No Image

USN-6027-1: Linux kernel vulnerabilities

2023-04-19 KENNETH 0

USN-6027-1: Linux kernel vulnerabilities It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-1281) Jiasheng Jiang discovered that the HSA Linux kernel driver for AMD Radeon GPU devices did not properly validate memory allocation in certain situations, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3108) It was discovered that the infrared transceiver USB driver did not properly handle USB control messages. A local attacker with physical access could plug in a specially crafted USB device to cause a denial of service (memory exhaustion). (CVE-2022-3903) Haowei Yan discovered that a race condition existed in the Layer 2 Tunneling Protocol (L2TP) [ more… ]

No Image

USN-6026-1: Vim vulnerabilities

2023-04-19 KENNETH 0

USN-6026-1: Vim vulnerabilities It was discovered that Vim was incorrectly processing Vim buffers. An attacker could possibly use this issue to perform illegal memory access and expose sensitive information. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-4166) It was discovered that Vim was using freed memory when dealing with regular expressions inside a visual selection. If a user were tricked into opening a specially crafted file, an attacker could crash the application, leading to a denial of service, or possibly achieve code execution with user privileges. This issue only affected Ubuntu 14.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-4192) It was discovered that Vim was incorrectly handling virtual column position operations, which could result in an out-of-bounds read. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 14.04 ESM, Ubuntu 18.04 [ more… ]

AWS 주간 소식 모음 – 생성 AI를 위한 Amazon Bedrock 및 Titan 모델 미리보기 공개 등

2023-04-19 KENNETH 0

AWS 주간 소식 모음 – 생성 AI를 위한 Amazon Bedrock 및 Titan 모델 미리보기 공개 등 이번 주 주간 소식 모음의 게시물의 제목을 “AWS AI/ML 소식 모음”이라고 붙일 수 있을 정도였습니다. 지난 주에 저희는 AWS에서 생성 AI (Generative AI)를 구축하기 위한 몇 가지의 새로운 혁신과 도구를 발표했습니다. 바로 시작해 봅시다. 지난 주 출시 사항 다음은 지난 주에 주목을 끌었던 몇 가지 출시 사항입니다. Amazon Bedrock 및 Amazon Titan 모델 발표 – Amazon Bedrock은 인프라를 관리하지 않고도 API를 통해 기반 모델을 사용하여 제너레이티브 AI 애플리케이션 개발을 가속화하는 새로운 서비스입니다. 사용자는 선도적인 AI 스타트업과 Amazon이 구축한 다양한 기반 모델 중에서 선택할 수 있습니다. 새로운 Amazon Titan 기반 모델은 대규모 데이터 세트를 사전 학습한 강력한 범용 모델입니다. 대용량 데이터에 주석을 달지 않고 그대로 사용하거나 비공개로 사용하여, 특정 작업에 대한 사용자 자체 데이터로 사용자 지정할 수 있습니다. Amazon Bedrock은 현재 제한되어 있는 프리뷰 버전입니다. [ more… ]

No Image

USN-6025-1: Linux kernel vulnerabilities

2023-04-19 KENNETH 0

USN-6025-1: Linux kernel vulnerabilities It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-1281) It was discovered that the OverlayFS implementation in the Linux kernel did not properly handle copy up operation in some conditions. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-0386) Haowei Yan discovered that a race condition existed in the Layer 2 Tunneling Protocol (L2TP) implementation in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-4129) It was discovered that the network queuing discipline implementation in the Linux kernel contained a null pointer dereference in some situations. A local attacker could use this to cause a [ more… ]

No Image

USN-6024-1: Linux kernel vulnerabilities

2023-04-19 KENNETH 0

USN-6024-1: Linux kernel vulnerabilities It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-1281) Lin Ma discovered a race condition in the io_uring subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-0468) It was discovered that a use-after-free vulnerability existed in the SGI GRU driver in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3424) Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not properly perform reference counting in some situations, leading to a use- [ more… ]