No Image

USN-5838-1: AdvanceCOMP vulnerabilities

2023-02-01 KENNETH 0

USN-5838-1: AdvanceCOMP vulnerabilities It was discovered that AdvanceCOMP did not properly manage memory while performing read operations on MNG file. If a user were tricked into opening a specially crafted MNG file, a remote attacker could possibly use this issue to cause AdvanceCOMP to crash, resulting in a denial of service. (CVE-2022-35014, CVE-2022-35017, CVE-2022-35018, CVE-2022-35019, CVE-2022-35020) It was discovered that AdvanceCOMP did not properly manage memory while performing read operations on ZIP file. If a user were tricked into opening a specially crafted ZIP file, a remote attacker could possibly use this issue to cause AdvanceCOMP to crash, resulting in a denial of service. (CVE-2022-35015, CVE-2022-35016) Source: USN-5838-1: AdvanceCOMP vulnerabilities

No Image

USN-5839-1: Apache HTTP Server vulnerabilities

2023-02-01 KENNETH 0

USN-5839-1: Apache HTTP Server vulnerabilities It was discovered that the Apache HTTP Server mod_dav module incorrectly handled certain If: request headers. A remote attacker could possibly use this issue to cause the server to crash, resulting in a denial of service. (CVE-2006-20001) ZeddYu_Lu discovered that the Apache HTTP Server mod_proxy_ajp module incorrectly interpreted certain HTTP Requests. A remote attacker could possibly use this issue to perform an HTTP Request Smuggling attack. (CVE-2022-36760) Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server mod_proxy module incorrectly truncated certain response headers. This may result in later headers not being interpreted by the client. (CVE-2022-37436) Source: USN-5839-1: Apache HTTP Server vulnerabilities

No Image

USN-5837-1: Django vulnerability

2023-02-01 KENNETH 0

USN-5837-1: Django vulnerability Nick Pope discovered that Django incorrectly handled certain Accept-Language headers. A remote attacker could possibly use this issue to cause Django to consume memory, leading to a denial of service. Source: USN-5837-1: Django vulnerability

No Image

USN-4781-2: Slurm vulnerabilities

2023-02-01 KENNETH 0

USN-4781-2: Slurm vulnerabilities USN-4781-1 fixed several vulnerabilities in Slurm. This update provides the corresponding updates for Ubuntu 14.04 ESM (CVE-2016-10030) and Ubuntu 16.04 ESM (CVE-2018-10995). Original advisory details: It was discovered that Slurm incorrectly handled certain messages between the daemon and the user. An attacker could possibly use this issue to assume control of an arbitrary file on the system. This issue only affected Ubuntu 16.04 ESM. (CVE-2016-10030) It was discovered that Slurm mishandled SPANK environment variables. An attacker could possibly use this issue to gain elevated privileges. This issue only affected Ubuntu 16.04 ESM. (CVE-2017-15566) It was discovered that Slurm mishandled certain SQL queries. A local attacker could use this issue to gain elevated privileges. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-7033) It was discovered that Slurm mishandled user names and [ more… ]

클라우드 활용 추진 조직(CCoE) 시작하기

2023-02-01 KENNETH 0

클라우드 활용 추진 조직(CCoE) 시작하기 최근 클라우드가 비즈니스에 미치는 경제적 가치를 찾아, 조직 전체로서 그 수혜를 누리기 위한 정책을 세우고 추진하는 팀을 만드는 고객이 적지 않습니다. 이러한 팀은 보통 「클라우드 활용 추진 조직」 , 「클라우드 CoE (Center of Excellence)」 또는 줄여서 「CCoE」 로 불립니다. 본 블로그에서는 CCoE의 필요성, CCoE가 원활히 기능하기 위한 환경조건, 그리고 CCoE에 임하는 마음가짐에 대해서 소개하고자 합니다. 본 블로그는 다음과 같은 분을 독자로 상정하였습니다. 아직 CCoE를 론칭해 본 경험은 없지만, CCoE에 대해 알고 싶거나 지금부터 CCoE를 고려하고 계신 분 CCoE를 이미 세운 고객으로, 관련 업무의 질을 높이거나 또는 업무의 폭을 넓히고 싶으신 분 CCoE 조직에 속해 있는 또는 유사한 역할을 수행하고 있는 구성원은 어떠한 사명감과 의지를 가지고 매일의 업무와 씨름하고 있을까요? AWS가 지금까지 지원해 온 많은 고객과의 대화에서 얻게된 핵심을 지금부터 소개해 드리겠습니다. 클라우드가 비즈니스에 미치는 경제적 가치 AWS Executive Insights에서 제시하고 있듯이, 클라우드 전환 (migration)으로 발생하는 [ more… ]