security update
APR could be made to expose sensitive information if it received a specially crafted input.
grilo could be made to allow MITM attacks.
An update for libsndfile is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for libX11 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Several vulnerabilities have been discovered in Exiv2, a C++ library and a command line utility to manage image metadata which could result in denial of service or the execution of arbitrary code if a malformed file is parsed.
An update for libsndfile is now available for Red Hat Enterprise Linux 8.2 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update that fixes one vulnerability is now available.
New upstream stable version 1.24.6; fixes CVE-2021-3716.
New upstream stable version 1.26.5; fixes CVE-2021-3716.
security update
An issue has been found in gthumb, an image viewer and browser. A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c allows attackers to
Michael Catanzaro reported a problem in Grilo, a framework for discovering and browsing media. TLS certificate verification is not enabled on the SoupSessionAsync objects created by Grilo, leaving users vulnerable to network MITM attacks.
– CVE-2021-37750 (explicit NULL deref on KDC)
A security flaw was found on rubygem-addressable that a crafted template may cause DOS. This issue is now assinged as CVE-2021-32740. This new rpm should fix this issue.
A security flaw was found on rubygem-addressable that a crafted template may cause DOS. This issue is now assinged as CVE-2021-32740. This new rpm should fix this issue.
An update that fixes one vulnerability is now available.
When the Institute for Security & Technology’s Ransomware Task Force published its report on combatting ransomware this spring, the Colonial Pipeline, JBS meatpacking and Kaseya VSA attacks were still around the corner. Nevertheless, the report took the danger presented by ransomware to both businesses and global security for granted. Already in 2020, according to the […]
An update that solves one vulnerability and has two fixes is now available.
An update that fixes 15 vulnerabilities is now available.
The man was after sexually explicit photos and videos that he would then share online or store in his own collection The post Man impersonates Apple support, steals 620,000 photos from iCloud accounts appeared first on WeLiveSecurity
Updated libass packages fix security vulnerability: libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction (CVE-2020-36430).
runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on a race condition (CVE-2021-30465).
An update that solves 7 vulnerabilities and has one errata is now available.
An update that solves one vulnerability, contains two features and has 6 fixes is now available.
An update that fixes one vulnerability is now available.
exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE7 — SL7 x86_64 – compat-exiv2-023-0.23-2.el7_9.i686.rpm – compat-exiv2-023-0.23-2.el7_9.x86_64.rpm – compat-exiv2-023-debuginfo-0.23-2.el7_9.i686.rpm – compat- [More…]
exiv2: Heap-based buffer overflow vulnerability in jp2image.cpp (CVE-2021-31291) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE7 — SL7 x86_64 – compat-exiv2-026-0.26-3.el7_9.i686.rpm – compat-exiv2-026-0.26-3.el7_9.x86_64.rpm – compat-exiv2-026-debuginfo-0.26-3.el7_9.i686.rpm – compat-e [More…]
libssh could be made to crash or run programs if it received specially crafted network traffic.
An update for servicemesh and servicemesh-proxy is now available for OpenShift Service Mesh 2.0. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for libsndfile is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for python27-babel, python27-python, python27-python-jinja2, and python27-python-pygments is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
security update
USN-5037-1 caused a regression in Firefox.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes one vulnerability is now available.
The container suse/sles12sp5 was updated. The following patches have been included in this update:
The container suse/sles12sp4 was updated. The following patches have been included in this update:
security update
security update
The caches of data that were publicly accessible included names, email addresses and social security numbers The post Microsoft Power Apps misconfiguration exposes millions of records appeared first on WeLiveSecurity
Meet SparklingGoblin, a member of the Winnti family The post The SideWalk may be as dangerous as the CROSSWALK appeared first on WeLiveSecurity
Several security issues were fixed in OpenSSL.
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit. CVE-2021-3711
