The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Update to v1.8.4.1 Security fix for CVE-2022-28919
Update to v1.8.4.1 Security fix for CVE-2022-28919
Update to v1.8.4.1 Security fix for CVE-2022-28919
An update that fixes two vulnerabilities is now available.
Security hotfix release addressing a critical vulnerability in PostgreSQL connections (CVE-2021-3850) Additional fixes: Fix usage of get_magic_* functions #619…
Out of bounds in php_pcre_replace_impl (CVE-2017-9118) Multiple bugs fixed. See referenced changelog for details. References: - https://bugs.mageia.org/show_bu…
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
**Version 4.4.35** (2021-11-24) * security **CVE-2021-41270** [Serializer] Use single quote to escape formulas (jderusse) * bug #44232 [Cache] fix connecting t…
Header injection via default_mimetype / default_charset mbstring may use pointer from some previous request Unexpected behavior with arrays and JIT Special cha…
An update that solves one vulnerability and has one errata is now available.
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
**Archive_Tar 1.4.14** * Properly fix symbolic link path traversal (**CVE-2021-32610**)
PHPMailer contained a vulnerability that can result in untrusted code being called (CVE-2021-3603). See upstream release notes.
Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode (CVE-2021-26119). Smarty before 3.1.39 allows code…
**Version 4.4.24** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) * bug #412…
**Version 3.4.49** (2021-05-19) * security **CVE-2021-21424** [SecurityCore] Fix user enumeration via response body on invalid credentials (chalasr) ---- **Ver…
**Version 6.4.1** (April 29th, 2021) * **SECURITY** Fixes CVE-2020-36326, a regression of CVE-2018-19296 object injection introduced in 6.1.8, see SECURITY.md …
An update that solves two vulnerabilities and has one errata is now available.
An update that solves two vulnerabilities and has one errata is now available.
**Version 4.4.13** (2020-09-02) * security **CVE-2020-15094** Remove headers with internal meaning from HttpClient responses (mpdude) * bug #38024 [Console] Fi…
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
In Horde Groupware, there has been an XSS vulnerability that could be exploited via the URL field in a "Calendar New Event" action. For Debian 9 stretch, this …
In Horde Groupware, there has been an XSS via the Name field during creation of a new Resource. This could have been leveraged for remote code execution after …