Month-long European operation focused on online fraudsters
Daily Archives: November 15, 2022
USN-5725-1: Go vulnerability
Diederik Loerakker, Jonny Rhea, Raúl Kripalani, and Preston
Van Loon discovered that Go incorrectly handled certain inputs.
An attacker could possibly use this issue to cause Go applications
to hang or crash, resulting in a denial of service.
Build a mature approach for better cybersecurity vendor evaluation
Seasoned CISO Mike Manrod knows the value of a good cybersecurity vendor evaluation. He recalls that in a past job he inherited some very expensive vaporware under a long-term services agreement. His predecessor had purchased an “innovative” beta identity and access management platform but hadn’t done any analysis on the product, simply accepting the vendor’s claims of its efficacy. It was a dud.
Inversely, as CISO at his current company Grand Canyon Education, Manrod set his team up to evaluate an allegedly “brilliant” web application security product only to discover through testing that its client-side validation was easy to bypass and thus subvert the product. That basic test saved them from making an expensive mistake. “Startups are trysforming, and sometimes they go back to the drawing board. Nothing wrong there, but if we as security leaders purchase something that’s not ready yet, that’s on us,” he says.
Google to Pay $392m in Landmark Privacy Case
python3.7-3.7.15-2.fc36
FEDORA-2022-385d2ea041
Packages in this update:
python3.7-3.7.15-2.fc36
Update description:
Security fix for CVE-2022-37454
python3.8-3.8.15-2.fc36
FEDORA-2022-5fd3e7f635
Packages in this update:
python3.8-3.8.15-2.fc36
Update description:
Security fix for CVE-2022-37454
freerdp-2.8.1-1.fc35
FEDORA-2022-e733724edb
Packages in this update:
freerdp-2.8.1-1.fc35
Update description:
Update to 2.8.1 (CVE-2022-39282, CVE-2022-39283).
freerdp-2.8.1-1.fc36
FEDORA-2022-45b9fbfcbe
Packages in this update:
freerdp-2.8.1-1.fc36
Update description:
Update to 2.8.1 (CVE-2022-39282, CVE-2022-39283).
freerdp-2.8.1-1.fc37
FEDORA-2022-d6310a1308
Packages in this update:
freerdp-2.8.1-1.fc37
Update description:
Update to 2.8.1 (CVE-2022-39282, CVE-2022-39283).
ZDI-22-1589: Microsoft Windows Output Protection Manager Integer Overflow Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.