It was discovered that mqtt-client incorrectly handled memory while parsing
malformed MQTT frames. An attacker could possibly use this issue to cause a
crash, resulting in a denial of service, or possibly execute arbitrary code.
Daily Archives: March 7, 2024
golang-github-cloudflare-circl-1.3.7-1.fc41
FEDORA-2024-97fd10b49f
Packages in this update:
golang-github-cloudflare-circl-1.3.7-1.fc41
Update description:
Automatic update for golang-github-cloudflare-circl-1.3.7-1.fc41.
Changelog
* Thu Mar 7 2024 Mikel Olasagasti Uranga <mikel@olasagasti.info> – 1.3.7-1
– Update to 1.3.7 – Closes rhbz#2165786 rhbz#2203758
* Sun Feb 11 2024 Maxwell G <maxwell@gtmx.me> – 1.3.1-6
– Rebuild for golang 1.22.0
* Wed Jan 24 2024 Fedora Release Engineering <releng@fedoraproject.org> – 1.3.1-5
– Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
USN-6684-1: ncurses vulnerability
It was discovered that ncurses incorrectly handled certain function return
values, possibly leading to segmentation fault. A local attacker could possibly
use this to cause a denial of service (system crash).
$12.5 billion lost to cybercrime, amid tidal wave of crypto investment fraud
If you have been optimistically daydreaming that losses attributed to cybercrime might have reduced in the last year, it’s time to wake up.
The FBI’s latest annual Internet Crime Complaint Center (IC3) report has just been published, and makes for some grim reading.
Read more in my article on the Tripwire State of Security blog.
RATs Spread Via Fake Skype, Zoom, Google Meet Sites
Zscaler’s ThreatLabz discovered malware spreading SpyNote RAT to Android and NjRAT/DCRat to Windows
Emergency. Ransomware halts beer production at Belgium’s Duvel brewery
I’m afraid that the people of Belgium are dealing with a national emergency.
python3.6-3.6.15-27.fc39
FEDORA-2024-d1f1084584
Packages in this update:
python3.6-3.6.15-27.fc39
Update description:
Security fix for CVE-2007-4559.
Evasive Panda Targets Tibet With Trojanized Software
ESET researchers said the attackers strategically leveraged the Monlam Festival, targeting individuals associated with Tibetan Buddhism
CIS Benchmarks March 2024 Update
Here is an overview of the CIS Benchmarks that the Center for Internet Security updated or released for March 2024.
python3.6-3.6.15-27.fc38
FEDORA-2024-ebb3c95344
Packages in this update:
python3.6-3.6.15-27.fc38
Update description:
Security fix for CVE-2007-4559.