No Image

USN-3147-1: Linux kernel vulnerabilities

2016-12-01 KENNETH 0

USN-3147-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3147-1 30th November, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details Andreas Gruenbacher and Jan Kara discovered that the filesystemimplementation in the Linux kernel did not clear the setgid bit during asetxattr call. A local attacker could use this to possibly elevate groupprivileges. (CVE-2016-7097) Marco Grassi discovered that the driver for Areca RAID Controllers in theLinux kernel did not properly validate control messages. A local attackercould use this to cause a denial of service (system crash) or possibly gainprivileges. (CVE-2016-7425) Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.10: linux-image-powerpc-smp 4.8.0.28.37 linux-image-powerpc-e500mc 4.8.0.28.37 linux-image-generic 4.8.0.28.37 linux-image-4.8.0-28-lowlatency 4.8.0-28.30 linux-image-lowlatency 4.8.0.28.37 linux-image-4.8.0-28-generic [ more… ]

No Image

RHSA-2016:2839-1: Important: CFME 5.6.3 security, bug fix, and enhancement update

2016-12-01 KENNETH 0

RHSA-2016:2839-1: Important: CFME 5.6.3 security, bug fix, and enhancement update Red Hat Enterprise Linux: An update is now available for Red Hat CloudForms 4.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-5402 Source: RHSA-2016:2839-1: Important: CFME 5.6.3 security, bug fix, and enhancement update

No Image

USN-3142-1: ImageMagick vulnerabilities

2016-12-01 KENNETH 0

USN-3142-1: ImageMagick vulnerabilities Ubuntu Security Notice USN-3142-1 30th November, 2016 imagemagick vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in ImageMagick. Software description imagemagick – Image manipulation programs and library Details It was discovered that ImageMagick incorrectly handled certain malformedimage files. If a user or automated system using ImageMagick were trickedinto opening a specially crafted image, an attacker could exploit this tocause a denial of service or possibly execute code with the privileges ofthe user invoking the program. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.10: libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu8.2 libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu8.2 imagemagick 8:6.8.9.9-7ubuntu8.2 imagemagick-6.q16 8:6.8.9.9-7ubuntu8.2 libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu8.2 Ubuntu 16.04 LTS: libmagick++-6.q16-5v5 8:6.8.9.9-7ubuntu5.3 libmagickcore-6.q16-2-extra 8:6.8.9.9-7ubuntu5.3 imagemagick 8:6.8.9.9-7ubuntu5.3 imagemagick-6.q16 8:6.8.9.9-7ubuntu5.3 libmagickcore-6.q16-2 8:6.8.9.9-7ubuntu5.3 [ more… ]

No Image

USN-3143-1: c-ares vulnerability

2016-12-01 KENNETH 0

USN-3143-1: c-ares vulnerability Ubuntu Security Notice USN-3143-1 30th November, 2016 c-ares vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary c-ares could be made to crash or run programs if it processed a specially crafted hostname. Software description c-ares – library for asynchronous name resolves Details Gzob Qq discovered that c-ares incorrectly handled certain hostnames. Aremote attacker could use this issue to cause applications using c-ares tocrash, resulting in a denial of service, or possibly execute arbitrarycode. Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.10: libc-ares2 1.11.0-1ubuntu0.1 Ubuntu 16.04 LTS: libc-ares2 1.10.0-3ubuntu0.1 Ubuntu 14.04 LTS: libc-ares2 1.10.0-2ubuntu0.1 Ubuntu 12.04 LTS: libc-ares2 1.7.5-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard [ more… ]

AWS Snowmobile – 엑사 바이트(Exabyte)급 데이터를 몇 주 만에 클라우드로

2016-12-01 KENNETH 0

AWS Snowmobile – 엑사 바이트(Exabyte)급 데이터를 몇 주 만에 클라우드로 클라우드 이전 중 기존 데이터 센터 혹은 회사에 대용량 데이터가 있다면, 이전이 매우 어려울 수 있습니다. 고속 인터넷을 통해서도 영상 파일, 금융 기록, 위성 이미지 등 페타바이트에서 엑사 바이트(Exabyte)에 이르는 데이터를 옮기는 건 매우 어렵고, 간단히 계산을 해봐도 수년에서 수십 년이 걸릴 수 있습니다. 작년에 AWS Snowball (출시 뉴스 참고)를 통해 손쉽게 대용량 장치를 통해 마이그레이션을 하기 위한 첫 단계를 밟았습니다. 80TB의 스토리지를 담은 전용 스토리지 장치를 배송 받아 데이터를 클라우드로 업로드 하는 방식을 통해 많은 고객들이 도움을 받고 있습니다. 그러나 여전히 엑사 바이트급 데이터를 운용하는 경우라면, 80TB 장치 관점에서 보면 엄청나게 많은 수의 장비와 이동에 대한 곤란한 점이 많습니다. AWS Snowmobile 저장 콘테이너 이러한 고객들의 요구 사항에 맞추어, 오늘 Snowmobile을 출시합니다. 최고 100PB의 데이터를 실을 수 있는 전용 트럭을 통해 몇 주 안에 엑사 바이트 데이터를 AWS로 이전할 수 [ more… ]