets thousands Last Friday, Algonquin College officials announced that an earlier data breachpotentially affected thousands of current and former students, as well as employees. While it is still unclear exactly what systems were affected, the officials have been working to contact all potential victims and inform them of the […]
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes two vulnerabilities is now available.
LinuxSecurity.com: An update that fixes one vulnerability is now available.
LinuxSecurity.com: An update that fixes three vulnerabilities is now available.
LinuxSecurity.com: It was discovered that the Soup HTTP library performed insuffient validation of cookie requests which could result in an out-of-bounds memory read.
LinuxSecurity.com: The system could be made to expose sensitive information.
LinuxSecurity.com: Some security vulnerabilities were found in Mercurial which allow authenticated users to trigger arbitrary code execution and unauthorized data access in certain server configuration. Malformed patches and repositories can also lead to crashes and arbitrary code
LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.
LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.
LinuxSecurity.com: Archive Zip module could be made to expose sensitive information if it received a specially crafted input.
Risk Level: Very Low. Type: Trojan.
Recommendations for pentesters looking for security flaws in iOS applications made by developers The post Five tips for pentesters in iOS appeared first on WeLiveSecurity
