Menu

Latest articles

Version 6.7.4 (2024-03-21) Upgrade tcpdf tag encryption algorithm. Version 6.7.3 (2024-03-20) Fix regression issue #699. Version 6.7.2 (2024-03-18)

podman-tui release v1.0.0

This update contains security fixes for CVE-2024-29131 and CVE-2024-29133. See https://github.com/apache/commons-configuration/blob/master/RELEASE- NOTES.txt for changes in versions 2.10.0 and 2.10.1.

CVE-2024-2004: Usage of disabled protocol If all protocols are disabled at run-time with none being added, curl/libcurl would still allow communication with the default set of allowed protocols, including some that are unencrypted. CVE-2024-2398: HTTP/2 push headers memory-leak

update to 123.0.6312.86 Critical CVE-2024-2883: Use after free in ANGLE High CVE-2024-2885: Use after free in Dawn High CVE-2024-2886: Use after free in WebCodecs High CVE-2024-2887: Type Confusion in WebAssembly

https://security-tracker.debian.org/tracker/DSA-5649-1

JetBrains keeps mum on 26 ‘security problems’ fixed after Rapid7 spat
FTX crypto-crook Sam Bankman-Fried gets 25 years in prison
Nvidia’s newborn ChatRTX bot patched for security bugs
Sellafield nuclear waste dump faces prosecution over cybersecurity failures
US critical infrastructure cyberattack reporting rules inch closer to reality

* bsc#1218610 Cross-References: * CVE-2023-51779

* bsc#1218487 * bsc#1218610 Cross-References: * CVE-2023-51779

* bsc#1218487 Cross-References: * CVE-2023-6531

* bsc#1208911 * bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

Canonical cracks down on crypto cons following Snap Store scam spree
INC Ransom claims responsibility for attack on NHS Scotland
These 17,000 unpatched Microsoft Exchange servers are a ticking time bomb
AI hallucinates software packages and devs download them – even if potentially poisoned with malware
Execs in Japan busted for winning dev bids then outsourcing to North Koreans
China encouraged armed offensive against Myanmar government to protest proliferation of online scams
Smashing Security podcast #365: Hacking hotels, Google’s AI goof, and cyberflashing
Apple fans deluged with phony password reset requests
Majority of Americans now use ad blockers
‘Thousands’ of businesses at mercy of miscreants thanks to unpatched Ray AI flaw
Ransomware hits The Big Issue. Qilin group leaks confidential data
Meta accused of snarfing people’s Snapchat data via traffic decryption
Miscreants are exploiting enterprise tech zero days more and more, Google warns

Several security issues were fixed in curl.

* bsc#1221237 * bsc#1221468 Cross-References: * CVE-2024-1441

* bsc#1220770 * bsc#1220771 Cross-References: * CVE-2024-26458

* bsc#1144060 * bsc#1176006 * bsc#1188307 * bsc#1203823 * bsc#1205502

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Street newspaper appears to have Big Issue with Qilin ransomware gang
Trezor’s Twitter account hijacked by cryptocurrency scammers via bogus Calendly invite
The easy road to pervasive DLP
Uncle Sam’s had it up to here with ‘unforgivable’ SQL injection flaws
Ransomware can mean life or death at hospitals, but DEF CON hackers have a plan

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

Several security issues were fixed in Thunderbird.

FreeBSD Foundation hands out Beacon gongs for safer software

PAM could be made to stop responding if it opened a specially crafted file.

UK elections are unaffected by China’s cyber-interference, says deputy PM

* bsc#1215887 * bsc#1216898 * bsc#1218487 * bsc#1218610

* bsc#1218487 * bsc#1218610 * bsc#1219157 Cross-References:

Row breaks out over true severity of two DNSSEC flaws
New Zealand to world: China attacked us, too!
US charges Chinese nationals with cyber-spying on pretty much everyone for Beijing

https://security-tracker.debian.org/tracker/DSA-5647-1

https://security-tracker.debian.org/tracker/DSA-5646-1

Over 170K users hit by poisoned Python package ruse
AceCryptor attacks surge in Europe – Week in security with Tony Anscombe

The second half of 2023 saw massive growth in AceCryptor-packed malware spreading in the wild, including courtesy of multiple spam campaigns where AceCryptor packed the Rescoms RAT

Notorious Nemesis Market zapped by video game-loving German police
Tech trade union confirms cyberattack behind IT, email outage
Puppet’s devops report plumbs the benefits of platform engineering
Mozilla fixes $100,000 Firefox zero-days following two-day hackathon
GoFetch security exploit can’t be disabled on M1 and M2 Apple chips

Stack-based buffer overflow has been fixed in gross, a server for greylisting emails. For Debian 10 buster, this problem has been fixed in version

QPDF could be made to crash or run programs if it opened a specially crafted file.

Net::CIDR::Lite could allow unintended access to network services.

It was discovered that there was a command-line injection issue in the FreeIPA identity, authentication and audit framework. A specially crafted HTTP request could have lead to a Denial of Service (DoS) attack and/or data exposure.

Insights Advisor for OpenShift – How to react to Advisor recommendations
Charting the Course of Cybersecurity Education for Linux Admins
Ransomware: lessons all companies can learn from the British Library attack
Time to examine the anatomy of the British Library ransomware nightmare
10 cloud development gotchas to watch out for
That Asian meal you eat on holidays could launder money for North Korea

Several security issues were fixed in Firefox.

Microsoft confirms memory leak in March Windows Server security update

New upstream version (124.0.1)

https://security-tracker.debian.org/tracker/DSA-5645-1

Some 300,000 IPs vulnerable to this Loop DoS attack

Multiple security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in cross-site scripting, SQL injection, or command injection.

Vans claims cyber crooks didn’t run off with its customers’ financial info

Buffer Overflow vulnerability in FreeImage_AllocateBitmap. (CVE-2023-47995) Infinite loop exits in Load in PluginTIFF.cpp. (CVE-2023-47997) References:

The updated package fixes security vulnerabilities: pluto in Libreswan before 4.11 allows a denial of service (responder SPI mishandling and daemon crash) via unauthenticated IKEv1 Aggressive Mode packets. (CVE-2023-30570) An issue was discovered in Libreswan before 4.12. When an IKEv2 Child SA

Patch CVE-2023-4256 and CVE-2023-43279

Updates google.golang.org/protobuf to v1.33.0 to resolve CVE-2024-24786. Kubernetes is now built with go 1.21.8.

Security fix for CVE-2024-22871 Update to upstream release 1.11.2

Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or leaks of encrypted email subjects.

Russia’s Cozy Bear caught phishing German politicos with phony dinner invites

An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could […]

Update to version 2.13.1 Fix CVE-2024-28054

update to xen-4.18.1 rebase xen.gcc12.fixes.patch remove patches now included or superceded upstream x86: Register File Data Sampling [XSA-452, CVE-2023-28746] GhostRace: Speculative Race Conditions [XSA-453, CVE-2024-2193]

Updated to 124.0 Updated to latest upstream (123.0.1)

Added upstream patch to fix out-of-bounds access due to multiple backspaces to address incomplete fix for CVE-2022-38223 (#2222775, #2222780, #2255207)

Chinese snoops use F5, ConnectWise bugs to sell access into top US, UK networks

https://security-tracker.debian.org/tracker/DSA-5644-1

Java 22 brings security enhancements
3 million doors open to uninvited guests in keycard exploit
Hardware-level Apple Silicon vulnerability can leak cryptographic keys
NVD slowdown leaves thousands of vulnerabilities without analysis data

Graphviz could be made to crash if it opened a specially crafted config6a file.

* bsc#1221323 Cross-References: * CVE-2023-22655 * CVE-2023-28746

* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773

* bsc#1219357 * bsc#1219554 Cross-References: * CVE-2020-36773