security update
security update
security update
security update
security update
The following vulnerabilities have been discovered in the WPE WebKit web engine: CVE-2022-32792
USN-5526-1 introduced a regression in PyJWT.
The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-32792
The container suse/sles12sp4 was updated. The following patches have been included in this update:
Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2
Update to yara-4.2.3 —- Update to 4.2.0 —- Update to 4.2.2
security update
Don’t worry, elections are safe. Our Security Researcher Cameron Camp provide us highlights from the DEF CON 30 conference. The post DEF CON – “don’t worry, the elections are safe” edition appeared first on WeLiveSecurity
An update that solves one vulnerability, contains one feature and has 7 fixes is now available.
An update that fixes 22 vulnerabilities is now available.
An update that contains security fixes can now be installed.
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
The Sender Policy Framework can’t help prevent spam and phishing if you allow billions of IP addresses to send as your domain The post How a spoofed email passed the SPF check and landed in my inbox appeared first on WeLiveSecurity
An update that fixes three vulnerabilities is now available.
The digital skills gap, especially in cybersecurity, is not a new phenomenon. This problematic is now exacerbate by the prevalence of burnout, which was presented at Black Hat USA 2022 The post Black Hat USA 2022: Burnout, a significant issue appeared first on WeLiveSecurity
Windows used to be the big talking point when it came to exploits resulting in mass casualties. Nowadays, talks turned to other massive attack platforms like #cloud and cars The post Black Hat – Windows isn’t the only mass casualty platform anymore appeared first on WeLiveSecurity
Several security issues were fixed in WebKitGTK.
An update for .NET Core 3.1 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.2 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for collectd-libpod-stats is now available for Red Hat OpenStack Platform 16.1 (Train). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for .NET 6.0 is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
Multiple vulnerabilities have been discovered in libarchive, the worst of which could result in arbitrary code execution.
Multiple vulnerabilities have been discovered in QEMU, the worst of which could result in remote code execution (guest sandbox escape).
Multiple vulnerabilities have been found in Chromium and its derivatives, the worst of which could result in remote code execution.
Multiple vulnerabilities have been discovered in the GNU C Library, the worst of which could result in denial of service.
Multiple vulnerabilities have been discovered in Xen, the worst of which could result in remote code execution (guest sandbox escape).
The 5.18.17 stable kernel update contains a number of important fixes across the tree.
security update
The NHS was victim of a potential cyberattack, which raises the question of the impact of those data breach for the public. The post The potential consequences of data breach, and romance scams – Week in security with Tony Anscombe appeared first on WeLiveSecurity
Our Security evangelist’s take on this first day of Black Hat 2022, where cyberdefense was on every mind. The post Black Hat 2022‑ Cyberdefense in a global threats era appeared first on WeLiveSecurity
Tinder, Bumble or Grindr – popular dating apps depend heavily on your location, personal data, and loose privacy settings. Find out how to put yourself out there safely by following our suggested settings tweaks. The post Safety first: how to tweak the settings on your dating apps appeared first on WeLiveSecurity
The container bci/bci-micro was updated. The following patches have been included in this update:
A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit (CVE-2022-34526) References: – https://bugs.mageia.org/show_bug.cgi?id=30716
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service. (CVE-2022-32189) References:
A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. (CVE-2022-27337) References:
An issue was discovered in Django 3.2 before 3.2.14 and 4.0 before 4.0.6. The Trunc() and Extract() database functions are subject to SQL injection if untrusted data is used as a kind/lookup_name value. Applications that constrain the lookup name and kind choice to a known safe list are unaffected. (CVE-2022-34265)
Sinatra before 2.2.0 does not validate that the expanded path matches public_dir when serving static files. (CVE-2022-29970) References: – https://bugs.mageia.org/show_bug.cgi?id=30542
security update
A deep-dive in Zero-trust, to help you navigate in a zero-trust world and further secure your organization. The post An eighties classic – Zero Trust appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
Several vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in HTTP request smuggling, cache poisoning or information disclosure.
The container bci/rust was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/bci-micro was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
