Security fix for [CVE-2018-1000877 CVE-2018-1000878 CVE-2018-1000879 CVE-2018-1000880] —- Applied various flaws from upsteam
CVE-2018-19364: 9pfs: use-after-free (bz #1651359) CVE-2018-19489: 9pfs: use- after-free renaming files (bz #1653157) CVE-2018-16867: usb-mtp: path traversal issue (bz #1656746) CVE-2018-16872: usb-mtp: path traversal issue (bz #1659150) CVE-2018-20191: pvrdma: uar_read leads to NULL deref (bz #1660315) CVE-2019-6778: slirp: heap buffer overflow (bz #1669072) CVE-2019-3812: Out-of-
Update to 3.0. License has changed to ASL 2.0 + exception. See https://github.com/michaelrsweet/mxml/releases/tag/v3.0 for more info.
Trail of Bits used the automated vulnerability discovery tools developed for the DARPA Cyber Grand Challenge to audit zlib. As rsync, a fast, versatile, remote (and local) file-copying tool, uses an embedded copy of
security update
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
It was discovered that Wireshark, a network traffic analyzer, contained several vulnerabilities in the dissectors for 6LoWPAN, P_MUL, RTSE, ISAKMP, TCAP, ASN.1 BER and RPCAP, which could result in denial of service.
An arbitrary file read vulnerability was discovered in passenger, a web application server. A local user allowed to deploy an application to passenger, can take advantage of this flaw by creating a symlink from the REVISION file to an arbitrary file on the system and have its
The package firefox before version 66.0.1-1 is vulnerable to arbitrary code execution.
security update
Several issues have been discovered in Apache module auth_mellon, which provides SAML 2.0 authentication. CVE-2019-3877
**Version 2.7.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 2.7.1** (2019-03-12) * fixed class aliases —- **Version 2.7.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array keys when fill
**Version 1.38.2** (2019-03-12) * added TemplateWrapper::getTemplateName() —- **Version 1.38.1** (2019-03-12) * fixed class aliases —- **Version 1.38.0** (2019-03-12) * fixed sandbox security issue (under some circumstances, calling the __toString() method on an object was possible even if not allowed by the security policy) * fixed batch filter clobbers array
Backport a security fix from PuTTY 0.71 affecting SFTP connections: Fix an integer overflow in the RSA key exchange preceeding host key verification
This update addresses various overflow conditions that could result in possible memory read/write out of bounds errors or zero byte allocations when connected to a malicious server.
security update
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Risk Level: Very Low. Type: Trojan.
Risk Level: Very Low. Type: Trojan.
A heap-based buffer overflow was discovered in NTFS-3G, a read-write NTFS driver for FUSE. A local user can take advantage of this flaw for local root privilege escalation.
Reading Time: ~2 min. Gnosticplayers Adds 26 Million More Records for Sale After the first 3 major data dumps, which totaled over 600 million records, the hacker known as Gnosticplayers has released his latest cache of data, which contains at least 26 million personal user records. These data caches hold customer information for 32 companies […]
Libzip could be made to crash if it received specially crafted input.
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0622
Upstream details at : https://access.redhat.com/errata/RHSA-2019:0623
An update that fixes one vulnerability is now available.
An update that solves two vulnerabilities and has two fixes is now available.
An update that fixes three vulnerabilities is now available.
Risk Level: Very Low. Type: Trojan.
Update tcpflow to 1.5.2 tag at github, fixing a security issue.
security update
security update
security update
The user module leaked parameters passed to ssh-keygen to the process environment (CVE-2018-16837). The fetch module was susceptible to path traversal (CVE-2019-3828).
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c. (CVE-2019-7397) References: – https://bugs.mageia.org/show_bug.cgi?id=24396
Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506). Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788).
Several security issues were fixed in Ghostscript.
An update for ghostscript is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
NTFS-3G could be made to crash or potentially run programs as anadministrator if executed with specially crafted arguments.
Our penchant for plugging in random memory sticks isn’t the only trouble with our USB hygiene, a study shows The post Most second-hand thumb drives contain data from past owners appeared first on WeLiveSecurity
More advice for detecting and avoiding sextortion scams The post I Still Didn’t See What You Did appeared first on WeLiveSecurity
Reading Time: ~4 min. Since the dawn of IT, there’s been a very consistent theme among admins: end users are the weakest link in your network, organization, security strategy, fill-in-the-blank. We’ve all heard the stories, and even experienced them first-hand. An employee falls for a phishing scam and the whole network is down. Another colleague […]
An update that fixes three vulnerabilities is now available.
Risk Level: Very Low. Type: Trojan.
An update for firefox is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update that fixes two vulnerabilities is now available.
