This kernel update is based on the upstream 4.14.106 and fixes atleast the following security issue: In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which makes it easier for attackers
The updated live, mplayer, vlc packages fix security vulnerabilities: liblivemedia in Live555 before 2019.02.03 mishandles the termination of an RTSP stream after RTP/RTCP-over-RTSP has been set up, which could lead to a Use-After-Free error that causes the RTSP server to crash (Segmentation
Updated pdns packages fix security vulnerability: An issue has been found in PowerDNS Authoritative Server when the HTTP remote backend is used in RESTful mode (without post=1 set), allowing a remote user to cause the HTTP backend to connect to an attacker-specified
The updated poppler packages fix security vulnerabilities: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in
The updated file packages fix security vulnerabilities: do_core_note in readelf.c in libmagic.a in file 5.35 has a stack-based buffer over-read, related to file_printable, a different vulnerability than CVE-2018-10360. (CVE-2019-8905)
Updated openjpeg2 packages fix security vulnerability: Division-by-zero vulnerabilities in the functions pi_next_pcrl, pi_next_cprl, and pi_next_rpcl in lib/openjp3d/pi.c in OpenJPEG through 2.3.0 allow remote attackers to cause a denial of service
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
The package imagemagick before version 7.0.8.35-1 is vulnerable to arbitrary code execution.
The package dovecot before version 2.3.5.1-1 is vulnerable to privilege escalation.
An update that fixes four vulnerabilities is now available.
An update that fixes one vulnerability is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
An update that fixes 18 vulnerabilities is now available.
An update that fixes 8 vulnerabilities is now available.
More trouble in dark markets? A notorious black-market bazaar announces plans to close up shop on the same day as police announce the arrests of 61 people The post Global police arrest dozens of people in dark web sting appeared first on WeLiveSecurity
security update
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
An update that fixes two vulnerabilities is now available.
An update that solves 8 vulnerabilities and has one errata is now available.
An update that fixes four vulnerabilities is now available.
An update that fixes two vulnerabilities is now available.
An update that fixes 5 vulnerabilities is now available.
xmltooling could be made to crash if it opened a specially crafted file.
Red Hat Ansible Tower 3.3.5 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:
Red Hat Ansible Tower 3.4.3 2. Description: For a list of changes included in this release, please read the Ansible Tower Release Notes:
Reading Time: ~3 min. The last decade has been one of digital revolution, leading to the rapid adoption of new technology standards, often without the consideration of privacy ramifications. This has left many of us with a less-than-secure trail of digital breadcrumbs—something cybercriminals are more than aware of. Identity theft is by no means a […]
Several vulnerabilities have recently been discovered in libssh2, a client-side C library implementing the SSH2 protocol
An update that fixes one vulnerability is now available.
openwsman: Disclosure of arbitrary files outside of the registered URIs (CVE-2019-3816) SL7 x86_64 libwsman1-2.6.3-6.git4391e5c.el7_6.i686.rpm libwsman1-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-client-2.6.3-6.git4391e5c.el7_6.x86_64.rpm openwsman-debuginfo-2.6.3-6.git4391e5c.el7_6.i686.rpm openwsman-debuginfo-2. [More…]
An update for kernel-rt is now available for Red Hat Enterprise MRG 2. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
Risk Level: Very Low. Type: Trojan, Virus.
Risk Level: Very Low. Type: Trojan, Virus.
Risk Level: Very Low. Type: Trojan, Virus.
security update
An update that fixes four vulnerabilities is now available.
The electric automaker is working to release a fix for the underlying vulnerability in a matter of days The post Two white hats hack a Tesla, get to keep it appeared first on WeLiveSecurity
Multiple scp client vulnerabilities have been discovered in OpenSSH, the premier connectivity tool for secure remote shell login and secure file transfer.
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
Two issues have been fixed in bash, the GNU Bourne-Again Shell: CVE-2016-9401
