SEC Charges SolarWinds and CISO With Misleading Investors

Read Time:3 Second

Complaint alleges company overstated security posture and understated risks

Read More

CVE-2015-20110

Read Time:20 Second

JHipster generator-jhipster before 2.23.0 allows a timing attack against validateToken due to a string comparison that stops at the first character that is different. Attackers can guess tokens by brute forcing one character at a time and observing the timing. This of course drastically reduces the search space to a linear amount of guesses based on the token length times the possible characters.

Read More

rubygem-rmagick-5.2.0-2.fc37

Read Time:13 Second

FEDORA-2023-8dd1a1a2e6

Packages in this update:

rubygem-rmagick-5.2.0-2.fc37

Update description:

A security flaw was found on rubygem-rmagick that Magick::Draw causes memleak. This issue is assigned as CVE-2023-5349. This new rpm fixes this issue.

Read More