No Image

MS 10월 보안 위협에 따른 정기 보안 업데이트 권고

2016-10-12 KENNETH 0

출처 : http://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=24643   □ 10월 보안업데이트 개요(총 10종) o 발표일 : 2016.10.12.(수) o 등급 : 긴급(Critical) 5종, 중요(Important) 4종, 보통(Moderate) 1종 o 업데이트 내용 패치번호 KB번호 중요도 발생 위치 영향 MS16-118 KB3192887 긴급 Windows, Internet Explorer 원격코드실행 MS16-119 KB3192890 긴급 Windows, Edge 원격코드실행 MS16-120 KB3192884 긴급 Windows, .NET Framework 등 원격코드실행 MS16-121 KB3194063 중요 Office, Office Services, Web Apps 원격코드실행 MS16-122 KB3195360 긴급 Windows 원격코드실행 MS16-123 KB3192892 중요 Windows 권한 상승 MS16-124 KB3193227 중요 Windows 권한 상승 MS16-125 KB3193229 중요 Windows 권한 상승 MS16-126 KB3196067 보통 Windows 정보 노출 MS16-127 KB3194343 긴급 Windows, Adobe Flash Player 원격코드실행 [MS16-118] Internet Explorer용 누적 보안 업데이트 □ 설명 o 이용자가 특수하게 제작된 악성 웹페이지를 방문하는 경우, 원격 코드 실행을 허용하는 취약점 o 관련취약점 : – 다중 메모리 손상 취약점(CVE-2016-3331, 3382~3385, 3390) – 다중 권한 상승 취약점(CVE-2016-3387, 3388) – 다중 정보 노출 취약점(CVE-2016-3267, 3391) [ more… ]

No Image

RHEA-2016:2053-1: new packages: kmod-qed, kmod-qede

2016-10-12 KENNETH 0

RHEA-2016:2053-1: new packages: kmod-qed, kmod-qede Red Hat Enterprise Linux: The kmod-qed packages contain the QLogic FastLinQ 4xxxx Core Module and the kmod-qede packages contain the QLogic FastLinQ 4xxxx Ethernet Driver. Source: RHEA-2016:2053-1: new packages: kmod-qed, kmod-qede

No Image

USN-3100-1: KDE-PIM Libraries vulnerability

2016-10-12 KENNETH 0

USN-3100-1: KDE-PIM Libraries vulnerability Ubuntu Security Notice USN-3100-1 12th October, 2016 kdepimlibs vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary KMail could be made to run HTML if it opened a specially crafted email. Software description kdepimlibs – the KDE PIM libraries Details Roland Tapken discovered that the KDE-PIM Libraries incorrectly filteredURLs. A remote attacker could use this issue to perform an HTML injectionattack in the KMail plain text viewer. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: libkpimutils4 4:4.8.5-0ubuntu0.3 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart KMail to make all thenecessary changes. References CVE-2016-7966 Source: USN-3100-1: KDE-PIM Libraries vulnerability

No Image

USN-3101-1: Tracker vulnerability

2016-10-12 KENNETH 0

USN-3101-1: Tracker vulnerability Ubuntu Security Notice USN-3101-1 12th October, 2016 tracker vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Tracker could be made to crash if it opened a specially crafted file. Software description tracker – metadata database, indexer and search tool Details It was discovered that Tracker incorrectly handled certain malformed GIFimages. If a user or automated system were tricked into downloading aspecially-crafted GIF image, Tracker could crash, resulting in a denial ofservice. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: tracker-extract 1.6.2-0ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart your session to makeall the necessary changes. References LP: 1178402 Source: USN-3101-1: Tracker vulnerability

No Image

MySQL 8.0 Labs – Descending Indexes in MySQL

2016-10-12 KENNETH 0

MySQL 8.0 Labs – Descending Indexes in MySQL Starting with the 8.0 optimizer labs release the MySQL server now supports descending indexes. As I will detail in this post, this new feature can be used to eliminate the need for sorting results, and lead to performance improvements in a number of queries.… Source: MySQL 8.0 Labs – Descending Indexes in MySQL