Category: Blog

Update nginx 1.22.1 and 1.23.2 addressing vulnerabilities

The main branch release of nginx 1.23.2 has been formed, in which the development of new features continues, as well as the release of the parallel stable branch nginx 1.22.1, into which only changes related to fixing serious bugs and vulnerabilities are made. In the new versions, two vulnerabilities (CVE-2022-41741, CVE-2022-41742) in the ngx_http_mp4_module, used for streaming from H.264/AAC formatted files, have been fixed. […]

Vulnerability in the io_uring subsystem of the Linux kernel that allows privilege escalation in the system

A vulnerability (CVE-2022-2602) has been identified in the implementation of the asynchronous input/output interface io_uring, which has been included in the Linux kernel since release 5.1, allowing an unprivileged user to gain root rights in the system. The presence of the issue has been confirmed in the 5.4 branch and kernels starting from the 5.15 branch. The vulnerability is caused by accessing an already freed memory block (use-after-free) in the io_uring subsystem, which occurs as a result of a race condition […]

GitHub has implemented support for tokens to provide selective access.

GitHub has implemented support for a new type of access tokens that can selectively define the permissions of a specific developer or script, covering only the tasks necessary for completing the work. It is expected that selective access provision will help reduce the risk of attacks in the event of credential compromise. Tokens can be used in scripts to organize selective access to the GitHub API and when connecting through […]

Vulnerabilities in Git that occur when cloning submodules and using git shell.

Corrective releases for the distributed source code management system Git 2.38.1, 2.30.6, 2.31.5, 2.32.4, 2.33.5, 2.34.5, 2.35.5, 2.36.3, and 2.37.4 have been published, addressing two vulnerabilities that appear when using the 'git clone' command in the '--recurse-submodules' mode with unverified repositories and while utilizing the interactive mode of 'git shell'. You can track package update releases in distributions on the Debian pages, […]

Release of Stratis 3.3, a toolkit for managing local storage

The release of Stratis 3.3 has been published, developed by Red Hat and the Fedora community to unify and simplify the tools for configuring and managing a pool of one or more local storage drives. Stratis provides features such as dynamic storage allocation, snapshots, integrity assurance, and layer creation for caching. Stratis support is integrated into the Fedora and RHEL distributions starting from […]

The server-side JavaScript platform Node.js 19.0 is now available.

The release of Node.js 19.0 has taken place, a platform for executing network applications written in JavaScript. Node.js 19 is classified under the normal support branch, with updates being released until June 2023. The stabilization of the Node.js 18 branch, which will receive LTS status and be supported until April 2025, will be completed in the coming days. Support for the previous LTS branch Node.js 16.0 […]

Update of the antivirus boot disk Ubuntu RescuePack 22.10

The Ubuntu RescuePack 22.10 build is available for free download, allowing a full antivirus check without booting the main operating system to detect and remove various malware, computer viruses, trojans, rootkits, worms, spyware, and ransomware from the system, as well as to treat infected computers. The size of the bootable Live image is 3.5 GB (x86_64). Included are antivirus packages ESET NOD32 4, […]

Release of Firefox 106

The release of the web browser Firefox 106 has occurred. Additionally, an update for the long-term support branch — 102.4.0 has been formed. The Firefox 107 branch has entered beta testing, with a release scheduled for November 15. Key new features in Firefox 106 include a redesigned private browsing window to make it harder to confuse with the regular mode. The private browsing window now […]

Release of ErgoFramework 2.2 for creating network applications

The latest release of ErgoFramework 2.2 has been made, implementing the full network stack of Erlang and its OTP library in the Go language. The framework provides developers with a flexible toolset from the Erlang world to create distributed solutions in Go, utilizing ready-made general-purpose design patterns such as gen.Application, gen.Supervisor, and gen.Server, along with specialized ones like gen.Stage (distributed pub/sub) and gen.Saga (distributed transactions).

The first release of libcamera, a stack for camera support in Linux.

After four years of development, the first release of the libcamera project (0.0.1) has been formed, offering a software stack for working with video cameras, still cameras, and TV tuners on Linux, Android, and ChromeOS, which continues the evolution of the V4L2 API and will eventually replace it. As the library's API is still evolving and has not yet stabilized, the project has so far developed without branching into separate releases.

Release of Tails 5.5 Distribution

A specialized distribution release of Tails 5.5 (The Amnesic Incognito Live System) has been formed, based on the Debian package base and designed for anonymous browsing. Anonymous access in Tails is provided by the Tor system. All connections, except traffic over the Tor network, are blocked by the packet filter by default. User data is encrypted for preservation between runs.

Vulnerability in LibKSBA leading to code execution when processing S/MIME in GnuPG.

A critical vulnerability (CVE-2022-3515) has been identified in the LibKSBA library, developed by the GnuPG project, which provides functions for working with X.509 certificates. This vulnerability leads to integer overflow and arbitrary data writing beyond the allocated buffer when parsing ASN.1 structures used in S/MIME, X.509, and CMS. The issue is exacerbated by the fact that the Libksba library is used in the GnuPG package, and the vulnerability could lead to severe consequences.

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster