Due to a data race in the crossbeam-deque in the crossbeam crate, one or more tasks in the worker queue could have been be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this could have caused a double free and a memory leak (CVE-2021-32810).
New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue.
Firefox could be made to crash or run programs as your login if it opened a malicious website.
Two-factor authentication is a simple way to greatly enhance the security of your account The post Google to turn on 2FA by default for 150 million users, 2 million YouTubers appeared first on WeLiveSecurity
Cryptocurrencies rise and fall, but one thing stays the same – cybercriminals attempt to cash in on the craze The post To the moon and hack: Fake SafeMoon app drops malware to spy on you appeared first on WeLiveSecurity
Several security issues were fixed in MySQL.
Rebase to libssh-0.9.6 Fix CVE-2021-3634
Updated container images that fix various bugs are now available for Red Hat OpenShift Container Storage 3.11 Update 8 in the Red Hat Container Registry. Red Hat Product Security has rated this update as having a security impact
Updated packages that provide Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9, and fix an important security issue, are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact
Red Hat JBoss Core Services Apache HTTP Server 2.4.37 Service Pack 9 zip release for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows is available. Red Hat Product Security has rated this update as having a security impact
Bottle could be made to cache malicious requests if it received a specially crafted input.
ESET research discovers a previously undocumented UEFI bootkit with roots going back all the way to at least 2012 The post UEFI threats moving to the ESP: Introducing ESPecter bootkit appeared first on WeLiveSecurity
The updated packages fix a security vulnerabilities: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Red Hat JBoss Web Server 5.5.1 zip release is now available for Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, and Microsoft Windows. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Updated Red Hat JBoss Web Server 5.5.1 packages are now available for Red Hat Enterprise Linux 7 and Red Hat Enterprise Linux 8. Red Hat Product Security has rated this release as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
New httpd packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix security issues.
security update
security update
Update to 8.6.0.
Squid could be made to crash or expose sensitive information over the network.
An update for kernel is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Updated samba packages that fix several bugs with added enhancement are now available for Red Hat Gluster Storage 3.5 on Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
Update to 8.6.0.
Imlib2 could be made to denial of service and possibly execute arbitrary code.
An update that fixes 9 vulnerabilities is now available.
Python could allow unintended access to network services.
Multiple security vulnerabilities have been discovered in fig2dev, utilities for converting XFig figure files. Buffer overflows, out-of-bounds reads and NULL pointer dereferences could lead to a denial-of-service or other unspecified impact.
– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]
– Update cranelift crates to version 0.77.0. – Update the wast crate to version 38.0.0. – Update the wat crate to version 1.0.40. – Update the wasmparser crate to version 0.80.1. – Update wasmtime crates to version 0.30.0. – Update the backtrace crate to version 0.3.61. – Update the addr2line crate to version 0.16.0. – […]
An update that contains security fixes can now be installed.
Update to 94.0.4606.61. Fixes a big pile of security issues: CVE-2021-30542 CVE-2021-30543 CVE-2021-30558 CVE-2021-30625 CVE-2021-30626 CVE-2021-30627 CVE-2021-30628 CVE-2021-30629 CVE-2021-30630 CVE-2021-30631 CVE-2021-30632 CVE-2021-30633 CVE-2021-37972 CVE-2021-37956 CVE-2021-37957 CVE-2021-37958 CVE-2021-37959 CVE-2021-37960 CVE-2021-37961 CVE-2021-37962 CVE-2021-37963
The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
Security fix for [PUT CVEs HERE]
One security issue has been discovered in plib. Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
2020 was a year of immense change. One thing is for certain – the world collectively witnessed the increase of digital interconnectivity. We began even more to rely on the internet as a conduit to the world. The rise of remote access to businesses, entertainment and interpersonal connections surged. The death of distance accelerated. The […]
The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
The 5.14.9 stable kernel update contains a number of important fixes across the tree. —- The 5.14.7 stable kernel rebase contains additional hardware support, new features, and a number of important fixes across the tree.
Security fix for [PUT CVEs HERE]
– CVE-2021-22947 – STARTTLS protocol injection via MITM – CVE-2021-22946 – protocol downgrade required TLS bypassed – CVE-2021-22945 – use-after-free and double-free in MQTT sending
An issue has been found in openssl1.0, a Secure Sockets Layer library. The issue is related to read buffer overruns while processing ASN.1 strings.
Two issues have been found in curl, a command line tool and an easy-to-use client-side library for transferring data with URL syntax.
Flaws in Apple Pay and Visa could allow criminals to make arbitrary contactless payments – no authentication needed, research finds The post Hackers could force locked iPhones to make contactless payments appeared first on WeLiveSecurity
A view of the T2 2021 threat landscape as seen by ESET telemetry and from the perspective of ESET threat detection and research experts The post ESET Threat Report T2 2021 appeared first on WeLiveSecurity
