πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ—“οΈ The Matrix Resurrections review: Latest film instalment offers nostalgia but no denouement πŸ—“οΈ

DΓ©jΓ  vu isn't what it used to be

πŸ“– Read

via "The Daily Swig".
πŸ—“οΈ Security done right: Celebrating infosec wins in 2021 πŸ—“οΈ

Kudos to Tonga’s ccTLD, the US Supreme Court, and others…

πŸ“– Read

via "The Daily Swig".
β€Ό CVE-2021-4193 β€Ό

vim is vulnerable to Out-of-bounds Read

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-4192 β€Ό

vim is vulnerable to Use After Free

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45933 β€Ό

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (8 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacket).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45926 β€Ό

MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd0c689be0) in mdb_numeric_to_string (called from mdb_xfer_bound_data and _mdb_attempt_bind).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45940 β€Ό

libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (4 bytes) in __bpf_object__open (called from bpf_object__open_mem and bpf-object-fuzzer.c).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45928 β€Ό

libjxl before 0.6, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup and jxl::ThreadPool::RunCallState<jxl::FrameDecoder::ProcessSections).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45934 β€Ό

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_HandlePacket and MqttClient_WaitType).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45930 β€Ό

Qt SVG in Qt 5.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45943 β€Ό

GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44716 β€Ό

net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45935 β€Ό

Grok 9.5.0 has a heap-based buffer overflow in openhtj2k::T1OpenHTJ2K::decompress (called from std::__1::__packaged_task_func<std::__1::__bind<grk::T1DecompressScheduler::deco and std::__1::packaged_task<int).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45938 β€Ό

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Unsubscribe).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45939 β€Ό

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Subscribe).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45942 β€Ό

OpenEXR 3.1.0 through 3.1.3 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45931 β€Ό

HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45941 β€Ό

libbpf 0.6.0 and 0.6.1 has a heap-based buffer overflow (8 bytes) in __bpf_object__open (called from bpf_object__open_mem and bpf-object-fuzzer.c).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44717 β€Ό

Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-41817 β€Ό

Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45932 β€Ό

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (4 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacket).

πŸ“– Read

via "National Vulnerability Database".