DSA-5462 linux – security update

Read Time:12 Second

Tavis Ormandy discovered that under specific microarchitectural
circumstances, a vector register in AMD Zen 2 CPUs may not be
written to 0 correctly. This flaw allows an attacker to leak
sensitive information across concurrent processes, hyper threads
and virtualized guests.

Read More

A Vulnerability in Ivanti Endpoint Manager Mobile Could Allow for Arbitrary Code Execution

Read Time:18 Second

A vulnerability has been discovered in Ivanti Endpoint Manager (EPMM), formerly known as MobileIron Core; which could allow for arbitrary code execution. Ivanti Endpoint Manager Mobile is a mobile management software engine that enables IT to set policies for mobile devices, applications and content. If successfully exploited, an attacker could perform arbitrary file writes to the EPMM server.

Read More

CVE-2021-4322

Read Time:12 Second

Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)

Read More

CVE-2021-4321

Read Time:9 Second

Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)

Read More

CVE-2021-4320

Read Time:12 Second

Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

Read More