Post Content
Monthly Archives: August 2022
GLSA 202208-25: Chromium, Google Chrome, Microsoft Edge, QtWebEngine: Multiple Vulnerabilities
GLSA 202208-20: Apache HTTPD: Multiple Vulnerabilities
GLSA 202208-21: libebml: Heap buffer overflow vulnerability
GLSA 202208-22: xterm: Multiple Vulnerabilities
Friday Squid Blogging: SQUID Acronym for Making Conscious Choices
I think the U is forced:
SQUID consists of five steps: Stop, Question, Understand, Imagine, and Decide.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
New exploits can bypass Secure Boot and modern UEFI security protections
Two teams of researchers have revealed vulnerabilities this week in Unified Extensible Firmware Interface (UEFI) implementations and bootloaders that could allow attackers to defeat the secure boot defenses of modern PCs and deploy highly persistent rootkits.
Researchers from firmware and hardware security firm Eclypsium published a report on vulnerabilities they found in three third-party bootloaders that are digitally signed by Microsoft’s root of trust. They can be deployed on PCs as a replacement for the OS bootloader to support pre-boot capabilities for specialized enterprise software such as PC hardware diagnostics, disk rollback, or full disk encryption.
CVE-2021-29118
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.
CVE-2021-29117
A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an unauthenticated attacker to achieve arbitrary code execution in the context of the current user.
CVE-2021-29112
An out-of-bounds read vulnerability exists when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) which allow an unauthenticated attacker to induce an information disclosure issue in the context of the current user.