CVE-2014-125102

Read Time:24 Second

A vulnerability classified as problematic was found in Bestwebsoft Relevant Plugin up to 1.0.7 on WordPress. Affected by this vulnerability is an unknown functionality of the component Thumbnail Handler. The manipulation leads to information disclosure. The attack can be launched remotely. Upgrading to version 1.0.8 is able to address this issue. The name of the patch is 860d1891025548cf0f5f97364c1f51a888f523c3. It is recommended to upgrade the affected component. The identifier VDB-230113 was assigned to this vulnerability.

Read More

CVE-2021-37845

Read Time:22 Second

An issue was discovered in Citadel through webcit-932. A meddler-in-the-middle attacker can fixate their own session during the cleartext phase before a STARTTLS command (a violation of “The STARTTLS command is only valid in non-authenticated state.” in RFC2595). This potentially allows an attacker to cause a victim’s e-mail messages to be stored into an attacker’s IMAP mailbox, but depends on details of the victim’s client behavior.

Read More

CVE-2020-29547

Read Time:12 Second

An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS, or SMTP STARTTLS commands, injecting cleartext commands into an encrypted user session. This can lead to credential disclosure.

Read More

CVE-2019-19791

Read Time:15 Second

In LemonLDAP::NG (aka lemonldap-ng) before 2.0.7, the default Apache HTTP Server configuration does not properly restrict access to SOAP/REST endpoints (when some LemonLDAP::NG setup options are used). For example, an attacker can insert index.fcgi/index.fcgi into a URL to bypass a Require directive.

Read More

USN-6112-1: Perl vulnerability

Read Time:13 Second

It was discovered that Perl was not properly verifying TLS certificates
when using CPAN together with HTTP::Tiny to download modules over HTTPS.
If a remote attacker were able to intercept communications, this flaw
could potentially be used to install altered modules.

Read More

ImageMagick-7.1.1.10-1.fc38

Read Time:12 Second

FEDORA-2023-347adb2ea0

Packages in this update:

ImageMagick-7.1.1.10-1.fc38

Update description:

Update to 7.1.1.10 (#2207788)
Security fix for CVE-2023-34151
Security fix for CVE-2023-34152
Security fix for CVE-2023-34153

Read More

Hackers hold city of Augusta hostage in a ransomware attack

Read Time:28 Second

BlackByte group has claimed responsibility for a ransomware attack on the city of Augusta in Georgia. 

The ransomware group has posted 10GB of sample data for free and claimed they have much more data available. 

“We have lots of sensitive data. Many people would like to see that as well as the media. You were given time to connect us but it seems like you are sleepy,” the screenshot shared by security researcher Brett Callow, who is also a threat analyst at Emsisoft. 

To read this article in full, please click here

Read More