No Image

USN-5889-1: ZoneMinder vulnerabilities

2023-02-27 KENNETH 0

USN-5889-1: ZoneMinder vulnerabilities It was discovered that ZoneMinder was not properly sanitizing URL parameters for certain views. An attacker could possibly use this issue to perform a cross-site scripting (XSS) attack. This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2019-6777) It was discovered that ZoneMinder was not properly sanitizing stored user input later printed to the user in certain views. An attacker could possibly use this issue to perform a cross-site scripting (XSS) attack. This issue was only fixed in Ubuntu 16.04 ESM. (CVE-2019-6990, CVE-2019-6992) It was discovered that ZoneMinder was not properly limiting data size and not properly performing bound checks when processing username and password data, which could lead to a stack buffer overflow. An attacker could possibly use this issue to bypass authentication, cause a denial of service or execute arbitrary code. This issue was only [ more… ]

No Image

USN-5887-1: ClamAV vulnerabilities

2023-02-27 KENNETH 0

USN-5887-1: ClamAV vulnerabilities Simon Scannell discovered that ClamAV incorrectly handled parsing HFS+ files. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2023-20032) Simon Scannell discovered that ClamAV incorrectly handled parsing DMG files. A remote attacker could possibly use this issue to expose sensitive information. (CVE-2023-20052) Source: USN-5887-1: ClamAV vulnerabilities

No Image

USN-5886-1: Intel Microcode vulnerabilities

2023-02-27 KENNETH 0

USN-5886-1: Intel Microcode vulnerabilities Erik C. Bjorge discovered that some Intel(R) Atom and Intel Xeon Scalable Processors did not properly implement access controls for out-of-band management. This may allow a privileged network-adjacent user to potentially escalate privileges. (CVE-2022-21216) Cfir Cohen, Erdem Aktas, Felix Wilhelm, James Forshaw, Josh Eads, Nagaraju Kodalapura Nagabhushana Rao, Przemyslaw Duda, Liron Shacham and Ron Anderson discovered that some Intel(R) Xeon(R) Processors used incorrect default permissions in some memory controller configurations when using Intel(R) Software Guard Extensions. This may allow a privileged local user to potentially escalate privileges. (CVE-2022-33196) It was discovered that some 3rd Generation Intel(R) Xeon(R) Scalable Processors did not properly calculate microkey keying. This may allow a privileged local user to potentially disclose information. (CVE-2022-33972) Joseph Nuzman discovered that some Intel(R) Processors when using Intel(R) Software Guard Extensions did not properly isolate shared resources. [ more… ]

No Image

USN-5885-1: APR vulnerability

2023-02-27 KENNETH 0

USN-5885-1: APR vulnerability Ronald Crane discovered integer overflow vulnerabilities in the Apache Portable Runtime (APR) that could potentially result in memory corruption. A remote attacker could possibly use these issues to cause a denial of service or execute arbitary code. Source: USN-5885-1: APR vulnerability

[도서] 소프트웨어 장인 정신 이야기

2023-02-27 KENNETH 0

[도서] 소프트웨어 장인 정신 이야기 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]소프트웨어 장인 정신 이야기 로버트 C. 마틴 저/정지용 역 | 인사이트(insight) | 2023년 03월 판매가 28,800원 (10%할인) | YES포인트 1,600원(5%지급) 이벤트 : 3월의 굿즈 : 빨강머리 앤 3단 우산/타포린백/물병파우치/미니 토트백/마티스 접시&테이블매트 세트 이벤트 : 3월의 굿즈 : 산리오캐릭터즈 타포린백/물병파우치/3단우산/미니 토트백/마티스 접시&테이블매트 세트 “세상을 떠받치는 장인으로 살고 싶은 개발자를 위해” 첨단 인력이 가득할 것 같은 이미지와는 사뭇 달리 소프트웨어 산업은 ‘숙련자 부족’이라는 문제에 자주 시달려 왔다. 상대적으로 짧은 산업의 역사, 거 Source: [도서] 소프트웨어 장인 정신 이야기