MS Family January 2024 Routine Security Update Advisory

Overview   Microsoft(https://www.microsoft.com) has released a security update that fixes vulnerabilities in products. Users of affected products are advised to update to the latest version.   Affected Products     Azure family Azure Storage Mover Agent Microsoft Identity Model v5.0.0 Microsoft Identity Model v5.0.0 for Nuget Microsoft Identity Model v6.0.0

OpenSSL Vulnerability Security Update Advisory (CVE-2023-6129)

Overview   An update has been made available to fix vulnerabilities in OpenSSL. Users of affected versions are advised to update to the latest version.   Affected Products   OpenSSL version 3.0.0 OpenSSL 3.1.0 OpenSSL 3.2.0   Resolved Vulnerabilities   Vulnerability in the OpenSSL Poly1305 Message Authentication Code (MAC) implementation

OpenSSH Vulnerability Security Update Advisory (CVE-2023-48795)

Overview An update has been made available to fix vulnerabilities in OpenSSH(https://www.openssh.com/). Users of affected products are advised to update to the latest version.   Affected Products OpenSSH versions earlier than 9.6   Resolved Vulnerabilities Terrapin attack exploiting a flaw in the initial key exchange phase of OpenSSH (CVE-2023-48795)  

Spreadsheet-ParseExcel Security Update Advisory (CVE-2023-7101)

Overview An update has been made available to address an arbitrary code execution vulnerability in the Perl module used by Spreadsheet::ParseExcel(https://github.com/jmcnamara/spreadsheet-parseexcel) when parsing Excel files. Users of affected versions are advised to update to the latest version.     Affected Products Spreadsheet::ParseExcel 0.65 and earlier versions   Resolved Vulnerabilities Arbitrary

Linux Kernel Netfilter Security Update Advisory (CVE-2023-3390)

Overview An update has been made available to address a UAF vulnerability in the Linux kernel Netfilter. Users of affected versions are advised to update to the latest version.     Affected Products Linux kernel versions earlier than 6.4   Resolved Vulnerabilities UAF vulnerability in Linux kernel Netfilter (CVE-2023-3390)  

Microsoft Edge browser (120.0.2210.121) version security update advisory

Overview   Microsoft(https://www.microsoft.com) has released a security update that fixes vulnerabilities in products it has supplied. Users of affected products are advised to update to the latest version.   Affected Products   Microsoft Edge (Chromium-based) before 120.0.2210.121    Resolved Vulnerabilities   UAF Vulnerability in the ANGLE function in Microsoft Edge

Dr.Soft NetClient6 Product Security Update Advisory

Overview   Dr.Soft has released a security update to fix vulnerabilities in Netclient6.   Attackers could exploit the vulnerability to cause damage, including malware infection, and users of the product are advised to update to the latest version.     Affected Products   NetClient6 6.6.x through 6.8.x packages    

Apktool Security Update Advisory (CVE-2024-21633)

Overview An update has been made available to address a vulnerability in Apktool. Users of affected versions are advised to update to the latest version.  Affected Products All versions of Apktool 2.9.1 and earlier   Resolved Vulnerabilities Arbitrary file write on decode vulnerability in Apktool (CVE-2024-21633)   Vulnerability Patches Vulnerability

Google Chrome Browser (120.0.6099.199) Security Update Advisory

Overview   Google has released an update to fix vulnerabilities in the Chrome(https://www.google.com/chrome) browser. Users of affected versions are advised to update to the latest version.   Affected Products   Chrome before 120.0.6099.199 (Mac, Linux) Chrome before 120.0.6099.199/200 (Windows)   Resolved Vulnerabilities   High-level memory free-and-reuse (UAF) vulnerability in the

Hitron Product Security Update Advisories (CVE-2024-22768, CVE-2024-22769, CVE-2024-22770, CVE-2024-22771, CVE-2024-22772, CVE-2024-23842)

Overview An update has been made available from Hitron Systems to fix vulnerabilities in their products. Users of affected versions are advised to update to the latest version.   Affected Products CVE-2024-22768 DVRs HVR-4781 versions 1.03 to 4.02   CVE-2024-22769 DVR HVR-8781 versions 1.03 through 4.02   CVE-2024-22770 DVR HVR-16781