No Image

USN-4280-2: ClamAV vulnerability

2020-02-19 KENNETH 0

USN-4280-2: ClamAV vulnerability clamav vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary ClamAV could be made to crash if it opened a specially crafted file. Software Description clamav – Anti-virus utility for Unix Details USN-4280-1 fixed a vulnerability in ClamAV. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. Original advisory details: It was discovered that ClamAV incorrectly handled memory when the Data-Loss-Prevention (DLP) feature was enabled. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM clamav – 0.102.2+dfsg-0ubuntu0.14.04.1+esm1 Ubuntu 12.04 ESM clamav – 0.102.2+dfsg-0ubuntu0.12.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This [ more… ]

No Image

USN-4282-1: PostgreSQL vulnerability

2020-02-18 KENNETH 0

USN-4282-1: PostgreSQL vulnerability postgresql-10, postgresql-11 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Summary PostgreSQL could allow unintended access to the database. Software Description postgresql-11 – Object-relational SQL database postgresql-10 – Object-relational SQL database Details It was discovered that PostgreSQL incorrectly performed authorization checks when handling the "ALTER … DEPENDS ON EXTENSION" sub-commands. A remote attacker could possibly use this issue to drop any function, procedure, materialized view, index, or trigger under certain conditions. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 postgresql-11 – 11.7-0ubuntu0.19.10.1 Ubuntu 18.04 LTS postgresql-10 – 10.12-0ubuntu0.18.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart [ more… ]

No Image

USN-4281-1: WebKitGTK+ vulnerabilities

2020-02-18 KENNETH 0

USN-4281-1: WebKitGTK+ vulnerabilities webkit2gtk vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Summary Several security issues were fixed in WebKitGTK+. Software Description webkit2gtk – Web content engine library for GTK+ Details A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 libjavascriptcoregtk-4.0-18 – 2.26.4-0ubuntu0.19.10.1 libwebkit2gtk-4.0-37 – 2.26.4-0ubuntu0.19.10.1 Ubuntu 18.04 LTS libjavascriptcoregtk-4.0-18 – 2.26.4-0ubuntu0.18.04.1 libwebkit2gtk-4.0-37 – 2.26.4-0ubuntu0.18.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This update uses a new upstream release, [ more… ]

No Image

USN-4280-1: ClamAV vulnerability

2020-02-18 KENNETH 0

USN-4280-1: ClamAV vulnerability clamav vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary ClamAV could be made to crash if it opened a specially crafted file. Software Description clamav – Anti-virus utility for Unix Details It was discovered that ClamAV incorrectly handled memory when the Data-Loss-Prevention (DLP) feature was enabled. A remote attacker could possibly use this issue to cause ClamAV to crash, resulting in a denial of service. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10 clamav – 0.102.2+dfsg-0ubuntu0.19.10.1 Ubuntu 18.04 LTS clamav – 0.102.2+dfsg-0ubuntu0.18.04.1 Ubuntu 16.04 LTS clamav – 0.102.2+dfsg-0ubuntu0.16.04.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. This update uses a new upstream release, which includes additional bug fixes. In general, a standard system [ more… ]

Amazon EC2 다중 인스턴스에 연결 가능한 프로비저닝 IOPS(io1) EBS 볼륨 출시 (서울 리전 포함)

2020-02-18 KENNETH 0

Amazon EC2 다중 인스턴스에 연결 가능한 프로비저닝 IOPS(io1) EBS 볼륨 출시 (서울 리전 포함) Amazon Elastic Compute Cloud(EC2)에서 Linux 운영 체제를 실행하는 고객 분들은 프로비저닝된 IOPS(io1) Elastic Block Store(EBS) 볼륨을 여러 대의 EC2 인스턴스에 연결할 수 있게 되었습니다. 각 EBS 볼륨에 새로운 다중 연결 옵션(Multi-Attach)을 구성하면 각 인스턴스를 단일 가용 영역 내에 있는 최대 16개의 EC2 인스턴스에 연결할 수 있습니다. 또한 각 Nitro 기반 EC2 인스턴스는 다중 연결을 사용하는 여러 EBS 볼륨을 연결하는 것을 지원할 수 있습니다. 다중 연결 기능을 사용하면 스토리지 일관성을 유지하기 위해 쓰기 순서 지정을 제공하는 애플리케이션의 가용성을 손쉽게 높일 수 있습니다. 이제 여러분의 애플리케이션은 전체 읽기 및 쓰기 권한으로 다중 연결 볼륨을 비-부팅 데이터 볼륨으로 연결할 수 있습니다. 다중 연결이 구성된 볼륨도 일반 볼륨처럼 볼륨 스냅샷을 생성할 수 있지만, 볼륨이 연결되어 있는 모든 인스턴스에서 스냅샷을 시작할 수 있으므로 한층 더욱 편리합니다. 또한 다중 연결 볼륨도 암호화를 [ more… ]