Type: Vulnerability. OpenAFS is prone to an information-disclosure vulnerability; fixes are available.
UPbit has announced that, as a precaution, all transactions will remain suspended for at least two weeks The post Cryptocurrency exchange loses US$50 million in apparent hack appeared first on WeLiveSecurity
An update that fixes four vulnerabilities is now available.
An update that fixes 18 vulnerabilities is now available.
An update that fixes 16 vulnerabilities is now available.
NSS could be made to crash or run programs if it received specially crafted input.
An update that fixes two vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
Risk Level: Very Low. Type: Trojan.
security update
Type: Vulnerability. Palo Alto Networks Zingbox Inspector is prone to a security vulnerability that may allow attackers to conduct spoofing attacks; fixes are available.
Type: Vulnerability. Google Chrome is prone to an information disclosure vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. FasterXML Jackson is prone to multiple XML External Entity injection vulnerabilities.
Type: Vulnerability. Google Chrome is prone to an out-of-bounds memory access vulnerability; fixes are available.
Type: Vulnerability. Google Chrome is prone to a security-bypass vulnerability; fixes are available.
Risk Level: Very Low. Type: Trojan.
Several security issues were fixed in Ruby.
ESET researchers have discovered that the criminals behind the Stantinko botnet are distributing a cryptomining module to the computers they control The post Stantinko botnet adds cryptomining to its pool of criminal activities appeared first on WeLiveSecurity
An update that fixes 7 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update for 389-ds-base is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
An update for kernel-rt is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
security update
Type: Vulnerability. The Jetpack plugin for WordPress is prone to an unspecified security vulnerability; fixes are available.
Type: Vulnerability. Linux Kernel is prone to multiple denial-of-service vulnerabilities; fixes are available.
Type: Vulnerability. HP ThinPro Linux is prone to multiple security vulnerabilities; fixes are available.
Type: Vulnerability. McAfee Client Proxy is prone to a local authentication-bypass vulnerability; fixes are available.
Type: Vulnerability. libgd is prone to multiple denial-of-service vulnerabilities; fixes are available.
Type: Vulnerability. Infinispan is prone to a privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. The Linux Kernel is prone to a local race-condition vulnerability; fixes are available.
An update that fixes one vulnerability is now available.
An update that fixes 42 vulnerabilities is now available.
An update that fixes 18 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An out-of-bounds write vulnerability was discovered in php-imagick, a PHP extension to create and modify images using the ImageMagick API, which could result in denial of service, or potentially the execution of arbitrary code.
How the field of play has changed and why endpoint protection still often comes down to doing the basics, even in the face of increasingly complex threats The post CyberwarCon – the future of nation‑state nastiness appeared first on WeLiveSecurity
Several security issues were fixed in libvpx.
Type: Vulnerability. Symantec Critical System Protection is prone to an unspecified authentication-bypass vulnerability; fixes are available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes 18 vulnerabilities is now available.
Security fix for CVE-2019-14869
rebase to upstream version 8.1911.0 ————————————————- new modules available: * ClickHouse output * generic REST API http output * docker API input * misc. external program input (takes output of specified binary as log source)
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump.
It was discovered that pam-python, a PAM Module that runs the Python interpreter, has an issue in regard to the default environment variable handling of Python. This issue could allow for local root escalation in certain PAM setups.
This update fixes CVE-2019-17545.
This update fixes CVE-2019-17545.
