No Image

USN-5666-1: OpenSSH vulnerability

2022-10-11 KENNETH 0

USN-5666-1: OpenSSH vulnerability It was discovered that OpenSSH incorrectly handled certain helper programs. An attacker could possibly use this issue to arbitrary code execution. Source: USN-5666-1: OpenSSH vulnerability

[도서] 10대를 위한 데이터과학 with 엔트리

2022-10-11 KENNETH 0

[도서] 10대를 위한 데이터과학 with 엔트리 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]10대를 위한 데이터과학 with 엔트리 구덕회,김갑수,김정은,좌하은 저 | 잇플ITPLE | 2022년 10월 판매가 23,850원 (10%할인) | YES포인트 1,320원(5%지급) 다가오는 인공지능 시대에 데이터 과학은 청소년들이 꼭 배워야 할 지식입니다. 이 책은 데이터 과학의 이론서보다는 차근차근 체험해보는 실습서에 가깝습니다. 데이터 과학에 처음 입문하는 청소년들이 복잡한 이 Source: [도서] 10대를 위한 데이터과학 with 엔트리

No Image

USN-5663-1: Thunderbird vulnerabilities

2022-10-08 KENNETH 0

USN-5663-1: Thunderbird vulnerabilities Multiple security issues were discovered in Thunderbird. If a user were tricked into opening a specially crafted website in a browsing context, an attacker could potentially exploit these to cause a denial of service, spoof the mouse pointer position, obtain sensitive information, spoof the contents of the addressbar, bypass security restrictions, or execute arbitrary code. (CVE-2022-2505, CVE-2022-36318, CVE-2022-36319, CVE-2022-38472, CVE-2022-38473, CVE-2022-38476 CVE-2022-38477, CVE-2022-38478) Multiple security issues were discovered in Thunderbird. An attacker could potentially exploit these in order to determine when a user opens a specially crafted message. (CVE-2022-3032, CVE-2022-3034) It was discovered that Thunderbird did not correctly handle HTML messages that contain a meta tag in some circumstances. If a user were tricked into replying to a specially crafted message, an attacker could potentially exploit this to obtain sensitive information. (CVE-2022-3033) A security issue was discovered [ more… ]

No Image

Microsoft Pluton helps secure AMD-powered Acer Swift Edge

2022-10-07 KENNETH 0

Microsoft Pluton helps secure AMD-powered Acer Swift Edge On-the-go professionals looking for the right PC for their hybrid work lives now have another choice: the Acer Swift Edge, a lightweight 16-inch OLED Windows 11 PC laptop powered by AMD Ryzen PRO 6000 series and AMD Ryzen 6000 processors and up to eight high performance Zen 3+ cores built on advanced 6 nm process technology. For IT administrators, AMD PRO technologies deliver multilayered security features to help keep threats at bay, and comprehensive manageability options that scale for long-term stability and reliability. The Acer Swift Edge comes with the Microsoft Pluton, a security processor designed by Microsoft that hardens new Windows 11 PCs with additional protection for sensitive assets such as credentials and encryption keys. To further keep users at ease, the addition of biometric authentication and a Noble Wedge Lock [ more… ]

No Image

USN-5371-3: nginx vulnerability

2022-10-07 KENNETH 0

USN-5371-3: nginx vulnerability USN-5371-1 and USN-5371-2 fixed several vulnerabilities in nginx. This update provides the corresponding update for CVE-2020-11724 for Ubuntu 16.04 ESM. Original advisory details: It was discovered that nginx Lua module mishandled certain inputs. An attacker could possibly use this issue to perform an HTTP Request Smuggling attack. This issue was fixed for Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-11724) It was discovered that nginx Lua module mishandled certain inputs. An attacker could possibly use this issue to disclose sensitive information. This issue only affects Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-36309) It was discovered that nginx mishandled the use of compatible certificates among multiple encryption protocols. If a remote attacker were able to intercept the communication, this issue could be used to redirect traffic between subdomains. (CVE-2021-3618) Source: USN-5371-3: nginx vulnerability