No Image

USN-6253-1: libvirt vulnerability

2023-07-27 KENNETH 0

USN-6253-1: libvirt vulnerability It wad discovered that libvirt incorrectly handled locking when processing certain requests. A local attacker could possibly use this issue to cause libvirt to stop responding or crash, resulting in a denial of service. Source: USN-6253-1: libvirt vulnerability

No Image

USN-6252-1: Linux kernel vulnerabilities

2023-07-27 KENNETH 0

USN-6252-1: Linux kernel vulnerabilities It was discovered that the ext4 file system implementation in the Linux kernel contained a use-after-free vulnerability. An attacker could use this to construct a malicious ext4 file system image that, when mounted, could cause a denial of service (system crash). (CVE-2022-1184) It was discovered that the sound subsystem in the Linux kernel contained a race condition in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3303) It was discovered that a race condition existed in the btrfs file system implementation in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-1611) It was discovered that the Xircom PCMCIA network device driver in the Linux kernel did not properly handle [ more… ]

No Image

USN-6251-1: Linux kernel vulnerabilities

2023-07-26 KENNETH 0

USN-6251-1: Linux kernel vulnerabilities It was discovered that the IP-VLAN network driver for the Linux kernel did not properly initialize memory in some situations, leading to an out-of- bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3090) Shir Tamari and Sagi Tzadik discovered that the OverlayFS implementation in the Ubuntu Linux kernel did not properly perform permission checks in certain situations. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-32629) It was discovered that the netfilter subsystem in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-3390) Tanguy Dubroca discovered that the netfilter subsystem in the Linux kernel [ more… ]

[도서] 얄코의 TOO MUCH 친절한 깃&깃허브

2023-07-26 KENNETH 0

[도서] 얄코의 TOO MUCH 친절한 깃&깃허브 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]얄코의 TOO MUCH 친절한 깃&깃허브 고현민 저 | 리코멘드 | 2023년 08월 판매가 19,800원 (10%할인) | YES포인트 1,100원(5%지급) 이벤트 : 월간 개발자 2023년 8월호 – “이렇게까지 설명한다고?” – 진짜 개발자답게 제대로 활용할 수 있도록 투머치 설명러 얄코가 다 알려주는 깃&깃허브 가이드 프로그래밍을 배워 개발자가 되겠다고 하면 주변에서는 묻지도 따지지도 않고 ‘ Source: [도서] 얄코의 TOO MUCH 친절한 깃&깃허브

No Image

USN-5807-3: libXpm vulnerability

2023-07-26 KENNETH 0

USN-5807-3: libXpm vulnerability USN-5807-1 fixed a vulnerability in libXpm. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Marco Ivaldi discovered that libXpm incorrectly handled certain XPM files. If a user or automated system were tricked into opening a specially crafted XPM file, a remote attacker could possibly use this issue to cause libXpm to stop responding, resulting in a denial of service. (CVE-2022-46285) Source: USN-5807-3: libXpm vulnerability