No Image

Releasing Windows 11 Build 22621.607 to the Release Preview Channel

2022-09-23 KENNETH 0

Releasing Windows 11 Build 22621.607 to the Release Preview Channel Hello Windows Insiders, today we’re releasing Windows 11 Build 22621.607 (KB5017389) to Insiders in the Release Preview Channel on Windows 11, version 22H2.   This update includes the following improvements: We fixed an issue that affects some apps that were not signed by the Microsoft Store. You must reinstall them after you upgrade the OS. We fixed issues that cause updates to the Microsoft Store to fail. We fixed an issue that stops you from signing in to various Microsoft Office 365 apps. This affects Outlook, Word, Teams, and so on. We updated the start date for daylight saving time in Chile. It will start on September 11, 2022 instead of on September 4, 2022. We fixed an issue that affects the Windows Search service. It causes the indexing progress [ more… ]

No Image

USN-5629-1: Python vulnerability

2022-09-23 KENNETH 0

USN-5629-1: Python vulnerability It was discovered that the Python http.server module incorrectly handled certain URIs. An attacker could potentially use this to redirect web traffic. Source: USN-5629-1: Python vulnerability

No Image

USN-5634-1: Linux kernel (OEM) vulnerability

2022-09-23 KENNETH 0

USN-5634-1: Linux kernel (OEM) vulnerability Domingo Dirutigliano and Nicola Guerrera discovered that the netfilter subsystem in the Linux kernel did not properly handle rules that truncated packets below the packet header size. When such rules are in place, a remote attacker could possibly use this to cause a denial of service (system crash). Source: USN-5634-1: Linux kernel (OEM) vulnerability

No Image

USN-5633-1: Linux kernel vulnerabilities

2022-09-23 KENNETH 0

USN-5633-1: Linux kernel vulnerabilities It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33655) Duoming Zhou discovered that race conditions existed in the timer handling implementation of the Linux kernel’s Rose X.25 protocol layer, resulting in use-after-free vulnerabilities. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-2318) Roger Pau Monné discovered that the Xen virtual block driver in the Linux kernel did not properly initialize memory pages to be used for shared communication with the backend. A local attacker could use this to expose sensitive information (guest kernel memory). (CVE-2022-26365) Roger Pau Monné discovered that the [ more… ]

No Image

USN-5632-1: OAuthLib vulnerability

2022-09-23 KENNETH 0

USN-5632-1: OAuthLib vulnerability Sebastian Chnelik discovered that OAuthLib incorrectly handled certain redirect uris. A remote attacker could possibly use this issue to cause OAuthLib to crash, resulting in a denial of service. Source: USN-5632-1: OAuthLib vulnerability