Vulnerability reigns supreme On Oct. 26, we co-hosted a live virtual event, Blackpoint ReCON, with partner Blackpoint Cyber. The event brought together industry experts and IT professionals to discuss how security professionals can continue to navigate the modern threat landscape through a pragmatic MDR approach. During the event, we learned how the increase in ransomware […]
Two issues have been found in libmodbus, a library for the Modbus protocol. Both issues are related to out of bound reads, which could result in a
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
LibreOffice could incorrectly validate document signatures.
Header injection via default_mimetype / default_charset mbstring may use pointer from some previous request Unexpected behavior with arrays and JIT Special character is breaking the path in xml function (CVE-2021-21707) XMLReader::getParserProperty may throw with a valid property
IPPUSB dissector crash (CVE-2021-39920). Modbus dissector crash (CVE-2021-39921). C12.22 dissector crash (CVE-2021-39922). PNRP dissector large loop (wnpa-sec-2021-11). Bluetooth DHT dissector large loop (CVE-2021-39924).
Updated rust packages fix security vulnerability This update mitigates a security concern in the Unicode standard, affecting source code containing “bidirectional override” Unicode codepoints: in some cases the use of those codepoints could lead to the reviewed code being
The chromium-browser-stable package has been updated to 96.0.4664.45 version that fixes multiples security vulnerabilities. For changes from 94.0.4606.71 (released on September 30, 2021) to the 96.0.4664.45 version, see referenced advisories.
An update that contains security fixes can now be installed.
The security update of Salt, a remote execution manager, to fix CVE-2021-21996 introduced a regression in salt/fileclient.py which raised an unexpected exception and made file.managed states fail.
An authenticated remote attacker can execute arbitrary code in Firebird, a relational database based on InterBase 6.0, by executing a malformed SQL statement. The only known solution is to disable external UDF libraries from being loaded. In order to achieve this,
The container bci/openjdk was updated. The following patches have been included in this update:
The container bci/openjdk-devel was updated. The following patches have been included in this update:
jQuery UI 1.13.0
Upstream announcement: [WordPress 5.8.2 Security and Maintenance Release](https://wordpress.org/news/2021/11/wordpress-5-8-2-security-and- maintenance-release/)
jQuery UI 1.13.0
US Government declassifies cybersecurity subjects they want you to learn about, and is hoping to pay you to learn them The post US Government declassifies data to foster would‑be defenders appeared first on WeLiveSecurity
A victim of identity theft tells us how criminals used his identity to commit fraud and what it took to put his life back in order The post ‘My bank account was in a shambles’: The ordeal of an identity theft victim appeared first on WeLiveSecurity
An update that fixes 16 vulnerabilities is now available.
An update that fixes 16 vulnerabilities is now available.
Multiple security vulnerabilities have been discovered in Salt, a powerful remote execution manager, that allow for local privilege escalation on a minion, server side template injection attacks, insufficient checks for eauth credentials, shell and command injections or incorrect validation of SSL
The package chromium before version 96.0.4664.45-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing, information disclosure, same-origin policy bypass, sandbox escape and denial of service.
The package opera before version 81.0.4196.54-1 is vulnerable to multiple issues including arbitrary code execution, insufficient validation and access restriction bypass.
The package kubectl-ingress-nginx before version 1.0.4-1 is vulnerable to information disclosure.
security update
An update that fixes 12 vulnerabilities is now available.
An update for devtoolset-11-annobin is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for devtoolset-11-binutils is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Several security issues were fixed in Mailman.
rpki-client 7.5 untrusted input: – Fail repository synchronisation after 15min runtime. – Limit the number of repositories per TAL. – Don’t allow `DOCTYPE` definitions in RRDP XML files. – Fix detection of HTTP redirect loops. * Limit the number of concurrent `rsync` processes. * Fix `CRLF` in TAL files.
Security fix for CVE-2021-3927 and CVE-2021-3928
ESET researchers have discovered strategic web compromise (aka watering hole) attacks against high‑profile websites in the Middle East The post Strategic web compromises in the Middle East with a pinch of Candiru appeared first on WeLiveSecurity
An update that fixes 10 vulnerabilities is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2021:3801
Upstream details at : https://access.redhat.com/errata/RHSA-2021:4619
Upstream details at : https://access.redhat.com/errata/RHSA-2021:4044
Upstream details at : https://access.redhat.com/errata/RHSA-2021:4033
Upstream details at : https://access.redhat.com/errata/RHSA-2021:3889
security update
