There has been released an update to wpDiscuz which is a WordPress plugin with over 80000 installations. The updated version fixes a critical categorized security vulnerability. The vulnerability gives unauthenticated attackers the ability to upload arbitrary files, including PHP files, and achieve remote code execution on a vulnerable site’s server.
Affected versions:
wpDiscuz versions between 7.0.0 and 7.0.4
More information in Wordfence blog here.
Sunday, August 2, 2020
Mozilla Firefox Updated
Mozilla have released updated versions of their Firefox web browser. New versions fix security vulnerabilities.
Affected versions:
-Mozilla Firefox earlier than 79 (advisory)
-Mozilla Firefox ESR 78.x earlier than 78.1 (advisory)
-Mozilla Firefox ESR 68.x earlier than 68.11 (advisory)
Fresh version can be obtained via inbuilt updater or by downloading (latest version) from the product site.
Affected versions:
-Mozilla Firefox earlier than 79 (advisory)
-Mozilla Firefox ESR 78.x earlier than 78.1 (advisory)
-Mozilla Firefox ESR 68.x earlier than 68.11 (advisory)
Fresh version can be obtained via inbuilt updater or by downloading (latest version) from the product site.
Labels:
Firefox,
Mozilla,
security,
security threat,
update,
vulnerability
Mozilla Thunderbird New Versions Released
Mozilla have released updated versions of their Thunderbird email client containing fixes to security vulnerabilities.
Affected versions:
- Mozilla Thunderbird earlier than 78.1 (advisory)
- Mozilla Thunderbird earlier than 68.11 (advisory)
Fresh version can be obtained via inbuilt updater or by downloading from the product site.
Affected versions:
- Mozilla Thunderbird earlier than 78.1 (advisory)
- Mozilla Thunderbird earlier than 68.11 (advisory)
Fresh version can be obtained via inbuilt updater or by downloading from the product site.
Labels:
Mozilla,
security,
security threat,
thunderbird,
update,
vulnerability
Saturday, August 1, 2020
Oracle Critical Patch Update For Q3 of 2020
Oracle have released updates for their products that fix 444 security issues (including 11 Java fixes) in total. The updates are a part of Oracle's quarterly released critical patch update (CPU).
Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.
Next Oracle CPU is planned to be released in October 2020.
Detailed list of vulnerabilities with patching instructions can be read from Oracle CPU Advisory.
Next Oracle CPU is planned to be released in October 2020.
Labels:
Java,
Oracle,
security,
security threat,
update,
vulnerability
Wednesday, July 22, 2020
All In One SEO Pack Vulnerability Fixed
There has been released an update to All In One SEO Pack which is a WordPress plugin with over 2 million installations. The updated version fixes a medium categorized security vulnerability.
Affected versions:
All In One SEO Pack versions earlier than 3.6.2
More information in Wordfence blog here.
Affected versions:
All In One SEO Pack versions earlier than 3.6.2
More information in Wordfence blog here.
Labels:
plugins,
security,
security threat,
update,
vulnerability,
Wordfence,
WordPress
New PHP versions available
PHP development team has released 7.4.8, 7.3.20 and 7.2.32 versions of the PHP scripting language. Among other bugs some security bugs have been fixed. All PHP users are recommended to upgrade their versions to the latest release of the correspondent branch.
Changelogs:
Version 7.4.8
Version 7.3.20
Version 7.2.32
Changelogs:
Version 7.4.8
Version 7.3.20
Version 7.2.32
Labels:
PHP,
security,
security threat,
update,
vulnerability,
Windows
Mozilla Thunderbird Updated
Mozilla have released an updated version of their Thunderbird email client containing fixes to security vulnerabilities.
Affected versions:
Mozilla Thunderbird versions earlier than 78
Fresh version can be obtained via inbuilt updater or by downloading from the product site.
Affected versions:
Mozilla Thunderbird versions earlier than 78
Fresh version can be obtained via inbuilt updater or by downloading from the product site.
Labels:
Mozilla,
security,
security threat,
thunderbird,
update,
vulnerability
Subscribe to:
Posts (Atom)