No Image

USN-5806-3: Ruby vulnerability

2023-03-21 KENNETH 0

USN-5806-3: Ruby vulnerability USN-5806-1 fixed vulnerabilities in Ruby. This update fixes the problem for Ubuntu 20.04 LTS. Original advisory details: Hiroshi Tokumaru discovered that Ruby did not properly handle certain user input for applications which generate HTTP responses using cgi gem. An attacker could possibly use this issue to maliciously modify the response a user would receive from a vulnerable application. Source: USN-5806-3: Ruby vulnerability

Managing NGINX Configuration at Scale with Instance Manager

2023-03-21 KENNETH 0

Managing NGINX Configuration at Scale with Instance Manager Since releasing NGINX Instance Manager in early 2021, we have continually added functionality based on feedback from our users about their top priorities and pain points. Instance Manager is now the core module of NGINX Management Suite, our collection of management‑plane modules which make it easier to manage and monitor NGINX at scale. After two years of focused work, today’s Instance Manager is, quite simply, better than ever. Some of the most notable recent enhancements to Instance Manager are: Remote configuration and configuration groups to help you scale Robust and granular role‑based access control (RBAC) to empower multiple teams to manage their deployments Improved monitoring options that offer more flexibility and deeper insight Enhanced security with capabilities for monitoring and managing NGINX App Protect WAF In this post we focus on the enhancements [ more… ]

[도서] 성공하는 상세페이지의 9+1 전략

2023-03-20 KENNETH 0

[도서] 성공하는 상세페이지의 9+1 전략 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]성공하는 상세페이지의 9+1 전략 나재영 저 | e비즈북스 | 2023년 03월 판매가 16,200원 (10%할인) | YES포인트 900원(5%지급) 잘 팔리는 상세페이지에 숨어 있는 디테일을 밝힌다! 유입부터 구매까지 고객을 사로잡는 상세페이지 9+1 전략! 상세페이지는 그저 경쟁자를 벤치마킹해서 멋지고 예쁘게만 만들면 된다고 생각하는 온라인 셀러 Source: [도서] 성공하는 상세페이지의 9+1 전략

No Image

USN-5964-1: curl vulnerabilities

2023-03-20 KENNETH 0

USN-5964-1: curl vulnerabilities Harry Sintonen discovered that curl incorrectly handled certain TELNET connection options. Due to lack of proper input scrubbing, curl could pass on user name and telnet options to the server as provided, contrary to expectations. (CVE-2023-27533) Harry Sintonen discovered that curl incorrectly handled special tilde characters when used with SFTP paths. A remote attacker could possibly use this issue to circumvent filtering. (CVE-2023-27534) Harry Sintonen discovered that curl incorrectly reused certain FTP connections. This could lead to the wrong credentials being reused, contrary to expectations. (CVE-2023-27535) Harry Sintonen discovered that curl incorrectly reused connections when the GSS delegation option had been changed. This could lead to the option being reused, contrary to expectations. (CVE-2023-27536) Harry Sintonen discovered that curl incorrectly reused certain SSH connections. This could lead to the wrong credentials being reused, contrary to expectations. (CVE-2023-27538) [ more… ]

No Image

USN-5963-1: Vim vulnerabilities

2023-03-20 KENNETH 0

USN-5963-1: Vim vulnerabilities It was discovered that Vim was not properly performing memory management operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-47024, CVE-2023-0049, CVE-2023-0054, CVE-2023-0288, CVE-2023-0433) It was discovered that Vim was not properly performing memory management operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2023-0051) It was discovered that Vim was not properly performing memory management operations. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2023-1170, CVE-2023-1175) It was discovered that Vim was not properly performing memory management operations. An attacker could possibly [ more… ]