No Image

USN-2885-1: OpenJDK 6 vulnerabilities

2016-02-02 KENNETH 0

Ubuntu Security Notice USN-2885-1 1st February, 2016 openjdk-6 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in OpenJDK 6. Software description openjdk-6 – Open Source Java implementation Details Multiple vulnerabilities were discovered in the OpenJDK JRE relatedto information disclosure, data integrity, and availability. Anattacker could exploit these to cause a denial of service, exposesensitive data over the network, or possibly execute arbitrary code.(CVE-2016-0483, CVE-2016-0494) A vulnerability was discovered in the OpenJDK JRE related to dataintegrity. An attacker could exploit this to expose sensitive dataover the network or possibly execute arbitrary code. (CVE-2016-0402) A vulnerability was discovered in the OpenJDK JRE related toinformation disclosure. An attacker could exploit this to exposesensitive data over the network. (CVE-2016-0448) A vulnerability was discovered in the OpenJDK JRE related toavailability. An attacker [ more… ]

No Image

USN-2884-1: OpenJDK 7 vulnerabilities

2016-02-02 KENNETH 0

Ubuntu Security Notice USN-2884-1 1st February, 2016 openjdk-7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 15.04 Ubuntu 14.04 LTS Summary Several security issues were fixed in OpenJDK 7. Software description openjdk-7 – Open Source Java implementation Details Multiple vulnerabilities were discovered in the OpenJDK JRE relatedto information disclosure, data integrity, and availability. Anattacker could exploit these to cause a denial of service, exposesensitive data over the network, or possibly execute arbitrary code.(CVE-2016-0483, CVE-2016-0494) A vulnerability was discovered in the OpenJDK JRE related to dataintegrity. An attacker could exploit this to expose sensitive dataover the network or possibly execute arbitrary code. (CVE-2016-0402) It was discovered that OpenJDK 7 incorrectly allowed MD5 to be usedfor TLS connections. If a remote attacker were able to perform aman-in-the-middle attack, this flaw could be exploited to exposesensitive [ more… ]

No Image

한컴 오피스 보안 업데이트 권고

2016-02-01 KENNETH 0

□ 개요 o 한글과컴퓨터社는 아래한글 등 오피스 제품에 대한 보안 업데이트를 발표 [1] o 영향 받는 버전의 사용자는 악성코드 감염에 취약할 수 있으므로 해결방안에 따라 최신버전으로 업데이트 권고 □ 영향 받는 소프트웨어 제품군 세부 제품 영향 받는 버전 한컴오피스 2014 공통요소 9.1.0.3060 이전버전 한글 9.1.0.2892 이전버전 한셀 9.1.0.2889 이전버전 한쇼 9.1.0.2963 이전버전 한컴 오피스 2010 공통요소 8.5.8.1566 이전버전 한글 8.5.8.1503 이전버전 한셀 8.5.8.1415 이전버전 한쇼 8.5.8.1558 이전버전 한컴 오피스 2007 공통요소 7.5.12.738 이전버전 한글 7.5.12.746 이전버전 넥셀 7.5.12.803 이전버전 슬라이드 7.5.12.946 이전버전 □ 해결 방안 o 한글과컴퓨터 홈페이지에서 보안업데이트 파일(보안#40)을 다운로드 받아 설치 – 다운로드 경로 : http://www.hancom.com/downLoad.downPU.do?mcd=005 o 한글과컴퓨터 자동 업데이트를 통해 최신 버전으로 업데이트 – 시작 → 모든 프로그램 → 한글과컴퓨터 → 한컴 자동 업데이트 □ 문의사항 o 한국인터넷진흥원 인터넷침해대응센터: 국번없이 118 [참고사이트] [1] http://www.hancom.com/downLoad.downPU.do?mcd=005