This update upgrades Thunderbird to version 102.9.0. * Mozilla: Incorrect code generation during JIT compilation (CVE-2023-25751) * Mozilla: Memory safety bugs fixed in Firefox 111 and Firefox ESR 102.9 (CVE-2023-28176) * Mozilla: Potential out-of-bounds when accessing throttled streams (CVE-2023-25752) * Mozilla: Invalid downcast in Worklets (CVE-2023-28162) * Mozilla: URL being dragged fr [More…]
Here are some of the key moments from the five hours of Shou Zi Chew’s testimony and other interesting news on the data privacy front The post Highlights from TikTok CEO’s Congress grilling – Week in security with Tony Anscombe appeared first on WeLiveSecurity
As TikTok CEO attempts to placate U.S. lawmakers, it’s time for us all to think about the wealth of personal information that TikTok and other social media giants collect about us The post What TikTok knows about you – and what you should know about TikTok appeared first on WeLiveSecurity
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
update to 111.0.5563.110. Fixes the following security issues: CVE-2023-1528 CVE-2023-1529 CVE-2023-1530 CVE-2023-1531 CVE-2023-1532 CVE-2023-1533 CVE-2023-1534
Rebuild for CVE-20220-{3064,41717,41723}
security update
security update
New tar packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.
This update includes the changes in tzdata 2023b for the Perl bindings. For the list of changes, see DLA-3366-1. For Debian 10 buster, this problem has been fixed in version
This update includes the changes in tzdata 2023b. Notable changes are: – – Egypt uses DST again, starting on April.
Incorrect code generation during JIT compilation. (CVE-2023-25751) Potential out-of-bounds when accessing throttled streams. (CVE-20223-25752) Invalid downcast in Worklets. (CVE-2023-28162) URL being dragged from a removed cross-origin iframe into the same tab triggered navigation. (CVE-2023-28164)
If a malicious Flatpak app is run on a Linux virtual console such as /dev/tty1, it can copy text from the virtual console and paste it back into the virtual console’s input buffer, from which the command might be run by the user’s shell after the Flatpak app has exited. This is similar to CVE-2017-5226, […]
In the MHD_PostProcessor, malformed inputs can be used to crash the server (for denial-of-service). References: – https://bugs.mageia.org/show_bug.cgi?id=31670
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. (CVE-2022-4645) References:
Why your organization should consider an MDR solution and five key things to look for in a service offering The post Understanding Managed Detection and Response – and what to look for in an MDR solution appeared first on WeLiveSecurity
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.3/toolbox was updated. The following patches have been included in this update:
Several security issues were fixed in amanda.
The container bci/golang was updated. The following patches have been included in this update:
The container suse/389-ds was updated. The following patches have been included in this update:
The container suse/sles12sp5 was updated. The following patches have been included in this update:
The container suse/sle-micro/5.4/toolbox was updated. The following patches have been included in this update:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Twitter’s ditching of free text-message authentication doesn’t mean that you should forgo using 2FA. Instead, switch to another – and, indeed, better – 2FA option. The post Twitter ends free SMS 2FA: Here’s how you can protect your account now appeared first on WeLiveSecurity
USN-5904-1 caused a minor regression in SoX.
The container bci/nodejs was updated. The following patches have been included in this update:
TigerVNC could be made to expose sensitive information over the network.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in Vim.
Python could be made to bypass blocklisting methods if a specially crafted URL was provided.
One of the security fixes released as DLA 3315 introduced a regression in the processing WAV files with variable bitrate encoding. Updated sox packages are available to correct this issue.
Multiple security issues were discovered in Thunderbird, which could result in denial of service, the execution of arbitrary code or spoofing.
The newest upstream commit Security fixes for CVE-2023-1175, CVE-2023-1170, CVE-2023-1264.
Update to 1.15.4 * Fix CVE-2023-28100 and CVE-2023-28101
Update to 102.9.0 ; https://www.mozilla.org/en- US/security/advisories/mfsa2023-11/ ; https://www.thunderbird.net/en- US/thunderbird/102.9.0/releasenotes/
Denial of service using crafted input. (CVE-2022-40152) References: – https://bugs.mageia.org/show_bug.cgi?id=31665 – https://lists.suse.com/pipermail/sle-security-updates/2023-March/013995.html
Remote code execution on feed enrichment. If “Extract full content from HTML5 and Google AMP” has been enabled for one or more feed subscriptions it is possible for a an attacker to inject a script command that runs with user priveleges. (CVE-2023-1350)
An out-of-bounds write vulnerability exists in TPM2.0’s Module Library allowing writing of a 2-byte data past the end of TPM2.0 command in the CryptParameterDecryption routine. An attacker who can successfully exploit this vulnerability can lead to denial of service (crashing the TPM chip/process or rendering it unusable) and/or arbitrary code execution in
A potential buffer overflow exists in the file src/w_help.c at line 55. Specifically, the length of the string returned by getenv(“LANG”) may become very long and cause a buffer overflow while executing the sprintf() function. This vulnerability could potentially allow an attacker to execute arbitrary code or cause a denial-of-service condition.
Some mod_proxy configurations on Apache HTTP Server allow a HTTP request smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied
Scammers are looking to cash in on the chaos that has set in following the startling meltdowns of Silicon Valley Bank and Signature Bank and the crisis at Credit Suisse The post Banking turmoil opens opportunities for fraud – Week in security with Tony Anscombe appeared first on WeLiveSecurity
The container suse/sle-micro/5.2/toolbox was updated. The following patches have been included in this update:
The container suse/sle-micro/5.1/toolbox was updated. The following patches have been included in this update:
