No Image

USN-4617-1: SPICE vdagent vulnerabilities

2020-11-04 KENNETH 0

USN-4617-1: SPICE vdagent vulnerabilities Matthias Gerstner discovered that SPICE vdagent incorrectly handled the active_xfers hash table. A local attacker could possibly use this issue to cause SPICE vdagent to consume memory, resulting in a denial of service. (CVE-2020-25650) Matthias Gerstner discovered that SPICE vdagent incorrectly handled the active_xfers hash table. A local attacker could possibly use this issue to cause SPICE vdagent to consume memory, resulting in a denial of service, or obtain sensitive file contents. (CVE-2020-25651) Matthias Gerstner discovered that SPICE vdagent incorrectly handled a large number of client connections. A local attacker could possibly use this issue to cause SPICE vdagent to consume resources, resulting in a denial of service. (CVE-2020-25652) Matthias Gerstner discovered that SPICE vdagent incorrectly handled client connections. A local attacker could possibly use this issue to obtain sensitive information, paste clipboard contents, and transfer [ more… ]

No Image

Congrats to the Winners of the NGINX for Good Hackathon

2020-11-04 KENNETH 0

Congrats to the Winners of the NGINX for Good Hackathon At NGINX, we’ve always been focused on serving and engaging with the open source community where we have our roots. Now more than ever, it’s incredibly important to give back to our communities, locally as well as globally. We’ve been humbled by the NGINX community’s enthusiastic willingness to join us in that effort. As part of our virtual NGINX Sprint conference in September, developers from around the world gathered (virtually of course!) for the first NGINX for Good Hackathon. We invited them to use NGINX Open Source and NGINX Unit to build an app or website that helps people impacted by the COVID‑19 pandemic or other social issues, whether at a local level or around the world. A number of developers from around the world – including India, Spain, Turkey, and the United [ more… ]

No Image

MySQL Audit Data Consolidation – Made Simple

2020-11-04 KENNETH 0

MySQL Audit Data Consolidation – Made Simple In this blog, I am going to demonstrate how to create your own consolidated audit log archive across many mysql instances. In a followup I’ll show how to extend this example by creating a simple hash chain on that archive – so you can prove whether or not its been modified or tainted in any way and if so where.… Facebook Twitter LinkedIn Source: MySQL Audit Data Consolidation – Made Simple

No Image

USN-4615-1: Yerase's TNEF vulnerabilities

2020-11-04 KENNETH 0

USN-4615-1: Yerase's TNEF vulnerabilities It was discovered that Yerase’s TNEF had null pointer dereferences, infinite loop, buffer overflow, out of bounds reads, directory traversal issues and other vulnerabilities. An attacker could use those issues to cause a crash and consequently a denial of service. (CVE-2017-6298, CVE-2017-6299, CVE-2017-6300, CVE-2017-6301, CVE-2017-6302, CVE-2017-6303, CVE-2017-6304, CVE-2017-6305, CVE-2017-6306, CVE-2017-6800, CVE-2017-6801, CVE-2017-6802) Source: USN-4615-1: Yerase's TNEF vulnerabilities

No Image

USN-4616-1: AccountsService vulnerabilities

2020-11-04 KENNETH 0

USN-4616-1: AccountsService vulnerabilities Kevin Backhouse discovered that AccountsService incorrectly dropped privileges. A local user could possibly use this issue to cause AccountsService to crash or hang, resulting in a denial of service. (CVE-2020-16126) Kevin Backhouse discovered that AccountsService incorrectly handled reading .pam_environment files. A local user could possibly use this issue to cause AccountsService to crash or hang, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 20.10. (CVE-2020-16127) Matthias Gerstner discovered that AccountsService incorrectly handled certain path checks. A local attacker could possibly use this issue to read arbitrary files. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-14036) Source: USN-4616-1: AccountsService vulnerabilities