No Image

USN-4912-1: Linux kernel (OEM) vulnerabilities

2021-04-14 KENNETH 0

USN-4912-1: Linux kernel (OEM) vulnerabilities Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux kernel did not properly validate computation of branch displacements in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-29154) It was discovered that a race condition existed in the binder IPC implementation in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-0423) It was discovered that the HID multitouch implementation within the Linux kernel did not properly validate input events in some situations. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-0465) It was discovered that the eventpoll [ more… ]

No Image

USN-4910-1: Linux kernel vulnerabilities

2021-04-14 KENNETH 0

USN-4910-1: Linux kernel vulnerabilities Ryota Shiga discovered that the sockopt BPF hooks in the Linux kernel could allow a user space program to probe for valid kernel addresses. A local attacker could use this to ease exploitation of another kernel vulnerability. (CVE-2021-20239) It was discovered that the BPF verifier in the Linux kernel did not properly handle signed add32 and sub integer overflows. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-20268) It was discovered that the priority inheritance futex implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3347) It was discovered that the network block device (nbd) driver in the Linux kernel contained [ more… ]

다중 계정 AWS 환경 설정을 위한 AWS Control Tower – 서울 리전 출시

2021-04-14 KENNETH 0

다중 계정 AWS 환경 설정을 위한 AWS Control Tower – 서울 리전 출시 다중 계정 AWS 환경을 설정하고 관리하는 가장 쉬운 방법을 제공하는 AWS Control Tower 서비스가 서울 리전에 출시되었습니다. AWS Control Tower는 안전하고 이상적으로 설계된 다중 계정 AWS 환경인 기준 환경, 즉 랜딩 영역의 설정을 자동화합니다. 랜딩 영역은 보안, 운영 및 규정 준수 규칙을 통해 AWS 워크로드를 더 쉽게 관리하게 해 주는 안전한 환경을 조성하기 위해 수많은 엔터프라이즈 고객이 구축한 모범 사례를 바탕으로 구성할 수 있습니다. 기존에 서울 리전에서는 Control Tower 대신 AWS Landing Zone이라는 별도 솔루션을 제공했습니다. 기존 AWS Landing Zone 솔루션은 계속 지원은 하지만, 향후 추가 기능을 제공하지 않습니다. 앞으로는 AWS Control Tower를 사용하시길 권장합니다. AWS Control Tower에는 다음과 같은 주요 기능을 바로 사용해 볼 수 있습니다. 계정 팩토리 계정 팩토리는 사내에서 사용할 새로운 AWS 계정 생성을 자동화합니다. 기존에 사전 승인된 계정 구성 템플릿으로 표준화된 계정을 만드는데 [ more… ]

No Image

Releasing Windows 10 Build 19043.928 (21H1) to Beta & Release Preview Channels

2021-04-14 KENNETH 0

Releasing Windows 10 Build 19043.928 (21H1) to Beta & Release Preview Channels Hello Windows Insiders, today we’re releasing 21H1 Build 19043.928 (KB5001330) the Beta Channel for those Insiders who are on 21H1 (Click here for the 21H1 announcement). This update is also available for commercial devices in the Release Preview Channel on 21H1 as mentioned here in this blog post. This security update includes quality improvements. Key changes include: We fixed an issue in which a principal in a trusted MIT realm fails to obtain a Kerberos service ticket from Active Directory domain controllers (DC). This occurs on devices that installed Windows Updates that contain CVE-2020-17049 protections and configured PerfromTicketSignature to 1 or higher. These updates were released between November 10, 2020 and December 8, 2020. Ticket acquisition also fails with the error, “KRB_GENERIC_ERROR”, if callers submit a PAC-less Ticket [ more… ]

[도서] 쿼커스 쿡북

2021-04-14 KENNETH 0

[도서] 쿼커스 쿡북 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]쿼커스 쿡북 알렉스 소토 부에노,제이슨 포터 저/유동환 역 | 한빛미디어 | 2021년 04월 판매가 31,500원 (10%할인) | YES포인트 1,750원(5%지급) 쿼커스를 쉽고 빠르게 익히는 145가지 레시피 쿼커스는 쿠버네티스에 최적화된 클라우드 네이티브 프레임워크다. 스프링, 하이버네이트, 이클립스 마이크로프로파일, 쿠버네티스, 아파치 캐멜과 이클립스 Vert.x Source: [도서] 쿼커스 쿡북