Collected every two hours from specialised publications — each link leads to the original article.
- avoid overwriting a local file with -J (CVE-2020-8177) - fix partial password leak over DNS on HTTP redirect (CVE-2020-8169)
This update fixes a security issue causing a memory leak when an AES-CMAC key is enabled for authentication.
Privacy and security are pressing concerns for all of us these days '' not a day goes by that we aren't bombarded with security news headlines about hacks, bre…
Several issues have been fixed in zziplib, a library providing read access on ZIP-archives. They are basically all related to invalid memory access and resulti…
- avoid overwriting a local file with -J (CVE-2020-8177) - fix partial password leak over DNS on HTTP redirect (CVE-2020-8169)
Mozilla: Security downgrade with IMAP STARTTLS leads to information leakage (CVE-2020-12398) * Mozilla: Use-after-free in SharedWorkerService (CVE-2020-12405) …
Mozilla: Security downgrade with IMAP STARTTLS leads to information leakage (CVE-2020-12398) * Mozilla: Use-after-free in SharedWorkerService (CVE-2020-12405) …
It was discovered that Django, a high-level Python web development framework, did not properly sanitize input. This would allow a remote attacker to perform SQ…
* Fix iptables No chain/target/match by that name (bz #1813830) * systemd: start libvirtd after firewalld/iptables services (bz #1697636) * CVE-2020-12430: mem…
It was discovered that there was a regression in the latest update to Django, the Python web development framework. The upstream fix for CVE-2020-13254 to addr…
After much debate, Linus Torvalds has rejected a controversial patch to address potential leaks of secrets from a CPU's cores.
Apache Ant could leak sensitive information or be made to run programs as your login.
git: Crafted URL containing new lines, empty host or lacks a scheme can cause credential leak (CVE-2020-11008) SL7 x86_64 git-1.8.3.1-23.el7_8.x86_64.rpm git-d…
**PHP version 7.4.6** (14 May 2020) **Core:** * Fixed bug php#78434 (Generator yields no items after valid() call). (Nikita) * Fixed bug php#79477 (casting obj…
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid poi…
**PHP version 7.3.17** (16 Apr 2020) **Core:** * Fixed bug php#79364 (When copy empty array, next key is unspecified). (cmb) * Fixed bug php#78210 (Invalid poi…
Have you heard about IPFire's new method of cryptographic kernel rootkit protection?ÂIPFire is an open-source software that protects the network from external …
Two vulnerabilities have recently been discovered in the stream-tcp code of the intrusion detection and prevention tool Suricata.
Multiple vulnerabilities have been discovered in the Xen hypervisor, which could result in denial of service, guest-to-host privilege escalation or information…
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, data exfiltrati…
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, data exfiltrati…
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code executi…
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code executi…
bluez 5.52: * improvements for bluetooth mesh * audio bug fixes * general bug fixes ---- ell 0.26: * Fix issue with memory leak and TLS certificates. * Fix iss…