A huge collection of 3400+ free website templates JAR theme com WP themes and more at the biggest community-driven free web design site

Alerts

Trend Micro Security Update

Trend Micro has released security updates to address a vulnerability in its multiple products. Exploitation of this vulnerability may allow an attacker to take control of an affected system.

Users and Administrators are encouraged to review Trend Micro Security Bulletin and apply necessary updates.

Google Chrome Zero Day Vulnerability (CVE-2023-2136)

Advisory No: TZCERT/SA/2023/04/20

Date of First Release: 20th April 2023

Source: Google

Software Affected:  Google Chrome prior to 112.0.5615.137 (Mac), and Google Chrome prior to 112.0.5615.137/138 (Windows)

Overview:

Google has released security patches to address the Zero Day vulnerability affecting Google Chrome browser for both Mac and Windows operating systems. This vulnerability could allow an attacker to take control of an affected system.

Description:

This vulnerability is tracked as CVE-2023-2136. It is caused by the Integer overflow in Skia in Google Chrome prior to 112.0.5615.137, which allows a remote attacker who had compromised the renderer process to potentially accomplish a sandbox escape via a crafted HTML page. Skia is an open source 2D graphics library used by the browser.

Impact:

Successful exploitation of this vulnerability may allow the attacker to control of the affected system.

Solution:

Google has released a patch for this vulnerability. Users and administrators are encouraged to apply necessary updates.

References:

  1. https://chromereleases.googleblog.com/2023/04/stable-channel-update-for-desktop_18.html
  2. https://thehackernews.com/2023/04/google-chrome-hit-by-second-zero-day.html

Ubuntu Security Update

Ubuntu has released security updates to address vulnerabilities in Linux kernel, libxml and vim. Exploitation of these vulnerabilities may allow an attacker to take control of affected system.

Users and administrators are encouraged to review Ubuntu Security Advisories USN-6033-1, USN-6028-1 and USN-6026-1 and apply necessary updates.

SUSE Security Update

SUSE has released security updates to address vulnerabilities in nodejs, openSSL and ImageMagik. Exploitation of these vulnerabilities may allow an attacker to take control of affected system.

Users and administrators are encouraged to review SUSE Security Advisories suse-su-20231923-1, suse-su-20231926-1 and suse-su-20231927-1 and apply necessary updates.