GE CIMPICITY versions 2022 and prior is vulnerable when data from faulting address controls code flow starting at gmmiObj!CGmmiOptionContainer, which could allow an attacker to execute arbitrary code.
Yearly Archives: 2022
Apple finally adds encryption to iCloud backups
Apple has rolled out a number of security features that will now offer end-to-end encryption to protect data, including backups, contacts, notes, photos, and wallet passes. The company also announced hardware Security Keys for Apple ID.
freeradius-3.0.26-1.fc36
FEDORA-2022-98832b2cc2
Packages in this update:
freeradius-3.0.26-1.fc36
Update description:
Update to upstream release 3.0.26.
USN-5765-1: PostgreSQL vulnerability
Jacob Champion discovered that PostgreSQL incorrectly handled SSL
certificate verification and encryption. A remote attacker could possibly
use this issue to inject arbitrary SQL queries when a connection is first
established.
Microsoft Warns Cryptocurrency Firms Against Complex Cyber-Attacks
Attacks included fraud, vulnerability exploitation, fake applications and info stealer deployments
CVE-2020-36565
Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
US Congress rolls back proposal to restrict use of Chinese chips
After business groups argued that proposed legislation to curb use of Chinese-made semiconductors would hurt national security, lawmakers amended it—but a final vote and the president’s approval of the proposed National Defense Authorization Act (NDAA) is still to come.
NZ Privacy Commissioner Investigates Mercury IT Ransomware Attack
The watchdog also confirmed it plans on opening a compliance investigation into the incident
Security Risks Found in Millions of XIoT Devices
Phosphorus published a report encapsulating five years of security research and device testing.
python3.8-3.8.16-1.fc35
FEDORA-2022-e1ce71ff40
Packages in this update:
python3.8-3.8.16-1.fc35
Update description:
Update to 3.8.16