News

Looking Glass Cyber
    Malware Patrol SecList securingtomorrow.mcafee.com
      Quick Heal Threat Post Naked Security Security Affairs

      Security Awareness Tips of the week

        Exploits

        Last 20 Website Defacements - Zone-h

        Advisories

        Symantec Packet Stoem Security

        • Ubuntu Security Notice USN-6128-1 Thu, 01 Jun 2023 14:52:18 GMT
          Ubuntu Security Notice 6128-1 - It was discovered that CUPS incorrectly handled logging. A remote attacker could use this issue to cause CUPS to crash, resulting in a denial of service, or possibly execute arbitrary code.
        • Red Hat Security Advisory 2023-3415-01 Thu, 01 Jun 2023 14:48:57 GMT
          Red Hat Security Advisory 2023-3415-01 - Updated images are now available for Red Hat Advanced Cluster Security (RHACS). The updated image includes security and bug fixes.
        • Red Hat Security Advisory 2023-3408-01 Thu, 01 Jun 2023 14:43:05 GMT
          Red Hat Security Advisory 2023-3408-01 - OpenSSL is a toolkit that implements the Secure Sockets Layer and Transport Layer Security protocols, as well as a full-strength general-purpose cryptography library. Issues addressed include double free and use-after-free vulnerabilities.
        • Ubuntu Security Notice USN-6127-1 Thu, 01 Jun 2023 14:42:46 GMT
          Ubuntu Security Notice 6127-1 - Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Gwangun Jung discovered that the Quick Fair Queueing scheduler implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.
        • Red Hat Security Advisory 2023-3397-01 Thu, 01 Jun 2023 14:39:17 GMT
          Red Hat Security Advisory 2023-3397-01 - QATzip is a user space library which builds on top of the Intel QuickAssist Technology user space library, to provide extended accelerated compression and decompression services by offloading the actual compression and decompression request to the Intel Chipset Series. Issues addressed include a privilege escalation vulnerability.
        • Red Hat Security Advisory 2023-3403-01 Thu, 01 Jun 2023 14:34:20 GMT
          Red Hat Security Advisory 2023-3403-01 - The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Issues addressed include a denial of service vulnerability.
        • Red Hat Security Advisory 2023-3387-01 Thu, 01 Jun 2023 14:31:54 GMT
          Red Hat Security Advisory 2023-3387-01 - Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Issues addressed include a cross site scripting vulnerability.
        • Red Hat Security Advisory 2023-3394-01 Thu, 01 Jun 2023 14:29:57 GMT
          Red Hat Security Advisory 2023-3394-01 - The Public Key Infrastructure Core contains fundamental packages required by Red Hat Certificate System.
        • Red Hat Security Advisory 2023-3388-01 Thu, 01 Jun 2023 14:17:56 GMT
          Red Hat Security Advisory 2023-3388-01 - The kernel packages contain the Linux kernel, the core of any Linux operating system. Issues addressed include bypass and use-after-free vulnerabilities.
        • Debian Security Advisory 5417-1 Wed, 31 May 2023 16:31:34 GMT
          Debian Linux Security Advisory 5417-1 - Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit.
        • Ubuntu Security Notice USN-6126-1 Wed, 31 May 2023 16:31:20 GMT
          Ubuntu Security Notice 6126-1 - It was discovered that libvirt incorrectly handled the nwfilter driver. A local attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. It was discovered that libvirt incorrectly handled queries for the SR-IOV PCI device capabilities. A local attacker could possibly use this issue to cause libvirt to consume resources, leading to a denial of service.
        • Ubuntu Security Notice USN-6125-1 Wed, 31 May 2023 16:31:07 GMT
          Ubuntu Security Notice 6125-1 - It was discovered that the snap sandbox did not restrict the use of the ioctl system call with a TIOCLINUX request. This could be exploited by a malicious snap to inject commands into the controlling terminal which would then be executed outside of the snap sandbox once the snap had exited. This could allow an attacker to execute arbitrary commands outside of the confined snap sandbox. Note: graphical terminal emulators like xterm, gnome-terminal and others are not affected - this can only be exploited when snaps are run on a virtual console.
        • Ubuntu Security Notice USN-6117-1 Wed, 31 May 2023 16:30:56 GMT
          Ubuntu Security Notice 6117-1 - It was discovered that Apache Batik incorrectly handled certain inputs. An attacker could possibly use this to perform a cross site request forgery attack. It was discovered that Apache Batik incorrectly handled Jar URLs in some situations. A remote attacker could use this issue to access files on the server. It was discovered that Apache Batik allowed running untrusted Java code from an SVG. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code.
        • Ubuntu Security Notice USN-6124-1 Wed, 31 May 2023 16:30:21 GMT
          Ubuntu Security Notice 6124-1 - Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Reima Ishii discovered that the nested KVM implementation for Intel x86 processors in the Linux kernel did not properly validate control registers in certain situations. An attacker in a guest VM could use this to cause a denial of service.
        • Ubuntu Security Notice USN-6123-1 Wed, 31 May 2023 16:30:06 GMT
          Ubuntu Security Notice 6123-1 - Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Reima Ishii discovered that the nested KVM implementation for Intel x86 processors in the Linux kernel did not properly validate control registers in certain situations. An attacker in a guest VM could use this to cause a denial of service.
        • Ubuntu Security Notice USN-6122-1 Wed, 31 May 2023 16:29:46 GMT
          Ubuntu Security Notice 6122-1 - Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Jean-Baptiste Cayrou discovered that the shiftfs file system in the Ubuntu Linux kernel contained a race condition when handling inode locking in some situations. A local attacker could use this to cause a denial of service.
        • Debian Security Advisory 5416-1 Wed, 31 May 2023 16:29:12 GMT
          Debian Linux Security Advisory 5416-1 - It was discovered that there was a potential buffer overflow and denial of service vulnerability in the gdhcp client implementation of connman, a command-line network manager designed for use on embedded devices.
        • Ubuntu Security Notice USN-6121-1 Tue, 30 May 2023 17:08:01 GMT
          Ubuntu Security Notice 6121-1 - It was discovered that Nanopb incorrectly handled certain decode messages. An attacker could possibly use this cause a denial of service or expose sensitive information. It was discovered that Nanopb incorrectly handled certain decode messages. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
        • Ubuntu Security Notice USN-6120-1 Tue, 30 May 2023 17:07:45 GMT
          Ubuntu Security Notice 6120-1 - Several security issues were discovered in the SpiderMonkey JavaScript library. If a user were tricked into opening malicious JavaScript applications or processing malformed data, a remote attacker could exploit a variety of issues related to JavaScript security, including denial of service attacks, and arbitrary code execution.
        • Ubuntu Security Notice USN-6119-1 Tue, 30 May 2023 17:07:30 GMT
          Ubuntu Security Notice 6119-1 - Matt Caswell discovered that OpenSSL incorrectly handled certain ASN.1 object identifiers. A remote attacker could possibly use this issue to cause OpenSSL to consume resources, resulting in a denial of service. Anton Romanov discovered that OpenSSL incorrectly handled AES-XTS cipher decryption on 64-bit ARM platforms. An attacker could possibly use this issue to cause OpenSSL to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 22.10, and Ubuntu 23.04.
        • Ubuntu Security Notice USN-6111-1 Tue, 30 May 2023 17:07:15 GMT
          Ubuntu Security Notice 6111-1 - It was discovered that Flask incorrectly handled certain data responses. An attacker could possibly use this issue to expose sensitive information.
        • Widevine Trustlet 5.x / 6.x / 7.x PRDiagParseAndStoreData Buffer Overflow Tue, 30 May 2023 16:49:13 GMT
          Widevine Trustlet versions 5.x, 6.x, and 7.x suffer from a buffer overflow vulnerability in PRDiagParseAndStoreData at 0x5cc8.
        • Widevine Trustlet 5.x / 6.x / 7.x PRDiagVerifyProvisioning Buffer Overflow Tue, 30 May 2023 16:47:13 GMT
          Widevine Trustlet versions 5.x, 6.x, and 7.x suffer from a buffer overflow vulnerability in PRDiagVerifyProvisioning at 0x5f90.
        • Widevine Trustlet 5.x drm_verify_keys Buffer Overflow Tue, 30 May 2023 16:45:25 GMT
          Widevine Trustlet versions 5.x suffer from a buffer overflow vulnerability in drm_verify_keys at 0x7370.
        • Widevine Trustlet 5.x drm_verify_keys Buffer Overflow Tue, 30 May 2023 16:43:45 GMT
          Widevine Trustlet versions 5.x suffer from a buffer overflow vulnerability in drm_verify_keys at 0x730c.