Author: ProHoster

Vulnerability in Samba that allows any user to change their password

Corrective releases of Samba 4.16.4, 4.15.9 and 4.14.14 have been published, fixing 5 vulnerabilities. The release of package updates in distributions can be tracked on the pages: Debian, Ubuntu, RHEL, SUSE, Arch, FreeBSD. The most dangerous vulnerability (CVE-2022-32744) allows users of the Active Directory domain to change the password of any user, including the ability to change the administrator password and take full control of the domain. Problem […]

Release of zeronet-conservancy 0.7.7, platform for decentralized sites

The release of the zeronet-conservancy project is available, which continues the development of the decentralized, censorship-resistant ZeroNet network, which uses Bitcoin addressing and verification mechanisms in combination with BitTorrent distributed delivery technologies to create sites. Site content is stored in the P2P network on visitors' machines and verified against the owner's digital signature. The fork was created after the disappearance of the original ZeroNet developer and aims to maintain and […]

Attacking Node.js through Manipulating JavaScript Object Prototypes

Researchers at the Helmholtz Center for Information Security (CISPA) and the Royal Institute of Technology (Sweden) analyzed the applicability of the JavaScript prototype object contamination technique (“prototype pollution”) to create attacks on the Node.js platform and popular applications based on it, leading to code execution. The prototype polluting method uses a feature of the JavaScript language that allows you to add new properties to the root prototype of any object. In applications […]

Robotics, Games and Security spin builds scheduled to end in Fedora Linux 37

Ben Cotton, who holds the position of Red Hat Fedora Program Manager, announced his intention to stop the formation of alternative live builds of the distribution - Robotics Spin (environment with applications and simulators for robot developers), Games Spin (environment with a selection of games) and Security Spin (environments with a set of tools for checking security), due to the termination of communication of maintainers or […]

ClamAV free antivirus package update 0.103.7, 0.104.4 and 0.105.1

Cisco has published new releases of the free anti-virus package ClamAV 0.105.1, 0.104.4 and 0.103.7. Recall that the project passed into the hands of Cisco in 2013 after the purchase of Sourcefire, which develops ClamAV and Snort. The project code is distributed under the GPLv2 license. Release 0.104.4 will be the last update in the 0.104 branch, and the 0.103 branch has been categorized as LTS and will be accompanied by […]

NPM 8.15 package manager release with support for local package integrity checking

GitHub has released the NPM 8.15 package manager that comes with Node.js and is used to distribute JavaScript modules. It is noted that more than 5 billion packages are downloaded via NPM daily. Key changes: A new "audit signatures" command has been added to perform a local audit of the integrity of installed packages, which does not require manipulations with PGP utilities. The new verification mechanism is based on […]

The OpenMandriva project began testing the rolling distribution of OpenMandriva Lx ROME

The developers of the OpenMandriva project have presented a preliminary release of a new edition of the OpenMandriva Lx ROME distribution kit, which uses a model of continuous update delivery (rolling releases). The proposed edition allows access to new versions of packages developed for the OpenMandriva Lx 5.0 branch. A 2.6 GB iso image has been prepared for download with a KDE desktop that supports booting in Live mode. From new package versions in […]

Release of Tor Browser 11.5.1 and Tails 5.3 distribution

The release of Tails 5.3 (The Amnesic Incognito Live System), a specialized distribution kit based on the Debian package base and designed for anonymous access to the network, has been released. Anonymous exit to Tails is provided by the Tor system. All connections, except traffic through the Tor network, are blocked by default by the packet filter. Encryption is used to store user data in the save user data between runs mode. […]

Firefox 103 release

The Firefox 103 web browser has been released. In addition, updates have been made to branches with a long support period - 91.12.0 and 102.1.0. The Firefox 104 branch, which is scheduled for release on August 23, will be transferred to the beta testing stage in the coming hours. The main innovations in Firefox 103: By default, Total Cookie Protection is enabled, which was previously only used when […]

The author of the Latte Dock panel announced the termination of work on the project

Michael Vourlakos has announced that he has retired from the Latte Dock project, which develops an alternative task control panel for KDE. The reasons given are the lack of free time and the loss of interest in further work on the project. Michael planned to leave the project and hand over maintenance after the release of 0.11, but in the end decided to leave early. […]

CDE 2.5.0 Desktop Environment Release

The classic industrial desktop environment CDE 2.5.0 (Common Desktop Environment) has been released. CDE was developed in the early nineties of the last century by the joint efforts of Sun Microsystems, HP, IBM, DEC, SCO, Fujitsu and Hitachi, and for many years acted as a regular graphics environment for Solaris, HP-UX, IBM AIX, Digital UNIX and UnixWare. In 2012 […]

Debian took over the debian.community domain, which published criticism of the project

The Debian project, the non-profit organization SPI (Software in the Public Interest) and Debian.ch, which represents Debian in Switzerland, won a World Intellectual Property Organization (WIPO) case involving a debian.community domain that hosted a blog critical of the project and its contributors, as well as publicizing confidential discussions from the debian-private mailing list. Unlike the failed […]