The 5.3.7 update contains a number of important fixes across the tree. The update also includes a fix for the [CVE-2019-17666](https://access.redhat.com/security/cve/CVE-2019-17666) security vulnerability regarding a buffer overflow in a Realtek wireless driver.
The 5.3.7 update contains a number of important fixes across the tree. The update also includes a fix for the [CVE-2019-17666](https://access.redhat.com/security/cve/CVE-2019-17666) security vulnerability regarding a buffer overflow in a Realtek wireless driver.
sudo: Privilege escalation via ‘Runas’ specification with ‘ALL’ keyword (CVE-2019-14287) SL7 x86_64 sudo-1.8.23-4.el7_7.1.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.1.x86_64.rpm sudo-debuginfo-1.8.23-4.el7_7.1.i686.rpm sudo-devel-1.8.23-4.el7_7.1.i686.rpm sudo-devel-1.8.23-4.el7_7.1.x86_64.rpm – Scientific Linux Development Team
An update is now available for Ansible Engine 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for sudo is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
An update for sudo is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
ESET researchers discovered a year-long adware campaign on Google Play and tracked down its operator. The apps involved, installed eight million times, use several tricks for stealth and persistence. The post Tracking down the developer of Android adware affecting millions of users appeared first on WeLiveSecurity
An update is now available for Ansible Engine 2.8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update is now available for Ansible Engine 2.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update is now available for Ansible Engine 2.6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Type: Vulnerability. Ansible is prone to multiple information-disclosure vulnerabilities; fixes are available.
Type: Vulnerability. Google Chrome is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Fortinet FortiOS is prone to an insufficient entropy vulnerability; fixes are available.
Type: Vulnerability. McAfee Endpoint Security is prone to a vulnerability that lets attackers inject and execute arbitrary code; fixes are available.
Type: Vulnerability. URL redirect extension for TYPO3 is prone to an SQL-injection vulnerability; fixes are available.
Type: Vulnerability. Citrix NetScaler ADC and NetScaler Gateway are prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Libexpat Expat is prone to a heap-based buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Google Chrome is prone to multiple vulnerabilities; fixes are available.
Type: Vulnerability. Mozilla Firefox and Firefox ESR are prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Mozilla Firefox is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. Juniper Junos is prone to a local directory-traversal vulnerability; fixes are available.
Type: Vulnerability. Mozilla Firefox ESR is prone to a memory-corruption vulnerability; fixes are available.
Type: Vulnerability. The Booking and Availability Management Tools module for Drupal is prone to an access-bypass vulnerability; fixes are available.
Type: Vulnerability. ISC BIND is prone to an authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. Schneider Electric ProClima is prone to multiple remote code-execution vulnerabilities; fixes are available.
Type: Vulnerability. NetApp SnapManager for Oracle is prone to an unspecified local information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Fortinet FortiMail is prone to multiple remote privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Trend Micro Anti-Threat Toolkit is prone to a remote code-execution vulnerability.
Reading Time: ~ 3 min. Entrepreneur Jim Rohn once said, “Time is more valuable than money. You can get more money, but you cannot get more time.” I think anyone involved in running a business can relate to this statement, but it carries a particularly deep meaning to those of us who deal with cybersecurity. […]
An update that solves 16 vulnerabilities and has four fixes is now available.
The package pacman before version 5.2.0-1 is vulnerable to arbitrary command execution.
The package go before version 2:1.13.3-1 is vulnerable to denial of service.
The package go-pie before version 2:1.13.3-1 is vulnerable to denial of service.
The package xpdf before version 4.02-1 is vulnerable to arbitrary code execution.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update for firefox is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
As cities turn to IoT to address long-standing urban problems, what are the risks of leaving cybersecurity behind at the planning phase? The post Smart cities must be cyber‑smart cities appeared first on WeLiveSecurity
Upstream details at : https://access.redhat.com/errata/RHSA-2019:3157
Upstream details at : https://access.redhat.com/errata/RHSA-2019:2964
Upstream details at : https://access.redhat.com/errata/RHSA-2019:3127
Upstream details at : https://access.redhat.com/errata/RHSA-2019:3128
security update
security update
Type: Vulnerability. Cisco Identity Services Engine is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. IBM Maximo Anywhere is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Cisco Identity Services Engine is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Cisco SPA122 ATA with Router Devices are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco Identity Services Engine is prone to an information disclosure vulnerability; fixes are available.
Type: Vulnerability. Multiple Sonatype Products are prone to an unspecified remote code execution vulnerability; fixes are available.
Type: Vulnerability. Cisco Identity Services Engine is prone to multiple HTML-injection vulnerabilities; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to multiple cross-site scripting vulnerabilities; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. CA Performance Management is prone to a security-bypass vulnerability; fixes are available.
Type: Vulnerability. Broken Link Checker plugin for WordPress is prone to a cross-site scripting vulnerability.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Cisco Small Business Smart and Managed Switches are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. TYPO3 freeCap CAPTCHA extension is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Cisco Aironet Access Points are prone to a denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Cisco Firepower Management Center is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to a buffer-overflow vulnerability; fixes are available.
Type: Vulnerability. Cisco SPA100 Series Analog Telephone Adapters are prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Cisco TelePresence CE Software is prone to a local command-injection vulnerability; fixes are available.
An update that fixes three vulnerabilities is now available.
An update that fixes one vulnerability is now available.
The company says that the incident, going back to March 2018, affected only 1 out of its 3,000 servers The post NordVPN reveals breach at datacenter provider appeared first on WeLiveSecurity
An update that solves 40 vulnerabilities and has 225 fixes is now available.
