Menu

Latest articles

The package firefox before version 70.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, denial of service, insufficient validation and same-origin policy bypass.

The package thunderbird before version 68.2.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, denial of service, insufficient validation and same-origin policy bypass.

The package php before version 7.3.11-1 is vulnerable to arbitrary code execution.

FBI extends voting security push, LA court hacker goes down, and more D-Link failures

This is a cumulative bug-fix update from upstream, including a fix for a pre- authentication remote denial of service issue.

New version 4.9.3, Security fix for CVE-2017-16808, CVE-2018-14468, CVE-2018-14469, CVE-2018-14470, CVE-2018-14466, CVE-2018-14461, CVE-2018-14462, CVE-2018-14465, CVE-2018-14881, CVE-2018-14464, CVE-2018-14463, CVE-2018-14467, CVE-2018-10103, CVE-2018-10105, CVE-2018-14880, CVE-2018-16451, CVE-2018-14882, CVE-2018-16227, CVE-2018-16229, CVE-2018-16301, CVE-2018-16230, CVE-2018-16452,

An update that solves 5 vulnerabilities and has 98 fixes is now available.

An update that fixes three vulnerabilities is now available.

An update that fixes 5 vulnerabilities is now available.

– Updated to latest upstream version (70.0)

Update to OpenJDK October CPU (security update). See: https://openjdk.java.net/groups/vulnerability/advisories/2019-10-15 http://mail.openjdk.java.net/pipermail/jdk-updates-dev/2019-October/002025.html

OpenJDK October CPU security update. See: https://openjdk.java.net/groups/vulnerability/advisories/2019-10-15 http://mail.openjdk.java.net/pipermail/jdk8u-dev/2019-October/010452.html

xpdf 4.02. Lots of security fixes here.

An update that fixes one vulnerability is now available.

Security fix for CVE-2018-16301, CVE-2019-15161, CVE-2019-15162, CVE-2019-15163, CVE-2019-15164, CVE-2019-15165

Security fix for CVE-2018-16301, CVE-2019-15161, CVE-2019-15162, CVE-2019-15163, CVE-2019-15164, CVE-2019-15165

Security fix for CVE-2018-16301, CVE-2019-15161, CVE-2019-15162, CVE-2019-15163, CVE-2019-15164, CVE-2019-15165

security update

security update

An update that fixes 5 vulnerabilities is now available.

Several issues have been found in mosquitto, a MQTT version 3.1/3.1.1 compatible message broker.

An issue has been found in libarchive, a multi-format archive and compression library.

An update that fixes one vulnerability is now available.

An update that fixes one vulnerability is now available.

Daniel Mandragona discovered that invalid DSA public keys can cause a panic in dsa.Verify(), resulting in denial of service. For the stable distribution (buster), this problem has been fixed in

A buffer overflow was found in file, a file type classification tool, which may result in denial of service or potentially the execution of arbitrary code if a malformed CDF (Composite Document File) file is processed.

An update that fixes one vulnerability is now available.

An update that fixes 10 vulnerabilities is now available.

An update that fixes 11 vulnerabilities is now available.

An update that fixes 12 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 28 vulnerabilities is now available.

Backport security fixes from [PR#145](https://github.com/libming/libming/pull/145) Fixes: CVE-2018-7866, CVE-2018-7873, CVE-2018-7876, CVE-2018-9009, CVE-2018-9132

Emil Lerner, beched and d90pwn found a buffer underflow in php5-fpm, a Fast Process Manager for the PHP language, which can lead to remote code execution.

security update

Is AWS Liable in Capital One Breach?

Type: Vulnerability. NixOS Nix is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. GNU Guix is prone to a local privilege-escalation vulnerability; fixes are available.

Type: Vulnerability. Elasticsearch is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Multiple VMware products are prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry UAA is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. Istio is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Qt QtBase module is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. Cloud Foundry SMB Volume is prone to an information disclosure vulnerability; fixes are available.

Type: Vulnerability. OpenSSH is prone to an integer overflow vulnerability; fixes are available.

Type: Vulnerability. SLUB Event Registration Extension is prone to an arbitrary-file-upload vulnerability; fixes are available.

Type: Vulnerability. vBulletin is prone to a remote code-execution vulnerability; fixes are available.

Type: Vulnerability. PHP is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Nessus is prone to a denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Adobe Creative Cloud Desktop Application is prone to an unspecified security-bypass vulnerability; fixes are available.

Type: Vulnerability. vBulletin is prone to multiple SQL-injection vulnerabilities.

Type: Vulnerability. Dnsmasq is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Adobe Acrobat and Reader are prone to information-disclosure vulnerability; fixes are available.

Time to check who left their database open and leaked 7.5m customer records: Hi there, Adobe Creative Cloud!
Uncle Sam demands summary judgement on Snowden memoir: We’re not saying it’s true, but no one should read it
U.N., UNICEF, Red Cross Under Ongoing Mobile Attack
News Wrap: Hotel Robot Hacks, FTC Stalkerware Crackdown
Firefox Privacy Protection makes website trackers visible
Japanese hotel robots can be hacked to spy on guests in their bedrooms
Ransomware, Mobile Malware Attacks to Surge in 2020
Keylogging data vampire pleads guilty to bleeding two companies
Phishers strike at mobile wellness app company

Reading Time: ~ 2 min. MedusaLocker Ransomware Spotted Worldwide While it’s still unclear how MedusaLocker is spreading, the victims have been confirmed around the world in just the last month. By starting with a preparation phase, this variant can ensure that local networking functionality is active and maintain access to network drives. After shutting down […]

An Open-Source Success Story: Apache SpamAssassin Celebrates 18 Years of Effectively Combating Spam Email
DeepCode taps AI for code reviews
Sensitive US government and military travel details left exposed online

Reading Time: ~ 3 min. Certain types of cybercrime targets always make headlines. In this two-part series, we’ll get into a pretty serious one: your health, and why hackers are targeting the healthcare industry for profit. The Short Answer: Medical Data is Worth a Lot Stolen medical data is valuable, plain and simple. In a […]

iBye, bad guy: Apple yanks 18 iOS store apps that sheltered advert-mashing malware
Religious Website Data Exposed for Months

Type: Vulnerability. Golang Go is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. file is prone to a heap-based buffer-overflow vulnerability; fixes are available.

Type: Vulnerability. Direct Mail Extension for TYPO3 is prone to an information-disclosure vulnerability; fixes are available.

Type: Vulnerability. F5 BIG-IQ Centralized Management is prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Multiple D-Link products are prone to a command-injection vulnerability.

Type: Vulnerability. ISC BIND is prone to a remote denial-of-service vulnerability; fixes are available.

Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.

Type: Vulnerability. F5 BIG-IQ Centralized Management is prone to an HTML-injection vulnerability; fixes are available.

Type: Vulnerability. Linux kernel is prone to a local memory-corruption vulnerability; fixes are available.

Type: Vulnerability. Python is prone to a security-bypass vulnerability; fixes are available.

Type: Vulnerability. Multiple Dell EMC products are prone to a remote security-bypass vulnerability; fixes are available.

Type: Vulnerability. Juniper Junos is prone to a local information-disclosure vulnerability; fixes are available.

Type: Vulnerability. libxslt is prone to an arbitrary code-execution vulnerability; fixes are available.

Raccoon Malware Scavenges 100,000+ Devices to Steal Data

Risk Level: Very Low. Type: Trojan, Virus, Worm.

Risk Level: Very Low. Type: Trojan.

Antivirus hid more than 9,000 ‘cybercrime’ reports from UK cops, says watchdog
Cash App Twitter Giveaway a Haven for Stealing Money
Samsung Rolls Out Fix For Galaxy S10 Fingerprint Sensor Glitch
Facebook lays out plan to protect elections

How is the social network preparing to curtail the spread of misinformation as the election season heats up? The post Facebook lays out plan to protect elections appeared first on WeLiveSecurity

5 tips for better cybersecurity
Vulnerability in content distribution networks found by researchers
Robot Hotel says sorry about the buggy bedside bots

An update that fixes 13 vulnerabilities is now available.

An update that fixes one vulnerability is now available.

An update that fixes 16 vulnerabilities is now available.

Google warns devs as it tightens Chrome cookie security: Stuff will break if you’re not clued up
12 year jail sentence for man who hacked Los Angeles Superior Court to send two million phishing emails
ThreatList: Sharp Increase in Fake Mobile Apps Impersonating Legit Ones