No Image

USN-5111-2: strongSwan vulnerability

2021-10-19 KENNETH 0

USN-5111-2: strongSwan vulnerability USN-5111-1 fixed a vulnerability in strongSwan. This update provides the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM. Original advisory details: It was discovered that strongSwan incorrectly handled replacing certificates in the cache. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-41991) Source: USN-5111-2: strongSwan vulnerability

No Image

Get ready for 3 months of back-to-back blockbuster game launches in Xbox Game Pass

2021-10-19 KENNETH 0

Get ready for 3 months of back-to-back blockbuster game launches in Xbox Game Pass As the Xbox 20th anniversary approaches in November, blockbuster games for PCs and consoles will be available through Xbox Game Pass, including the Oct. 28 launch of Age of Empires IV (bringing the evolved real-time strategy game to a new generation on Steam and Game Pass for PC on day one), Minecraft on Nov. 2 and Forza Horizon 5 on Nov. 9. “We’ve been hard at work to deliver three months of back-to-back game launches,” writes Matt Booty, head of Xbox Game Studios, in an Xbox Wire post. “And while we hope you’ll join us in celebrating 20 years of Xbox history, know that we’re hard at work on the road ahead and what’s to come in the next 20 years.” Other games launching are Microsoft [ more… ]

No Image

USN-5111-1: strongSwan vulnerabilities

2021-10-19 KENNETH 0

USN-5111-1: strongSwan vulnerabilities It was discovered that strongSwan incorrectly handled certain RSASSA-PSS signatures. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service. (CVE-2021-41990) It was discovered that strongSwan incorrectly handled replacing certificates in the cache. A remote attacker could use this issue to cause strongSwan to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2021-41991) Source: USN-5111-1: strongSwan vulnerabilities

No Image

USN-5092-3: Linux kernel (Azure) regression

2021-10-19 KENNETH 0

USN-5092-3: Linux kernel (Azure) regression USN-5092-2 fixed vulnerabilities in Linux 5.11-based kernels. Unfortunately, for Linux kernels intended for use within Microsoft Azure environments, that update introduced a regression that could cause the kernel to fail to boot in large Azure instance types. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Valentina Palmiotti discovered that the io_uring subsystem in the Linux kernel could be coerced to free adjacent memory. A local attacker could use this to execute arbitrary code. (CVE-2021-41073) Ofek Kirzner, Adam Morrison, Benedict Schlueter, and Piotr Krysiuk discovered that the BPF verifier in the Linux kernel missed possible mispredicted branches due to type confusion, allowing a side-channel attack. An attacker could use this to expose sensitive information. (CVE-2021-33624) Benedict Schlueter discovered that the BPF subsystem in the Linux kernel did not properly protect against [ more… ]

[도서] 데브옵스를 지탱하는 클라우드 네이티브 입문

2021-10-19 KENNETH 0

[도서] 데브옵스를 지탱하는 클라우드 네이티브 입문 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]데브옵스를 지탱하는 클라우드 네이티브 입문 오누르 일마즈,술레이만 아크바스 저/오주환 역 | 에이콘출판사 | 2021년 10월 판매가 27,000원 (10%할인) | YES포인트 1,500원(5%지급) 마이크로서비스 구성을 전제로 컨테이너와 쿠버네티스, 클라우드 네이티브 응용 프로그램 구축 생태계의 한 축을 담당하고 있는 기술들의 활용 방법을 다룬다. 도커 사용법부터 쿠버네티스 클러스터 생성, 응용 프로 Source: [도서] 데브옵스를 지탱하는 클라우드 네이티브 입문