Security Leftovers
-
Mozilla Releases Security Updates for Multiple Products | CISA
Mozilla has released security updates to address vulnerabilities in Thunderbird, Firefox ESR, and Firefox. An attacker could exploit these vulnerabilities to cause user confusion or conduct spoofing attacks.
-
Critical Escalation Vulnerability Found in the Linux Kernel
A new local privilege escalation vulnerability has been discovered in the Linux kernel and users are encouraged to upgrade/patch immediately.
RedHat added a new CVE code, listed as 2022-3977, which is described as a use-after-free flaw. A use-after flaw can occur when a program attempts to use memory that has been released.
CVE 2022-3977 resides in the Linux kernel MCTP (Management Component Transport Protocol). How this vulnerability works is after a user simultaneously calls DROPTAG ioctl at the same time a socket close occurs. When this happens, the vulnerability can then be used to elevate privileges all the way up to root.
-
Samba Releases Security Updates
The Samba Team has released security updates to address vulnerabilities in multiple versions of Samba. An attacker could exploit some of these vulnerabilities to take control of an affected system.