No Image

USN-4085-1: Sigil vulnerability

2019-08-01 KENNETH 0

USN-4085-1: Sigil vulnerability Sigil vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Sigil could be made to overwrite files. Software Description sigil – multi-platform ebook editor Details Mike Salvatore discovered that Sigil mishandled certain malformed EPUB files. An attacker could use this vulnerability to write arbitrary files to the filesystem. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 sigil – 0.9.13+dfsg-1ubuntu0.1 sigil-data – 0.9.13+dfsg-1ubuntu0.1 Ubuntu 18.04 LTS sigil – 0.9.9+dfsg-1ubuntu0.1~esm1 sigil-data – 0.9.9+dfsg-1ubuntu0.1~esm1 Ubuntu 16.04 LTS sigil – 0.9.5+dfsg-0ubuntu1+esm1 sigil-data – 0.9.5+dfsg-0ubuntu1+esm1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-14452 Source: USN-4085-1: Sigil vulnerability

No Image

USN-4084-1: Django vulnerabilities

2019-08-01 KENNETH 0

USN-4084-1: Django vulnerabilities python-django vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Django. Software Description python-django – High-level Python web development framework Details It was discovered that Django incorrectly handled the Truncator function. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service. (CVE-2019-14232) It was discovered that Django incorrectly handled the strip_tags function. A remote attacker could possibly use this issue to cause Django to consume resources, leading to a denial of service. (CVE-2019-14233) It was discovered that Django incorrectly handled certain lookups in the PostgreSQL support. A remote attacker could possibly use this issue to perform SQL injection attacks. (CVE-2019-14234) It was discovered that Django incorrectly handled certain invalid [ more… ]

No Image

The Month in WordPress: July 2019

2019-08-01 KENNETH 0

The Month in WordPress: July 2019 This month has been characterized by exciting plans and big announcements – read on to find out what they are and what it all means for the future of the WordPress project. WordCamp Asia Announced The inaugural WordCamp Asia will be in Bangkok, Thailand, on February 21-23, 2020. This will be the first regional WordCamp in Asia and it comes after many years of discussions and planning. You can find more information about the event on their website and subscribe to stay up to date with the latest information. This is the latest flagship event in the WordCamp program, following WordCamps Europe and US. Tickets are now on sale and the call for speakers is open. Want to get involved in WordCamp Asia? Keep an eye out for volunteer applications, or buy a micro [ more… ]

No Image

USN-4069-2: Linux kernel (HWE) vulnerabilities

2019-08-01 KENNETH 0

USN-4069-2: Linux kernel (HWE) vulnerabilities linux-hwe vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Summary Several security issues were fixed in the Linux kernel. Software Description linux-hwe – Linux hardware enablement (HWE) kernel Details USN-4069-1 fixed vulnerabilities in the Linux kernel for Ubuntu 19.04. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 19.04 for Ubuntu 18.04 LTS. It was discovered that an integer overflow existed in the Linux kernel when reference counting pages, leading to potential use-after-free issues. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2019-11487) Jann Horn discovered that a race condition existed in the Linux kernel when performing core dumps. A local attacker could use this to cause a denial of service [ more… ]

No Image

GraphQL 개념잡기

2019-08-01 KENNETH 0

GraphQL 개념잡기 GraphQL은 페이스북에서 만든 쿼리 언어입니다. 요즘 개발자들 사이에 자주 입에 오르내리고 있으나 2019년 4월 기준으로는 아직 얼리스테이지임은 분명합니다. 실제 국내에서 GraphQL API를 Open API로서 공식적으로 제공하는 곳은 존재하지 않는것 같고, 해외에서는 사례(Github v4 GraphQL)를 찾을 수는 있지만 GraphQL을 공식 API로 제공 하는 곳은 많지 않아 보입니다. 하지만 등장한지 얼마되지 않았음에도 불구하고, GraphQL의 인기는 매우 가파르게 올라가고 있다는 사실을 확인 할 수 있습니다. GraphQL 이란? Graph QL(이하 gql)은 Structed Query Language(이하 sql)와 마찬가지로 쿼리 언어입니다. 어떻게 보면 gql은 sql의 개념과 유사하다고 볼 수 있습니다. 하지만 gql과 sql의 언어적 구조 차이는 매우 큽니다. 또한 gql과 sql이 실전에서 쓰이는 방식의 차이도 매우 큽니다. gql과 sql의 언어적 구조 차이가 실제 활용 측면에서의 차이를 가져왔다고 볼 수도 있을것 같습니다. 이 둘은 애초에 탄생 시기도 다르고 배경도 다릅니다. sql은 데이터베이스 시스템에서 저장된 효율적으로 데이터를 가져오는 것이 목적고, gql은 웹 클라이언트가 서버로부터 데이터를 효율적으로 데이터를 [ more… ]