The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
Upstream details at : https://access.redhat.com/errata/RHSA-2020:0194
Included in Log4j 1.2, a logging library for Java, is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to re…
An update that fixes one vulnerability is now available.
The updated package fixes a security vulnerability: A flaw was found in mod_auth_openidc before version 2.4.0.1. An open redirect issue exists in URLs with tr…
The updated packages fix security vulnerabilities: Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to …
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that solves one vulnerability and has one errata is now available.
An update that fixes one vulnerability is now available.
Update to version 1.9.4. Resolves CVE-2019-10086.
Update to version 1.9.4. Resolves CVE-2019-10086.
An update that fixes one vulnerability is now available.
An update that fixes one vulnerability is now available.
Update to version 1.19. Resolves CVE-2019-12402.
Update to version 1.19. Resolves CVE-2019-12402.
An update is now available for JBoss Core Services on RHEL 6 and RHEL 7. Red Hat Product Security has rated this update as having a security impact of Importan…
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There…
Apache is asking OpenOffice users to turn off its Java integration after warning that a malicious document could run code on their computer.
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analy…
Multiple vulnerabilities in the Apache Portable Runtime Utility library apr-util could lead to denial of service or arbitrary code execution; updates are avail…
Fedora 44 has released apr-util version 1.6.5 with security fixes, enhancing its Apache Portable Runtime Utility library for better handling of XML, LDAP, and …
The Fedora 44 update for Apache Traffic Server version 10.1.4 addresses multiple security vulnerabilities, including request smuggling and memory-safety issues…
Oracle Linux released updates for Apache HTTP Server and related modules addressing multiple CVEs for security vulnerabilities, along with package version chan…
A newly disclosed attack technique called HTTP/2 Bomb is drawing attention because it targets the software that sits at the front of much of the Linux internet…