No Image

USN-5947-1: Twig vulnerabilities

2023-03-13 KENNETH 0

USN-5947-1: Twig vulnerabilities Fabien Potencier discovered that Twig was not properly enforcing sandbox policies when dealing with objects automatically cast to strings by PHP. An attacker could possibly use this issue to expose sensitive information. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2019-9942) Marlon Starkloff discovered that Twig was not properly enforcing closure constraints in some of its array filtering functions. An attacker could possibly use this issue to execute arbitrary code. This issue was only fixed in Ubuntu 20.04 ESM. (CVE-2022-23614) Dariusz Tytko discovered that Twig was not properly verifying input data utilized when defining pathnames used to access files in a system. An attacker could possibly use this issue to access unauthorized resources and expose sensitive information. (CVE-2022-39261) Source: USN-5947-1: Twig vulnerabilities

No Image

USN-5945-1: Protocol Buffers vulnerabilities

2023-03-13 KENNETH 0

USN-5945-1: Protocol Buffers vulnerabilities It was discovered that Protocol Buffers did not properly validate field com.google.protobuf.UnknownFieldSet in protobuf-java. An attacker could possibly use this issue to perform a denial of service attack. This issue only affected protobuf Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2021-22569) It was discovered that Protocol Buffers did not properly parse certain symbols. An attacker could possibly use this issue to cause a denial of service or other unspecified impact. (CVE-2021-22570) It was discovered that Protocol Buffers did not properly manage memory when parsing specifically crafted messages. An attacker could possibly use this issue to cause applications using protobuf to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-1941) Source: USN-5945-1: Protocol Buffers vulnerabilities

No Image

USN-5943-1: Thunderbird vulnerabilities

2023-03-13 KENNETH 0

USN-5943-1: Thunderbird vulnerabilities Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass security restrictions, cross-site tracing, or execute arbitrary code. (CVE-2023-0616, CVE-2023-25735, CVE-2023-25737, CVE-2023-25739, CVE-2023-25729, CVE-2023-25742, CVE-2023-25746) Johan Carlsson discovered that Thunderbird did not properly implement CSP policy on a header when using iframes. An attacker could potentially exploits this to exfiltrate data. (CVE-2023-25728) Irvan Kurniawan discovered that Thunderbird was not properly handling background fullscreen scripts when the window goes into fullscreen mode. An attacker could possibly use this issue to spoof the user and obtain sensitive information. (CVE-2023-25730) Christian Holler discovered that Thunderbird did not properly check the Safe Bag attributes in PKCS 12 certificate bundle. An attacker could possibly [ more… ]

[도서] 챗GPT와 업무자동화

2023-03-13 KENNETH 0

[도서] 챗GPT와 업무자동화 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]챗GPT와 업무자동화 김철수 저 | 위키북스 | 2023년 03월 판매가 16,200원 (10%할인) | YES포인트 900원(5%지급) 코드 한 줄 몰라도 1분 만에 끝내는 엑셀, 구글 스프레드시트, 파워포인트 업무 자동화! 우리는 ChatGPT에게 코드를 요청하고, ChatGPT가 작성한 코드를 사용해서 엑셀이든 파워포인트든 구글 시스프레드시트든 Source: [도서] 챗GPT와 업무자동화

[도서] 진짜 챗GPT 활용법

2023-03-13 KENNETH 0

[도서] 진짜 챗GPT 활용법 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]진짜 챗GPT 활용법 김준성,유원준,안상준 저 | 위키북스 | 2023년 03월 판매가 16,200원 (10%할인) | YES포인트 900원(5%지급) 챗GPT의 ‘진짜 활용법’을 담았습니다! ChatGPT의 원리 및 기본 사용법부터 블로그, 영상 제작, 업무 등에서 다양하게 활용하는 ‘진짜 활용법’을 담았습니다. 일상에서도 업무에서도 ChatGPT 그리고 다양한 AI 도 Source: [도서] 진짜 챗GPT 활용법