* An exploitable heap overflow vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. * An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of
Archive for March, 2020
The **phpMyAdmin** team announces the release of both **4.9.5** and **5.0.2**. Both versions contain several security fixes: * PMASA-2020-2 SQL injection vulnerability in the user accounts page, particularly when changing a password * PMASA-2020-3 SQL injection vulnerability relating to the search feature * PMASA-2020-4 SQL injection and XSS having to do with displaying results *
You need a professional email address for your business, and here’s how to make that happen with cPanel webmail. Putting your best foot forward as both an individual and a business can start with something as simple as having a professional-looking email address. For a bit of context- think back to the email address you had in high school or college. How many of you had a favorite movie or band or sports team in …
An update for dpdk is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from
An update for podman is now available for Red Hat Enterprise Linux 7 Extras. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
WordPress 5.4 “Adderley”
Version 5.4 “Adderley” of WordPress is available for download or update in your WordPress dashboard. This version brings you more ways to make content come alive with your best images and helps make your vision real by putting blocks in the perfect place.
Russ Allbery discovered a buffer overflow in the PAM module for MIT Kerberos, which could result in denial of service or potentially the execution of arbitrary code.
pam-krb5 could be made to execute arbitrary code if it received a specially crafted response.
Security fix for CVE-2020-9359
This update incorporates fixes from the upstream glibc 2.31 stable release branch, including 2 fixes for medium severity security vulnerabilities. (CVE-2020-10029, CVE-2020-1752)
Several security issues were fixed in BlueZ.
The system could be made to expose sensitive information or run programs as an administrator.
Timeshift could be made to run programs as an administrator.
Several security issues were fixed in WebKitGTK+.
Several security issues were fixed in Twisted.
Software tools to prevent attacks on servers and sites
The post Software tools to prevent attacks on servers and sites appeared first on Plesk.

Joomla, one of the world’s most popular Content Management Systems (CMS), announced today its partnership with Report URI, the Application Security and Health Monitoring leader.
Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719)
Fix DoS vulnerability (CVE-2019-19886, RHBZ #1801720 / #1801719)
Fix CVE-2018-19655
Fix CVE-2018-19655
WordPress 5.4 RC5
The fifth release candidate for WordPress 5.4 is live! WordPress 5.4 is currently scheduled to land on March 31 2020, and we need your help to get there—if you haven’t tried 5.4 yet, now is the time! You can test the WordPress 5.4 release candidate in two ways: Try the WordPress Beta Tester plugin (choose the “bleeding edge nightlies” option) […]
As a customer and partner, you have multiple ways to receive our help and support at any time, from anywhere. You have the power in your hands to obtain the knowledge and expertise necessary for your business to continue successfully without interruption. cPanel & WHM is a robust assortment of tools with a variety of applications for their use. These tools are widely used and adopted, and there are a lot of resources available. That means …
Netcraft has tracked Coronavirus-themed cybercrime since 16th March, shortly after it was declared a pandemic by the WHO. Scammers have been quick to take advantage of the massive worldwide attention to Coronavirus (COVID-19), and are increasingly making use of it as a theme for online fraud.
Netcraft is the largest provider of anti-phishing takedowns in the world and provides countermeasures against some 75 other types of cybercrime for governments, internet infrastructure and many of the world’s largest banks and enterprises.
* New upstream release 5.3.1 (rhbz#1814882) * Fixes CVE-2020-1747 (rhbz#1807367,1809011)
The 5.5.11 stable kernel update contains a number of important fixes across the tree.
cPanel employees are sharing their experiences working remotely to help everyone succeed while working from their homes. Below you’ll find some of our best tips for working remotely that the cPanel team has been passing back and forth.
It was reported that the BlueZ’s HID and HOGP profile implementations don’t specifically require bonding between the device and the host. Malicious devices can take advantage of this flaw to connect to a target host and impersonate an existing HID device without security or to cause
An update for ipmitool is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability
A minor version update (from 7.5 to 7.6) is now available for Red Hat Fuse. The purpose of this text-only errata is to inform you about the security issues fixed in this release. Red Hat Product Security has rated this update as having a security impact