Author: ProHoster

Chrome update 96.0.4664.110 fixing critical and 0-day vulnerabilities

Google has created an update to Chrome 96.0.4664.110, which fixes 5 vulnerabilities, including a vulnerability (CVE-2021-4102) already used by attackers in exploits (0-day) and a critical vulnerability (CVE-2021-4098) that allows you to bypass all levels of browser protection and execute code on the system outside the sandbox environment. Details have not yet been disclosed, only that the 0-day vulnerability is caused by the use of memory after it has been freed […]

YaOS is a prototype of a secure Russian-language operating system based on the A2 project

The YaOS project develops a fork of the A2 operating system, also known as Bluebottle and Active Oberon. One of the main goals of the project is the radical introduction of the Russian language into the entire system, including (at least partial) translation of the source texts into Russian. YaOS can work as an application in a window under Linux or Windows, and also as a separate operating […]

Three Malicious Libraries Found in PyPI Python Packages Directory

Three libraries containing malicious code were identified in the PyPI (Python Package Index) directory. Before problems were identified and removed from the catalog, the packages had been downloaded almost 15 thousand times. The dpp-client (10194 downloads) and dpp-client1234 (1536 downloads) packages have been distributed since February and include code for sending the contents of environment variables, which for example could include access keys, tokens, or […]

Dart 2.15 programming language and Flutter 2.8 framework available

Google has published the release of the Dart 2.15 programming language, which continues the development of a radically redesigned Dart 2 branch, which differs from the original version of the Dart language in the use of strong static typing (types can be inferred automatically, so specifying types is not necessary, but dynamic typing is no longer used and the initial calculation the type is assigned to the variable and strict checking is subsequently applied […]

Intel moves Cloud Hypervisor development to Linux Foundation

Intel has transferred the Cloud Hypervisor hypervisor, optimized for use in cloud systems, under the auspices of the Linux Foundation, whose infrastructure and services will be used in further development. Moving under the wing of the Linux Foundation will free the project from dependence on a separate commercial company and simplify collaboration with the involvement of third parties. The following companies have already announced their support for the project: [...]

Release of operating system ToaruOS 2.0

The release of the Unix-like operating system ToaruOS 2.0 has been published, written from scratch and supplied with its own kernel, boot loader, standard C library, package manager, user space components and a graphical interface with a composite window manager. The project code is written in C and distributed under the BSD license. A live image of 14.4 MB in size has been prepared for download, which can be tested in QEMU, VMware or […]

Winter update of ALT p10 starter kits

The third release of starter kits on the Tenth ALT platform has been published. The proposed images are suitable for starting to work with a stable repository for those experienced users who prefer to independently determine the list of application packages and customize the system (even creating their own derivatives). As composite works, they are distributed under the terms of the GPLv2+ license. Options include the base system and one of the […]

Release of the GitBucket 4.37 collaborative development system

The release of the GitBucket 4.37 project has been presented, developing a system for collaboration with Git repositories with an interface in the style of GitHub and Bitbucket. The system is easy to install, has the ability to expand functionality through plugins, and is compatible with the GitHub API. The code is written in Scala and is available under the Apache 2.0 license. MySQL and PostgreSQL can be used as a DBMS. Key features of GitBucket: […]

Release of KDE Gear 21.12, a set of applications from the KDE project

The December consolidated update of applications (21.12) developed by the KDE project has been presented. As a reminder, the consolidated set of KDE applications has been published under the name KDE Gear since April, instead of KDE Apps and KDE Applications. In total, as part of the update, releases of 230 programs, libraries and plugins were published. Information about the availability of Live builds with new application releases can be found on this page. The most notable innovations: […]

Vulnerabilities in Grafana that allow access to files in the system

A vulnerability (CVE-2021-43798) has been identified in the open data visualization platform Grafana, which allows you to escape beyond the base directory and gain access to arbitrary files in the local file system of the server, as far as the access rights of the user under which Grafana is running allows. The problem is caused by incorrect operation of the path handler “/public/plugins/ /", which allowed the use of ".." characters to access underlying directories. Vulnerability […]

Release of Ventoy 1.0.62, a toolkit for booting arbitrary systems from USB sticks

The Ventoy 1.0.62 toolkit for creating bootable USB media containing multiple operating systems has been released. The program is remarkable in that it provides the ability to boot the OS from unchanged ISO, WIM, IMG, VHD and EFI images without requiring unpacking the image or reformatting the media. For example, it is enough to simply copy the set of iso images of interest to a USB Flash with the Ventoy bootloader, and Ventoy will provide the ability to boot […]

Wine 7.0 release candidate

Testing has begun on the first release candidate Wine 7.0, an open implementation of WinAPI. The code base has been put into a freeze phase ahead of release, which is expected in mid-January. Since the release of Wine 6.23, 32 bug reports have been closed and 211 changes have been made. The most important changes: A new implementation of the joystick driver for WinMM (Windows Multimedia API) has been proposed. All Unix Wine libraries […]