Mozilla patches critical security flaw that impacts several popular software offerings
Flaw affects multiple open source email clients and PDF viewers.
Stay updated with breaking news from Tavis Ormandy. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Flaw affects multiple open source email clients and PDF viewers.
Join / Sign In CNET editors pick the products and services we write about. When you buy through our links, we may get a commission. LastPass review: A leading password manager with a changing value proposition Heavy is the head that wears the crown. Listen - 16:22 LastPass "'Don't put all your eggs in one basket' is all wrong. I tell you 'put all your eggs in one basket, and then watch that basket.'" -- Andrew Carnegie, 1885 When it comes to privacy tools, Andrew Carnegie is usually dead wro...
Major changes in afl++ 3.00 + 3.10 With afl++ 3.10 we introduced the following changes from previous behaviours: The '+' feature of the '-t' option now means to auto-calculate the timeout with the value given being the maximum timeout. The original meaning of "skipping timeouts instead of abort" is now inherent to the -t option. With afl++ 3.00 we introduced changes that break some previous afl and afl++ behaviours and defaults: There are no llvm_mode and gcc_plugin subdirectories anymore and there is only one compiler: afl-cc. All previous compilers now symlink to this one. All instrumentat...
Serious bug discovered in widely used cryptographic software Events About If you already have an account please use the link below to sign in. If you have any problems with your access or would like to request an individual access account please contact our customer service team. GnuPG users urged to install latest upgrade immediately Serious bug discovered in GnuPG library Version 1.9.0 of Libgcrypt, GnuPG's cryptographic library, is impacted by a serious remote code execution (RCE) vulnerability that could allow an attacker to execute arbitrary code on the target machine. However, the good ...
Recently released cryptography code easily undone by trivial buffer overflow Share Copy Google Project Zero researcher Tavis Ormandy on Thursday reported a severe flaw in Libgcrypt 1.9.0, an update to the widely used cryptographic library that was released ten days ago. Libgcrypt is a general-purpose crypto module developed for GNU Privacy Guard (GnuPG or GPG), a free software implementation of the OpenPGP standard (RFC4880). It provides assorted cryptographic primitives or building blocks that applications can implement to encrypt and decrypt data. The code is present in Linux distri...