In httplib2, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2344
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2337
Upstream details at : https://access.redhat.com/errata/RHSA-2020:2334
Flask could be made to consume a large amount of memory if it received a specially crafted input.
An update is now available for Red Hat OpenShift Application Runtimes. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Gollem, as used in Horde Groupware Webmail Edition and other products, had been affected by a reflected Cross-Site Scripting (XSS) vulnerability via the HTTP GET dir parameter in the browser functionality, affecting
The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
An update that solves one vulnerability and has one errata is now available.
New upstream release with bug and security fixes. Also, consolidates duplicate pakages marked and nodejs-marked. I tested upgrades from both, but may have missed some wonky situation.
New version 3.2.4, enabled build with androiddump.
Two memory management issues were found in the asfdemux element of the GStreamer “ugly” plugin collection, which can be triggered via a maliciously crafted file.
Two memory handling issues were found in gst-plugins-good0.10, a collection of GStreamer plugins from the “good” set:
It was discovered that there was both an invalid memory and heap overflow vulnerability in dosfstools, a collection of utilities for making and checking MS-DOS FAT filesystems.
Several vulnerabilities were discovered in package salt, a configuration management and infrastructure automation software.
New version 3.2.4, enabled build with androiddump.
An update that fixes one vulnerability is now available.
And most people don’t change their password even after hearing about a breach, a survey finds The post People know reusing passwords is risky – then do it anyway appeared first on WeLiveSecurity
An update that solves one vulnerability and has two fixes is now available.
git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008) SL7 x86_64 git-1.8.3.1-23.el7_8.x86_64.rpm git-daemon-1.8.3.1-23.el7_8.x86_64.rpm git-debuginfo-1.8.3.1-23.el7_8.x86_64.rpm git-gnome-keyring-1.8.3.1-23.el7_8.x86_64.rpm git-svn-1.8.3.1-23.el7_8.x86_64.rpm noarch emacs-git-1.8.3.1-23.el7_8.noarch.rpm [More…]
## Python 3.8.3 This is the third maintenance release of Python 3.8. See [the c hangelog](https://docs.python.org/release/3.8.3/whatsnew/changelog.html#changelo g) for details. Contains the security fix for CVE-2020-8492.
An update that fixes three vulnerabilities is now available.
USN-4369-1 introduced a regression in the Linux kernel.
USN-4367-1 introduced a regression in the Linux kernel.
Left unpatched, the vulnerability could expose almost all Android users to the risk of having their personal data intercepted by attackers The post Critical Android flaw lets attackers hijack almost any app, steal data appeared first on WeLiveSecurity
Several security vulnerabilities have been discovered in the Tomcat servlet and JSP engine.
An update for freerdp is now available for Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for freerdp is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Various minor vulnerabilities have been addredd in libexif, a library to parse EXIF metadata files.
This is a security update for JBoss EAP Continuous Delivery 19. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update that fixes 5 vulnerabilities is now available.
security update
security update
Turla has updated its ComRAT backdoor and now uses the Gmail web interface for Command and Control The post From Agent.BTZ to ComRAT v4: A ten‑year journey appeared first on WeLiveSecurity
An update that fixes three vulnerabilities is now available.
Several security issues were fixed in Unbound.
Updated transmission packages fix security vulnerability: Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent
Updated sleuthkit packages fix security vulnerabilities: An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table (CVE-2019-14532).
