apng2gif could be made to expose sensitive information if it opened a specifically crafted APNG file.
An update for Red Hat Data Grid is now available. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Samba would allow unintended access to files over the network.
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength. (CVE-2020-15503)
util-linux could be made to run programs when performing bash completion.
Reading Time: ~ 4 min. Since launching our web classification service in 2006, we’ve seen tremendous interest in our threat and web classification services, along with an evolution of the types and sizes of cybersecurity vendors and service providers looking to integrate this type of curated data into their product or service. Over the years, […]
The cyber attack affects 14 inboxes belonging to the Department of Justice was confirmed by ESET researchers. The post Emotet strikes Quebec’s Department of Justice: An ESET Analysis appeared first on WeLiveSecurity
Zoom now supports phone calls, text messages and authentication apps as forms of two-factor authentication The post Zoom makes 2FA available for all its users appeared first on WeLiveSecurity
An update that contains security fixes can now be installed.
An update that solves three vulnerabilities and has 26 fixes is now available.
An update that solves one vulnerability and has 8 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
MCabber could be made to modify the roster and intercept messages if it received specially crafted XMPP packets.
security update
Apache XML-RPC could be made to execute arbitrary code if it received specially crafted data by a malicious XML-RPC server.
An update for librepo is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for the mysql:8.0 module is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Update to version 0.9.5 * https://www.libssh.org/2020/09/10/libssh-0-9-5/ * Fixes CVE-2020-16135
QEMU: usb: out-of-bounds r/w access issue [XSA-335, CVE-2020-14364] (#1871850)
Apache Log4j could be made to remotely execute arbitrary code if it received specially crafted log data.
Reading Time: ~ 3 min. Women of Webroot and Carbonite talk about what drew them to the field and their advice for others looking to break into STEM. The lack of representative diversity in tech has been long acknowledged and well-studied. Organizations and non-profit groups like National Center for Women & Information Technology (NCWIT), Girls […]
An update that solves 8 vulnerabilities and has 17 fixes is now available.
An update that solves 8 vulnerabilities and has 17 fixes is now available.
An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3617
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3631
Upstream details at : https://access.redhat.com/errata/RHSA-2020:3643
An update that fixes one vulnerability is now available.
New mozilla-thunderbird packages are available for Slackware 14.2 and -current to fix security issues.
– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –
https://lists.gnupg.org/pipermail/gnutls-help/2020-September/004669.html
– https://www.drupal.org/project/drupal/releases/7.72 – [Drupal core – Critical – Cross Site Request Forgery – SA- CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 – https://www.drupal.org/project/drupal/releases/7.71 – https://www.drupal.org/project/drupal/releases/7.70 – [Drupal core –
An update that fixes one vulnerability is now available.
Update to upstream bugfix and security release 2.9.13.
update to 2.2.16, CVE-2020-24583, CVE-2020-24584
New F31 selinux-policy build
Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md
Update to .NET Core SDK 3.1.107 and Runtime 3.1.7. This fixes CVE-2020-1597 – Release Notes: https://github.com/dotnet/core/blob/master/release- notes/3.1/3.1.7/3.1.7.md
ESET researchers have discovered and analyzed malware that targets Voice over IP (VoIP) softswitches. The post Who is calling? CDRThief targets Linux VoIP softswitches appeared first on WeLiveSecurity
Multiple vulnerabilities were discovered in WordPress, a popular content management framework. CVE-2019-17670
Reading Time: ~ 3 min. This year more than others, for many of us, it’s gaming that’s gotten us through. Lockdowns, uncertainty, and some pretty darn good releases have kept our computers and consoles switched on in 2020. GamesIndustry.biz, a website tracking the gaming sector, reported a record number of concurrent users on the gaming […]
An update that solves 8 vulnerabilities and has 12 fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes two vulnerabilities is now available.
8u265 update, disable LTO
Update built with the new CMake settings Number of files which should have been owned by the testsuite subpackage are now owned by it Started building MeCab plugin
Reading Time: ~ 4 min. Today’s work-from-home environment has created an abundance of opportunities for offering new cybersecurity services in addition to your existing business. With cyberattacks increasing in frequency and sophistication, business owners and managers need protection now more than ever. MSPs are ideally positioned to deliver the solutions businesses need in order to […]
