No Image

USN-5703-1: Linux kernel (Intel IoTG) vulnerabilities

2022-10-27 KENNETH 0

USN-5703-1: Linux kernel (Intel IoTG) vulnerabilities Selim Enes Karaduman discovered that a race condition existed in the General notification queue implementation of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1882) Pawan Kumar Gupta, Alyssa Milburn, Amit Peled, Shani Rehana, Nir Shildan and Ariel Sabba discovered that some Intel processors with Enhanced Indirect Branch Restricted Speculation (eIBRS) did not properly handle RET instructions after a VM exits. A local attacker could potentially use this to expose sensitive information. (CVE-2022-26373) Eric Biggers discovered that a use-after-free vulnerability existed in the io_uring subsystem in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3176) It was discovered that the [ more… ]

No Image

USN-5702-2: curl vulnerability

2022-10-27 KENNETH 0

USN-5702-2: curl vulnerability USN-5702-1 fixed a vulnerability in curl. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: Robby Simpson discovered that curl incorrectly handled certain POST operations after PUT operations. This issue could cause applications using curl to send the wrong data, perform incorrect memory operations, or crash. (CVE-2022-32221) Source: USN-5702-2: curl vulnerability

[도서] 쿠버네티스 개발 전략

2022-10-27 KENNETH 0

[도서] 쿠버네티스 개발 전략 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]쿠버네티스 개발 전략 허준 저 | 인사이트(insight) | 2022년 11월 판매가 19,800원 (10%할인) | YES포인트 1,100원(5%지급) 쿠버네티스는 개발 및 배포 환경의 통일, 운영 자동화, 효율적인 자원 관리 등 엔지니어들이 가지고 있던 해묵은 고민을 해결해 주며, 개발환경과 운영환경을 극적으로 바꾸어 놓았다. ‘설정보다 관례(convention o Source: [도서] 쿠버네티스 개발 전략

No Image

USN-5696-2: MySQL vulnerabilities

2022-10-27 KENNETH 0

USN-5696-2: MySQL vulnerabilities USN-5696-1 fixed several vulnerabilities in MySQL. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.7.40 in Ubuntu 16.04 ESM. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-40.html https://www.oracle.com/security-alerts/cpuoct2022.html Source: USN-5696-2: MySQL vulnerabilities

No Image

USN-5702-1: curl vulnerabilities

2022-10-27 KENNETH 0

USN-5702-1: curl vulnerabilities Robby Simpson discovered that curl incorrectly handled certain POST operations after PUT operations. This issue could cause applications using curl to send the wrong data, perform incorrect memory operations, or crash. (CVE-2022-32221) Hiroki Kurosawa discovered that curl incorrectly handled parsing .netrc files. If an attacker were able to provide a specially crafted .netrc file, this issue could cause curl to crash, resulting in a denial of service. This issue only affected Ubuntu 22.10. (CVE-2022-35260) It was discovered that curl incorrectly handled certain HTTP proxy return codes. A remote attacker could use this issue to cause curl to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, and Ubuntu 22.10. (CVE-2022-42915) Hiroki Kurosawa discovered that curl incorrectly handled HSTS support when certain hostnames included IDN characters. A remote [ more… ]