The container bci/python was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/bci-init was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
The container bci/golang was updated. The following patches have been included in this update:
The attack involved the first recorded abuse of a security vulnerability in a Dell driver that was patched in May 2021 The post ESET Research into new attacks by Lazarus – Week in security with Tony Anscombe appeared first on WeLiveSecurity
ESET researchers have discovered Lazarus attacks against targets in the Netherlands and Belgium that use spearphishing emails connected to fake job offers The post Amazon‑themed campaigns of Lazarus in the Netherlands and Belgium appeared first on WeLiveSecurity
An update that fixes two vulnerabilities is now available.
The container suse/sles12sp4 was updated. The following patches have been included in this update:
Two issues were found in GDAL, a geospatial library, that could lead to denial of service via application crash or possibly the execution of arbitrary code if maliciously crafted data was parsed.
thenify is a Promisify a callback-based function using any-promise. Affected versions of this package are vulnerable to Arbitrary Code Execution. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval
Update to 102.3.1 * https://www.mozilla.org/en- US/security/advisories/mfsa2022-43/ * https://www.thunderbird.net/en- US/thunderbird/102.3.1/releasenotes/
security update
An issue has been found in tinyxml, a C++ XML parsing library. Crafted XML messages could lead to an infinite loop in TiXmlParsingData::Stamp(), which results in a denial of service.
Online predators increasingly trick or coerce youth into sharing explicit videos and photos of themselves before threatening to post the content online The post Protecting teens from sextortion: What parents should know appeared first on WeLiveSecurity
An issue has been found in libhttp-daemon-perl, a simple http server class. Due to insufficient Content-Length: handling in HTTP-header an attacker
An update that solves three vulnerabilities and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
This update upgrades Thunderbird to version 102.3.0. * Mozilla: Leaking of sensitive information when composing a response to an HTML email with a META refresh tag (CVE-2022-3033) * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 […]
This update upgrades Firefox to version 102.3.0 ESR. * Mozilla: Bypassing FeaturePolicy restrictions on transient pages (CVE-2022-40959) * Mozilla: Data-race when parsing non-UTF-8 URLs in threads (CVE-2022-40960) * Mozilla: Memory safety bugs fixed in Firefox 105 and Firefox ESR 102.3 (CVE-2022-40962) * Mozilla: Bypassing Secure Context restriction for cookies with __Host and __Secure pref [More…]
security update
security update
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes three vulnerabilities is now available.
security update
security update
Several vulnerabilities were discovered in lighttpd, a fast webserver with minimal memory footprint. CVE-2022-37797
An update that fixes two vulnerabilities is now available.
It was discovered that the Commandline class in maven-shared-utils, a collection of various utility classes for the Maven build system, can emit double-quoted strings without proper escaping, allowing shell injection attacks.
An update that solves 20 vulnerabilities and has 8 fixes is now available.
Memory-related security fixes, BZ 2127755
The container suse/sle15 was updated. The following patches have been included in this update:
security update
security update
Had your Instagram account stolen? Don’t panic – here’s how to get your account back and how to avoid getting hacked (again) The post What happens with a hacked Instagram account – and how to recover it appeared first on WeLiveSecurity
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
Several security issues were fixed in Ghostscript.
An update that solves 11 vulnerabilities and has 21 fixes is now available.
Several security issues were fixed in WebKitGTK.
Several security issues were fixed in Squid.
Several security issues were fixed in the Linux kernel.
Several security issues were fixed in the Linux kernel.
An update that solves one vulnerability and has two fixes is now available.
Expat could be made to crash or execute arbitrary code.
