It was discovered that Graphite2 mishandled specially crafted files. An
attacker could possibly use this issue to cause a denial of service or
other unspecified impact.
Yearly Archives: 2022
python3-mod_wsgi-4.7.1-3.el7
FEDORA-EPEL-2022-3f600666f9
Packages in this update:
python3-mod_wsgi-4.7.1-3.el7
Update description:
Backported fix for CVE-2022-2255
python3.6-3.6.15-13.fc38
FEDORA-2022-3bc8e7f017
Packages in this update:
python3.6-3.6.15-13.fc38
Update description:
Automatic update for python3.6-3.6.15-13.fc38.
Changelog
* Wed Oct 5 2022 Victor Stinner <vstinner@python.org> – 3.6.15-13
– Prevent denial of service (DoS) by very large integers.
Resolves: rhbz#1834423
nodejs-18.10.0-1.fc37
FEDORA-2022-d84d27c5ad
Packages in this update:
nodejs-18.10.0-1.fc37
Update description:
Update to 18.10.0
https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V18.md#18.10.0
September Security Updates for Node.js
Update to 18.9.0
https://github.com/nodejs/node/blob/main/doc/changelogs/CHANGELOG_V18.md#18.9.0
North Korea’s Lazarus group uses vulnerable Dell driver to blind security solutions
The notorious North Korean state-sponsored hacker group Lazarus has begun exploiting a known vulnerability in an OEM driver developed by Dell to evade detection by security solutions. This is a prime example of why it’s important to always keep third-party PC manufacturer software, which is often neglected, up to date, as well as to add vulnerable versions to blocklists.
“The most notable tool delivered by the attackers was a user-mode module that gained the ability to read and write kernel memory due to the CVE-2021-21551 vulnerability in a legitimate Dell driver,” security researchers from antivirus firm ESET said in a recent report. “This is the first ever recorded abuse of this vulnerability in the wild. The attackers then used their kernel memory write access to disable seven mechanisms the Windows operating system offers to monitor its actions, like registry, file system, process creation, event tracing etc., basically blinding security solutions in a very generic and robust way.”
October Is Cybersecurity Awareness Month
For the past nineteen years, October has been Cybersecurity Awareness Month here in the US, and that event that has always been part advice and part ridicule. I tend to fall on the apathy end of the spectrum; I don’t think I’ve ever mentioned it before. But the memes can be funny.
Here’s a decent rundown of some of the chatter.
Canadian Sentenced 20 Years in US Prison For Ransomware Attacks
USN-5658-1: DHCP vulnerabilities
It was discovered that DHCP incorrectly handled option reference counting.
A remote attacker could possibly use this issue to cause DHCP servers to
crash, resulting in a denial of service. (CVE-2022-2928)
It was discovered that DHCP incorrectly handled certain memory operations.
A remote attacker could possibly use this issue to cause DHCP clients and
servers to consume resources, leading to a denial of service.
(CVE-2022-2929)
CISA Advisory Details How Hackers Targeted Defense Industrial Base Organization
golang-1.18.7-1.fc36
FEDORA-2022-0e313cc582
Packages in this update:
golang-1.18.7-1.fc36
Update description:
This release includes security fixes to the archive/tar, net/http/httputil, and regexp packages, as well as bug fixes to the compiler, the linker, and the go/types package. See the Go 1.18.7 milestone on the issue tracker for details.