An update that fixes one vulnerability is now available.
security update
Etienne Stalmans discovered that unsquashfs in squashfs-tools, the tools to create and extract Squashfs filesystems, does not validate filenames for traversal outside of the destination directory. An attacker can take advantage of this flaw for writing to arbitrary files to the filesystem
Update to 2.0.1 (fix RHBZ#1998578); fix RHBZ#1932066 (unsafe use of strncpy)
Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)
Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)
Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)
Update NTFS-3G to 2021.8.22 to fix multiple CVEs —- New upstream development version 1.45.7. —- Upstream patch to work with qemu 6.1 (RHBZ#1998820)
An XML external entity (XXE) injection in pywps allows an attacker to view files on the application server filesystem by assigning a path to the entity.
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sle15 was updated. The following patches have been included in this update:
The container suse/sles12sp5 was updated. The following patches have been included in this update:
Dubbed Safety Mode, the feature will temporarily block authors of offensive tweets from being able to contact or follow users. The post Twitter introduces new feature to automatically block abusive behavior appeared first on WeLiveSecurity
An update that solves one vulnerability and has two fixes is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has two fixes is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 7 vulnerabilities is now available.
Security release for the 0.4 branch: https://lib.openmpt.org/libopenmpt/2021/08/22/security- updates-0.5.11-0.4.23-0.3.32/
An update that solves 11 vulnerabilities and has 7 fixes is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 8 vulnerabilities is now available.
The container sles-15-sp3-chost-byos-v20210827 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20210827-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
The container suse-sles-15-sp3-chost-byos-v20210827-gen2 was updated. The following patches have been included in this update:
security update
Vaccination passports may facilitate the return to normalcy, but there are also concerns about what kinds of personal data they collect and how well they protect it. Here’s what you should know. The post Vaccine passports: Is your personal data in safe hands? appeared first on WeLiveSecurity
Upstream details at : https://access.redhat.com/errata/RHSA-2021:3338
Upstream details at : https://access.redhat.com/errata/RHSA-2021:3336
Upstream details at : https://access.redhat.com/errata/RHSA-2021:3325
Upstream details at : https://access.redhat.com/errata/RHSA-2020:1021
Upstream details at : https://access.redhat.com/errata/RHSA-2018:3140
An update that solves two vulnerabilities, contains one feature and has one errata is now available.
ESET’s cybersecurity expert Marc-Étienne Léveillé analyses in-depth the Quebec’s vaccine proof apps VaxiCode and VaxiCode Verif. The post Flaw in the Quebec vaccine passport: analysis appeared first on WeLiveSecurity
The federal agency urges organizations to ditch the bad practice and instead use multi-factor authentication methods The post Don’t use single‑factor authentication, warns CISA appeared first on WeLiveSecurity
NTFS-3G could be made to execute arbitrary code if it received a specially crafted image file.
sssd: shell command injection in sssctl (CVE-2021-3621) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Memory leak in the simple access provider * id lookup is failing intermittently * SSSD is NOT able to contact the Global Catalog […]
kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555) * kernel: race condition for removal of the HCI controller (CVE-2021-32399) * kernel: powerpc: RTAS calls can be used to compromise kernel integrity (CVE-2020-27777) * kernel: Local privilege escalation due to incorrect BPF JIT branch displacement computation (CVE-2021-29154) * kernel: [More…]
bind: Broken inbound incremental zone update (IXFR) can cause named to terminate unexpectedly (CVE-2021-25214) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 bind-9.11.4-26.P2.el7_9.7.x86_64.rpm bind-chroot-9.11.4-26.P2.el7_9.7.x86_64.rpm bind-debuginfo-9.11.4-26.P2.el7_9.7.i68 [More…]
libsndfile: Heap buffer overflow via crafted WAV file allows arbitrary code execution (CVE-2021-3246) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 libsndfile-1.0.25-12.el7_9.1.i686.rpm libsndfile-1.0.25-12.el7_9.1.x86_64.rpm libsndfile-debuginfo-1.0.25-12.el7_9.1.i686.rpm li [More…]
hivex: stack overflow due to recursive call of _get_children() (CVE-2021-3622) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE — SL7 x86_64 hivex-1.3.10-6.12.el7_9.i686.rpm hivex-1.3.10-6.12.el7_9.x86_64.rpm hivex-debuginfo-1.3.10-6.12.el7_9.i686.rpm hivex-debuginfo-1.3.10-6.12.el7_9.x86_64 [More…]
