No Image

USN-4130-1: WebKitGTK+ vulnerabilities

2019-09-12 KENNETH 0

USN-4130-1: WebKitGTK+ vulnerabilities webkit2gtk vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Summary Several security issues were fixed in WebKitGTK+. Software Description webkit2gtk – Web content engine library for GTK+ Details A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 libjavascriptcoregtk-4.0-18 – 2.24.4-0ubuntu0.19.04.1 libwebkit2gtk-4.0-37 – 2.24.4-0ubuntu0.19.04.1 Ubuntu 18.04 LTS libjavascriptcoregtk-4.0-18 – 2.24.4-0ubuntu0.18.04.1 libwebkit2gtk-4.0-37 – 2.24.4-0ubuntu0.18.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This update uses a new upstream release, [ more… ]

No Image

USN-4129-1: curl vulnerabilities

2019-09-11 KENNETH 0

USN-4129-1: curl vulnerabilities curl vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in curl. Software Description curl – HTTP, HTTPS, and FTP client and client libraries Details Thomas Vegas discovered that curl incorrectly handled memory when using Kerberos over FTP. A remote attacker could use this issue to crash curl, resulting in a denial of service. (CVE-2019-5481) Thomas Vegas discovered that curl incorrectly handled memory during TFTP transfers. A remote attacker could use this issue to crash curl, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2019-5482) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 curl – 7.64.0-2ubuntu1.2 libcurl3-gnutls – 7.64.0-2ubuntu1.2 libcurl3-nss – 7.64.0-2ubuntu1.2 libcurl4 – 7.64.0-2ubuntu1.2 Ubuntu 18.04 [ more… ]

No Image

USN-4115-2: Linux kernel regression

2019-09-11 KENNETH 0

USN-4115-2: Linux kernel regression linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2 regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary USN 4115-1 introduced a regression in the Linux kernel. Software Description linux – Linux kernel linux-aws – Linux kernel for Amazon Web Services (AWS) systems linux-gke-4.15 – Linux kernel for Google Container Engine (GKE) systems linux-kvm – Linux kernel for cloud environments linux-oracle – Linux kernel for Oracle Cloud systems linux-raspi2 – Linux kernel for Raspberry Pi 2 linux-aws-hwe – Linux kernel for Amazon Web Services (AWS-HWE) systems linux-azure – Linux kernel for Microsoft Azure Cloud systems linux-gcp – Linux kernel for Google Cloud Platform (GCP) systems linux-hwe – Linux hardware enablement (HWE) kernel Details USN 4115-1 fixed vulnerabilities in the Linux 4.15 kernel for Ubuntu 18.04 [ more… ]

No Image

NGINX Conf 2019, Day 1: Bringing Your Apps to Life, from Code to Customer

2019-09-11 KENNETH 0

NGINX Conf 2019, Day 1: Bringing Your Apps to Life, from Code to Customer NGINX Conf 2019 kicked off in Seattle this morning at a pivotal time for NGINX, F5, and our mutual customers. Leaders from the two companies shared their vision of how the world of applications is evolving today, and how the companies are coming together as one. The theme of this year’s NGINX Conf is “Level Up”, and each of today’s speakers lent a unique perspective on what leveling up entails for applications, infrastructure, and teams. In the end, organizations need a way to bridge the divide between DevOps teams, NetOps teams, SecOps teams, and users, with an eye toward increasing the speed to market for the next generation of what I term “living apps“. Day 1 was jam‑packed with keynotes and panel discussions featuring executives, analysts, and customers. [ more… ]

No Image

2019 年 9 月のセキュリティ更新プログラム (月例)

2019-09-11 KENNETH 0

2019 年 9 月のセキュリティ更新プログラム (月例) 2019 年 9 月 11 日 (日本時間)、マイクロソフトは以下のソフトウェアのセキュリティ更新プログラムを公開しました。 The post 2019 年 9 月のセキュリティ更新プログラム (月例) appeared first on Microsoft Security Response Center. Source: 2019 年 9 月のセキュリティ更新プログラム (月例)