Ubisoft changes employee passwords after “cyber security incident”

Read Time:10 Second

Video game company Ubisoft, maker of hit titles like Assassin’s Creed and Just Dance says that it has “experienced a cyber security incident” – and as a consequence is changing its employees’ passwords.

Read More

python-paramiko-2.10.1-1.fc35

Read Time:32 Second

FEDORA-2022-8eb95d8611

Packages in this update:

python-paramiko-2.10.1-1.fc35

Update description:

CVE-2022-24302: Creation of new private key files using ~paramiko.pkey.PKey subclasses was subject to a race condition between file creation and mode modification, which could be exploited by an attacker with knowledge of where the Paramiko-using code would write out such files; this has been patched by using os.open and os.fdopen to ensure new files are opened with the correct mode immediately (we’ve left the subsequent explicit ‘chmod’ in place to minimize any possible disruption, though it may get removed in future backwards-incompatible updates).

Read More

python-paramiko-2.10.1-1.fc36

Read Time:32 Second

FEDORA-2022-bb5c461682

Packages in this update:

python-paramiko-2.10.1-1.fc36

Update description:

CVE-2022-24302: Creation of new private key files using ~paramiko.pkey.PKey subclasses was subject to a race condition between file creation and mode modification, which could be exploited by an attacker with knowledge of where the Paramiko-using code would write out such files; this has been patched by using os.open and os.fdopen to ensure new files are opened with the correct mode immediately (we’ve left the subsequent explicit ‘chmod’ in place to minimize any possible disruption, though it may get removed in future backwards-incompatible updates).

Read More

python-paramiko-2.10.1-1.fc34

Read Time:32 Second

FEDORA-2022-806492f1d1

Packages in this update:

python-paramiko-2.10.1-1.fc34

Update description:

CVE-2022-24302: Creation of new private key files using ~paramiko.pkey.PKey subclasses was subject to a race condition between file creation and mode modification, which could be exploited by an attacker with knowledge of where the Paramiko-using code would write out such files; this has been patched by using os.open and os.fdopen to ensure new files are opened with the correct mode immediately (we’ve left the subsequent explicit ‘chmod’ in place to minimize any possible disruption, though it may get removed in future backwards-incompatible updates).

Read More

DSA-5101 libphp-adodb – security update

Read Time:14 Second

Emmet Leahy reported that libphp-adodb, a PHP database abstraction layer
library, allows to inject values into a PostgreSQL connection string.
Depending on how the library is used this flaw can result in
authentication bypass, reveal a server IP address or have other
unspecified impact.

Read More

News, Advisories and much more

Exit mobile version