php-nyholm-psr7-1.7.0-1.fc38

Read Time:15 Second

FEDORA-2023-b0811dc6e4

Packages in this update:

php-nyholm-psr7-1.7.0-1.fc38

Update description:

Version 1.7.0

Bump to PHP 7.2 minimum
Allow psr/http-message v2
Use copy-on-write for streams created from strings

Version 1.6.1

Security fix: CVE-2023-29197

Read More

CVE-2014-125099

Read Time:25 Second

A vulnerability has been found in I Recommend This Plugin up to 3.7.2 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality of the file dot-irecommendthis.php. The manipulation leads to sql injection. The attack can be launched remotely. Upgrading to version 3.7.3 is able to address this issue. The name of the patch is 058b3ef5c7577bf557557904a53ecc8599b13649. It is recommended to upgrade the affected component. The identifier VDB-226309 was assigned to this vulnerability.

Read More

Global intelligence assessments: you are the target

Read Time:40 Second

The duty and responsibility of every intelligence service is to collect, analyze, and disseminate intelligence information to its country’s policymakers. In a prior piece, we discussed the US Office of the Director of National Intelligence (ODNI) global threat assessment in the cyber domain. What follows is the perspective from other countries’ intelligence services on what the future may hold.

Those services whose assessments were reviewed and whose perspective is shared include the Australian Security Intelligence Organization (ASIO), Estonia Foreign Intelligence Service (EFIS), Finnish Security and Intelligence Service (SUPO), Norwegian Police Security Service (PST), Swedish Security Service (SAPO) and the European Union Agency for Cybersecurity (ENISA). The great power competition is alive and well and is the constant theme throughout the various assessments.

To read this article in full, please click here

Read More

libsignal-protocol-c-2.3.3-7.fc36

Read Time:22 Second

FEDORA-2023-8b0938312e

Packages in this update:

libsignal-protocol-c-2.3.3-7.fc36

Update description:

Backport a fix for CVE-2022-48468 for protobuf-c, which is bundled in libsignal-protocol-c.

https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217
https://github.com/protobuf-c/protobuf-c/issues/499
https://github.com/protobuf-c/protobuf-c/pull/513
https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1

Read More

libsignal-protocol-c-2.3.3-8.el8

Read Time:22 Second

FEDORA-EPEL-2023-4f43a624e1

Packages in this update:

libsignal-protocol-c-2.3.3-8.el8

Update description:

Backport a fix for CVE-2022-48468 for protobuf-c, which is bundled in libsignal-protocol-c.

https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217
https://github.com/protobuf-c/protobuf-c/issues/499
https://github.com/protobuf-c/protobuf-c/pull/513
https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1

Read More

libsignal-protocol-c-2.3.3-8.fc37

Read Time:22 Second

FEDORA-2023-6cfe134db6

Packages in this update:

libsignal-protocol-c-2.3.3-8.fc37

Update description:

Backport a fix for CVE-2022-48468 for protobuf-c, which is bundled in libsignal-protocol-c.

https://github.com/protobuf-c/protobuf-c/commit/ec3d900001a13ccdaa8aef996b34c61159c76217
https://github.com/protobuf-c/protobuf-c/issues/499
https://github.com/protobuf-c/protobuf-c/pull/513
https://github.com/protobuf-c/protobuf-c/releases/tag/v1.4.1

Read More