No Image

USN-4252-1: tcpdump vulnerabilities

2020-01-28 KENNETH 0

USN-4252-1: tcpdump vulnerabilities tcpdump vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in tcpdump. Software Description tcpdump – command-line network traffic analyzer Details Multiple security issues were discovered in tcpdump. A remote attacker could use these issues to cause tcpdump to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS tcpdump – 4.9.3-0ubuntu0.18.04.1 Ubuntu 16.04 LTS tcpdump – 4.9.3-0ubuntu0.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References CVE-2017-16808 CVE-2018-10103 CVE-2018-10105 CVE-2018-14461 CVE-2018-14462 CVE-2018-14463 CVE-2018-14464 CVE-2018-14465 CVE-2018-14466 [ more… ]

No Image

USN-4251-1: Tomcat vulnerabilities

2020-01-28 KENNETH 0

USN-4251-1: Tomcat vulnerabilities tomcat8 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in Tomcat. Software Description tomcat8 – Servlet and JSP engine Details It was discovered that Tomcat incorrectly handled the RMI registry when configured with the JMX Remote Lifecycle Listener. A local attacker could possibly use this issue to obtain credentials and gain complete control over the Tomcat instance. (CVE-2019-12418) It was discovered that Tomcat incorrectly handled FORM authentication. A remote attacker could possibly use this issue to perform a session fixation attack. (CVE-2019-17563) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libtomcat8-java – 8.0.32-1ubuntu1.11 tomcat8 – 8.0.32-1ubuntu1.11 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make [ more… ]

No Image

USN-4250-1: MySQL vulnerabilities

2020-01-27 KENNETH 0

USN-4250-1: MySQL vulnerabilities mysql-5.7, mysql-8.0 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in MySQL. Software Description mysql-8.0 – MySQL database mysql-5.7 – MySQL database Details Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.19 in Ubuntu 19.10. Ubuntu 16.04 LTS and Ubuntu 18.04 LTS have been updated to MySQL 5.7.29. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-29.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-19.html https://www.oracle.com/security-alerts/cpujan2020.html Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 mysql-server-8.0 – 8.0.19-0ubuntu0.19.10.3 Ubuntu 18.04 LTS mysql-server-5.7 – 5.7.29-0ubuntu0.18.04.1 Ubuntu [ more… ]

AWS 주간 소식 모음 – 2020년 1월 27일

2020-01-27 KENNETH 0

AWS 주간 소식 모음 – 2020년 1월 27일 안녕하세요! 여러분~ 매주 월요일 마다 지난 주 업데이트된 국내 AWS관련 콘텐츠를 정리해 드리는 AWS 주간 소식 모음입니다. AWS 클라우드에 대한 새로운 소식을 확인하시는데 많은 도움 되시길 바랍니다. 이번 주의 주요 업데이트는 지난 주에 진행된 AWS Community Day 행사 발표 자료, Amazon EKS 50% 가격 인하, Amazon Personalize 및 CloudWatch Synthetics 서울 리전 출시 소식 등 입니다. 혹시 빠지거나 추가할 내용이 있으시면, 저에게 메일 주시면 다음 중에 추가 공유해 드리겠습니다. AWS코리아 블로그 Amazon CloudWatch Synthetics 서울 리전 출시 (2020-01-22) Amazon Personalize 서울 리전 출시 (2020-01-22) CloudEndure기반 자동 재해 복구 출시 및 80% 요금 인하 (2020-01-22) 출시 예고 – AWS 오사카 로컬 리전을 정식 리전 확장 (2020-01-22) Amazon EKS, 전격 50% 가격 인하 (2020-01-22) AWS코리아 동영상 AWS Community Day 2020 – Seoul 스케치 영상 (2020-01-23) AWS 추천 콘텐츠 [AWS Community Day 2020 세션 레포트] [ more… ]

No Image

People of WordPress: Robert Cheleuka

2020-01-26 KENNETH 0

People of WordPress: Robert Cheleuka You’ve probably heard that WordPress is open-source software, and may know that it’s created and run by volunteers. WordPress enthusiasts share many examples of how WordPress changed people’s lives for the better. This monthly series shares some of those lesser-known, amazing stories. Meet Robert Cheleuka Robert is a self-taught graphic and motion designer turned web designer (and aspiring web developer) from Malawi, Africa. Over the years, he has grown fond of WordPress and has become a loyal user. Still, the journey is rough. Robert Cheleuka Malawi Malawi is one of the poorest countries in the world. A tiny landlocked country with a population of 17 million, it’s largely rural and still considered a developing country. The average entry-level monthly pay for most skilled jobs is about $110. If you’re employed full-time in the creative industry [ more… ]