Igor Ponomarev discovered that LAVA, a continuous integration system for deploying operating systems onto physical and virtual hardware for running tests, was susceptible to denial of service via recursive XML entity expansion.
It was discovered that the CompareTool of iText, a Java PDF library which uses the external ghostscript software to compare PDFs at a pixel level, allowed command injection when parsing a specially crafted filename.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
security update
security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or spoofing.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42852
– Update to 109.0
New sudo packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix a security issue.
It was discovered that the CompareTool of iText, a Java PDF library which uses the external ghostscript software to compare PDFs at a pixel level, allowed command injection when parsing a specially crafted filename.
Sudo could be made to possibly edit arbitrary files if it received a specially crafted input.
Don’t be the next victim – here’s what to know about some of the most common tricks that scammers use on the payment app The post Top 10 Venmo scams – and how to stay safe appeared first on WeLiveSecurity
New mozilla-firefox packages are available for Slackware 15.0 and -current to fix security issues.
New libXpm packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.
New httpd packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.
New git packages are available for Slackware 14.0, 14.1, 14.2, 15.0, and -current to fix security issues.
Security fix for CVE-2022-46391
Security fix for CVE-2022-46391
security update
It is now acceptable to find a job on a dating app! The post Hybrid commerce: Blurring the lines between business and pleasure appeared first on WeLiveSecurity
The container bci/python was updated. The following patches have been included in this update:
The container bci/python was updated. The following patches have been included in this update:
The container suse/389-ds was updated. The following patches have been included in this update:
An update that contains security fixes can now be installed.
The container sles-15-sp4-chost-byos-v20230111-arm64 was updated. The following patches have been included in this update:
A logic error was discovered in the implementation of the “SafeSocks” option of Tor, a connection-based low-latency anonymous communication system, which did result in allowing unsafe SOCKS4 traffic to pass.
An update for libxml2 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for dpdk is now available for Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for dpdk is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for dpdk is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for dpdk is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support, Red Hat Enterprise Linux 8.2 Telecommunications Update Service, and Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions.
An update for dpdk is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
menglong2234 discovered NULL pointer exceptions in net-snmp, a suite of Simple Network Management Protocol applications, which could could result in debian of service.
The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.
The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.
The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.
The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.
The 6.1.5 stable kernel rebase contains new features, enhanced hardware support, and a number of important fixes across the tree.
security update
security update
security update
StrongPity’s backdoor is fitted with various spying features and can record phone calls, collect texts, and gather call logs and contact lists The post APT group trojanizes Telegram app – Week in security with Tony Anscombe appeared first on WeLiveSecurity
v1.5.1 – fix logging to stdout when –stdout is used *thanks to Eta – update –treshold option accept decimal numbers as parameter – fix crashes when processing certain broken JPEG images – fix memory leaks – fix (logging) output in parallel processing mode
Security fix for CVE-2022-45061: CPU denial of service via inefficient IDNA decoder
New netatalk packages are available for Slackware 14.1, 14.2, 15.0, and -current to fix a security issue.
Several security issues were fixed in the Linux kernel.
Two vulnerabilities were discovered in the LLPD implementation of Open vSwitch, software-based Ethernet virtual switch, which could result in denial of service.
Igor Ponomarev discovered that LAVA, a continuous integration system for deploying operating systems onto physical and virtual hardware for running tests, was suspectible to denial of service via recursive XML entity expansion.
ESET Research announces IPyIDA 2.0, a Python plugin integrating IPython and Jupyter Notebook into IDA The post Introducing IPyIDA: A Python plugin for your reverse‑engineering toolkit appeared first on WeLiveSecurity
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
security update
security update
security update
