No Image

USN-4697-2: Pillow vulnerabilities

2021-01-20 KENNETH 0

USN-4697-2: Pillow vulnerabilities USN-4697-1 fixed several vulnerabilities in Pillow. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: It was discovered that Pillow incorrectly handled certain PCX image files. If a user or automated system were tricked into opening a specially-crafted PCX file, a remote attacker could possibly cause Pillow to crash, resulting in a denial of service. (CVE-2020-35653) It was discovered that Pillow incorrectly handled certain image files. If a user or automated system were tricked into opening a specially-crafted image file, a remote attacker could possibly cause Pillow to crash, resulting in a denial of service. (CVE-2020-10177) Source: USN-4697-2: Pillow vulnerabilities

No Image

USN-4689-3: NVIDIA graphics drivers vulnerabilities

2021-01-20 KENNETH 0

USN-4689-3: NVIDIA graphics drivers vulnerabilities It was discovered that the NVIDIA GPU display driver for the Linux kernel contained a vulnerability that allowed user-mode clients to access legacy privileged APIs. A local attacker could use this to cause a denial of service or escalate privileges. (CVE-2021-1052) It was discovered that the NVIDIA GPU display driver for the Linux kernel did not properly validate a pointer received from userspace in some situations. A local attacker could use this to cause a denial of service. (CVE-2021-1053) Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux kernel did not properly restrict device-level GPU isolation. A local attacker could use this to cause a denial of service or possibly expose sensitive information. (CVE-2021-1056) Source: USN-4689-3: NVIDIA graphics drivers vulnerabilities

No Image

USN-4701-1: Thunderbird vulnerabilities

2021-01-20 KENNETH 0

USN-4701-1: Thunderbird vulnerabilities Multiple security issues were discovered in Thunderbird. If a user were tricked in to opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass the CSS sanitizer, or execute arbitrary code. (CVE-2020-16042, CVE-2020-16044, CVE-2020-26971, CVE-2020-26973, CVE-2020-26974, CVE-2020-26978, CVE-2020-35113) It was discovered that the proxy.onRequest API did not catch view-source URLs. If a user were tricked in to installing an extension with the proxy permission and opening View Source, an attacker could potentially exploit this to obtain sensitive information. (CVE-2020-35111) A stack overflow was discovered due to incorrect parsing of SMTP server response codes. An attacker could potentially exploit this to execute arbitrary code. (CVE-2020-26970) Source: USN-4701-1: Thunderbird vulnerabilities

[도서] 자연어 처리와 딥러닝

2021-01-20 KENNETH 0

[도서] 자연어 처리와 딥러닝 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]자연어 처리와 딥러닝 리 덩,양 리우 공저/김재민 역 | 에이콘출판사 | 2021년 01월 판매가 36,000원 (10%할인) | YES포인트 2,000원(5%지급) 딥러닝을 포함한 머신러닝의 역사, 딥러닝과 통계 기반 머신러닝이 적용되는 영역, 딥러닝 디자인, 디자인 한계점과 해결 방법, 향후 연구 과제 등 코드 이면에 담겨있는 이야기를 전달하고자 여러 전문가가 참여했 Source: [도서] 자연어 처리와 딥러닝

[도서] 데이터베이스 인터널스

2021-01-20 KENNETH 0

[도서] 데이터베이스 인터널스 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]데이터베이스 인터널스 알렉스 페트로프 저/이우현 역/이태휘 감수 | 에이콘출판사 | 2021년 01월 판매가 31,500원 (10%할인) | YES포인트 1,750원(5%지급) 데이터베이스에 데이터를 저장하는 방식과 분산 시스템의 일관성을 유지할 때 사용되는 개념과 알고리즘을 설명한다. 나아가 이들을 개선하기 위해 등장한 여러 새로운 알고리즘도 설명한다. 최신 분산 시스템과 논 Source: [도서] 데이터베이스 인터널스