No Image

USN-4557-1: Tomcat vulnerabilities

2020-09-30 KENNETH 0

USN-4557-1: Tomcat vulnerabilities It was discovered that the Tomcat realm implementations incorrectly handled passwords when a username didn’t exist. A remote attacker could possibly use this issue to enumerate usernames. (CVE-2016-0762) Alvaro Munoz and Alexander Mirosh discovered that Tomcat incorrectly limited use of a certain utility method. A malicious application could possibly use this to bypass Security Manager restrictions. (CVE-2016-5018) It was discovered that Tomcat incorrectly controlled reading system properties. A malicious application could possibly use this to bypass Security Manager restrictions. (CVE-2016-6794) It was discovered that Tomcat incorrectly controlled certain configuration parameters. A malicious application could possibly use this to bypass Security Manager restrictions. (CVE-2016-6796) It was discovered that Tomcat incorrectly limited access to global JNDI resources. A malicious application could use this to access any global JNDI resource without an explicit ResourceLink. (CVE-2016-6797) Regis Leroy discovered that Tomcat [ more… ]

Diagnostic Logging with the NGINX JavaScript Module

2020-09-30 KENNETH 0

Diagnostic Logging with the NGINX JavaScript Module Troubleshooting in Production Without Tuning the Error Log Editor – This blog is one of several that discuss logging with NGINX and NGINX Plus. Please also see: Application Tracing with NGINX and NGINX Plus Sampling Requests with NGINX Conditional Logging It’s also one of many blogs about use cases for the NGINX JavaScript module. For the complete list, see Introduction to the NGINX JavaScript Module. NGINX helps organizations of all sizes to run their mission‑critical websites, applications, and APIs. Regardless of your scale and choice of deployment infrastructure, running in production is not easy. In this article we talk about just one of the hard things about a production deployment – logging. More specifically, we discuss the balancing act of collecting the right amount of detailed logs for troubleshooting without being swamped with unnecessary data. [ more… ]

No Image

USN-4556-1: netqmail vulnerabilities

2020-09-30 KENNETH 0

USN-4556-1: netqmail vulnerabilities It was discovered that netqmail did not properly handle certain input. Both remote and local attackers could use this vulnerability to cause netqmail to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514, CVE-2005-1515) It was discovered that netqmail did not properly handle certain input when validating email addresses. An attacker could use this to bypass email address validation. (CVE-2020-3811) It was discovered that netqmail did not properly handle certain input when validating email addresses. An attacker could use this vulnerability to cause netqmail to disclose sensitive information. (CVE-2020-3812) Source: USN-4556-1: netqmail vulnerabilities

[도서] 파이썬을 활용한 지리공간 분석 마스터하기

2020-09-29 KENNETH 0

[도서] 파이썬을 활용한 지리공간 분석 마스터하기 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]파이썬을 활용한 지리공간 분석 마스터하기 폴 크릭커드,에릭 반 리스,사일러스 톰스 공저/김동호 역 | 에이콘출판사 | 2020년 10월 판매가 36,000원 (10%할인) | YES포인트 2,000원(5%지급) 사용하기 쉽고 다양한 분야에서 인기 있는 언어인 파이썬을 사용해 값비싼 도구 없이 전문적인 GIS 프로세싱을 배울 수 있다. 또한 지리공간분석, 통계분석, 데이터관리를 위해 준비된 다양한 파이썬 라이브러리 사 Source: [도서] 파이썬을 활용한 지리공간 분석 마스터하기

No Image

USN-4547-2: SSVNC vulnerabilities

2020-09-29 KENNETH 0

USN-4547-2: SSVNC vulnerabilities It was discovered that the LibVNCClient vendored in SSVNC incorrectly handled certain packet lengths. A remote attacker could possibly use this issue to obtain sensitive information, cause a denial of service, or execute arbitrary code. (CVE-2018-20020, CVE-2018-20021, CVE-2018-20022, CVE-2018-2024) Source: USN-4547-2: SSVNC vulnerabilities