Category: Internet News

Critical vulnerabilities in the SaltStack configuration management system

In the new releases of the centralized configuration management system SaltStack 3002.5, 3001.6, and 3000.8, a vulnerability (CVE-2020-28243) has been fixed that allows a non-privileged local user on the host to escalate their privileges in the system. The issue was caused by a bug in the salt-minion handler, which is used to receive commands from the central server. The vulnerability was identified in November but was not fixed until now. During the 'restartcheck' operation, substitution may be possible […]

Analysis of the incident involving a loss of control over the domain perl.com has been published

Brian Foy, the founder of the Perl Mongers organization, published a detailed analysis of the incident in which the domain perl.com was hijacked by external parties. The domain hijacking did not affect the project's server infrastructure and was carried out at the level of ownership change and DNS server parameter alterations at the registrar. It is claimed that the computers responsible for the domain were also not compromised, and the attackers used […]

The maintainers of Fedora and Gentoo have discontinued support for packages with Telegram Desktop

The maintainer of the Telegram Desktop packages for Fedora and RPM Fusion announced the removal of packages from the repositories. A day prior, the package maintainer for Gentoo also announced the discontinuation of support for Telegram Desktop. In both cases, there was a willingness to restore the packages to the repositories if a new maintainer can be found to take over the support. […]

Release of aTox 0.6.0, a private and secure messenger for Android

The release of aTox 0.6.0 has taken place — a new version of the free mobile messenger with open source, which uses the Tox protocol (c-toxcore). Tox offers a decentralized P2P model for message distribution, utilizing cryptographic methods for user identification and protecting transit traffic from interception. The application is written in Kotlin. The source code and ready-made builds of the application are distributed under the GNU GPLv3 license. Features of aTox: […]

Release of fish shell 3.2

The release of the interactive command shell fish 3.2.0 (friendly interactive shell) has been published, evolving as a more user-friendly alternative to bash and zsh. Fish supports features such as syntax highlighting with automatic error detection, suggestions for input based on the history of past operations, and the auto-completion of options and commands using their descriptions in man pages, all working out of the box […]

Vulnerability in wpa_supplicant allowing remote code execution

A vulnerability (CVE-2021-27803) has been identified in the wpa_supplicant package, which is used for connecting to wireless networks in many Linux distributions, *BSD, and Android. This vulnerability could potentially be exploited to execute code by an attacker when processing specially crafted control frames for Wi-Fi Direct (Wi-Fi P2P). To carry out an attack, the attacker must be within the range of the wireless network to send the victim a specially crafted […]

Linux Mint aims to address the issue of ignoring updates installation

The developers of the Linux Mint distribution plan to redesign the update manager in the next release to encourage users to keep the distribution up to date. A study showed that only about 30% of users install updates in a timely manner, within a week of their release. Linux Mint does not collect telemetry, so an indirect method based on analysis was used to assess the relevance of the distribution components […]

Correction Release OpenVPN 2.5.1

A correction release of OpenVPN 2.5.1 has been prepared. This package allows the creation of virtual private networks, enabling encrypted connections between two client machines or facilitating the operation of a centralized VPN server for multiple clients. OpenVPN code is distributed under the GPLv2 license, and ready-made binary packages are available for Debian, Ubuntu, CentOS, RHEL, and Windows. New features: A new connection state AUTH_PENDING has been added to the connection states list, […]

Void Linux Returns to OpenSSL from LibreSSL

The developers of the Void Linux distribution have approved the proposal that has been under consideration since April of last year to revert to the use of the OpenSSL library. The switch from LibreSSL to OpenSSL is scheduled for March 5. It is expected that this change will not affect the systems of most users, but it will significantly simplify the maintenance of the distribution and resolve many issues, for example, enabling OpenVPN to be built with the standard TLS library (currently due to issues […]

KFence Subsystem for Memory Error Detection Accepted in Linux Kernel 5.12

The development version of the Linux kernel 5.12 includes the implementation of the KFence (Kernel Electric Fence) mechanism, which checks memory operations, catching buffer overflows, accessing memory after it has been freed, and other similar errors. This functionality was already present in the kernel as a KASAN (kernel address sanitizer) build option, utilizing Address Sanitizer in modern GCC […]

Chrome Experiments with Default HTTPS Site Opening

Chrome developers have announced the addition of a new experimental setting in the test branches of Chrome Canary, Dev, and Beta, ‘chrome://flags#omnibox-default-typed-navigations-to-https’, which, when activated, will cause sites to open by default using the ‘https://’ scheme instead of ‘http://’ when typing host names in the address bar. This feature is scheduled to be enabled by default in the upcoming release of Chrome 89 on March 2 for a small […]

Mozilla has refuted false information regarding the removal of the fox from the Firefox logo

Mozilla has assured users that it will not abandon the image of the fox in the Firefox logo. In recent days, misinformation about the disappearance of the fox from the Firefox logo has been actively discussed online, leading to memes and outrage. The Firefox logos have not changed since 2019, and the logo without the fox, presented in discussions as the new Firefox logo, is not supported.

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster