No Image

RHSA-2016:0286-1: Critical: chromium-browser security update

2016-02-23 KENNETH 0

RHSA-2016:0286-1: Critical: chromium-browser security update Red Hat Enterprise Linux: Updated chromium-browser packages that fix two security issues are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Critical security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. CVE-2016-1629 Source: RHSA-2016:0286-1: Critical: chromium-browser security update

Amazon RDS – MySQL 5.7 지원 시작

2016-02-23 KENNETH 0

Amazon RDS – MySQL 5.7 지원 시작 오늘부터 Amazon RDS에서 MySQL 5.7을 사용하실 수 있게 되었습니다. 이번 출시에는 MySQL 성능 향상 및 확장성, 보안 기능 향상 등도 함께 포함되어 있습니다. MySQL JSON 네이티브 지원: JSON 데이터 및 빌트인 함수 (JSON_ARRAY, JSON_OBJECT, JSON_QUOTE, JSON_CONTAINS, JSON_CONTAINS_PATH, JSON_EXTRACT, JSON_KEYS, JSON_SEARCH, JSON_APPEND, JSON_ARRAY_APPEND, JSON_ARRAY_INSERT, JSON_INSERT, JSON_MERGE, JSON_REMOVE, JSON_REPLACE, JSON_SET, JSON_UNQUOTE, JSON_DEPTH, JSON_LENGTH, JSON_TYPE, and JSON_VALID). Performance Schema를 통한 성능 향상 통계 제공 파싱, EXPLAIN 및 쿼리 최적화 성능 개선 GIS를 위한 네이티브 InnoDB 공간 데이터 인덱스 지원 및 Boost.Geometry 통합 (자세한 것은 MySQL 5.7 and GIS, an Example 및 Making Use of Boost Geometry in MySQL GIS을 참고하세요.) 신규 클락 모드를 통한 병렬 리플리케이션 성능 향상 (더 자세한 것은 Multi-threaded Replication Performance in MySQL 5.7을 참고하세요.) InnoDB 확장성 및 임시 테이블 성능 향상 및 동적 buffer pool 크기 변경과 충돌 복구 개선. 기타 더 [ more… ]

No Image

USN-2909-1: Linux kernel (Utopic HWE) vulnerabilities

2016-02-23 KENNETH 0

USN-2909-1: Linux kernel (Utopic HWE) vulnerabilities Ubuntu Security Notice USN-2909-1 22nd February, 2016 linux-lts-utopic vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-utopic – Linux hardware enablement kernel from Utopic Details halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,incorrectly propagated file attributes, including setuid. A localunprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS in the Linux kernel incorrectlypropagated security sensitive extended attributes, such as POSIX ACLs. Alocal unprivileged attacker could use this to gain privileges.(CVE-2016-1575) It was discovered that the Linux kernel's Filesystem in Userspace (FUSE)implementation did not handle initial zero length segments properly. Alocal attacker could use this to cause a denial of service (unkillabletask). (CVE-2015-8785) Update instructions The problem can be [ more… ]

No Image

USN-2910-1: Linux kernel (Vivid HWE) vulnerabilities

2016-02-23 KENNETH 0

USN-2910-1: Linux kernel (Vivid HWE) vulnerabilities Ubuntu Security Notice USN-2910-1 22nd February, 2016 linux-lts-vivid vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-vivid – Linux hardware enablement kernel from Vivid Details halfdog discovered that OverlayFS, when mounting on top of a FUSE mount,incorrectly propagated file attributes, including setuid. A localunprivileged attacker could use this to gain privileges. (CVE-2016-1576) halfdog discovered that OverlayFS in the Linux kernel incorrectlypropagated security sensitive extended attributes, such as POSIX ACLs. Alocal unprivileged attacker could use this to gain privileges.(CVE-2016-1575) It was discovered that the Linux kernel keyring subsystem contained a racebetween read and revoke operations. A local attacker could use this tocause a denial of service (system crash). (CVE-2015-7550) 郭永刚 discovered that the Linux kernel networking implementation [ more… ]

No Image

USN-2911-1: Linux kernel vulnerability

2016-02-23 KENNETH 0

USN-2911-1: Linux kernel vulnerability Ubuntu Security Notice USN-2911-1 22nd February, 2016 linux vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary The system could be made to crash under certain conditions. Software description linux – Linux kernel Details It was discovered that the Linux kernel keyring subsystem contained a racebetween read and revoke operations. A local attacker could use this tocause a denial of service (system crash). Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 12.04 LTS: linux-image-3.2.0-99-generic-pae 3.2.0-99.139 linux-image-3.2.0-99-powerpc64-smp 3.2.0-99.139 linux-image-3.2.0-99-generic 3.2.0-99.139 linux-image-3.2.0-99-virtual 3.2.0-99.139 linux-image-3.2.0-99-highbank 3.2.0-99.139 linux-image-3.2.0-99-powerpc-smp 3.2.0-99.139 linux-image-3.2.0-99-omap 3.2.0-99.139 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to reboot your computer to makeall the necessary changes. ATTENTION: Due to an unavoidable ABI change the [ more… ]