Skip to main content

CND News and Blog

New Vulnerabilities Monday 26 February


New Alerts for Microsoft Edge, WithSecure, HPE, HP, F5, IBM, and Linux.

Microsoft 

Edge has been updated to fix the latest chromium-based vulnerabilities.
Note the normal Edge announcement page doesn't yet show this update.
More info. And (maybe) here.

WithSecure 

A DoS vulnerability was discovered in WithSecure products where the engine scanner goes into infinite loop when processing certain archive file. The exploit can be triggered remotely by an attacker. CVSSv3 score of 7.5
More info.

HPE 

A vulnerability in GNU C Library impacts HPE IceWall products. A remote attacker could cause a DoS. CVSSv3 score of 5.9
Manual fixes, no actual "patch".
More info.

HP 

A DoS vulnerability has been identified in Tera2 Zero Client and Remote Workstation Card Firmware when using Service Location Protocol. CVSSv3 score of 7.5
More info.

F5 

A vulnerability in OpenSSH in BIG-IP and Traffix SDC could allow a remtoe attacker to establish an SSH Proxy session when it should have been denied. CVSSv3 score of 4.8
Patches are available for Traffix SDC but not BIG-IP.
More info.

IBM 

OpenSSH used by IBM i is vulnerable to a remote attacker executing arbitrary commands due to improper validation. CVSSv3 score of 9.8
More info.

IBM Cognos Analytics contains vulnerabilities in open-source software. Highest CVSSv3 score of 9.8
More info.

Vulnerabilities in Go-git were remediated in IBM Observability with Instana. Highest CVSSv3 score of 9.8
More info.

Linux 

Red Hat has updated the kernel. More info.
Ubuntu has updated the kernel. More info.
Mageia has updated systemd. More info.
Amazon Linux has updated sudo. More info.
Amazon Linux 2 has updated sudo. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Friday, 03 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/