A vulnerability has been discovered in Atlassian Confluence Server and Data Center, which could allow for Privilege Escalation. Confluence is a collaboration tool that brings people, knowledge, and ideas together in a shared workspace. Successful exploitation of this vulnerability could allow an attacker to create unauthorized Confluence administrator accounts to access the instance. An attacker could then perform administrator actions in the context of the confluence instance.
Monthly Archives: October 2023
A Vulnerability in Cisco Emergency Responder Could Allow for Arbitrary Code Execution
A vulnerability has been discovered in Cisco Emergency Responder that could allow for arbitrary code execution on a targeted host. Successful exploitation could allow an unauthenticated remote attacker to log in to the affected system using the root account and execute arbitrary commands. Cisco Emergency Responder is used to enhance the existing emergency 9-1-1 functionality offered by Cisco Unified Communications Manager. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
icecat-115.3.1-7.rh2.fc38
FEDORA-2023-7342330743
Packages in this update:
icecat-115.3.1-7.rh2.fc38
Update description:
Release 115.3.1
icecat-115.3.1-7.rh2.fc39
FEDORA-2023-035866b576
Packages in this update:
icecat-115.3.1-7.rh2.fc39
Update description:
Release 115.3.1
Smashing Security podcast #342: Royal family attacked, keyless car theft, and a deepfake Tom Hanks
Is a deepfake Tom Hanks better than the real thing? Who has been attacking the British Royal Family’s website, and why? And how can you protect your vehicle from the spate of keyless car thefts?
All this and much much more is discussed in the latest edition of the “Smashing Security” podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.
Plus don’t miss our featured interview with Devo CISO Kayla Williams.
CISA and NSA Tackle IAM Security Challenges in New Report
netatalk-3.1.18-1.el7
FEDORA-EPEL-2023-36e0ca3184
Packages in this update:
netatalk-3.1.18-1.el7
Update description:
3.1.18 release
Security fix for CVE-2022-22995
netatalk-3.1.18-1.el8
FEDORA-EPEL-2023-99a9054ad1
Packages in this update:
netatalk-3.1.18-1.el8
Update description:
3.1.18 release
Security fix for CVE-2022-22995
netatalk-3.1.18-1.el9
FEDORA-EPEL-2023-9c790c33f7
Packages in this update:
netatalk-3.1.18-1.el9
Update description:
3.1.18 release
Security fix for CVE-2022-22995
netatalk-3.1.18-1.fc37
FEDORA-2023-ef901c862c
Packages in this update:
netatalk-3.1.18-1.fc37
Update description:
3.1.18 release
Security fix for CVE-2022-22995