No Image

USN-6145-1: Sysstat vulnerabilities

2023-06-07 KENNETH 0

USN-6145-1: Sysstat vulnerabilities It was discovered that Sysstat incorrectly handled certain arithmetic multiplications. An attacker could use this issue to cause Sysstat to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue was only fixed for Ubuntu 16.04 LTS. (CVE-2022-39377) It was discovered that Sysstat incorrectly handled certain arithmetic multiplications in 64-bit systems, as a result of an incomplete fix for CVE-2022-39377. An attacker could use this issue to cause Sysstat to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2023-33204) Source: USN-6145-1: Sysstat vulnerabilities

No Image

USN-6028-2: libxml2 vulnerabilities

2023-06-07 KENNETH 0

USN-6028-2: libxml2 vulnerabilities USN-6028-1 fixed vulnerabilities in libxml2. This update provides the corresponding updates for Ubuntu 23.04. Original advisory details: It was discovered that libxml2 incorrectly handled certain XML files. An attacker could possibly use this issue to cause a crash. (CVE-2022-2309) It was discovered that lixml2 incorrectly handled certain XML files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2023-28484) It was discovered that libxml2 incorrectly handled certain XML files. An attacker could possibly use this issue to cause a crash. (CVE-2023-29469) Source: USN-6028-2: libxml2 vulnerabilities

No Image

USN-6144-1: LibreOffice vulnerabilities

2023-06-07 KENNETH 0

USN-6144-1: LibreOffice vulnerabilities It was discovered that LibreOffice did not properly validate the number of parameters passed to the formula interpreter, leading to an array index underflow attack. If a user were tricked into opening a specially crafted spreadsheet file, an attacker could possibly use this issue to execute arbitrary code. (CVE-2023-0950) Amel Bouziane-Leblond discovered that LibreOffice did not prompt the user before loading the host document inside an IFrame. If a user were tricked into opening a specially crafted input file, an attacker could possibly use this issue to cause information disclosure or execute arbitrary code. (CVE-2023-2255) Source: USN-6144-1: LibreOffice vulnerabilities

No Image

USN-6143-1: Firefox vulnerabilities

2023-06-07 KENNETH 0

USN-6143-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-34414, CVE-2023-34416, CVE-2023-34417) Jun Kokatsu discovered that Firefox did not properly validate site-isolated process for a document loaded from a data: URL that was the result of a redirect, leading to an open redirect attack. An attacker could possibly use this issue to perform phishing attacks. (CVE-2023-34415) Source: USN-6143-1: Firefox vulnerabilities

SaaS 솔루션의 테넌트당 비용 가시성 최적화

2023-06-07 KENNETH 0

SaaS 솔루션의 테넌트당 비용 가시성 최적화 이 글은 AWS 파트너 블로그의 Optimizing Cost Per Tenant Visibility in SaaS Solutions를 기반으로 서호성, 김정원 AWS 파트너 솔루션즈 아키텍트가 한국어로 번역 및 편집하였습니다. SaaS(Software-as-a-Service) 솔루션 운영의 가장 큰 과제 중 하나는 개별 테넌트의 리소스 소비를 측정하여 사용 패턴, 비용 귀속 등을 파악하는 것입니다. 하지만, SaaS 환경의 역동적인 특성과 변화하는 요구사항은 이를 더욱 어렵게 만듭니다. 이 블로그에서는 테넌트 리소스 소비를 측정하는 전략에 대해 설명하고, 이러한 전략을 SaaS 환경에 적용하여 비용을 할당하는 방법에 대한 예를 보여 드리겠습니다. 수집한 테넌트 리소스 소비 데이터를 사용하여 SaaS 아키텍처를 최적화하고, SaaS 환경의 운영 부담을 개선하고, 비즈니스 의사 결정을 내리는 방법에 대해 간략하게 살펴보겠습니다. 테넌트 리소스 소비량을 측정하는 것은 SaaS 환경 운영 비용을 결정하고, 테넌트당 비용을 계산하고, 테넌트의 활동 및 소비 패턴을 프로파일링하고, 더 많은 관련 인사이트를 수집하는 데 매우 중요합니다. 이러한 인사이트는 SaaS 애플리케이션을 구축, 판매 및 마케팅하는 방법에 [ more… ]