Category: Blog

Angie 1.3.0 — a fork of Nginx

Angie is an efficient, powerful, and scalable web server built by some of the former core developers of nginx with the intention of expanding functionality far beyond the original version. It is distributed under the BSD license. Angie is a complete replacement for nginx, allowing you to use your existing nginx configuration without significant changes. A key feature of Angie is its acquisition by the project […]

Vulnerability in the NTFS driver from GRUB2 allowing code execution and bypassing UEFI Secure Boot

A vulnerability (CVE-2023-4692) has been identified in the driver handling NTFS filesystem operations in the GRUB2 bootloader, allowing for the execution of arbitrary code at the bootloader level when accessing a specifically crafted filesystem image. This vulnerability can be exploited to bypass the UEFI Secure Boot verified boot mechanism. The vulnerability stems from an error in parsing the NTFS attribute '$ATTRIBUTE_LIST' (grub-core/fs/ntfs.c), which can be used to write […]

fwmx 1.3 — a lightweight window manager for x11

Version 1.3 of the fwmx software suite has been released, which includes the window manager (fwm), an application launcher menu, and a volume control. The layout indicator used is xxkb. What's new since the last release (v1.2): added root daemon for monitoring battery status and managing screen brightness on laptops, along with corresponding elements in the taskbar; improved drag and drop behavior […]

Firefox 119 will change the behavior of session restoration.

In the next Firefox release, some settings related to session recovery after exiting the browser will be changed. Unlike previous versions, information about not only active tabs but also recently closed tabs will be saved between sessions, allowing users to restore accidentally closed tabs after restarting and view their list in Firefox View. More details […]

Vulnerabilities in the ARM GPU driver are already being exploited for attacks

ARM has disclosed information about three vulnerabilities in the drivers for its GPUs used in Android, ChromeOS, and Linux distributions. The vulnerabilities allow an unprivileged local user to execute their code with kernel privileges. The October security report for the Android platform mentions that one of the vulnerabilities (CVE-2023-4211) has already been exploited by attackers in working exploits before a fix is available […]

A vulnerability in Glibc ld.so allows obtaining root privileges on the system.

Qualys has identified a dangerous vulnerability (CVE-2023-4911) in the ld.so linker, included with the system C library Glibc (GNU libc). The vulnerability allows a local user to elevate their privileges in the system by specifying specially crafted data in the GLIBC_TUNABLES environment variable before launching an executable file with the suid root flag, such as /usr/bin/su. Successful exploitation of the vulnerability has been demonstrated in Fedora 37 and 38, […]

Linux Mint Edge 21.2 has been released with a new Linux kernel.

The developers of the Linux Mint distribution have announced the release of a new ISO image called 'Edge', which is based on the July release of Linux Mint 21.2 with a Cinnamon desktop and features the Linux kernel 6.2 instead of 5.15. Additionally, the proposed ISO image restores support for UEFI SecureBoot mode. This build is aimed at users of new hardware experiencing installation and booting issues […]

Release of portable version OpenBGPD 8.2

The portable version of the OpenBGPD routing package 8.2 has been released, developed by the OpenBSD project and adapted for use in FreeBSD and Linux (support is claimed for Alpine, Debian, Fedora, RHEL/CentOS, Ubuntu). To ensure portability, parts of the code from the OpenNTPD, OpenSSH, and LibreSSL projects have been used. The project supports most of the BGP 4 specifications and complies with the requirements of RFC8212, but it does not attempt to cover everything […]

Malicious packages discovered in the Ubuntu Snap Store

Canonical has announced a temporary suspension of the automatic publishing package verification system in the Snap Store due to the appearance of packages with malicious code intended to steal cryptocurrency from users. It is unclear whether the incident is limited to the publication of malicious packages by third-party authors or whether there are security issues directly with the repository, as the situation in the official announcement is characterized by […]

Release of SBCL 2.3.9, implementation of the Common Lisp language

The release of SBCL 2.3.9 (Steel Bank Common Lisp), a free implementation of the Common Lisp programming language, has been published. The project's code is written in Common Lisp and C, and is distributed under the BSD license. In this new release: Stack allocation via DYNAMIC-EXTENT now applies not only to the initial binding but also to all values that a variable can take (for example, via SETQ). This […]

Release of the energy consumption and performance optimizer auto-cpufreq 2.0

After four years of development, the release of the auto-cpufreq 2.0 utility has been announced, designed for automatic optimization of CPU speed and power consumption in the system. The utility monitors the laptop's battery state, CPU load, CPU temperatures, and activity in the system, and dynamically activates power-saving or high-performance modes based on the situation and selected options. For example, auto-cpufreq can be used to automatically […]

Vulnerabilities in the Linux kernel, Glibc, GStreamer, Ghostscript, BIND, and CUPS

Several recently identified vulnerabilities: CVE-2023-39191 — a vulnerability in the eBPF subsystem that allows a local user to escalate their privileges and execute code at the Linux kernel level. This vulnerability is caused by improper verification of eBPF programs submitted by a user for execution. To exploit this, the user must be able to load their BPF program (if the kernel.unprivileged_bpf_disabled parameter is set to 0, for example, as in Ubuntu 20.04). […]

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster