No Image

USN-6102-1: xmldom vulnerabilities

2023-05-24 KENNETH 0

USN-6102-1: xmldom vulnerabilities It was discovered that xmldom incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause unexpected syntactic changes during XML processing. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-21366) It was discovered that xmldom incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-37616, CVE-2022-39353) Source: USN-6102-1: xmldom vulnerabilities

No Image

USN-6074-3: Firefox regressions

2023-05-24 KENNETH 0

USN-6074-3: Firefox regressions USN-6074-1 fixed vulnerabilities and USN-6074-2 fixed minor regressions in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-32205, CVE-2023-32207, CVE-2023-32210, CVE-2023-32211, CVE-2023-32212, CVE-2023-32213, CVE-2023-32215, CVE-2023-32216) Irvan Kurniawan discovered that Firefox did not properly manage memory when using RLBox Expat driver. An attacker could potentially exploits this issue to cause a denial of service. (CVE-2023-32206) Anne van Kesteren discovered that Firefox did not properly validate the import() call in service workers. An attacker could potentially exploits this to obtain sensitive information. (CVE-2023-32208) Sam Ezeh discovered that Firefox [ more… ]

No Image

USN-6101-1: GNU binutils vulnerabilities

2023-05-24 KENNETH 0

USN-6101-1: GNU binutils vulnerabilities It was discovered that GNU binutils incorrectly handled certain DWARF files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. This issue only affected Ubuntu 22.10. (CVE-2023-1579) It was discovered that GNU binutils did not properly verify the version definitions in zer0-lengthverdef table. An attacker could possibly use this issue to cause a crash or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972) It was discovered that GNU binutils did not properly validate the size of length parameter in vms-alpha. An attacker could possibly use this issue to cause a crash or access sensitive information. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2023-25584) It was discovered that GNU binutils did not properly initialized [ more… ]

No Image

제1회 Kakao Tech Meet 후기

2023-05-24 KENNETH 0

제1회 Kakao Tech Meet 후기 2023년 5월 11일 목요일, 카카오 판교아지트 지하 1층 세미나실에서는 첫 번째 ‘Kakao Tech Meet’을 성황리에 마무리했습니다.  이번 세미나의 주제는 “AI(인공지능)”이었는데요. 생성형 AI를 활용한 챗봇 개발 사례 및 서비스를 쉽게 개발하는 방법, 카카오 개발자의 일하는 방식의 변화에 대해 3명의 카카오 크루가 발표해 주셨고, 관련 내용을 함께 이야기하는 패널 토론 시간도 가졌습니다.  다양한 배경을 가진 발표자와 참가자들이 […] Source: 제1회 Kakao Tech Meet 후기

No Image

USN-6100-1: HTML::StripScripts vulnerability

2023-05-24 KENNETH 0

USN-6100-1: HTML::StripScripts vulnerability It was discovered that HTML::StripScripts does not properly parse HTML content with certain style attributes. A remote attacker could use this issue to cause a regular expression denial of service (ReDoS). Source: USN-6100-1: HTML::StripScripts vulnerability