No Image

USN-5898-1: OpenJDK vulnerabilities

2023-02-28 KENNETH 0

USN-5898-1: OpenJDK vulnerabilities It was discovered that the Serialization component of OpenJDK did not properly handle the deserialization of some CORBA objects. An attacker could possibly use this to bypass Java sandbox restrictions. (CVE-2023-21830) Markus Loewe discovered that the Java Sound subsystem in OpenJDK did not properly validate the origin of a Soundbank. An attacker could use this to specially craft an untrusted Java application or applet that could load a Soundbank from an attacker controlled remote URL. (CVE-2023-21843) Source: USN-5898-1: OpenJDK vulnerabilities

No Image

USN-5897-1: OpenJDK vulnerabilities

2023-02-28 KENNETH 0

USN-5897-1: OpenJDK vulnerabilities Juraj Somorovsky, Marcel Maehren, Nurullah Erinola, and Robert Merget discovered that the DTLS implementation in the JSSE subsystem of OpenJDK did not properly restrict handshake initiation requests from clients. A remote attacker could possibly use this to cause a denial of service. (CVE-2023-21835) Markus Loewe discovered that the Java Sound subsystem in OpenJDK did not properly validate the origin of a Soundbank. An attacker could use this to specially craft an untrusted Java application or applet that could load a Soundbank from an attacker controlled remote URL. (CVE-2023-21843) Source: USN-5897-1: OpenJDK vulnerabilities

[도서] 머신러닝 for 키즈와 함께하는 AI 인공지능 실습

2023-02-28 KENNETH 0

[도서] 머신러닝 for 키즈와 함께하는 AI 인공지능 실습 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]머신러닝 for 키즈와 함께하는 AI 인공지능 실습 박영희 저 | 광문각출판미디어 | 2023년 03월 판매가 19,000원 (0%할인) | YES포인트 0원(0%지급) 본 교재는 인공지능 분야의 다양한 주제를 다루고 있으며, 예제와 실습 문제를 통해 학습자들이 직접 코드를 작성하고 테스트해 볼 수 있도록 구성되었다. 이 교재를 통해, 학생들은 머신러닝 for 키즈를 이용하여 Source: [도서] 머신러닝 for 키즈와 함께하는 AI 인공지능 실습

No Image

USN-5896-1: Rack vulnerabilities

2023-02-28 KENNETH 0

USN-5896-1: Rack vulnerabilities It was discovered that Rack was not properly parsing data when processing multipart POST requests. If a user or automated system were tricked into sending a specially crafted multipart POST request to an application using Rack, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-30122) It was discovered that Rack was not properly escaping untrusted data when performing logging operations, which could cause shell escaped sequences to be written to a terminal. If a user or automated system were tricked into sending a specially crafted request to an application using Rack, a remote attacker could possibly use this issue to execute arbitrary code in the machine running the application. (CVE-2022-30123) Source: USN-5896-1: Rack vulnerabilities

No Image

USN-5888-1: Python vulnerabilities

2023-02-28 KENNETH 0

USN-5888-1: Python vulnerabilities It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2015-20107) Hamza Avvan discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2021-28861) It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2022-37454, CVE-2022-42919) It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, [ more… ]