No Image

USN-3529-1: Thunderbird vulnerabilities

2018-01-30 KENNETH 0

USN-3529-1: Thunderbird vulnerabilities Ubuntu Security Notice USN-3529-1 29th January, 2018 thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Thunderbird. Software description thunderbird – Mozilla Open Source mail and newsgroup client Details It was discovered that a From address encoded with a null character iscut off in the message header display. An attacker could potentiallyexploit this to spoof the sender address. (CVE-2017-7829) It was discovered that it is possible to execute JavaScript in RSS feedsin some circumstances. If a user were tricked in to opening a speciallycrafted RSS feed, an attacker could potentially exploit this incombination with another vulnerability, in order to cause unspecifiedproblems. (CVE-2017-7846) It was discovered that the RSS feed can leak local path names. If a userwere tricked [ more… ]

[도서] 드론, 그것이 궁금하다

2018-01-30 KENNETH 0

[도서] 드론, 그것이 궁금하다 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]드론, 그것이 궁금하다 비피기술거래 저 | 비피기술거래 | 2018년 02월 판매가 54,000원 (10%할인) | YES포인트 3,000원(5%지급) Source: [도서] 드론, 그것이 궁금하다

No Image

USN-3549-1: Linux kernel (KVM) vulnerabilities

2018-01-30 KENNETH 0

USN-3549-1: Linux kernel (KVM) vulnerabilities Ubuntu Security Notice USN-3549-1 29th January, 2018 linux-kvm vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-kvm – Linux kernel for cloud environments Details Jann Horn discovered that microprocessors utilizing speculativeexecution and branch prediction may allow unauthorized memoryreads via sidechannel attacks. This flaw is known as Spectre. Alocal attacker could use this to expose sensitive information,including kernel memory. (CVE-2017-5715, CVE-2017-5753) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: linux-image-4.4.0-1017-kvm 4.4.0-1017.22 linux-image-kvm 4.4.0.1017.16 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. Please note that fully mitigating CVE-2017-5715 (Spectre Variant 2)requires corresponding processor microcode/firmware updates or,in virtual environments, hypervisor updates. On i386 and amd64architectures, the IBRS [ more… ]

No Image

RHEA-2018:0232-1: tzdata enhancement update

2018-01-30 KENNETH 0

RHEA-2018:0232-1: tzdata enhancement update Red Hat Enterprise Linux: Updated tzdata packages that add various enhancements are now available for Red Hat Enterprise Linux 5.9 Advanced Update Support, Red Hat Enterprise Linux 5 Extended Life Cycle Support, Red Hat Enterprise Linux 6.2 Advanced Update Support, Red Hat Enterprise Linux 6.4 Advanced Update Support, Red Hat Enterprise Linux 6.5 Advanced Update Support, Red Hat Enterprise Linux 6.6 Advanced Update Support, Red Hat Enterprise Linux 6.6 Telco Extended Update Support, Red Hat Enterprise Linux 6.7 Extended Update Support, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7.2 Advanced Update Support, Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions, Red Hat Enterprise Linux 7.2 Telco Extended Update Support, Red Hat Enterprise Linux 7.3 Extended Update Support, and Red Hat Enterprise Linux 7. Source: RHEA-2018:0232-1: tzdata enhancement update

No Image

Dynamic A/B Testing with NGINX Plus

2018-01-30 KENNETH 0

Dynamic A/B Testing with NGINX Plus The key-value store feature was introduced in NGINX Plus R13 for HTTP traffic and extended to Stream traffic in NGINX Plus R14. This feature provides an API to dynamically maintain values that can be used as part of the NGINX Plus configuration, without requiring a reload of the configuration. There are many possible use cases for this feature and I have no doubt that our customers will find a variety of ways to take advantage it. This blog post describes one use case, dynamically altering how the split_clients module is used to do A/B testing. The Key-Value Store The NGINX Plus API can be used to maintain a set of key-value pairs that can be accessed at runtime by NGINX Plus. For example, let’s look at the use case where you want to keep [ more… ]