No Image

USN-6207-1: Linux kernel (Intel IoTG) vulnerabilities

2023-07-07 KENNETH 0

USN-6207-1: Linux kernel (Intel IoTG) vulnerabilities It was discovered that the TUN/TAP driver in the Linux kernel did not properly initialize socket data. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-1076) It was discovered that the Real-Time Scheduling Class implementation in the Linux kernel contained a type confusion vulnerability in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-1077) It was discovered that the ASUS HID driver in the Linux kernel did not properly handle device removal, leading to a use-after-free vulnerability. A local attacker with physical access could plug in a specially crafted USB device to cause a denial of service (system crash). (CVE-2023-1079) It was discovered that the Xircom PCMCIA network device driver in the Linux kernel did not properly handle device removal [ more… ]

No Image

USN-6206-1: Linux kernel (OEM) vulnerabilities

2023-07-07 KENNETH 0

USN-6206-1: Linux kernel (OEM) vulnerabilities Hangyu Hua discovered that the Flower classifier implementation in the Linux kernel contained an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35788, LP: #2023577) It was discovered that the NTFS file system implementation in the Linux kernel contained a null pointer dereference in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-4842) Seth Jenkins discovered that the CPU data to memory implementation for x86 processors in the Linux kernel did not properly perform address randomization. A local attacker could use this to expose sensitive information (kernel memory) or in conjunction with another kernel vulnerability. (CVE-2023-0597) It was discovered that the XFS file system implementation in the Linux kernel did not properly perform metadata [ more… ]

No Image

USN-6205-1: Linux kernel (GKE) vulnerabilities

2023-07-07 KENNETH 0

USN-6205-1: Linux kernel (GKE) vulnerabilities Hangyu Hua discovered that the Flower classifier implementation in the Linux kernel contained an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35788, LP: #2023577) It was discovered that for some Intel processors the INVLPG instruction implementation did not properly flush global TLB entries when PCIDs are enabled. An attacker could use this to expose sensitive information (kernel memory) or possibly cause undesired behaviors. (LP: #2023220) Source: USN-6205-1: Linux kernel (GKE) vulnerabilities

Fighting notification spam in Microsoft Edge

2023-07-07 KENNETH 0

Fighting notification spam in Microsoft Edge Web site notifications are great for staying up to date on your favorite webapps, but they can also be used to spam you with messages that can be unwanted or even misleading. We’ve made changes to help customers avoid these spammy messages and increase their peace of mind.Edge now blocks prompts like these from unfamiliar sites to help protect users from aggressive fake advertising.Sites intending to spam visitors will try to trick users to allow notifications, like in the example above. This site is really trying to get permission to show spammy notifications. Within minutes, this site pushed dozens of fake warnings, all trying to trick victim users into buying software. While these notifications don’t cause direct harm on their own, they can be unsettling and some customers don’t know how to disable them. [ more… ]

AWS 주간 소식 모음 – 신규 생성형 AI 실습 과정, Amazon SageMaker Data Wrangler 업데이트 등

2023-07-06 KENNETH 0

AWS 주간 소식 모음 – 신규 생성형 AI 실습 과정, Amazon SageMaker Data Wrangler 업데이트 등 지난 주 AWS 주간 리뷰 포스트에서 Danilo는 현재 런던이 여름이라고 했습니다. 음, 저는 싱가포르에 있는데 여기는 이제 거의 여름에 접어들었습니다. 하지만 여기서 6월은 두리안 시즌이 시작되는 특별한 달입니다. 다음 주부터 저는 태국, 말레이시아, 필리핀으로 여행을 떠날 예정입니다. 하지만 여행 가기 전에 지난 주에 있었던 몇 가지 흥미로운 일들을 여러분께 알려드리고자 합니다. 그럼, 시작해 보겠습니다. 지난주 출시 사항 다음은 저의 이목을 끌었던 몇 가지 출시 사항입니다. 새로운 실습 과정: 대규모 언어 모델을 사용하는 생성형 AI – 생성형 AI는 지난 몇 개월 동안 주목을 받아온 기술입니다. 대규모 언어 모델(LLM)을 배우려고 한다면 Coursera에서 LLM을 사용하는 생성형 AI라는 신규 실습 과정을 들어보세요. Antje는 이러한 DeepLearning.AI와 AWS의 협업 과정을 발표하는 게시물을 작성했습니다. 이 과정은 데이터 사이언티스트와 엔지니어가 실제적인 적용을 위해 LLM을 선택하고 교육하고 미세 조정하고 배포하는 데 있어서 전문가가 [ more… ]