ty Ubuntu Security Notice USN-4332-2 By packetstormsecurity.com Published On :: Mon, 27 Apr 2020 22:55:55 GMT Ubuntu Security Notice 4332-2 - USN-4332-1 fixed vulnerabilities in File Roller. This update provides the corresponding update for Ubuntu 20.04 LTS. It was discovered that File Roller incorrectly handled symlinks. An attacker could possibly use this issue to expose sensitive information. Full Article
ty Ubuntu Security Notice USN-4340-1 By packetstormsecurity.com Published On :: Mon, 27 Apr 2020 23:03:33 GMT Ubuntu Security Notice 4340-1 - It was discovered that CUPS incorrectly handled certain language values. A local attacker could possibly use this issue to cause CUPS to crash, leading to a denial of service, or possibly obtain sensitive information. This issue only applied to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10. Stephan Zeisberg discovered that CUPS incorrectly handled certain malformed ppd files. A local attacker could possibly use this issue to execute arbitrary code. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4338-2 By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 15:00:17 GMT Ubuntu Security Notice 4338-2 - USN-4338-1 fixed vulnerabilities in re2c. This update provides the corresponding update for Ubuntu 20.04 LTS. Agostino Sarubbo discovered that re2c incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. Full Article
ty Ubuntu Security Notice USN-4341-1 By packetstormsecurity.com Published On :: Tue, 28 Apr 2020 20:42:15 GMT Ubuntu Security Notice 4341-1 - Andrei Popa discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could use this issue to cause Samba to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 19.10 and Ubuntu 20.04 LTS. It was discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could possibly use this issue to cause Samba to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4342-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:46:39 GMT Ubuntu Security Notice 4342-1 - Al Viro discovered that the Linux kernel for s390x systems did not properly perform page table upgrades for kernel sections that use secondary address mode. A local attacker could use this to cause a denial of service or execute arbitrary code. It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4343-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:46:53 GMT Ubuntu Security Notice 4343-1 - Al Viro discovered that the Linux kernel for s390x systems did not properly perform page table upgrades for kernel sections that use secondary address mode. A local attacker could use this to cause a denial of service or execute arbitrary code. Full Article
ty Ubuntu Security Notice USN-4344-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:55:05 GMT Ubuntu Security Notice 4344-1 - It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. It was discovered that the Intel WiMAX 2400 driver in the Linux kernel did not properly deallocate memory in certain situations. A local attacker could use this to cause a denial of service. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4345-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:56:59 GMT Ubuntu Security Notice 4345-1 - Al Viro discovered that the Linux kernel for s390x systems did not properly perform page table upgrades for kernel sections that use secondary address mode. A local attacker could use this to cause a denial of service or execute arbitrary code. It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4346-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 15:58:35 GMT Ubuntu Security Notice 4346-1 - It was discovered that the QLogic Fibre Channel driver in the Linux kernel did not properly check for error, leading to a NULL pointer dereference. A local attacker could possibly use this to cause a denial of service. It was discovered that the Intel Wi-Fi driver in the Linux kernel did not properly check for errors in some situations. A local attacker could possibly use this to cause a denial of service. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4341-3 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 16:05:01 GMT Ubuntu Security Notice 4341-3 - USN-4341-1 fixed vulnerabilities in Samba. The updated packages for Ubuntu 16.04 LTS introduced a regression when using LDAP. This update fixes the problem. It was discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could possibly use this issue to cause Samba to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4348-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 17:22:51 GMT Ubuntu Security Notice 4348-1 - It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this to issue execute arbitrary scripts or HTML. It was discovered that Mailman incorrectly handled certain inputs. An attacker could possibly use this issue to display arbitrary text on a web page. It was discovered that Mailman incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4341-2 By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 14:46:29 GMT Ubuntu Security Notice 4341-2 - USN-4341-1 fixed a vulnerability in Samba. This update provides the corresponding update for Ubuntu 14.04 ESM. It was discovered that Samba incorrectly handled certain LDAP queries. A remote attacker could possibly use this issue to cause Samba to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4333-2 By packetstormsecurity.com Published On :: Thu, 30 Apr 2020 14:48:19 GMT Ubuntu Security Notice 4333-2 - USN-4333-1 fixed vulnerabilities in Python. This update provides the corresponding update for Ubuntu 20.04 LTS. It was discovered that Python incorrectly stripped certain characters from requests. A remote attacker could use this issue to perform CRLF injection. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4349-1 By packetstormsecurity.com Published On :: Fri, 01 May 2020 13:52:43 GMT Ubuntu Security Notice 4349-1 - A buffer overflow was discovered in the network stack. An unprivileged user could potentially enable escalation of privilege and/or denial of service. This issue was already fixed in a previous release for 18.04 LTS and 19.10. A buffer overflow was discovered in BlockIo service. An unauthenticated user could potentially enable escalation of privilege, information disclosure and/or denial of service. This issue was already fixed in a previous release for 18.04 LTS and 19.10. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4350-1 By packetstormsecurity.com Published On :: Mon, 04 May 2020 17:29:10 GMT Ubuntu Security Notice 4350-1 - Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.80 in Ubuntu 19.10 and Ubuntu 20.04 LTS. Ubuntu 16.04 LTS and Ubuntu 18.04 LTS have been updated to MySQL 5.7.30. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4330-2 By packetstormsecurity.com Published On :: Wed, 06 May 2020 14:54:02 GMT Ubuntu Security Notice 4330-2 - USN-4330-1 fixed vulnerabilities in PHP. This update provides the corresponding update for Ubuntu 20.04 LTS. It was discovered that PHP incorrectly handled certain EXIF files. An attacker could possibly use this issue to access sensitive information or cause a crash. Various other issues were also addressed. Full Article
ty Ubuntu Security Notice USN-4351-1 By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:27:24 GMT Ubuntu Security Notice 4351-1 - Eli Biham and Lior Neumann discovered that certain Bluetooth devices incorrectly validated key exchange parameters. An attacker could possibly use this issue to obtain sensitive information. Full Article
ty Ubuntu Security Notice USN-4352-1 By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:33:27 GMT Ubuntu Security Notice 4352-1 - It was discovered that OpenLDAP incorrectly handled certain queries. A remote attacker could possibly use this issue to cause OpenLDAP to consume resources, resulting in a denial of service. Full Article
ty Ubuntu Security Notice USN-4352-2 By packetstormsecurity.com Published On :: Thu, 07 May 2020 15:33:32 GMT Ubuntu Security Notice 4352-2 - USN-4352-1 fixed a vulnerability in OpenLDAP. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. It was discovered that OpenLDAP incorrectly handled certain queries. A remote attacker could possibly use this issue to cause OpenLDAP to consume resources, resulting in a denial of service. Various other issues were also addressed. Full Article
ty Bradford ‘most improved UK city for growth’ By www.fdiintelligence.com Published On :: Thu, 12 Dec 2019 12:38:06 +0000 Bradford has been rated as the most improved city by the Good Growth for Cities 2019 index, while Oxford remained the highest performing UK city. Full Article
ty Tokyo world’s most talked about city online By www.fdiintelligence.com Published On :: Mon, 27 Jan 2020 09:03:59 +0000 ING Media names Tokyo, New York, London and Paris as global super brands for digital visibility. Full Article
ty Safari Webkit Proxy Object Type Confusion By packetstormsecurity.com Published On :: Sun, 02 Jun 2019 15:30:59 GMT This Metasploit module exploits a type confusion bug in the Javascript Proxy object in WebKit. The DFG JIT does not take into account that, through the use of a Proxy, it is possible to run arbitrary JS code during the execution of a CreateThis operation. This makes it possible to change the structure of e.g. an argument without causing a bailout, leading to a type confusion (CVE-2018-4233). The type confusion leads to the ability to allocate fake Javascript objects, as well as the ability to find the address in memory of a Javascript object. This allows us to construct a fake JSCell object that can be used to read and write arbitrary memory from Javascript. The module then uses a ROP chain to write the first stage shellcode into executable memory within the Safari process and kick off its execution. The first stage maps the second stage macho (containing CVE-2017-13861) into executable memory, and jumps to its entrypoint. The CVE-2017-13861 async_wake exploit leads to a kernel task port (TFP0) that can read and write arbitrary kernel memory. The processes credential and sandbox structure in the kernel is overwritten and the meterpreter payloads code signature hash is added to the kernels trust cache, allowing Safari to load and execute the (self-signed) meterpreter payload. Full Article
ty Red Hat Security Advisory 2019-1821-01 By packetstormsecurity.com Published On :: Mon, 22 Jul 2019 15:22:22 GMT Red Hat Security Advisory 2019-1821-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include bypass and denial of service vulnerabilities. Full Article
ty Ubuntu Security Notice USN-4130-1 By packetstormsecurity.com Published On :: Wed, 11 Sep 2019 20:00:19 GMT Ubuntu Security Notice 4130-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty Red Hat Security Advisory 2019-2925-01 By packetstormsecurity.com Published On :: Mon, 30 Sep 2019 13:33:33 GMT Red Hat Security Advisory 2019-2925-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include a denial of service vulnerability. Full Article
ty Red Hat Security Advisory 2019-2939-01 By packetstormsecurity.com Published On :: Mon, 30 Sep 2019 22:22:22 GMT Red Hat Security Advisory 2019-2939-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include a denial of service vulnerability. Full Article
ty Red Hat Security Advisory 2019-2955-01 By packetstormsecurity.com Published On :: Wed, 02 Oct 2019 15:03:59 GMT Red Hat Security Advisory 2019-2955-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include a denial of service vulnerability. Full Article
ty Ubuntu Security Notice USN-4178-1 By packetstormsecurity.com Published On :: Fri, 08 Nov 2019 15:35:29 GMT Ubuntu Security Notice 4178-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty Ubuntu Security Notice USN-4181-1 By packetstormsecurity.com Published On :: Tue, 12 Nov 2019 18:56:35 GMT Ubuntu Security Notice 4181-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty Ubuntu Security Notice USN-4261-1 By packetstormsecurity.com Published On :: Thu, 30 Jan 2020 14:46:06 GMT Ubuntu Security Notice 4261-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty Ubuntu Security Notice USN-4281-1 By packetstormsecurity.com Published On :: Tue, 18 Feb 2020 15:06:49 GMT Ubuntu Security Notice 4281-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty Red Hat Security Advisory 2020-0573-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:14:57 GMT Red Hat Security Advisory 2020-0573-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
ty Red Hat Security Advisory 2020-0579-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:19:52 GMT Red Hat Security Advisory 2020-0579-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
ty Red Hat Security Advisory 2020-0597-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:23:31 GMT Red Hat Security Advisory 2020-0597-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
ty Red Hat Security Advisory 2020-0598-01 By packetstormsecurity.com Published On :: Tue, 25 Feb 2020 15:24:19 GMT Red Hat Security Advisory 2020-0598-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
ty Red Hat Security Advisory 2020-0602-01 By packetstormsecurity.com Published On :: Wed, 26 Feb 2020 05:02:22 GMT Red Hat Security Advisory 2020-0602-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. HTTP request smuggling was addressed along with other security issues. Full Article
ty Ubuntu Security Notice USN-4310-1 By packetstormsecurity.com Published On :: Mon, 30 Mar 2020 15:43:08 GMT Ubuntu Security Notice 4310-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty Red Hat Security Advisory 2020-1293-01 By packetstormsecurity.com Published On :: Thu, 02 Apr 2020 14:46:47 GMT Red Hat Security Advisory 2020-1293-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include an integer overflow vulnerability. Full Article
ty Red Hat Security Advisory 2020-1317-01 By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 18:24:03 GMT Red Hat Security Advisory 2020-1317-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include an integer overflow vulnerability. Full Article
ty Red Hat Security Advisory 2020-1325-01 By packetstormsecurity.com Published On :: Mon, 06 Apr 2020 18:40:24 GMT Red Hat Security Advisory 2020-1325-01 - python-XStatic-jQuery is the jQuery javascript library packaged for Python's setuptools. Issues addressed include code execution and denial of service vulnerabilities. Full Article
ty Red Hat Security Advisory 2020-1343-01 By packetstormsecurity.com Published On :: Tue, 07 Apr 2020 16:40:52 GMT Red Hat Security Advisory 2020-1343-01 - Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Issues addressed include an integer overflow vulnerability. Full Article
ty Ubuntu Security Notice USN-4331-1 By packetstormsecurity.com Published On :: Mon, 20 Apr 2020 15:24:18 GMT Ubuntu Security Notice 4331-1 - A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty Ubuntu Security Notice USN-4347-1 By packetstormsecurity.com Published On :: Wed, 29 Apr 2020 16:01:43 GMT Ubuntu Security Notice 4347-1 - A large number of security issues were discovered in the WebKitGTK Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Full Article
ty US Congress: Spying Law Is Flawed, Open To Abuse, And Lacking In Accountability - So Let's Reauthorize It By packetstormsecurity.com Published On :: Fri, 13 Mar 2020 14:49:20 GMT Full Article headline government privacy usa phone spyware nsa
ty US-CERT Reiterates $5 Million Bounty On North Korean Hackers By packetstormsecurity.com Published On :: Thu, 16 Apr 2020 15:30:49 GMT Full Article headline hacker government usa cyberwar spyware korea
ty A European draw: Eco Equity breaks new ground in medicinal cannabis By www.fdiintelligence.com Published On :: Thu, 16 Apr 2020 12:04:02 +0000 Eco Equity is one of only a few Europe-based investors in medicinal cannabis from Africa and the Caribbean, an area in which the UK is missing an opportunity, according to CEO Jon-Paul Doran. Full Article
ty Mara's Phones makes African manufacturing a priority By www.fdiintelligence.com Published On :: Thu, 12 Dec 2019 12:01:24 +0000 Having opened new production facilities in Rwanda and South Africa, Mara Phones is looking to alter Africa's mindset from being a 'consumer' to being a 'manufacturer'. Full Article
ty Brexit uncertainty drives auto industry towards Germany By www.fdiintelligence.com Published On :: Fri, 15 Nov 2019 17:14:11 +0000 Tesla's decision part of broader trend of investment into Germany at UK's expense. Full Article
ty Mobility expertise boosts Braunschweig's ambitions By www.fdiintelligence.com Published On :: Thu, 12 Dec 2019 12:01:00 +0000 Despite nurturing its R&D capacity, the city of Braunschweig lags its German peers in attracting FDI. Now it hopes a focus on the mobility sector will mean its technical skills are matched with investment. Full Article
ty Pakistan’s UK high commissioner hails land of opportunity By www.fdiintelligence.com Published On :: Mon, 16 Dec 2019 16:56:05 +0000 Mohammad Nafees Zakaria, Pakistan’s UK high commissioner, talks about his country’s potential for foreign investors. Full Article