No Image

USN-4358-1: libexif vulnerabilities

2020-05-13 KENNETH 0

USN-4358-1: libexif vulnerabilities libexif vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 20.04 LTS Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary Several security issues were fixed in libexif. Software Description libexif – library to parse EXIF files Details It was discovered that libexif incorrectly handled certain tags. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-20030) It was discovered that libexif incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash. (CVE-2020-12767) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS libexif12 – 0.6.21-6ubuntu0.1 Ubuntu 19.10 libexif12 – 0.6.21-5.1ubuntu0.2 Ubuntu 18.04 LTS libexif12 – 0.6.21-4ubuntu0.2 Ubuntu 16.04 LTS libexif12 – 0.6.21-2ubuntu0.2 Ubuntu 14.04 ESM libexif12 – 0.6.21-1ubuntu1+esm2 [ more… ]

No Image

USN-4357-1: IPRoute vulnerability

2020-05-13 KENNETH 0

USN-4357-1: IPRoute vulnerability iproute2 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Summary IPRoute could be made to execute arbitrary code if it received a specially crafted input. Software Description iproute2 – networking and traffic control tools Details It was discovered that IPRoute incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS iproute2 – 4.15.0-2ubuntu1.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-20795 Source: USN-4357-1: IPRoute vulnerability

No Image

USN-3911-2: file regression

2020-05-13 KENNETH 0

USN-3911-2: file regression file regression A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary USN-3911-1 introduced a regression in file. Software Description file – Tool to determine file types Details USN-3911-1 fixed vulnerabilities in file. One of the backported security fixes introduced a regression that caused the interpreter string to be truncated. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that file incorrectly handled certain malformed ELF files. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS file – 1:5.32-2ubuntu0.4 libmagic1 – 1:5.32-2ubuntu0.4 Ubuntu 16.04 LTS file – 1:5.25-2ubuntu1.4 libmagic1 – 1:5.25-2ubuntu1.4 To update your system, [ more… ]

No Image

USN-4356-1: Squid vulnerabilities

2020-05-13 KENNETH 0

USN-4356-1: Squid vulnerabilities squid, squid3 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 20.04 LTS Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Squid. Software Description squid – Web proxy cache server squid3 – Web proxy cache server Details Jeriko One discovered that Squid incorrectly handled certain Edge Side Includes (ESI) responses. A malicious remote server could cause Squid to crash, possibly poison the cache, or possibly execute arbitrary code. (CVE-2019-12519, CVE-2019-12521) It was discovered that Squid incorrectly handled the hostname parameter to cachemgr.cgi when certain browsers are used. A remote attacker could possibly use this issue to inject HTML or invalid characters in the hostname parameter. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 19.10. (CVE-2019-18860) Clément Berthaux and Florian Guilbert discovered that [ more… ]

AWS Graviton2 기반 Amazon EC2 M6g 인스턴스 정식 출시

2020-05-13 KENNETH 0

AWS Graviton2 기반 Amazon EC2 M6g 인스턴스 정식 출시 오늘부터 AWS의 첫 번째 6세대 Amazon Elastic Compute Cloud(EC2) 범용 인스턴스인 M6g를 사용할 수 있습니다. “g”는 64비트 Arm Neoverse N1 코어를 사용하여 AWS( 및 Amazon 회사 Annapurna Labs)가 설계한 차세대 Arm 기반 칩인 “Graviton2“를 나타냅니다. 이러한 프로세서는 상시 실행되는 256비트 DRAM 암호화를 지원합니다. 여기에는 1세대 Graviton에 비해 부동 소수점 성능을 두 배로 늘리는 듀얼 SIMD 장치도 포함되어 있으며 기계 학습 추론 워크로드를 가속화하기 위해 int8/fp16 명령을 지원합니다. 자세한 내용은 AnandTech에서 게시한 이 전체 리뷰를 읽어보시기 바랍니다. M6g 인스턴스는 1, 2, 4, 8, 16, 32, 48 및 64 vCPU의 8개 크기 또는 베어 메탈 인스턴스로 사용할 수 있습니다. 이러한 인스턴스는 최대 256GiB의 메모리, 25Gbps의 네트워크 성능 및 19Gbps의 EBS 대역폭을 사용한 구성을 지원합니다. 이러한 인스턴스는 전용 하드웨어와 경량 하이퍼바이저의 조합인 AWS Nitro System을 기반으로 합니다. 일반적으로 x86-64 아키텍처에 배포된 오픈 소스 애플리케이션 [ more… ]