A vulnerability classified as problematic has been found in Halulu simple-download-button-shortcode Plugin 1.0 on WordPress. Affected is an unknown function of the file simple-download-button_dl.php of the component Download Handler. The manipulation of the argument file leads to information disclosure. It is possible to launch the attack remotely. Upgrading to version 1.1 is able to address this issue. The patch is identified as e648a8706818297cf02a665ae0bae1c069dea5f1. It is recommended to upgrade the affected component. VDB-242190 is the identifier assigned to this vulnerability.
Monthly Archives: October 2023
CVE-2011-10004
A vulnerability was found in reciply Plugin up to 1.1.7 on WordPress. It has been rated as critical. This issue affects some unknown processing of the file uploadImage.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. Upgrading to version 1.1.8 is able to address this issue. The identifier of the patch is e3ff616dc08d3aadff9253f1085e13f677d0c676. It is recommended to upgrade the affected component. The identifier VDB-242189 was assigned to this vulnerability.
DSA-5529-1 slurm-wlm – security update
Francois Diakhate discovered that several race conditions in file
processing of the Simple Linux Utility for Resource Management (SLURM),
a cluster resource management and job scheduling system, could result
in denial of service by overwriting arbitrary files.
DSA-5529 slurm-wlm – security update
Francois Diakhate discovered that several race conditions in file
processing of the Simple Linux Utility for Resource Management (SLURM),
a cluster resource management and job scheduling system, could result
in denial of service by overwriting arbitrary files.
A Vulnerability in Cisco IOS XE Software Web UI Could Allow for Privilege Escalation
A vulnerability in Cisco IOS XE Software Web UI that could allow for privilege escalation. Successful exploitation could allow an unauthenticated remote attacker to create an account on an affected system with privilege level 15 access, allowing them to use that account to gain control of the affected system. The Cisco IOS XE Software web UI is an embedded GUI-based system-management tool, that comes with the default image.
virglrenderer-0.8.2-1.20200212git7d204f39.el8
FEDORA-EPEL-2023-c5b83b4c87
Packages in this update:
virglrenderer-0.8.2-1.20200212git7d204f39.el8
Update description:
Update from 0.8.0 to 0.8.2 to pick up the fixes for two CVEs.
Fraudsters target Booking.com customers claiming hotel stay could be cancelled
One of the world’s largest online travel agencies, Booking.com, is being used by fraudsters to trick hotel guests into handing over their payment card details.
How do I know? The fraudsters tried the trick with me.
USN-6431-3: iperf3 vulnerability
USN-6431-1 fixed a vulnerability in iperf3. This update provides
the corresponding update for Ubuntu 22.04 LTS.
Original advisory details:
Jorge Sancho Larraz discovered that iperf3 did not properly manage certain
inputs, which could cause the server process to stop responding, waiting
for input on the control connection. A remote attacker could possibly use
this issue to cause a denial of service. (LP: #2038654)
Ransomware Targets Unpatched WS_FTP Servers
The threat actors attempted to escalate privileges using the open-source GodPotato tool
dotnet6.0-6.0.123-1.fc37
FEDORA-2023-dcf59d2db2
Packages in this update:
dotnet6.0-6.0.123-1.fc37
Update description:
This the October 2023 monthly update for .NET 6
Release Notes: https://github.com/dotnet/core/blob/main/release-notes/6.0/6.0.23/6.0.23.md