Announcing NGINX Plus R30

2023-08-16 KENNETH 0

Announcing NGINX Plus R30 We’re happy to announce the availability of NGINX Plus Release 30 (R30). Based on NGINX Open Source, NGINX Plus is the only all-in-one software web server, load balancer, reverse proxy, content cache, and API gateway. New and enhanced features in NGINX Plus R30 include: Native support for QUIC+HTTP/3 – NGINX Plus now has official support for HTTP/3. The implementation does not depend on third-party libraries to provide the missing OpenSSL TLS functionality required to deliver HTTP/3 support over QUIC protocol. It uses an OpenSSL Compatibility Layer developed by the NGINX team to circumvent the challenges with QUIC TLS interfaces that are not supported by OpenSSL. Per-worker connection telemetry – Monitoring connections at a per-worker level is now supported. This enables users to fine tune NGINX performance by regulating the number of worker processes and effectively distributing connections amongst workers for [ more… ]

No Image

USN-6288-1: MySQL vulnerabilities

2023-08-15 KENNETH 0

USN-6288-1: MySQL vulnerabilities Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.34 in Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-34.html https://www.oracle.com/security-alerts/cpujul2023.html Source: USN-6288-1: MySQL vulnerabilities

No Image

USN-4897-2: Pygments vulnerabilities

2023-08-14 KENNETH 0

USN-4897-2: Pygments vulnerabilities USN-4897-1 fixed several vulnerabilities in Pygments. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: Ben Caller discovered that Pygments incorrectly handled parsing certain files. If a user or automated system were tricked into parsing a specially crafted file, a remote attacker could cause Pygments to hang or consume resources, resulting in a denial of service. (CVE-2021-27291) It was discovered that Pygments incorrectly handled parsing certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2021-20270) Source: USN-4897-2: Pygments vulnerabilities

No Image

USN-6287-1: Go yaml vulnerabilities

2023-08-14 KENNETH 0

USN-6287-1: Go yaml vulnerabilities Simon Ferquel discovered that the Go yaml package incorrectly handled certain YAML documents. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause the system to crash, resulting in a denial of service. (CVE-2021-4235) It was discovered that the Go yaml package incorrectly handled certain large YAML documents. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause the system to crash, resulting in a denial of service. (CVE-2022-3064) Source: USN-6287-1: Go yaml vulnerabilities

Mountpoint for Amazon S3 정식 출시 – 오픈 소스 기반 파일 시스템 클라이언트

2023-08-14 KENNETH 0

Mountpoint for Amazon S3 정식 출시 – 오픈 소스 기반 파일 시스템 클라이언트 Mountpoint for Amazon S3는 파일 인식 Linux 애플리케이션을 Amazon Simple Storage Service(S3) 버킷에 직접 쉽게 연결할 수 있게 하는 오픈 소스 파일 클라이언트입니다. 올해 초 알파 릴리스로 발표된 이 제품이 이제 정식 출시되어 데이터 레이크, 기계 학습 교육, 이미지 렌더링, 자율 주행 차량 시뮬레이션, ETL 등의 대규모 읽기 집약적 애플리케이션에서 프로덕션 용도로 사용할 수 있습니다. 이 제품은 순차 및 임의 읽기, 순차적(추가만) 쓰기를 수행하고 전체 POSIX 의미 체계가 필요 없는 파일 기반 워크로드를 지원합니다. 왜 파일인가? 많은 AWS 고객이 S3 API와 AWS SDK를 사용하여 S3 버킷의 콘텐츠를 나열, 액세스 및 처리할 수 있는 애플리케이션을 구축합니다. 그러나 많은 고객이 UNIX 스타일로 파일에 액세스하는 방법(디렉터리 읽기, 기존 파일 열기 및 읽기, 새 파일 생성 및 작성)을 알고 있는 기존 애플리케이션, 명령, 도구 및 워크플로를 가지고 있습니다. 이러한 고객들은 S3에 [ more… ]