Get Me to the Cluster…with BGP?

2023-03-01 KENNETH 0

Get Me to the Cluster…with BGP? Creating and managing a robust Kubernetes environment demands smooth collaboration between your Network and Application teams. But their priorities and working styles are usually quite different, leading to conflicts with potentially serious consequences – slow app development, delayed deployment, and even network downtime. Only the success of both teams, working towards a common goal, can ensure today’s modern applications are delivered on time with proper security and scalability. So, how do you leverage the skills and expertise of each team, while helping them work in tandem? In our whitepaper Get Me to the Cluster, we detail a solution for enabling external access to Kubernetes services that enables Network and Application teams to combine their strengths without conflict. How to Expose Apps in Kubernetes Clusters The solution works specifically for Kubernetes clusters hosted on premises, with [ more… ]

No Image

USN-5903-1: lighttpd vulnerabilities

2023-03-01 KENNETH 0

USN-5903-1: lighttpd vulnerabilities It was discovered that lighttpd incorrectly handled certain inputs, which could result in a stack buffer overflow. A remote attacker could possibly use this issue to cause a denial of service (DoS). (CVE-2022-22707, CVE-2022-41556) Source: USN-5903-1: lighttpd vulnerabilities

No Image

USN-5638-4: Expat vulnerabilities

2023-03-01 KENNETH 0

USN-5638-4: Expat vulnerabilities USN-5638-1 fixed several vulnerabilities in Expat. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Rhodri James discovered that Expat incorrectly handled memory when processing certain malformed XML files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. Source: USN-5638-4: Expat vulnerabilities

No Image

USN-5902-1: PHP vulnerabilities

2023-02-28 KENNETH 0

USN-5902-1: PHP vulnerabilities It was discovered that PHP incorrectly handled certain invalid Blowfish password hashes. An invalid password hash could possibly allow applications to accept any password as valid, contrary to expectations. (CVE-2023-0567) It was discovered that PHP incorrectly handled resolving long paths. A remote attacker could possibly use this issue to obtain or modify sensitive information. (CVE-2023-0568) It was discovered that PHP incorrectly handled a large number of parts in HTTP form uploads. A remote attacker could possibly use this issue to cause PHP to consume resources, leading to a denial of service. (CVE-2023-0662) Source: USN-5902-1: PHP vulnerabilities

No Image

USN-5821-3: pip regression

2023-02-28 KENNETH 0

USN-5821-3: pip regression USN-5821-1 fixed a vulnerability in wheel and pip. Unfortunately, it was missing a commit to fix it properly in pip. We apologize for the inconvenience. Original advisory details: Sebastian Chnelik discovered that wheel incorrectly handled certain file names when validated against a regex expression. An attacker could possibly use this issue to cause a denial of service. Source: USN-5821-3: pip regression