Fabian Vogt and Dominik Penner discovered that the Ark archive manager did not sanitize extraction paths, which could result in maliciously crafted archives with symlinks writing outside the extraction directory.
An update that contains security fixes can now be installed.
An update that solves one vulnerability and has one errata is now available.
The container suse/sle15 was updated. The following patches have been included in this update:
The container bci/ruby was updated. The following patches have been included in this update:
The container bci/openjdk was updated. The following patches have been included in this update:
Webroot Console 6.5 is here To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To help get us closer to retiring the Endpoint Protection Console, we’ve introduced three new functionality features with Webroot Console 6.5. Friendly name support To improve […]
OpenLDAP could be made to perform arbitrary modifications to the database.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes 6 vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2022:4642
Cybercriminals continue to mine for opportunities in the crypto space – here’s what you should know about coin-mining hacks and crypto theft The post The flip side of the coin: Why crypto is catnip for criminals appeared first on WeLiveSecurity
security update
security update
security update
In the age of the perpetual news cycle and digital media, the risks that stem from the fake news problem are all too real The post Fake news – why do people believe it? appeared first on WeLiveSecurity
Several security issues were fixed in PCRE.
Several security issues were fixed in Apport.
needrestart could be made to run programs.
zlib: A flaw found in zlib when compressing (not decompressing) certain inputs (CVE-2018-25032) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 zlib-1.2.7-20.el7_9.i686.rpm zlib-1.2.7-20.el7_9.x86_64.rpm zlib-debuginfo-1.2.7-20.el7_9.i686.rpm zlib-debuginfo-1.2.7-20 [More…]
Jakub Wilk discovered a local privilege escalation in needrestart, a utility to check which daemons need to be restarted after library upgrades. Regular expressions to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate
OpenLDAP could be made to perform arbitrary modifications to the database.
The ffmpeg project released the new version 3.2.18 with fixes for various issues found by the OSS-Fuzz project. For Debian 9 stretch, this release is packaged in version 7:3.2.18-0+deb9u1.
An update that contains security fixes can now be installed.
An update that fixes one vulnerability is now available.
An update that fixes 8 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
The decision to release a ransomware decryptor involves a delicate balancing act between helping victims recover their data and alerting criminals to errors in their code The post The downside of ‘debugging’ ransomware appeared first on WeLiveSecurity
Infinite loop vulnerability in the CHM file parser. Issue affects versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions. (CVE-2022-20770) Infinite loop vulnerability in the TIFF file parser. Issue affects versions
cairo-truetype-subset.c in cairo 1.15.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) because of mishandling of an unexpected malloc(0) call. (CVE-2017-9814) References:
CERTINFO never-ending busy-loop. (CVE-2022-27781) TLS and SSH connection too eager reuse. (CVE-2022-27782) References: – https://bugs.mageia.org/show_bug.cgi?id=30410
FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face. (CVE-2022-27404) FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context. (CVE-2022-25235) References:
When using Waitress versions 2.1.0 and prior behind a proxy that does not properly validate the incoming HTTP request matches the RFC7230 standard, Waitress and the frontend proxy may disagree on where one request starts and where it ends. This would allow requests to be smuggled via the front-end proxy to waitress and later behavior. […]
CVE-2021-3596 A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in
Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in information disclosure or denial of service. For Debian 9 stretch, these problems have been fixed in version
The container trento/trento-runner was updated. The following patches have been included in this update:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
The container bci/nodejs was updated. The following patches have been included in this update:
security update
security update
security update
