No Image

USN-2960-1: Oxide vulnerabilities

2016-05-19 KENNETH 0

USN-2960-1: Oxide vulnerabilities Ubuntu Security Notice USN-2960-1 18th May, 2016 oxide-qt vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Summary Several security issues were fixed in Oxide. Software description oxide-qt – Web browser engine for Qt (QML plugin) Details An out of bounds write was discovered in Blink. If a user were tricked into opening a specially crafted website, an attacker could potentiallyexploit this to cause a denial of service via renderer crash, or executearbitrary code. (CVE-2016-1660) It was discovered that Blink assumes that a frame which passes same-originchecks is local in some cases. If a user were tricked in to opening aspecially crafted website, an attacker could potentially exploit this tocause a denial of service via renderer crash, or execute arbitrary code.(CVE-2016-1661) A use-after-free was discovered in [ more… ]

No Image

USN-2973-1: Thunderbird vulnerabilities

2016-05-19 KENNETH 0

USN-2973-1: Thunderbird vulnerabilities Ubuntu Security Notice USN-2973-1 18th May, 2016 thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Thunderbird. Software description thunderbird – Mozilla Open Source mail and newsgroup client Details Christian Holler, Tyson Smith, and Phil Ringalda discovered multiplememory safety issues in Thunderbird. If a user were tricked in to openinga specially crafted message, an attacker could potentially exploit theseto cause a denial of service via application crash, or execute arbitrarycode. (CVE-2016-2805, CVE-2016-2807) Hanno Böck discovered that calculations with mp_div and mp_exptmod in NSSproduce incorrect results in some circumstances, resulting incryptographic weaknesses. (CVE-2016-1938) A use-after-free was discovered in ssl3_HandleECDHServerKeyExchange inNSS. A remote attacker could potentially exploit this to cause a denial ofservice via application crash, or [ more… ]

No Image

USN-2936-3: Firefox regression

2016-05-19 KENNETH 0

USN-2936-3: Firefox regression Ubuntu Security Notice USN-2936-3 18th May, 2016 firefox regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary USN-2936-1 introduced a regression in Firefox. Software description firefox – Mozilla Open Source web browser Details USN-2936-1 fixed vulnerabilities in Firefox. The update caused an issuewhere a device update POST request was sent every time about:preferences#syncwas shown. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Christian Holler, Tyson Smith, Phil Ringalda, Gary Kwong, Jesse Ruderman, Mats Palmgren, Carsten Book, Boris Zbarsky, David Bolter, Randell Jesup, Andrew McCreight, and Steve Fink discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of [ more… ]

Microservices Reference Architecture, Part 2 – The Proxy Model

2016-05-19 KENNETH 0

Microservices Reference Architecture, Part 2 – The Proxy Model The NGINX Microservices Reference Architecture is under development. It will be made publically available later this year, and will be discussed in detail at nginx.conf 2016, September 7–9 in Austin, TX. Early bird discounts are available now. Author’s note – This blog post is the second in a series; we will extend this list as new posts appear: Introducing the NGINX Microservices Reference Architecture Microservices Reference Architecture, Part 2 – The Proxy Model (this post) Upcoming posts will cover the other two models included in the Microservices Reference Architecture (MRA) and related topics. I’ve written a separate article about web frontends for microservices applications. We also have a very useful and popular series about microservices application design, plus other microservices blog posts and microservices webinars. Introducing the Proxy Model As the name implies, the Proxy Model places NGINX Plus as a reverse proxy server [ more… ]

No Image

Microservices: From Design to Deployment, a Free Ebook from NGINX

2016-05-19 KENNETH 0

Microservices: From Design to Deployment, a Free Ebook from NGINX We’re happy to announce the release of a new ebook from NGINX, Microservices: From Design to Deployment, by Chris Richardson and Floyd Smith. Download your copy now. Microservices architecture is the new state of the art in application development and deployment. Microservices enable architects, developers, and operations people can meet the needs of users for continually updated feature-rich, capable, and robust apps. The architecture of NGINX and NGINX Plus is uniquely suited to the development of microservices apps, from initial implementation to a complete suite of services. But how do you tie it all together? This ebook will help you find the best microservices design strategies for your applications, show you how to begin refactoring monolithic applications into microservices, and demonstrate how NGINX and NGINX Plus can support your transition [ more… ]