No Image

USN-5780-1: Linux kernel (OEM) vulnerabilities

2022-12-15 KENNETH 0

USN-5780-1: Linux kernel (OEM) vulnerabilities It was discovered that a memory leak existed in the IPv6 implementation of the Linux kernel. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2022-3524) It was discovered that the Bluetooth HCI implementation in the Linux kernel did not properly deallocate memory in some situations. An attacker could possibly use this cause a denial of service (memory exhaustion). (CVE-2022-3619) It was discovered that the Broadcom FullMAC USB WiFi driver in the Linux kernel did not properly perform bounds checking in some situations. A physically proximate attacker could use this to craft a malicious USB device that when inserted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3628) Tamás Koczka discovered that the Bluetooth L2CAP implementation in the Linux kernel did not properly initialize memory [ more… ]

No Image

Ring in the new year early with Minecraft

2022-12-15 KENNETH 0

Ring in the new year early with Minecraft Celebrate the coming of 2023 in Minecraft Marketplace with free worlds and Character Creator items, plus deals of up to 75% off selected content until Jan. 3. “Each year we try and give back some of the creativity and joy that you, our community puts into Minecraft by showering you with our gratitude – and gifts,” writes Sophie Austin on Minecraft.net. “That’s why we’re stuffing the next five weeks full of fun, freebies and discounts, starting Dec. 20! Come with me for a secret, and a sneak peek of what celebratory delights await you this New Year.” Head over to Minecraft.net to watch the video and find out what Minecraft has in store for you to ring in 2023. Source: Ring in the new year early with Minecraft

No Image

Delivering Microsoft Edge WebView2 Runtime to managed Windows 10 devices

2022-12-15 KENNETH 0

Delivering Microsoft Edge WebView2 Runtime to managed Windows 10 devices Microsoft Edge WebView2 is a UI control that allows developers to embed web content into their Win32 C++, .NET, and WinUI applications. It powers many applications today such as Microsoft Office, Microsoft Power BI, and Visual Studio. Earlier this summer, we announced that we were beginning to roll out WebView2 Runtime – the runtime powering WebView2 applications – to Windows 10 Consumer devices to make it easier for developers to deploy their WebView2 applications. We are happy to report that WebView2 Runtime is now installed on most active eligible Windows 10 Consumer devices and will continue to be deployed on newly active Windows 10 devices. As a follow-up step to the Consumer rollout, we are also announcing that after January 16th, 2023, we will start rolling out WebView2 Runtime to [ more… ]

No Image

USN-5779-1: Linux kernel (Azure) vulnerabilities

2022-12-15 KENNETH 0

USN-5779-1: Linux kernel (Azure) vulnerabilities It was discovered that the NFSD implementation in the Linux kernel did not properly handle some RPC messages, leading to a buffer overflow. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-43945) Jann Horn discovered that the Linux kernel did not properly track memory allocations for anonymous VMA mappings in some situations, leading to potential data structure reuse. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42703) It was discovered that a memory leak existed in the IPv6 implementation of the Linux kernel. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2022-3524) It was discovered that a race condition existed in the Bluetooth subsystem in the Linux [ more… ]

[공지] Amazon S3 보안 변경 사항 – 2023년 4월 적용 예정

2022-12-15 KENNETH 0

[공지] Amazon S3 보안 변경 사항 – 2023년 4월 적용 예정 2023년 4월부터, 버킷 보안에 대한 최신 모범 사례가 자동으로 적용되도록 Amazon Simple Storage Service(S3)에 두 가지 변경 사항을 적용할 예정입니다. 대상 리전에 변경 사항이 적용되면 리전에 새로 생성된 모든 버킷에는 기본적으로 S3 퍼블릭 액세스 차단 기능이 활성화되고 액세스 제어 목록(ACL)이 비활성화됩니다. 이 변경 사항은 4월부터 몇 주 내에 모든 AWS 리전에 적용될 예정입니다. 이 두 옵션은 이미 콘솔 기본값으로 적용되고 있으며, 오랫동안 모범 사례로 권장되어왔습니다. 이들 옵션은 S3 API, S3 CLI, AWS SDK 또는 AWS CloudFormation 템플릿을 사용하여 생성되는 버킷에 기본값으로 적용됩니다. 이에 대한 배경을 조금 살펴보자면, S3 버킷과 객체는 항상 프라이빗으로 기본 설정되었습니다. AWS는 2018년에 퍼블릭 액세스 차단을 추가하고 2021년에 ACL을 비활성화하는 기능을 추가하여 고객에게 더 많은 제어권을 부여했으며, 이전부터 보다 현대적이고 유연한 대안으로서 AWS Identity and Access Management(IAM) 정책을 사용하도록 권장해왔습니다. 이러한 변화를 고려할 때, 퍼블릭 버킷이나 ACL을 [ more… ]