Author: ProHoster

Mozilla releases 2021 financial report

Mozilla has released its 2021 financial report. In 2021, Mozilla's revenue increased by $104 million to $600 million. For comparison, Mozilla earned $2020 million in 496, $2019 million in 828, $2018 million in 450, $2017 million in 562, […]

Mozilla will start accepting add-ons based on the third version of the Chrome manifest

On November 21, the AMO directory (addons.mozilla.org) will begin accepting and digitally signing add-ons that use the third version of the Chrome manifest. These add-ons can be tested in nightly builds of Firefox. In stable releases, support for the third version of the manifest will be enabled in Firefox 109, scheduled for January 17, 2023. Support for the second version of the manifest will be maintained for the foreseeable future, but […]

openSUSE Leap Micro 5.3 distribution available

The openSUSE project developers have published an atomically upgradable openSUSE Leap Micro 5.3 distribution for building microservices and for use as a base system for virtualization platforms and container isolation. Builds for x86_64 and ARM64 (Aarch64) architectures are available for download, supplied both with an installer (Offline builds, 1.9 GB in size) and in the form of ready-made boot images: 782MB […]

Vulnerability in the implementation of the MCTP protocol for Linux, allowing you to elevate your privileges

A vulnerability has been identified in the Linux kernel (CVE-2022-3977) that could potentially be used by a local user to elevate their privileges on the system. The vulnerability manifests itself starting from the 5.18 kernel and is fixed in the 6.1 branch. The appearance of the fix in distributions can be traced on the pages: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch. The vulnerability exists in the implementation of the Management Component Transport Protocol (MCTP) used to […]

Buffer overflow vulnerability in Samba and MIT/Heimdal Kerberos

Corrective releases of the Samba 4.17.3, 4.16.7 and 4.15.12 package have been published with the elimination of the vulnerability (CVE-2022-42898) in the Kerberos libraries, leading to an integer overflow and writing data outside the allocated buffer when processing PAC (Privileged Attribute Certificate) parameters sent by the authenticated user. The publication of package updates in distributions can be tracked on the pages: Debian, Ubuntu, Gentoo, RHEL, SUSE, Arch, FreeBSD. In addition to Samba […]

Critical vulnerabilities in Netatalk leading to remote code execution

Netatalk, a server that implements the AppleTalk and Apple Filing Protocol (AFP) network protocols, has six remotely exploitable vulnerabilities that allow you to organize the execution of your code as root by sending specially crafted packets. Netatalk is used by many manufacturers of storage devices (NAS) to provide file sharing and printer access from Apple computers, for example, used in […]

Release of the Rocky Linux 8.7 distribution developed by the founder of CentOS

The Rocky Linux 8.7 distribution has been released, aimed at creating a free build of RHEL that can take the place of the classic CentOS, after Red Hat stopped supporting the CentOS 8 branch ahead of schedule at the end of 2021, and not in 2029, as originally intended. This is the third stable release of the project, recognized as ready for production deployments. Rocky Linux builds prepared […]

Release of the distribution kit Alt Workstation K 10.1

The release of the distribution kit "Alt Workstation K 10.1", supplied with a graphical environment based on KDE Plasma, has been published. Boot and live images prepared for x86_64 architecture (6.1 GB, 4.3 GB). The operating system is included in the Unified Register of Russian Programs and will satisfy the requirements for the transition to infrastructure running domestic operating systems. Russian root encryption certificates are integrated into the main structure. Like […]

Two vulnerabilities in GRUB2 that can bypass UEFI Secure Boot protection

Two vulnerabilities have been disclosed in the GRUB2 bootloader that could lead to code execution when using specially designed fonts and handling certain Unicode sequences. Vulnerabilities can be used to bypass the UEFI Secure Boot verified boot mechanism. Known vulnerabilities: CVE-2022-2601 - Buffer overflow in the grub_font_construct_glyph() function when processing specially designed fonts in pf2 format, which occurs due to incorrect […]

Release of BackBox Linux 8, Security Testing Distribution

Two and a half years after the publication of the last release, the BackBox Linux 8 distribution is available, based on Ubuntu 22.04 and comes with a collection of tools for system security checks, exploit testing, reverse engineering, network traffic and wireless network analysis, malware research, stress -testing, revealing hidden or lost data. The user environment is based on Xfce. ISO image size 3.9 […]

Canonical Publishes Ubuntu Builds Optimized for Intel IoT Platforms

Canonical announced that they are preparing separate builds of Ubuntu Desktop (20.04 and 22.04), Ubuntu Server (20.04 and 22.04) and Ubuntu Core (20 and 22) that ship with the Linux 5.15 kernel and are specifically optimized for SoC and Internet of Things (IoT) devices with 10, 11 and 12 generation Intel Core and Atom processors (Alder Lake, Tiger Lake […]

The KDE project has set development goals for the next few years

The KDE Akademy 2022 conference set new goals for the KDE project, which will be given increased attention during development in the next 2-3 years. The targets are selected based on a community vote. Past goals were set in 2019 and included implementing Wayland support, unifying apps, and tidying up app distribution tools. New goals: Accessibility for […]