Researchers reveal the Sandworm group attempted to cut power to a large region of Ukraine
Yearly Archives: 2022
dhcp-4.4.3-2.fc36
FEDORA-2022-3f293290c3
Packages in this update:
dhcp-4.4.3-2.fc36
Update description:
Security fix for CVE-2021-25220
New version 4.4.3
Add keama migration utility
USN-5378-3: XZ Utils vulnerability
USN-5378-2 fixed a vulnerability in XZ Utils. This update provides
the corresponding update for Ubuntu 14.04 ESM and 16.04 ESM.
Original advisory details:
Cleemy Desu Wayo discovered that Gzip incorrectly handled certain
filenames. If a user or automated system were tricked into performing zgrep
operations with specially crafted filenames, a remote attacker could
overwrite arbitrary files.
golang-x-crypto-0-0.43.20220412git7b82a4e.fc34
FEDORA-2022-d37fb34309
Packages in this update:
golang-x-crypto-0-0.43.20220412git7b82a4e.fc34
Update description:
Update for CVE-2022-27191
golang-x-crypto-0-0.43.20220412git7b82a4e.fc35
FEDORA-2022-a4c9009f3e
Packages in this update:
golang-x-crypto-0-0.43.20220412git7b82a4e.fc35
Update description:
Update for CVE-2022-27191
golang-x-crypto-0-0.43.20220412git7b82a4e.fc36
FEDORA-2022-14712f9699
Packages in this update:
golang-x-crypto-0-0.43.20220412git7b82a4e.fc36
Update description:
Update for CVE-2022-27191
CVE-2020-29653
Froxlor through 0.10.22 does not perform validation on user input passed in the customermail GET parameter. The value of this parameter is reflected in the login webpage, allowing the injection of arbitrary HTML tags.
Security blind spots in the era of cloud communication & collaboration. Are you protected?
Graham Cluley Security News is sponsored this week by the folks at Perception Point. Thanks to the great team there for their support! The need to communicate, collaborate and do business on a global level has created a proliferation of cloud based applications and services: Email. Cloud Storage. Messaging platforms. CRM. Digital Apps and Services. … Continue reading “Security blind spots in the era of cloud communication & collaboration. Are you protected?”
USN-5378-2: XZ Utils vulnerability
Cleemy Desu Wayo discovered that XZ Utils incorrectly handled certain
filenames. If a user or automated system were tricked into performing
xzgrep operations with specially crafted filenames, a remote attacker could
overwrite arbitrary files.
USN-5378-1: Gzip vulnerability
Cleemy Desu Wayo discovered that Gzip incorrectly handled certain
filenames. If a user or automated system were tricked into performing zgrep
operations with specially crafted filenames, a remote attacker could
overwrite arbitrary files.