Category: Internet News

A new variant of the attack on Log4j 2 allows bypassing the added protection.

Another vulnerability (CVE-2021-45046) has been discovered in the JNDI lookup implementation within the Log4j 2 library, appearing despite the fixes added in release 2.15 and regardless of the use of the 'log4j2.noFormatMsgLookup' configuration for protection. The issue poses a danger mainly for older versions of Log4j 2, protected by the 'noFormatMsgLookup' flag, as it allows for bypassing the protections against the previous vulnerability (Log4Shell, CVE-2021-44228), […]

Vulnerabilities in X.Org Server

Four vulnerabilities have been identified in the X.Org Server that allow for privilege escalation on the system if the X server is running with root rights, or remote code execution if access is gained through X11 session forwarding via SSH. These issues are expected to be fixed in the upcoming xorg-server 21.1.2 release, which is anticipated in the coming days. In distributions, the issues remain unresolved (Debian, Ubuntu, RHEL, […]

17 Apache projects affected by a vulnerability in Log4j 2

The Apache Software Foundation has published a summary report on the projects affected by a critical vulnerability in Log4j 2 that allows arbitrary code execution on the server. The following Apache projects are vulnerable: Archiva, Druid, EventMesh, Flink, Fortress, Geode, Hive, JMeter, Jena, JSPWiki, OFBiz, Ozone, SkyWalking, Solr, Struts, TrafficControl, and Calcite Avatica. The vulnerability has also affected GitHub products, including GitHub.com, GitHub Enterprise […]

Chrome update 96.0.4664.110 addresses critical and 0-day vulnerabilities.

Google has released Chrome version 96.0.4664.110, which fixes five vulnerabilities, including a (CVE-2021-4102) vulnerability that is already being exploited by attackers in exploits (0-day) and a critical vulnerability (CVE-2021-4098) that allows bypassing all layers of browser protection and executing code in the system outside of the sandbox environment. Details are not yet disclosed, but it is known that the 0-day vulnerability is caused by use-after-free memory […]

YAOC — a prototype of a secure Russian-language operating system based on the A2 project

The YOS project is developing a branch from the A2 operating system, also known as Bluebottle and Active Oberon. One of the main goals of the project is the radical implementation of the Russian language throughout the system, including (at least partial) translation of the source texts into Russian. YOS can operate as a windowed application under Linux or Windows, as well as in the form of a standalone operating […]

Three malicious libraries have been discovered in the Python package directory PyPI.

Three libraries containing malicious code have been identified in the PyPI (Python Package Index) directory. Before the issues were detected and the packages removed, they had been downloaded nearly 15,000 times in total. The dpp-client (10,194 downloads) and dpp-client1234 (1,536 downloads) packages were distributed since February and included code to send the contents of environment variables, which could have included access keys, tokens, or […

The programming language Dart 2.15 and the Flutter 2.8 framework are now available.

Google has released version 2.15 of the Dart programming language, continuing the development of the fundamentally redesigned Dart 2 branch, which differs from the original version of Dart by employing strong static typing (types can be inferred automatically, so specifying types is not mandatory, but dynamic typing is no longer used and the initially inferred type is bound to the variable, applying strict checks thereafter […]

Intel has transferred the development of Cloud Hypervisor to the Linux Foundation.

Intel has transferred the Cloud Hypervisor, optimized for use in cloud systems, under the auspices of the Linux Foundation, whose infrastructure and services will be used for further development. This transition to the Linux Foundation will free the project from dependence on a single commercial entity and simplify collaboration by involving external participants. Companies such as […] have already expressed their support for the project.

Release of the ToaruOS 2.0 operating system

The release of ToaruOS 2.0, a Unix-like operating system written from scratch and delivered with its own kernel, bootloader, standard C library, package manager, user space components, and a graphical interface with a compositing window manager, has been announced. The project’s code is written in C and is distributed under the BSD license. A live image, sized at 14.4 MB, is prepared for download and can be tested in QEMU, VMware, or […]

Winter update of ALT p10 starter kits

The third release of starter kits on the ALT Ten platform has been published. The provided images are suitable for getting started with the stable repository for experienced users who prefer to define their own list of application packages and configure the system (even down to creating their own derivatives). As composite works, they are distributed under the GPLv2+ license. Options include a base system and one of the environments […]

Release of the collaborative development system GitBucket 4.37

The release of GitBucket 4.37 has been announced, a project that develops a system for collaborative work with Git repositories featuring a GitHub and Bitbucket-style interface. The system is characterized by easy installation, extensibility through plugins, and compatibility with the GitHub API. The code is written in Scala and is available under the Apache 2.0 license. MySQL and PostgreSQL can be used as the database. Key features of GitBucket: […]

Vulnerabilities in Grafana allow access to system files

A vulnerability (CVE-2021-43798) has been discovered in the open data visualization platform Grafana, which allows users to escape the base directory and access arbitrary files in the server's local file system, depending on the permissions of the user running Grafana. The issue is caused by incorrect processing of the path handler '/public/plugins//', where the use of '..' characters was allowed to access lower-level directories. The vulnerability […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster