No Image

USN-5396-2: Ghostscript vulnerability

2022-06-09 KENNETH 0

USN-5396-2: Ghostscript vulnerability USN-5396-1 addressed a vulnerability in Ghostscript. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: It was discovered that Ghostscript incorrectly handled certain PostScript files. If a user or automated system were tricked into processing a specially crafted file, a remote attacker could possibly use this issue to access arbitrary files, execute arbitrary code, or cause a denial of service. Source: USN-5396-2: Ghostscript vulnerability

No Image

USN-5474-1: Varnish Cache vulnerabilities

2022-06-09 KENNETH 0

USN-5474-1: Varnish Cache vulnerabilities It was dicovered that Varnish Cache did not clear a pointer between the handling of one client request and the next request within the same connection. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2019-20637) It was discovered that Varnish Cache could have an assertion failure when a TLS termination proxy uses PROXY version 2. A remote attacker could possibly use this issue to restart the daemon and cause a performance loss. (CVE-2020-11653) It was discovered that Varnish Cache allowed request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. A remote attacker could possibly use this issue to obtain sensitive information. (CVE-2021-36740) It was discovered that Varnish Cache allowed request smuggling for HTTP/1 connections. A remote attacker could possibly use this issue to obtain sensitive information. [ more… ]

No Image

USN-5472-1: FFmpeg vulnerabilities

2022-06-08 KENNETH 0

USN-5472-1: FFmpeg vulnerabilities It was discovered that FFmpeg would attempt to divide by zero when using Linear Predictive Coding (LPC) or AAC codecs. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2020-20445, CVE-2020-20446, CVE-2020-20453) It was discovered that FFmpeg incorrectly handled certain input. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 21.10. (CVE-2020-20450) It was discovered that FFmpeg incorrectly handled file conversion to APNG format. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-21041) It was discovered that FFmpeg incorrectly handled remuxing RTP-hint tracks. A remote attacker could possibly [ more… ]

No Image

USN-5473-1: ca-certificates update

2022-06-08 KENNETH 0

USN-5473-1: ca-certificates update The ca-certificates package contained outdated CA certificates. This update refreshes the included certificates to those contained in the 2.50 version of the Mozilla certificate authority bundle. Source: USN-5473-1: ca-certificates update

AWS 주간 소식 모음 – AWS Builders Korea 6월 프로그램 등 :: 2022년 6월 첫째주

2022-06-08 KENNETH 0

AWS 주간 소식 모음 – AWS Builders Korea 6월 프로그램 등 :: 2022년 6월 첫째주 저는 미국에서 휴일이 낀 긴 주말을 보내고 막 돌아와서 이제 지난 주의 모든 AWS 출시 소식을 확인하고 있습니다. 몇 가지 데이터, 기계 학습 및 양자 컴퓨팅 뉴스가 특히 눈길을 끄네요. 함께 살펴보겠습니다. AWS Builders Korea 6월 프로그램 AWS 에서는 클라우드에 관심이 있으신 한국 고객분들을 위해 클라우드 기초부터 기본, 심화 및 특집 과정을 제공합니다. 6월 21일 (화) – AWS 서버리스로 서버 없이 간단한 웹 애플리케이션 만들기 6월 21일 (화) – AWS 코어 서비스로 간단한 웹 애플리케이션 직접 만들기 6월 22일 (수) – AWS의 컨테이너 서비스인 Amazon ECS를 이용해 손쉽게 애플리케이션 배포하기 6월 22일 (수) – AWS 관리형 쿠버네티스 컨테이너 서비스 Amazon EKS로 애플리케이션 배포 및 운영하기 6월 23일 (목) – AWS Step Functions 로 AWS 서비스 기능 조합하여 워크플로우 및 API 만들기 6월 23일 (목) – [ more… ]