No Image

USN-6278-1: .NET vulnerabilities

2023-08-09 KENNETH 0

USN-6278-1: .NET vulnerabilities It was discovered that .NET did not properly handle the execution of certain commands. An attacker could possibly use this issue to achieve remote code execution. (CVE-2023-35390) Benoit Foucher discovered that .NET did not properly implement the QUIC stream limit in HTTP/3. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38178) It was discovered that .NET did not properly handle the disconnection of potentially malicious clients interfacing with a Kestrel server. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-38180) Source: USN-6278-1: .NET vulnerabilities

No Image

Use Infrastructure as Code to Deploy F5 NGINX Management Suite

2023-08-09 KENNETH 0

Use Infrastructure as Code to Deploy F5 NGINX Management Suite Unlocking the full potential of F5 NGINX Management Suite can help your organization simplify app and API deployment, management, and security. The new NGINX Management Suite Infrastructure as Code (IaC) project aims to help you get started as quickly as possible, while also encouraging the best practices for your chosen deployment environment. If you are responsible for building software infrastructure, you’re likely familiar with IaC as a modern approach to getting consistent results. However, because there are many ways to achieve an IaC setup, it may be daunting to get started or time consuming to create from scratch. This blog post introduces the NGINX Management Suite Infrastructure as Code repository and outlines how to set up its individual modules to quickly get them up and running. Project Overview There are [ more… ]

No Image

USN-6277-1: Dompdf vulnerabilities

2023-08-08 KENNETH 0

USN-6277-1: Dompdf vulnerabilities It was discovered that Dompdf was not properly validating untrusted input when processing HTML content under certain circumstances. An attacker could possibly use this issue to expose sensitive information or execute arbitrary code. This issue only affected Ubuntu 16.04 LTS. (CVE-2014-5011, CVE-2014-5012, CVE-2014-5013) It was discovered that Dompdf was not properly validating processed HTML content that referenced PHAR files, which could result in the deserialization of untrusted data. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-3838) It was discovered that Dompdf was not properly validating processed HTML content that referenced both a remote base and a local file, which could result in the bypass of a chroot check. An attacker could possibly use this issue to expose sensitive information. (CVE-2022-2400) Source: USN-6277-1: Dompdf vulnerabilities

No Image

USN-6267-2: Firefox regressions

2023-08-08 KENNETH 0

USN-6267-2: Firefox regressions USN-6267-1 fixed vulnerabilities in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-4047, CVE-2023-4048, CVE-2023-4049, CVE-2023-4051, CVE-2023-4053, CVE-2023-4055, CVE-2023-4056, CVE-2023-4057, CVE-2023-4058) Max Vlasov discovered that Firefox Offscreen Canvas did not properly track cross-origin tainting. An attacker could potentially exploit this issue to access image data from another site in violation of same-origin policy. (CVE-2023-4045) Alexander Guryanov discovered that Firefox did not properly update the value of a global variable in WASM JIT analysis in some circumstances. An attacker could potentially exploit this issue to cause a [ more… ]

[도서] 오토캐드 기계설계제도 테크니컬 가이드북

2023-08-08 KENNETH 0

[도서] 오토캐드 기계설계제도 테크니컬 가이드북 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]오토캐드 기계설계제도 테크니컬 가이드북 메카피아교육사업부 저 | 메카피아 | 2023년 09월 판매가 25,200원 (10%할인) | YES포인트 1,400원(5%지급) 본 서는 기계제조 엔지니어링 분야의 CAD 입문자를 위한 도면작성 위주의 내용으로 구성을 하였으며 실무에서도 사용 가능하도록 주요 핵심 명령어들에 대한 상세한 해설과 실습 위주로 기술하고 있을뿐만 아니라 기 Source: [도서] 오토캐드 기계설계제도 테크니컬 가이드북