No Image

RHSA-2017:2538-1: Low: rh-nginx110-nginx security update

2017-08-29 KENNETH 0

RHSA-2017:2538-1: Low: rh-nginx110-nginx security update Red Hat Enterprise Linux: An update for rh-nginx110-nginx is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-7529 Source: RHSA-2017:2538-1: Low: rh-nginx110-nginx security update

New WinDbg available in preview!

2017-08-29 KENNETH 0

New WinDbg available in preview! We are excited to announce a preview version of a brand new WinDbg. We’ve update WinDbg to have more modern visuals, faster windows, a full-fledged scripting experience, built with the easily extensible debugger data model front and center. I’ll start this by saying that WinDbg Preview is using the same underlying engine as WinDbg today, so all the commands extensions and workflows you’re used to will still work just as they did before. Getting started I know a lot of you are going to want to dive right in and try it out, so here are the things you should know before doing so. Installation – You can install the WinDbg Preview from the Store if you have Windows 10 Anniversary Update or newer at https://www.microsoft.com/en-us/store/p/windbg/9pgjgd53tn86 – WinDbg Preview uses some features from the Windows 10 [ more… ]

No Image

USN-3403-1: Ghostscript vulnerabilities

2017-08-29 KENNETH 0

USN-3403-1: Ghostscript vulnerabilities Ubuntu Security Notice USN-3403-1 28th August, 2017 ghostscript vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Ghostscript. Software description ghostscript – PostScript and PDF interpreter Details Kamil Frankowicz discovered that Ghostscript mishandles references.A remote attacker could use this to cause a denial of service.(CVE-2017-11714) Kim Gwan Yeong discovered that Ghostscript could allow a heap-based bufferover-read and application crash. A remote attacker could use a crafteddocument to cause a denial of service. (CVE-2017-9611, CVE-2017-9726,CVE-2017-9727, CVE-2017-9739) Kim Gwan Yeong discovered an use-after-free vulnerability in Ghostscript.A remote attacker could use a crafted file to cause a denial of service.(CVE-2017-9612) Kim Gwan Yeong discovered a lack of integer overflow check in Ghostscript.A remote attacker could use crafted PostScript document to cause a [ more… ]

Windows 10 Tip: Five ways to personalize notifications on your PC

2017-08-29 KENNETH 0

Windows 10 Tip: Five ways to personalize notifications on your PC To get started, head to Settings > System > Notifications & actions‌ – or, if you’re on a Windows 10 PC, click here to open notifications & actions. First, send notifications, reminders and alarms directly to the action center by right-clicking action center in your taskbar, then selecting Turn on quiet hours. Stop notifications from showing during a presentation by turning on Hide notifications when I’m duplicating my screen. Or, keep them from showing on your lock screen when you’re not logged in by turning off Show notifications on the lock screen. If you’re tired of seeing notifications from a particular app, turn them off next to the app under Get notifications from these senders – or, click on the app for more options. You also always have the option to [ more… ]

No Image

USN-3199-3: Python Crypto vulnerability

2017-08-29 KENNETH 0

USN-3199-3: Python Crypto vulnerability Ubuntu Security Notice USN-3199-3 28th August, 2017 python-crypto vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Programs using the Python Cryptography Toolkit could be made to crash or run programs if they receive specially crafted network traffic or other input. Software description python-crypto – cryptographic algorithms and protocols for Python Details USN-3199-1 fixed a vulnerability in Python Crypto. This updateprovides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that the ALGnew function in block_templace.c in the Python Cryptography Toolkit contained a heap-based buffer overflow vulnerability. A remote attacker could use this flaw to execute arbitrary code by using a crafted initialization vector parameter. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: python3-crypto [ more… ]