No Image

USN-3024-1: Tomcat vulnerabilities

2016-07-06 KENNETH 0

USN-3024-1: Tomcat vulnerabilities Ubuntu Security Notice USN-3024-1 5th July, 2016 tomcat6, tomcat7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Tomcat. Software description tomcat6 – Servlet and JSP engine tomcat7 – Servlet and JSP engine Details It was discovered that Tomcat incorrectly handled pathnames used by webapplications in a getResource, getResourceAsStream, or getResourcePathscall. A remote attacker could use this issue to possibly list a parentdirectory . This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS andUbuntu 15.10. (CVE-2015-5174) It was discovered that the Tomcat mapper component incorrectly handledredirects. A remote attacker could use this issue to determine theexistence of a directory. This issue only affected Ubuntu 12.04 LTS,Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-5345) It was discovered [ more… ]

No Image

USN-3025-1: GIMP vulnerability

2016-07-06 KENNETH 0

USN-3025-1: GIMP vulnerability Ubuntu Security Notice USN-3025-1 5th July, 2016 gimp vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary GIMP could be made to crash or run programs as your login if it opened a specially crafted file. Software description gimp – The GNU Image Manipulation Program Details It was discovered that GIMP incorrectly handled malformed XCF files. If auser were tricked into opening a specially crafted XCF file, an attackercould cause GIMP to crash, or possibly execute arbitrary code with theuser's privileges. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 15.10: gimp 2.8.14-1ubuntu2.1 Ubuntu 14.04 LTS: gimp 2.8.10-0ubuntu1.1 Ubuntu 12.04 LTS: gimp 2.6.12-1ubuntu1.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system [ more… ]

No Image

USN-3026-1: libimobiledevice vulnerability

2016-07-06 KENNETH 0

USN-3026-1: libimobiledevice vulnerability Ubuntu Security Notice USN-3026-1 5th July, 2016 libimobiledevice vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Summary libimobiledevice would allow unintended access to devices over the network. Software description libimobiledevice – Library for communicating with iPhone and iPod Touch devices Details It was discovered that libimobiledevice incorrectly handled socketpermissions. A remote attacker could use this issue to access services oniOS devices, contrary to expectations. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libimobiledevice6 1.2.0+dfsg-3~ubuntu0.2 Ubuntu 15.10: libimobiledevice4 1.1.6+dfsg-3.1ubuntu0.1 Ubuntu 14.04 LTS: libimobiledevice4 1.1.5+git20140313.bafe6a9e-0ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-5104 Source: USN-3026-1: libimobiledevice vulnerability

No Image

USN-3026-2: libusbmuxd vulnerability

2016-07-06 KENNETH 0

USN-3026-2: libusbmuxd vulnerability Ubuntu Security Notice USN-3026-2 5th July, 2016 libusbmuxd vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Summary libusbmuxd would allow unintended access to devices over the network. Software description libusbmuxd – USB multiplexor daemon for iPhone and iPod Touch devices Details It was discovered that libusbmuxd incorrectly handled socket permissions.A remote attacker could use this issue to access services on iOS devices,contrary to expectations. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: libusbmuxd4 1.0.10-2ubuntu0.1 Ubuntu 15.10: libusbmuxd2 1.0.9-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-5104 Source: USN-3026-2: libusbmuxd vulnerability

No Image

이것이 mysql 이다 – 한빛미디어

2016-07-06 KENNETH 0

이것이 mysql 이다 저자 : 우재남 (오오… ) 출판사 : 한빛미디어 책정보 : http://www.hanbit.co.kr/store/books/look.php?p_code=B1475432243   개요 대상 독자 ”처음으로 데이터 베이스를 접하는 사용자나 데이터베이스를 배우기를 원하는 웹 프로그래머” ㅇㅇ.. 그렇다. 지금까지 읽은 저자의 책은 입문자를 위한 책이 많았다.   개인적으로 입문자를 위한 책을 사랑한다. 내가 보기에도 편하거니와… 누구한테 소개해 주기도 좋쟎아… ㅋ   특징 및 장/단점 이번 리뷰는 저자에 대한 기대치가 높았던 만큼 단점 기술이 많이 되어있다. 굳이 이를 먼저 얘기 하는 것은 후술할 단점 전부가 ”이 책이 나쁘다”를 얘기하고자 하는 것이 아니라 ”이 저자 였으면…” 하는 아쉬움이 큰 부분임을 알리고자 한다. 자.. 시작해 보자… ㅋ   간략한 장점 1. 예제 그림 커맨드창(명령어 프롬프트) 가 흰색 바탕이라 좋았음 지난번 책인 이것이리눅스다의 경우 주로 설명에 필요한 커맨드창의 바탕이 검정이라 보기가 좀 힘들었는데 이번에 개선 한듯 ㅋ   2. 추억 데이터베이스 예제그림중 회원이름 컬럼에 당탕이 가 나왔다. 아마도 내 기억이 맞다면 뇌를자극하는sqlserver 에서도 [ more… ]