No Image

USN-4672-1: unzip vulnerabilities

2020-12-17 KENNETH 0

USN-4672-1: unzip vulnerabilities Rene Freingruber discovered that unzip incorrectly handled certain specially crafted password protected ZIP archives. If a user or automated system using unzip were tricked into opening a specially crafted zip file, an attacker could exploit this to cause a crash, resulting in a denial of service. (CVE-2018-1000035) Antonio Carista discovered that unzip incorrectly handled certain specially crafted ZIP archives. If a user or automated system using unzip were tricked into opening a specially crafted zip file, an attacker could exploit this to cause a crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. (CVE-2018-18384) It was discovered that unzip incorrectly handled certain specially crafted ZIP archives. If a user or automated system using unzip were tricked into opening a specially crafted zip file, an attacker could exploit this [ more… ]

No Image

USN-4671-1: Firefox vulnerabilities

2020-12-16 KENNETH 0

USN-4671-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass the CSS sanitizer, bypass security restrictions, spoof the URL bar, or execute arbitrary code. (CVE-2020-16042, CVE-2020-26971, CVE-2020-26972, CVE-2020-26793, CVE-2020-26974, CVE-2020-26976, CVE-2020-26978, CVE-2020-26979, CVE-2020-35113, CVE-2020-35114) It was discovered that the proxy.onRequest API did not catch view-source URLs. If a user were tricked in to installing an extension with the proxy permission and opening View Source, an attacker could potentially exploit this to obtain sensitive information. (CVE-2020-35111) Source: USN-4671-1: Firefox vulnerabilities

[도서] 다양한 예제로 배우는 Fusion360 (퓨전360) : 중급편

2020-12-16 KENNETH 0

[도서] 다양한 예제로 배우는 Fusion360 (퓨전360) : 중급편 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]다양한 예제로 배우는 Fusion360 (퓨전360) : 중급편 조성일 저 | 청담북스 | 2021년 01월 판매가 28,500원 (5%할인) | YES포인트 600원(2%지급) 『다양한 예제로 배우는 Fusion360 중급편』은 지난번 1권에서 모델링에 집중한 내용 이후의 조립품과 애니메이션 렌더링 도면에 대한 내용을 다루고 있다. Source: [도서] 다양한 예제로 배우는 Fusion360 (퓨전360) : 중급편

No Image

USN-4670-1: ImageMagick vulnerabilities

2020-12-16 KENNETH 0

USN-4670-1: ImageMagick vulnerabilities It was discovered that ImageMagick incorrectly handled certain specially crafted image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service or other unspecified impact. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.10. (CVE-2019-19948, CVE-2019-19949) It was discovered that ImageMagick incorrectly handled certain specially crafted image files. If a user or automated system using ImageMagick were tricked into opening a specially crafted image, an attacker could exploit this to cause a denial of service. (CVE-2020-27560) Source: USN-4670-1: ImageMagick vulnerabilities

Threat Visibility and Analytics with NGINX Controller App Security

2020-12-16 KENNETH 0

Threat Visibility and Analytics with NGINX Controller App Security Organizations at all different phases of the digital transformation journey are adopting DevOps practices to make app development and deployment more efficient. At the same time, one requirement remains paramount: apps must be protected from malicious traffic. In support of that goal, many organizations are applying a common DevOps practice – monitoring app performance after deployment for insights into required fixes or potential new features – to security as well. In particular, they’re using threat visibility and analytics tools that reveal what malicious traffic consists of and what part of the app it is targeting. Threat visibility enables security (SecOps) and development (AppDev) teams to monitor security compliance and assess changes to the threat surface of apps as new app versions get released. As with monitoring the performance of new app versions for [ more… ]