An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
Vulnerabilities have been discovered in nss, the Mozilla Network Security Service library.
Jann Horn discovered that the ptrace subsystem in the Linux kernel mishandles the management of the credentials of a process that wants to create a ptrace relationship, allowing a local user to obtain root privileges under certain scenarios.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has four fixes is now available.
An update that fixes one vulnerability is now available.
An update that fixes four vulnerabilities is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes four vulnerabilities is now available.
Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435
Update to Samba 4.9.11 —- Update to Samba 4.9.9 Security fixes for CVE-2019-12435
Reading Time: ~ 2 min. Over 100 Million Accounts Exposed in Evite Breach More than 100 million users of Evite were exposed after the company’s servers were compromised earlier this year. While the company doesn’t store financial information, plenty of other personally identifiable information was found in the leaked database dump. The initial figures for […]
An update that fixes four vulnerabilities is now available.
An update that fixes four vulnerabilities is now available.
It was discovered that there was an integer overflow vulnerability in exiv2, a tool to manipulate images containing (eg.) EXIF metadata. This could have resulted in a denial of service via a specially-
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
Update to v5.1.18 —- Update to v5.1.17
Update to v5.1.18 —- Update to v5.1.17
– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html
– fixes security issues CVE-2019-10190 and CVE-2019-10191 – https://lists.nic.cz/pipermail/knot-resolver-announce/2019/000009.html
Several security issues were fixed in LibreOffice.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that solves two vulnerabilities and has three fixes is now available.
Tracking the malicious activities of the elusive Ke3chang APT group, ESET researchers have discovered new versions of malware families linked to the group, and a previously unreported backdoor The post Okrum: Ke3chang group targets diplomatic missions appeared first on WeLiveSecurity
security update
Several security issues were fixed in Thunderbird.
Keeping up with BlueKeep; or how many internet-facing systems, and in which countries and industries, remain ripe for exploitation? The post BlueKeep patching isn’t progressing fast enough appeared first on WeLiveSecurity
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
An update that fixes three vulnerabilities is now available.
An update that fixes 12 vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 10 vulnerabilities is now available.
An update that solves 7 vulnerabilities and has three fixes is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1775
The package chromium before version 75.0.3770.142-1 is vulnerable to multiple issues including arbitrary code execution and information disclosure.
The package squid before version 4.8-1 is vulnerable to arbitrary code execution.
The package firefox before version 68.0-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site request forgery, sandbox escape, arbitrary filesystem access, content spoofing, cross-site scripting, denial of service, information disclosure, insufficient validation and silent downgrade.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1774
Upstream details at : https://access.redhat.com/errata/RHSA-2019:1777
A use-after-free in onig_new_deluxe() in regext.c allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker
Risk Level: Very Low. Type: Trojan.
