No Image

USN-5964-1: curl vulnerabilities

2023-03-20 KENNETH 0

USN-5964-1: curl vulnerabilities Harry Sintonen discovered that curl incorrectly handled certain TELNET connection options. Due to lack of proper input scrubbing, curl could pass on user name and telnet options to the server as provided, contrary to expectations. (CVE-2023-27533) Harry Sintonen discovered that curl incorrectly handled special tilde characters when used with SFTP paths. A remote attacker could possibly use this issue to circumvent filtering. (CVE-2023-27534) Harry Sintonen discovered that curl incorrectly reused certain FTP connections. This could lead to the wrong credentials being reused, contrary to expectations. (CVE-2023-27535) Harry Sintonen discovered that curl incorrectly reused connections when the GSS delegation option had been changed. This could lead to the option being reused, contrary to expectations. (CVE-2023-27536) Harry Sintonen discovered that curl incorrectly reused certain SSH connections. This could lead to the wrong credentials being reused, contrary to expectations. (CVE-2023-27538) [ more… ]

No Image

USN-5963-1: Vim vulnerabilities

2023-03-20 KENNETH 0

USN-5963-1: Vim vulnerabilities It was discovered that Vim was not properly performing memory management operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-47024, CVE-2023-0049, CVE-2023-0054, CVE-2023-0288, CVE-2023-0433) It was discovered that Vim was not properly performing memory management operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2023-0051) It was discovered that Vim was not properly performing memory management operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2023-1170, CVE-2023-1175) It was discovered that Vim was not properly performing memory management operations. An attacker could possibly [ more… ]

Amazon Linux 2023 – 클라우드에 최적화된 Linux 배포판 출시 (장기 지원 제공)

2023-03-20 KENNETH 0

Amazon Linux 2023 – 클라우드에 최적화된 Linux 배포판 출시 (장기 지원 제공) Amazon Linux 2023(AL2023)의 상용 출시를 발표하게 되어 기쁩니다. AWS는 2010년부터 클라우드에 최적화된 Linux 배포판을 제공해왔습니다. 이 배포판은 3세대 Amazon Linux 배포판입니다. 모든 세대의 Amazon Linux 배포판은 보안이 적용되고 클라우드에 최적화되며 장기적인 AWS 지원을 받습니다. 이러한 원칙에 따라 Amazon Linux 2023을 구축했으며 기능을 더욱 개선하고 있습니다. Amazon Linux 2023에 워크로드를 배포하면 세 가지 주요 이점, 즉 엄격한 보안 표준, 예측 가능한 수명 주기 및 일관된 업데이트 경험을 얻을 수 있습니다. 먼저 보안에 대해 살펴보겠습니다. Amazon Linux 2023에는 일반적인 업계 지침을 손쉽게 구현할 수 있도록 사전 구성된 보안 정책이 포함되어 있습니다. 시작 시 또는 런타임에 이러한 정책을 구성할 수 있습니다. 예를 들어 시스템 전체에서 특정 암호화 스위트 세트, TLS 버전 또는 인증서와 키 교환에서 허용되는 파라미터를 사용하도록 시스템 암호화 정책을 구성할 수 있습니다. 또한 Linux 커널에는 기본적으로 많은 강화 기능이 [ more… ]

A principled approach to app pinning and app defaults in Windows

2023-03-18 KENNETH 0

A principled approach to app pinning and app defaults in Windows Today we’re reaffirming our long-standing approach to put people in control of their Windows PC experience and to empower developers to take advantage of our open platform. We want to ensure that people are in control of what gets pinned to their Desktop, their Start menu and their Taskbar as well as to be able to control their default applications such as their default browser through consistent, clear and trustworthy Windows provided system dialogs and settings. Third party applications running on Windows and Microsoft’s own apps and features will have access to methods for pinning to these key user experiences and access to directing users to change defaults. Apps may offer features to lead users to the appropriate dialog or setting, but users are ultimately in control through standardized [ more… ]

[도서] 개발자에게 물어보세요

2023-03-17 KENNETH 0

[도서] 개발자에게 물어보세요 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]개발자에게 물어보세요 제프 로슨 저/박설영 역 | 인사이트(insight) | 2023년 03월 판매가 18,000원 (10%할인) | YES포인트 1,000원(5%지급) 스마트 팩토리 구축, 데이터가 흐르는 조직, 실험하는 문화··· 가야 할 곳은 알지만 가는 방법은 막막한 레거시 조직이 21세기 API 경제에서 디지털 공급망으로 승리하는 법 기회는 사라지지 않는다. 이동 Source: [도서] 개발자에게 물어보세요