Skip to main content

Posts

Showing posts with the label vulnerability

Multiple Critical Security Vulnerabilities Discovered In Linux Systemd

Researchers have discovered some serious security flaws threatening Linux. These vulnerabilities exist in Linux systemd component. According to the researchers, the vulnerabilities pose a risk to all systemd-based Linux distros. Linux Systemd Barraged With Multiple Vulnerabilities Allegedly, researchers at Qualys have disclosed some bugs targeting the Linux systemd component. Systemd provides the core building blocks for Linux and handles major processes after booting. As revealed, three vulnerabilities have targeted the systemd-journald, which is responsible for data collection and log storage. The vulnerabilities let an attacker gain root privileges on the target device. The researchers state that these vulnerabilities threaten all Linux distros based on systemd except a few. As stated in their  report , “To the best of our knowledge, all systemd-based Linux distributions are vulnerable, but SUSE Linux Enterprise 15, openSUSE Leap 15.0, and Fedora 28 and 29 are not explo

Yoast SEO 9.1 Vulnerability Could Allow Command Execution

A few days ago, a researcher discovered a serious security flaw in Yoast plugin. This Yoast SEO 9.1 Vulnerability could allow an attacker to execute arbitrary commands. Fortunately, Yoast has patched the flaw in the recent release 9.2. Therefore, the users should ensure upgrading to the latest version to stay protected from potential attacks. Yoast SEO 9.1 Vulnerability Discovered As disclosed by Search Engine Journal in a  blog post , a security researcher has discovered a Yoast SEO 9.1 vulnerability that remained unannounced. As per his findings, the flaw could an attacker to execute  arbitrary commands  on the target system. The researcher Dimopoulos Ilias, with alias  gweeperx  on Twitter, first disclosed his findings in his tweet. He allegedly broke the news after the fix. According to SEJ, Ilias found a race condition vulnerability in Yoast SEO 9.1 (CVE-2018-19370). To exploit this vulnerability, an attacker could simply convince the victim to open a specially crafted