No Image

USN-4476-1: NSS vulnerability

2020-08-28 KENNETH 0

USN-4476-1: NSS vulnerability It was discovered that NSS incorrectly handled some inputs. An attacker could possibly use this issue to expose sensitive information. Source: USN-4476-1: NSS vulnerability

No Image

USN-4475-1: Chrony vulnerability

2020-08-27 KENNETH 0

USN-4475-1: Chrony vulnerability It was discovered that Chrony incorrectly handled certain symbolic links. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. Source: USN-4475-1: Chrony vulnerability

No Image

USN-4446-2: Squid regression

2020-08-27 KENNETH 0

USN-4446-2: Squid regression USN-4446-1 fixed vulnerabilities in Squid. The update introduced a regression when using Squid with the icap or ecap protocols. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Jeriko One discovered that Squid incorrectly handled caching certain requests. A remote attacker could possibly use this issue to perform cache-injection attacks or gain access to reverse proxy features such as ESI. (CVE-2019-12520) Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly handled certain URN requests. A remote attacker could possibly use this issue to bypass access checks. (CVE-2019-12523) Jeriko One discovered that Squid incorrectly handled URL decoding. A remote attacker could possibly use this issue to bypass certain rule checks. (CVE-2019-12524) Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly handled input validation. A remote attacker could use this issue to cause Squid to [ more… ]

No Image

USN-4474-1: Firefox vulnerabilities

2020-08-27 KENNETH 0

USN-4474-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, trick the user in to installing a malicious extension, spoof the URL bar, leak sensitive information between origins, or execute arbitrary code. (CVE-2020-15664, CVE-2020-15665, CVE-2020-15666, CVE-2020-15670) It was discovered that NSS incorrectly handled certain signatures. An attacker could possibly use this issue to expose sensitive information. (CVE-2020-12400, CVE-2020-12401, CVE-2020-6829) A data race was discovered when importing certificate information in to the trust store. An attacker could potentially exploit this to cause an unspecified impact. (CVE-2020-15668) Source: USN-4474-1: Firefox vulnerabilities

No Image

USN-4473-1: libmysofa vulnerabilities

2020-08-26 KENNETH 0

USN-4473-1: libmysofa vulnerabilities It was discovered that libmysofa incorrectly handled certain input files. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. (CVE-2019-16091, CVE-2019-16092, CVE-2019-16093, CVE-2019-16094, CVE-2019-16095) Source: USN-4473-1: libmysofa vulnerabilities