No Image

USN-5942-1: Apache HTTP Server vulnerabilities

2023-03-09 KENNETH 0

USN-5942-1: Apache HTTP Server vulnerabilities Lars Krapf discovered that the Apache HTTP Server mod_proxy module incorrectly handled certain configurations. A remote attacker could possibly use this issue to perform an HTTP Request Smuggling attack. (CVE-2023-25690) Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server mod_proxy_uwsgi module incorrectly handled certain special characters. A remote attacker could possibly use this issue to perform an HTTP Request Smuggling attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2023-27522) Source: USN-5942-1: Apache HTTP Server vulnerabilities

No Image

USN-5941-1: Linux kernel (KVM) vulnerabilities

2023-03-09 KENNETH 0

USN-5941-1: Linux kernel (KVM) vulnerabilities It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel did not properly handle VLAN headers in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0179) It was discovered that the NVMe driver in the Linux kernel did not properly handle reset events in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3169) Maxim Levitsky discovered that the KVM nested virtualization (SVM) [ more… ]

No Image

USN-5940-1: Linux kernel (Raspberry Pi) vulnerabilities

2023-03-09 KENNETH 0

USN-5940-1: Linux kernel (Raspberry Pi) vulnerabilities It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) It was discovered that the NVMe driver in the Linux kernel did not properly handle reset events in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3169) It was discovered that a use-after-free vulnerability existed in the SGI GRU driver in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3424) Gwangun Jung discovered a race condition in the IPv4 implementation [ more… ]

AWS Application Composer 정식 출시 – 시각적 도구로 빠르게 서버리스 앱 구성하기

2023-03-09 KENNETH 0

AWS Application Composer 정식 출시 – 시각적 도구로 빠르게 서버리스 앱 구성하기 AWS re:Invent 2022에서는 배포가 가능한 코드형 인프라(IaC)를 기반으로 AWS 서비스에서 서버리스 애플리케이션을 구성할 수 있는 시각적 빌더인 AWS Application Composer의 평가판을 살펴보았습니다. 기조 연설에서 Amazon.com의 CTO인 Werner Vogels는 이렇게 말했습니다. 이전에 서버리스를 사용해본 적이 없는 개발자들은 어디서부터 시작해야 할지 어떻게 알 수 있을까요? 그들에겐 어떤 서비스가 필요하며 어떻게 협업할까요? AWS는 이러한 과제를 더 수월하게 처리하고 싶었습니다. AWS Application Composer는 서버리스 애플리케이션의 설계, 구성, 빌드를 간소화하고 가속화합니다. 평가판 이용 기간 동안 고객들로부터 많은 관심과 좋은 피드백을 받았습니다. 오늘 저는 고객 피드백을 바탕으로 새로운 개선 사항이 반영된 AWS Application Composer의 정식 출시를 발표하게 되어 기쁩니다. 빠르게 기능을 검토하고 몇 가지 개선 사항을 소개하고자 합니다. AWS Application Composer 소개 AWS Application Composer를 시작하려면 AWS Management Console에서 Open demo(데모 열기)를 선택하세요. 이 데모에서는 Amazon API Gateway, AWS Lambda, Amazon DynamoDB 리소스를 활용한 [ more… ]

No Image

USN-5939-1: Linux kernel (GCP) vulnerabilities

2023-03-09 KENNETH 0

USN-5939-1: Linux kernel (GCP) vulnerabilities It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) It was discovered that the NVMe driver in the Linux kernel did not properly handle reset events in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3169) It was discovered that a use-after-free vulnerability existed in the SGI GRU driver in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3424) Gwangun Jung discovered a race condition in the IPv4 implementation in [ more… ]