Category: Internet News

Release of Apache HTTP Server 2.4.61 addressing vulnerabilities

The release of the Apache HTTP server 2.4.61 is now available, which was published almost immediately after the 2.4.60 release and includes a fix for a regression issue that caused a vulnerability (CVE-2024-39884) allowing for code viewing of scripts configured using the AddType directive (for example, it is possible to craft a specially formatted request to a PHP script that leads to displaying its contents, rather than executing it). The Apache httpd version 2.4.60 fixed 8 […]

Google will begin offering rewards for identifying vulnerabilities in the KVM hypervisor.

Google has introduced the kvmCTF initiative, under which security researchers can receive monetary rewards for detecting vulnerabilities in the KVM (Kernel-based Virtual Machine) hypervisor. Google's interest in KVM is driven by its use in Google Cloud services as well as in Android and ChromeOS platforms (CrosVM is based on KVM). To receive a reward, a demonstration of an exploit against specially prepared […]

Release of the GNU findutils 4.10.0 toolkit with renewed support for the Musl C library

The GNU Project has released version 4.10.0 of the findutils package, which includes implementations of utilities for organizing file searches in the system, such as find, updatedb, and locate. The findutils also develop the xargs utility, designed to build commands executed with data from standard input, typically generated by the find utility. In the new version: Support for the Musl C library, distributed under the […]

Fedora 42 intends to implement telemetry and change the access model for disks and flatpak.

In the upcoming release of Fedora Workstation 42, scheduled for spring next year, there is a proposal to add components for collecting and sending metrics, which will allow for studying real user preferences and considering them in decision-making related to the distribution's development, priority setting in development, and enhancing user comfort. The proposal is still under discussion and has not yet been reviewed by the FESCo committee (Fedora […]

The MySQL DBMS 9.0.0 is available

Oracle has launched a new branch of the MySQL DBMS 9.0.0. The MySQL Community Server 9.0.0 builds are prepared for all major Linux distributions, FreeBSD, macOS, and Windows. Under the release model introduced last year, MySQL 9.0 is categorized under the 'Innovation' branches, which will also include the upcoming significant releases MySQL 9.1 and 9.2. The Innovation branches are recommended for those […]

Release of OpenSSH 9.8 with the disabling of the DSA algorithm and additional security mechanisms.

The OpenSSH 9.8 release has been published, an open implementation of a client and server for operating with SSH 2.0 and SFTP protocols. Besides addressing a separately announced critical vulnerability (CVE-2024-6387) that allows remote code execution with root privileges before authentication, the new version also fixes another less severe vulnerability and proposes several significant changes aimed at enhancing security. […]

A vulnerability in OpenSSH allows remote code execution with root privileges on servers with Glibc.

Qualys has identified a critical vulnerability (CVE-2024-6387) in OpenSSH, allowing remote code execution with root privileges without authentication. The vulnerability, code-named regreSSHion, occurs in the default configuration starting from OpenSSH 8.5 on systems with the standard Glibc library. The possibility of an attack has been demonstrated on a 32-bit system with Glibc with ASLR (Address Space Layout Randomization) protection enabled […]

The dhclient utility has been removed from OpenBSD in favor of the background process dhcpleased.

Theo de Raadt has introduced a change in the OpenBSD-current codebase, which forms the basis for the next significant release, removing the DHCP client dhclient. Instead of dhclient, a continuously running background process called dhcpleased is recommended, which has been included since OpenBSD 6.9 and uses the ifconfig utility to enable automatic configuration of network interfaces via DHCP (enabled by launching 'ifconfig $if autoconf' or adding […]

The NS servers for the .top domain have stopped servicing Let’s Encrypt validation requests.

Users of the Let’s Encrypt non-profit certificate authority, community-controlled and providing certificates free of charge to anyone, have encountered issues confirming domain ownership in the '.top' zone via DNS when obtaining certificates. Since June 25, the DNS servers responsible for the top-level domain '.top' have ceased accepting queries from the resolvers used by the Let’s Encrypt project during the DNS-01 verification process, which, for example, […]

The Eclipse community has introduced the integrated development environment Theia IDE

The first official release of the new integrated development environment Theia IDE has occurred, developed by the Eclipse Foundation based on the Theia code editor and the plugins designed for it. The project code is written in TypeScript and is distributed under the EPLv2 (Eclipse Public License). The Theia IDE product is provided as a self-contained desktop application intended for installation on local systems, and […]

New Versions of Debian 12.6 and 11.10

The sixth corrective update of the Debian 12 distribution has been formed, which includes accumulated package updates and fixes in the installer. The release includes 162 updates addressing stability issues and 84 updates fixing vulnerabilities. Notable changes in Debian 12.6 include updates to the latest stable versions of packages such as clamav, dpdk, flatpak, nvidia, openssl, ovn, postfix, postgresql-15, qemu […]

Wine 9.12 Release

An experimental release of the open implementation of the Win32 API — Wine 9.12 has been launched. Since the 9.11 release, 24 bug reports have been closed and 310 changes have been made. The most significant changes include: the Wine Mono engine with .NET platform implementation has been updated to version 9.2.0. Initial support for placing data structures of the user32 library in shared memory has been added. The engine used in the command interpreter has been rewritten […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster