No Image

USN-6010-3: Firefox regressions

2023-04-26 KENNETH 0

USN-6010-3: Firefox regressions USN-6010-1 fixed vulnerabilities and USN-6010-2 fixed minor regressions in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-29537, CVE-2023-29540, CVE-2023-29543, CVE-2023-29544, CVE-2023-29547, CVE-2023-29548, CVE-2023-29549, CVE-2023-29550, CVE-2023-29551) Irvan Kurniawan discovered that Firefox did not properly manage fullscreen notifications using a combination of window.open, fullscreen requests, window.name assignments, and setInterval calls. An attacker could potentially exploit this issue to perform spoofing attacks. (CVE-2023-29533) Lukas Bernhard discovered that Firefox did not properly manage memory when doing Garbage Collector compaction. An attacker could potentially exploits this issue to cause a [ more… ]

AWS Developer Innovation Day 행사 안내 – 개발자를 위한 AWS 최신 업데이트

2023-04-26 KENNETH 0

AWS Developer Innovation Day 행사 안내 – 개발자를 위한 AWS 최신 업데이트 오는 4월 26일 (한국 시간 4월 27일 새벽)에 무료로 참석할 수 있는 온라인 이벤트인 AWS Developer Innovation Day에 저희와 함께하시길 바랍니다. AWS는 LinkedIn Live, 트위터, 유튜브, 트위치를 비롯한 여러 플랫폼에서 동시에 이벤트를 스트리밍할 예정입니다. AWS Developer Innovation Day는 개발자와 개발팀을 위해 특별히 마련된 새로운 행사입니다. 이 행사에서 하루 종일 진행되는 여러 세션에서는 생산성과 협업을 개선하고, 신제품 관련 새로운 소식을 처음 살펴보고, 개발 및 전달을 위한 AWS 도구에 대해 자세히 알아볼 수 있는 방법을 보여줍니다. 세션에서는 웹 및 모바일 애플리케이션 개발 속도를 높이는 방법과 모던 인프라, DevOps 및 생성형 AI 지원 도구를 활용하여 더 빠르게 구축하고 전달할 수 있는 방법 등의 주제를 다루게 됩니다. 행사는 가장 먼저 AWS의 개발자 경험 담당 부사장인 Adam Seligman의 기조 연설로 시작됩니다. 그리고 Amazon의 CTO인 Dr. Werner Vogels, AWS Code Suite의 이사인 Harry Mower, [ more… ]

No Image

USN-6039-1: OpenSSL vulnerabilities

2023-04-26 KENNETH 0

USN-6039-1: OpenSSL vulnerabilities It was discovered that OpenSSL was not properly managing file locks when processing policy constraints. If a user or automated system were tricked into processing a certificate chain with specially crafted policy constraints, a remote attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-3996) David Benjamin discovered that OpenSSL was not properly performing the verification of X.509 certificate chains that include policy constraints, which could lead to excessive resource consumption. If a user or automated system were tricked into processing a specially crafted X.509 certificate chain that includes policy constraints, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-0464) David Benjamin discovered that OpenSSL was not properly handling invalid certificate policies in leaf certificates, which would result [ more… ]

No Image

USN-6040-1: Linux kernel (HWE) vulnerabilities

2023-04-25 KENNETH 0

USN-6040-1: Linux kernel (HWE) vulnerabilities It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-1281) It was discovered that the OverlayFS implementation in the Linux kernel did not properly handle copy up operation in some conditions. A local attacker could possibly use this to gain elevated privileges. (CVE-2023-0386) Haowei Yan discovered that a race condition existed in the Layer 2 Tunneling Protocol (L2TP) implementation in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-4129) It was discovered that the network queuing discipline implementation in the Linux kernel contained a null pointer dereference in some situations. A local attacker could use this to cause [ more… ]

No Image

USN-6038-1: Go vulnerabilities

2023-04-25 KENNETH 0

USN-6038-1: Go vulnerabilities It was discovered that the Go net/http module incorrectly handled Transfer-Encoding headers in the HTTP/1 client. A remote attacker could possibly use this issue to perform an HTTP Request Smuggling attack. (CVE-2022-1705) It was discovered that Go did not properly manage memory under certain circumstances. An attacker could possibly use this issue to cause a panic resulting into a denial of service. (CVE-2022-1962, CVE-2022-27664, CVE-2022-28131, CVE-2022-30630, CVE-2022-30631, CVE-2022-30632, CVE-2022-30633, CVE-2022-30635, CVE-2022-32189, CVE-2022-41715, CVE-2022-41717, CVE-2023-24534, CVE-2023-24537) It was discovered that Go did not properly implemented the maximum size of file headers in Reader.Read. An attacker could possibly use this issue to cause a panic resulting into a denial of service. (CVE-2022-2879) It was discovered that the Go net/http module incorrectly handled query parameters in requests forwarded by ReverseProxy. A remote attacker could possibly use this issue to perform [ more… ]