No Image

USN-3381-1: Linux kernel vulnerabilities

2017-08-08 KENNETH 0

USN-3381-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3381-1 7th August, 2017 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel Details Peter Pi discovered that the colormap handling for frame buffer devices inthe Linux kernel contained an integer overflow. A local attacker could usethis to disclose sensitive information (kernel memory). (CVE-2016-8405) It was discovered that the Linux kernel did not properly restrictRLIMIT_STACK size. A local attacker could use this in conjunction withanother vulnerability to possibly execute arbitrary code.(CVE-2017-1000365) It was discovered that SELinux in the Linux kernel did not properly handleempty writes to /proc/pid/attr. A local attacker could use this to cause adenial of service (system crash). (CVE-2017-2618) 石磊 discovered that the RxRPC Kerberos 5 ticket handling [ more… ]

No Image

USN-3381-2: Linux kernel (Trusty HWE) vulnerabilities

2017-08-08 KENNETH 0

USN-3381-2: Linux kernel (Trusty HWE) vulnerabilities Ubuntu Security Notice USN-3381-2 7th August, 2017 linux-lts-trusty vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-lts-trusty – Linux hardware enablement kernel from Trusty for Precise ESM Details USN-3381-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04LTS. This update provides the corresponding updates for the LinuxHardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu12.04 ESM. Peter Pi discovered that the colormap handling for frame buffer devices inthe Linux kernel contained an integer overflow. A local attacker could usethis to disclose sensitive information (kernel memory). (CVE-2016-8405) It was discovered that the Linux kernel did not properly restrictRLIMIT_STACK size. A local attacker could use this in conjunction withanother vulnerability to possibly execute arbitrary code.(CVE-2017-1000365) It [ more… ]

[도서] 웹으로 시작하는 모바일 게임

2017-08-08 KENNETH 0

[도서] 웹으로 시작하는 모바일 게임 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]웹으로 시작하는 모바일 게임 배철민,윤정민,신호철 공저 | 지앤선(志&嬋) | 2017년 08월 판매가 20,700원 (10%할인) | YES포인트 230원(1%지급) 1, 2 장에서는 웹환경에서 게임관련된 요소들인 게임엔진, Canvas API, WebGL 등에 대한 간단한 소개를 하고 있다. 3, 4 장은 HTML5 Canvas 대한 기본 내용과 그것을 활용한 테트리스 게임 만들기에 대해 이야기하고 Source: [도서] 웹으로 시작하는 모바일 게임

No Image

The MSRC 2017 list of “Top 100” security researchers

2017-08-08 KENNETH 0

The MSRC 2017 list of “Top 100” security researchers Security researchers play an essential role in Microsoft’s security strategy and are key to community-based defense. To show our appreciation for their hard work and partnership, each year at BlackHat North America, the Microsoft Security Response Center highlights contributions of these researchers through the list of “Top 100” security researchers reporting to Microsoft. This list ranks security researchers reporting directly to Microsoft according to the quantity and quality of all reports for which we’ve issued fixes. While one criteria for the ranking is volume of reports a researcher has made, the severity and impact of the reports is very important to the ranking. Higher-impact issues carry more weight than lower-impact ones. While this list does not include security researchers who report to our partners ZDI and iDefense as we do not [ more… ]

No Image

USN-3380-1: FreeRDP vulnerabilities

2017-08-08 KENNETH 0

USN-3380-1: FreeRDP vulnerabilities Ubuntu Security Notice USN-3380-1 7th August, 2017 freerdp vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in FreeRDP. Software description freerdp – RDP client for Windows Terminal Services Details It was discovered that FreeRDP incorrectly handled certain width and heightvalues. A malicious server could use this issue to cause FreeRDP to crash,resulting in a denial of service, or possibly execute arbitrary code. Thisissue only applied to Ubuntu 14.04 LTS. (CVE-2014-0250) It was discovered that FreeRDP incorrectly handled certain values in aScope List. A malicious server could use this issue to cause FreeRDP tocrash, resulting in a denial of service, or possibly execute arbitrarycode. (CVE-2014-0791) Tyler Bohan discovered that FreeRDP incorrectly handled certain lengthvalues. A malicious server could use this [ more… ]