Author: Yuri Gagarin

Vulnerabilities in the Grails web framework and Ruby module TZInfo.

A vulnerability has been discovered in the Grails web framework, designed for developing web applications according to the MVC paradigm in Java, Groovy, and other JVM languages, allowing remote code execution in the environment where the web application is running. Exploitation of the vulnerability occurs through the submission of a specially crafted request that provides the attacker access to the ClassLoader. The issue is caused by an oversight in the data-binding logic, […]

Release of the LKRG module 0.9.4 to protect against kernel vulnerabilities in Linux

The Openwall project has released version 0.9.4 of the LKRG kernel module (Linux Kernel Runtime Guard), which is intended to detect and block attacks and integrity violations of kernel structures. For instance, the module can protect against unauthorized modifications to a running kernel and attempts to alter the privileges of user processes (which defines exploit use). The module is suitable for providing protection against exploits exploiting already known kernel vulnerabilities, […]

Document-oriented DBMS MongoDB 6.0 is now available

After a year of development, version 6.0 of the document-oriented database MongoDB has been released, which occupies a niche between fast and scalable key/value-based systems and relational databases that are functional and convenient for query formation. The MongoDB code is written in C++ and is distributed under the SSPL license, which is based on the AGPLv3 license but is not open because it contains discriminatory […]

Release of Multimedia Package FFmpeg 5.1

After six months of development, the multimedia package FFmpeg 5.1 is now available, which includes a set of applications and a collection of libraries for operations on various multimedia formats (recording, transforming, and decoding audio and video formats). The package is distributed under the LGPL and GPL licenses, and FFmpeg development is carried out in parallel with the MPlayer project. The significant version number change is explained by substantial changes in the API and the transition to a new formation scheme, […]

Release of Apache OpenOffice 4.1.13

A corrected release of the Apache OpenOffice 4.1.13 office suite is now available, featuring 7 fixes. Packaged versions are ready for Linux, Windows, and macOS. This new release notes the resolution of a vulnerability, details of which have not yet been provided, but it is mentioned that the issue is related to the master password. The new release alters the method of encoding and storing the master password, so users should take care before installing version 4.1.13 […]

vSMTP — a mail server with a built-in language for traffic filtering

The vSMTP project is developing a new mail server (MTA) aimed at delivering high performance and flexible traffic filtering and management capabilities. The project's code is written in Rust and is released under the GPLv3 license. According to the testing results published by the developers, vSMTP is ten times faster than competing MTAs. For example, vSMTP demonstrated performance that is 4 to 13 times higher […]

GameMode 1.7 is now available, a performance optimizer for games on Linux.

Feral Interactive has released GameMode 1.7, an optimizer implemented as a background process that on-the-fly adjusts various Linux system settings for optimal performance of gaming applications. The project's code is written in C and is distributed under the BSD license. For games, a special library called libgamemode is provided, which allows the request of specific optimizations during gameplay without […]

A vulnerability in the Linux kernel that allows bypassing Lockdown mode restrictions.

A vulnerability has been identified in the Linux kernel (CVE-2022-21505) that easily circumvents the Lockdown protection mechanism, which restricts root user access to the kernel and blocks UEFI Secure Boot bypass paths. To exploit this, the kernel's IMA (Integrity Measurement Architecture) subsystem can be used, which is designed to verify the integrity of operating system components via digital signatures and hashes. In lockdown mode, access to /dev/mem is restricted […]

Release of VirtualBox 6.1.36

Oracle has released a corrective update for the VirtualBox virtualization system version 6.1.36, which includes 27 fixes. Key changes: Addressed a potential kernel crash of the guest system with Linux when enabling the ‘Speculative Store Bypass’ protection mode for a single vCPU VM. Resolved a mouse usage issue in the virtual machine configuration dialog that occurs when using KDE. Improved update performance […]

The release of nomenus-rex 0.7.0, a utility for batch renaming files.

A new release of Nomenus-rex is available, a console utility for batch file renaming. It can be configured using a simple configuration file. The program is written in C++ and is distributed under the GPL 3.0 license. Since the last news, the utility has gained functionality and numerous bugs and issues have been fixed: New rule: "file creation date". The syntax is similar to the Date rule. A significant amount of boilerplate code has been removed. Notable […]

Release of nginx 1.23.1 and njs 0.7.6

The release of the main branch nginx 1.23.1 has been formed, continuing the development of new features. The parallel stable branch 1.22.x only includes changes related to fixing serious bugs and vulnerabilities. Next year, a stable branch 1.24 will be formed based on the main branch 1.23.x. Changes include: Optimization of memory consumption in SSL proxy configurations. In the directive […]

The toolkit for decoding Intel microcode has been released

A group of security researchers from the uCode team have published source texts for decrypting Intel microcode. The Red Unlock technique, developed by the same researchers in 2020, can be used to extract the encrypted microcode. The proposed microcode decryption capability allows for the exploration of the internal structure of the microcode and the implementation methods of x86 machine instructions. Additionally, the researchers have restored the update format for the microcode, the encryption algorithm, and the key, […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster