Posted by Apple Product Security via Fulldisclosure on Jul 25
APPLE-SA-2023-07-24-3 iOS 15.7.8 and iPadOS 15.7.8
iOS 15.7.8 and iPadOS 15.7.8 addresses the following issues.
Information about the security content is also available at https://support.apple.com/kb/HT213842.
Apple maintains a Security Updates page at https://support.apple.com/HT201222 which lists recent
software updates with security advisories.
Apple Neural Engine
Available for devices with Apple Neural Engine: iPhone 8 and later, iPad
Pro…
Posted by Apple Product Security via Fulldisclosure on Jul 25
APPLE-SA-2023-07-24-2 iOS 16.6 and iPadOS 16.6
iOS 16.6 and iPadOS 16.6 addresses the following issues.
Information about the security content is also available at https://support.apple.com/kb/HT213841.
Apple maintains a Security Updates page at https://support.apple.com/HT201222 which lists recent
software updates with security advisories.
Apple Neural Engine
Available for devices with Apple Neural Engine: iPhone 8 and later, iPad
Pro (3rd…
Tavis Ormandy discovered that some AMD processors did not properly handle
speculative execution of certain vector register instructions. A local attacker
could use this to expose sensitive information.
USN-6129-1 fixed a vulnerability in Avahi. This update provides the
corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS and Ubuntu 18.04
LTS.
Original advisory details:
It was discovered that Avahi incorrectly handled certain DBus messages. A
local attacker could possibly use this issue to cause Avahi to crash,
resulting in a denial of service.
USN-6203-1 fixed a vulnerability in Django. This update provides
the corresponding update for Ubuntu 18.04 ESM.
Original advisory details:
Seokchan Yoon discovered that Django incorrectly handled certain regular
expressions. A remote attacker could possibly use this issue to cause
Django to consume resources, leading to a denial of service.
The details are scant—the article is based on a “heavily redacted” contract—but the New York subway authority is using an “AI system” to detect people who don’t pay the subway fare.
Joana Flores, an MTA spokesperson, said the AI system doesn’t flag fare evaders to New York police, but she declined to comment on whether that policy could change. A police spokesperson declined to comment.
If we spent just one-tenth of the effort we spend prosecuting the poor on prosecuting the rich, it would be a very different world.