No Image

Recognizing Security Researchers in 2020

2020-02-04 KENNETH 0

Recognizing Security Researchers in 2020 Is it too early to talk about the 2020 MSRC Most Valuable Security Researchers? Five months from now, at the end of June, the program period closes for researchers to be considered for inclusion in the Most Valuable Researchers list. The top researcher list will be revealed at Black Hat North America in August. For … Recognizing Security Researchers in 2020 Read More » The post Recognizing Security Researchers in 2020 appeared first on Microsoft Security Response Center. Source: Recognizing Security Researchers in 2020

No Image

USN-4263-1: Sudo vulnerability

2020-02-03 KENNETH 0

USN-4263-1: Sudo vulnerability sudo vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Sudo could allow unintended access to the administrator account. Software Description sudo – Provide limited super user privileges to specific users Details Joe Vennix discovered that Sudo incorrectly handled memory operations when the pwfeedback option is enabled. A local attacker could possibly use this issue to obtain unintended access to the administrator account. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 sudo – 1.8.27-1ubuntu4.1 sudo-ldap – 1.8.27-1ubuntu4.1 Ubuntu 18.04 LTS sudo – 1.8.21p2-3ubuntu1.2 sudo-ldap – 1.8.21p2-3ubuntu1.2 Ubuntu 16.04 LTS sudo – 1.8.16-0ubuntu1.9 sudo-ldap – 1.8.16-0ubuntu1.9 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary [ more… ]

No Image

Announcing the Xbox Bounty program

2020-01-31 KENNETH 0

Announcing the Xbox Bounty program Announcing the new Xbox Bounty. The Xbox bounty program invites gamers, security researchers, and technologists around the world to help identify security vulnerabilities in the Xbox network and services, and share them with the Microsoft Xbox team through Coordinated Vulnerability Disclosure (CVD). The post Announcing the Xbox Bounty program appeared first on Microsoft Security Response Center. Source: Announcing the Xbox Bounty program

No Image

USN-4234-2: Firefox regressions

2020-01-30 KENNETH 0

USN-4234-2: Firefox regressions firefox regressions A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary USN-4234-1 caused some minor regressions in Firefox. Software Description firefox – Mozilla Open Source web browser Details USN-4234-1 fixed vulnerabilities in Firefox. The update introduced various minor regressions. This update fixes the problems. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass Content Security Policy (CSP) restrictions, conduct cross-site scripting (XSS) attacks, or execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 firefox – 72.0.2+build1-0ubuntu0.19.10.1 Ubuntu 18.04 LTS firefox [ more… ]

No Image

USN-4262-1: OpenStack Keystone vulnerability

2020-01-30 KENNETH 0

USN-4262-1: OpenStack Keystone vulnerability keystone vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Summary OpenStack Keystone could be made to expose sensitive information over the network. Software Description keystone – OpenStack identity service Details Daniel Preussker discovered that OpenStack Keystone incorrectly handled the list credentials API. A user with a role on the project could use this issue to view any other user’s credentials. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 keystone – 2:16.0.0-0ubuntu1.1 python3-keystone – 2:16.0.0-0ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-19687 Source: USN-4262-1: OpenStack Keystone vulnerability