No Image

USN-5866-1: Nova vulnerabilities

2023-02-13 KENNETH 0

USN-5866-1: Nova vulnerabilities It was discovered that Nova did not properly manage data logged into the log file. An attacker with read access to the service’s logs could exploit this issue and may obtain sensitive information. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543) It was discovered that Nova did not properly handle attaching and reattaching the encrypted volume. An attacker could possibly use this issue to perform a denial of service attack. This issue only affected Ubuntu 16.04 ESM. (CVE-2017-18191) It was discovered that Nova did not properly handle the updation of domain XML after live migration. An attacker could possibly use this issue to corrupt the volume or perform a denial of service attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-17376) It was discovered that Nova was not properly validating the URL passed [ more… ]

[도서] 포토샵 CC 2023 무작정 따라하기

2023-02-13 KENNETH 0

[도서] 포토샵 CC 2023 무작정 따라하기 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]포토샵 CC 2023 무작정 따라하기 문수민,앤미디어,민지영 저 | 길벗 | 2023년 02월 판매가 19,800원 (10%할인) | YES포인트 1,100원(5%지급) GTQ 전문 강사의 ‘동영상 강의’와 ‘맞춤형 학습법’으로 내게 필요한 툴만 실속있게 공부하자! 어도비에서 새롭게 선보인 포토샵 CC 2023은 보다 섬세하고 빠르게 고품질의 디자인 작업을 할 수 있도록 기능 Source: [도서] 포토샵 CC 2023 무작정 따라하기

No Image

USN-5865-1: Linux kernel (Azure) vulnerabilities

2023-02-10 KENNETH 0

USN-5865-1: Linux kernel (Azure) vulnerabilities It was discovered that an out-of-bounds write vulnerability existed in the Video for Linux 2 (V4L2) implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-20369) Pawan Kumar Gupta, Alyssa Milburn, Amit Peled, Shani Rehana, Nir Shildan and Ariel Sabba discovered that some Intel processors with Enhanced Indirect Branch Restricted Speculation (eIBRS) did not properly handle RET instructions after a VM exits. A local attacker could potentially use this to expose sensitive information. (CVE-2022-26373) David Leadbeater discovered that the netfilter IRC protocol tracking implementation in the Linux Kernel incorrectly handled certain message payloads in some situations. A remote attacker could possibly use this to cause a denial of service or bypass firewall filtering. (CVE-2022-2663) Johannes Wikner and Kaveh Razavi discovered [ more… ]

No Image

쿠버네티스 프로비저닝 툴과의 만남부터 헤어짐까지 . . .

2023-02-10 KENNETH 0

쿠버네티스 프로비저닝 툴과의 만남부터 헤어짐까지 . . . 들어가며 안녕하세요, 카카오 클라우드 네이티브 파트에서 DKOS의 개발을 맡고 있는 우주, 후니, 존, 루키입니다. DKOS는 카카오 사내 개발자들을 위한 KaaS (Kubernetes as a service)입니다. 지난 4년간 DKOS를 서비스하며, 다수의 프로젝트가 리소스를 잘 사용할 수 있도록 Kubespray를 사용하여 쿠버네티스를 프로비저닝(Provisioning) 했었습니다. 이번 글에서는 “왜” Kubespray를 걷어내게 되었고, 또 “어떻게” 걷어낼 수 있었는지에 대해 이야기해보려 합니다. 쿠버네티스 프로비저닝이란?쿠버네티스 […] Source: 쿠버네티스 프로비저닝 툴과의 만남부터 헤어짐까지 . . .

No Image

USN-5863-1: Linux kernel (Azure) vulnerabilities

2023-02-10 KENNETH 0

USN-5863-1: Linux kernel (Azure) vulnerabilities It was discovered that the NFSD implementation in the Linux kernel did not properly handle some RPC messages, leading to a buffer overflow. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-43945) Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42896) It was discovered that the Xen netback driver in the Linux kernel did not properly handle packets structured in certain ways. An attacker in a guest VM could possibly use this to cause a denial of service (host NIC availability). (CVE-2022-3643) It was discovered that an integer overflow vulnerability existed in the Bluetooth subsystem [ more… ]