Listen to Aryeh Goretsky, Martin Smolár, and Jean-Ian Boutin discuss what UEFI threats are capable of and what the ESPecter bootkit tells us about their evolution The post ESET Research Podcast: UEFI in crosshairs of ESPecter bootkit appeared first on WeLiveSecurity
It was discovered that the previous upload to neutron to Debian 9 “Stretch” (ie. version 2:9.1.1-3+deb9u2) was incomplete and did not actually apply the fix for CVE-2021-40085.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
Several security issues were fixed in OpenSSL.
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious ‘fzsftp’ binary in the user’s home directory.
Several security issues were fixed in subversion.
security update
security update
Max Justicz reported a directory traversal vulnerability in Dpkg::Source::Archive in dpkg, the Debian package management system. This affects extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar.
Max Justicz reported a directory traversal vulnerability in Dpkg::Source::Archive in dpkg, the Debian package management system. This affects extracting untrusted source packages in the v2 and v3 source package formats that include a debian.tar.
An update that fixes one vulnerability is now available.
An update that fixes 15 vulnerabilities is now available.
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:
The landmark regulation changed everyone’s mindset on how companies worldwide collect and use the personal data of EU citizens The post 5 reasons why GDPR was a milestone for data protection appeared first on WeLiveSecurity
This update upgrades Firefox to version 91.9.1 ESR. * Mozilla: Untrusted input used in JavaScript object indexing, leading to prototype pollution (CVE-2022-1529) * Mozilla: Prototype pollution in Top-Level Await implementation (CVE-2022-1802) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 [More…]
Multiple security vulnerabilities were discovered in Puma, a HTTP server for Ruby/Rack applications, which could result in HTTP request smuggling or information disclosure.
Multiple vulnerabilities have been discovered in the lrzip compression program which could result in denial of service or potentially the execution of arbitrary code.
An update that solves one vulnerability, contains one feature and has two fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
security update
security update
security update
Several security issues were fixed in libpng.
Several security issues were fixed in Thunderbird.
Firefox could be made to execute JavaScript in a privileged context if it opened a malicious website.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
As NFTs exploded in popularity, scammers also jumped on the hype. Watch out for counterfeit NFTs, rug pulls, pump-and-dumps and other common scams plaguing the industry. The post Common NFT scams and how to avoid them appeared first on WeLiveSecurity
The updated postgresql packages fix a security vulnerability: Autovacuum, REINDEX, and others omit “security restricted operation” sandbox (CVE-2022-1552).
Manfred Paul discovered two security issues in the Mozilla Firefox web browser, which could result in the execution of arbitrary code. For the oldstable distribution (buster), these problems have been fixed
Nokogiri did not type-check all inputs into the XML and HTML4 SAX parsers, allowing specially crafted untrusted inputs to cause illegal memory access errors (segfault) or reads from unrelated memory. Version 1.13.6 contains a patch for this issue. As a workaround, ensure the untrusted input is a ‘String’ by calling ‘#to_s’ or equivalent.
This update provides ffmpeg version 4.3.4, which fixes several security vulnerabilities and other bugs which were corrected upstream. References: – https://bugs.mageia.org/show_bug.cgi?id=30444
Updated nvidia-current packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead
Updated nvidia390 packages fix security vulnerabilities: NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead
This kernel-linus update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem
This kernel update is based on upstream 5.15.41 and fixes at least the following security issues: A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel BPF subsystem
Updated microcodes for Intel processors, fixing various functional issues, and at least the following security issues: Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to
A bug was found in runc where runc exec –cap executed processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate those capabilities to the permitted set during execve(2). This bug did not affect the container security sandbox as the inheritable set
The container bci/dotnet-aspnet was updated. The following patches have been included in this update:
New mozilla-thunderbird packages are available for Slackware 15.0 and -current to fix security issues.
security update
security update
When you hear the term ‘cryptocurrency’, does ‘secure’ also spring to mind? Here are some implications of the lack of sound security practices in the world of crypto. The post Cryptocurrency: secure or not? – Week in security with Tony Anscombe appeared first on WeLiveSecurity
ESET researchers spot an updated version of the malware loader used in the Industroyer2 and CaddyWiper attacks The post Sandworm uses a new version of ArguePatch to attack targets in Ukraine appeared first on WeLiveSecurity
Fabian Vogt and Dominik Penner discovered that the Ark archive manager did not sanitize extraction paths, which could result in maliciously crafted archives with symlinks writing outside the extraction directory.
An update that contains security fixes can now be installed.
An update that solves one vulnerability and has one errata is now available.
The container suse/sle15 was updated. The following patches have been included in this update:
