No Image

USN-4415-1: coTURN vulnerabilities

2020-07-06 KENNETH 0

USN-4415-1: coTURN vulnerabilities Felix Dörre discovered that coTURN response buffer is not initialized properly. An attacker could possibly use this issue to obtain sensitive information. (CVE-2020-4067) It was discovered that coTURN web server incorrectly handled HTTP POST requests. An attacker could possibly use this issue to cause a denial of service, obtain sensitive information or other unspecified impact. (CVE-2020-6061, CVE-2020-6062) Source: USN-4415-1: coTURN vulnerabilities

No Image

USN-4416-1: GNU C Library vulnerabilities

2020-07-06 KENNETH 0

USN-4416-1: GNU C Library vulnerabilities Florian Weimer discovered that the GNU C Library incorrectly handled certain memory operations. A remote attacker could use this issue to cause the GNU C Library to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-12133) It was discovered that the GNU C Library incorrectly handled certain SSE2-optimized memmove operations. A remote attacker could use this issue to cause the GNU C Library to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-18269) It was discovered that the GNU C Library incorrectly handled certain pathname operations. A remote attacker could use this issue to cause the GNU C Library to crash, resulting in a denial of service, or possibly execute arbitrary code. This [ more… ]

No Image

USN-4419-1: Linux kernel vulnerabilities

2020-07-06 KENNETH 0

USN-4419-1: Linux kernel vulnerabilities It was discovered that a race condition existed in the Precision Time Protocol (PTP) implementation in the Linux kernel, leading to a use-after- free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-10690) Matthew Sheets discovered that the SELinux network label handling implementation in the Linux kernel could be coerced into de-referencing a NULL pointer. A remote attacker could use this to cause a denial of service (system crash). (CVE-2020-10711) It was discovered that the DesignWare SPI controller driver in the Linux kernel contained a race condition. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2020-12769) It was discovered that the SCSI generic (sg) driver in the Linux kernel did not properly handle certain error conditions [ more… ]

AWS 주간 소식 모음 – 2020년 7월 6일

2020-07-06 KENNETH 0

AWS 주간 소식 모음 – 2020년 7월 6일 안녕하세요! 여러분~ 매주 월요일 마다 지난 주 업데이트된 국내 AWS관련 콘텐츠를 정리해 드리는 AWS 주간 소식 모음입니다. AWS 클라우드에 대한 새로운 소식을 확인하시는데 많은 도움 되시길 바랍니다. 혹시 빠지거나 추가할 내용이 있으시면, 저에게 메일 주시면 다음 중에 추가 공유해 드리겠습니다. AWS코리아 블로그 닷넷 코어 이전을 위한 AWS Porting Assistant for .NET 개발자 도구 출시 (2020-07-03) Amazon Simple Email Service (SES) 서울 리전 출시 (2020-07-03) AWS App2Container – Java 및 .NET 애플리케이션을 위한 컨테이너화 도구 출시 (2020-07-02) Amazon RDS Proxy 정식 출시 (서울 리전 포함) (2020-07-02) Amazon CodeGuru 정식 출시 – 비용 절감을 위한 코드 리뷰 서비스 (2020-07-01) AWS코리아 동영상 Amazon FSx 완전 관리형 Windows 및 Luster파일 시스템 활용하기 – 윤석찬 :: AWS Unboxing 온라인 세미나 (2020-06-30) Amazon AppFlow와 EventBridge를 통한 SaaS 데이터 연동하기 – 윤석찬 :: AWS Unboxing 온라인 세미나 (2020-06-30) Amazon [ more… ]

No Image

NGINX Unit 1.18.0 Adds Filesystem Isolation and Other Enhancements

2020-07-03 KENNETH 0

NGINX Unit 1.18.0 Adds Filesystem Isolation and Other Enhancements Usually, we’d start a blog post like this one rather light‑heartedly, but the mood of the times is undoubtedly somber, the reasons for that being too numerous to joke about. However, we hope you’re doing well – and again, we have some news to share. For starters, we at the NGINX Unit team believe that the term “isolation” doesn’t necessarily deserve the bad rap it has gained recently around the globe, and our most recent release, NGINX Unit 1.18.0, has arrived with an accordingly themed major update. Filesystem Isolation The isolation family of application settings, introduced in NGINX Unit 1.11.0, now includes a new rootfs object. If the underlying OS allows it, you can use rootfs to designate an arbitrary directory as the filesystem root. An application configured this way is locked within [ more… ]