Several security vulnerabilities were discovered in Graphicsmagick, a collection of image processing tools. Heap-based buffer over-reads and a memory leak may lead to a denial-of-service or information disclosure.
This update backports a fix for CVE-2018-20096, CVE-2018-20097, CVE-2018-20098, CVE-2018-20099.
* Yaws ver. 2.0.6
The update of jasper issued as DLA-1628-1 caused a regression due to the fix for CVE-2018-19542, a NULL pointer dereference in the function jp2_decode, which could lead to a denial-of-service. In some cases not only invalid jp2 files but also valid jp2 files were rejected.
This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18
An update that solves two vulnerabilities and has four fixes is now available.
rssh could be made to run arbitrary commands if it received specially crafted input.
This update fixes security vulnerability – Checkstyle loads external DTDs by default. Upstream issue: https://github.com/checkstyle/checkstyle/issues/6474 https://github.com/checkstyle/checkstyle/issues/6478 References: https://checkstyle.org/releasenotes.html#Release_8.18
Reading Time: ~4 min. The process of bringing a cybersecurity product to market can be long and tedious, but Kiran Kumar, Product Director at Webroot, loves to oversee all the moving parts. It keeps him on his toes and immersed in the ever-changing world of security technology. We sat down to chat with Kumar about […]
security update
security update
security update
Risk Level: Very Low. Type: Trojan, Worm.
Reading Time: ~2 min. Tax Extortion Emails Bring Major Threats A new email campaign has been spotted threatening ransomware and DDoS attacks over fake tax documents allegedly held by the attackers if a Bitcoin ransom isn’t paid. The campaign authors also threaten to send fake tax documents to the IRS through a poorly-worded ransom email […]
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has 13 fixes is now available.
More than 50 universities in the United Kingdom had their cyber-defenses tested by ethical hackers, and the ‘grades’ aren’t pretty The post Hackers crack university defenses in just two hours appeared first on WeLiveSecurity
An update that fixes one vulnerability is now available.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0710
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0697
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0717
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0711
An update that fixes 6 vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that fixes three vulnerabilities is now available.
An update that solves one vulnerability and has 15 fixes is now available.
Risk Level: Very Low. Type: Trojan, Worm.
The new wireless security protocol contains multiple design flaws that hackers could exploit for attacks on Wi-Fi passwords The post WPA3 flaws may let attackers steal Wi-Fi passwords appeared first on WeLiveSecurity
An update that solves two vulnerabilities and has three fixes is now available.
An update that fixes 5 vulnerabilities is now available.
Several security issues were fixed in Ruby.
An update for ceph and grafana is now available for Red Hat Ceph Storage 2.5 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
An update for httpd24-httpd and httpd24-mod_auth_mellon is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,
Mathy Vanhoef (NYUAD) and Eyal Ronen (Tel Aviv University & KU Leuven) found multiple vulnerabilities in the WPA implementation found in wpa_supplication (station) and hostapd (access point). These vulnerability are also collectively known as “Dragonblood”.
The package apache before version 2.4.39-1 is vulnerable to multiple issues including privilege escalation, access restriction bypass and denial of service.
The package thunderbird before version 60.6.1-1 is vulnerable to arbitrary code execution.
The package gnutls before version 3.6.7-1 is vulnerable to multiple issues including arbitrary code execution and denial of service.
The package evolution before version 3.32.0-1 is vulnerable to content spoofing.
Backport more patches: – shared/install: Preserve escape characters for escaped unit names (https://github.com/coreos/bugs/issues/2569) – timedate: fix emitted value when ntp client is enabled/disabled (#1696586) – udev: run programs in the specified order (#1696784) – core: add Manager::honor_device_enumeration flag (https://pagure.io/fedora-
Multiple vulnerabilities have been found in Git, the worst of which could result in the arbitrary execution of code.
Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Azure DevOps Server and Team Foundation Server are prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a local privilege-escalation vulnerability; fixes are available.
Type: Vulnerability. Microsoft Azure DevOps Server is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Azure DevOps Server is prone to a spoofing vulnerability; fixes are available.
Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Team Foundation Server is prone to a cross-site scripting vulnerability; fixes are available.
Type: Vulnerability. Microsoft Azure DevOps Server is prone to an HTML-injection vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Internet Explorer is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft Open Enclave SDK is prone to an information-disclosure vulnerability; fixes are available.
Type: Vulnerability. Microsoft Windows is prone to a remote code-execution vulnerability; fixes are available.
Type: Vulnerability. Microsoft ASP.NET Core is prone to a remote denial-of-service vulnerability; fixes are available.
Type: Vulnerability. Microsoft Edge is prone to a remote memory-corruption vulnerability; fixes are available.
