No Image

USN-4126-2: FreeType vulnerabilities

2019-09-10 KENNETH 0

USN-4126-2: FreeType vulnerabilities freetype vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 ESM Ubuntu 12.04 ESM Summary FreeType could be made to expose sensitive information if it opened a specially crafted font file. Software Description freetype – FreeType 2 is a font engine library Details USN-4126-1 fixed a vulnerability in FreeType. This update provides the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM. It was discovered that FreeType incorrectly handled certain font files. An attacker could possibly use this issue to access sensitive information. (CVE-2015-9381, CVE-2015-9382) Original advisory details: It was discovered that FreeType incorrectly handled certain font files. An attacker could possibly use this issue to access sensitive information. (CVE-2015-9383) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM libfreetype6 – [ more… ]

No Image

USN-4127-1: Python vulnerabilities

2019-09-10 KENNETH 0

USN-4127-1: Python vulnerabilities python2.7, python3.5, python3.6, python3.7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Python. Software Description python2.7 – An interactive high-level object-oriented language python3.7 – An interactive high-level object-oriented language python3.6 – An interactive high-level object-oriented language python3.5 – An interactive high-level object-oriented language Details It was discovered that Python incorrectly handled certain pickle files. An attacker could possibly use this issue to consume memory, leading to a denial of service. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2018-20406) It was discovered that Python incorrectly validated the domain when handling cookies. An attacker could possibly trick Python into sending cookies to the wrong domain. (CVE-2018-20852) Jonathan Birch and Panayiotis Panayiotou discovered that Python incorrectly handled [ more… ]

No Image

USN-4126-1: FreeType vulnerability

2019-09-10 KENNETH 0

USN-4126-1: FreeType vulnerability freetype vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary FreeType could be made to expose sensitive information if if it opened a specially crafted font file. Software Description freetype – FreeType 2 is a font engine library Details It was discovered that FreeType incorrectly handled certain font files. An attacker could possibly use this issue to access sensitive information. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libfreetype6 – 2.6.1-0.1ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. After a standard system update you need to restart your session to make all the necessary changes. References CVE-2015-9383 Source: USN-4126-1: FreeType vulnerability

No Image

USN-4125-1: Memcached vulnerability

2019-09-09 KENNETH 0

USN-4125-1: Memcached vulnerability memcached vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Memcached could be made to expose sensitive information if it received a specially crafted UNIX socket. Software Description memcached – high-performance memory object caching system Details It was discovered that Memcached incorrectly handled certain UNIX sockets. An attacker could possibly use this issue to access sensitive information. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 memcached – 1.5.10-0ubuntu1.19.04.2 Ubuntu 18.04 LTS memcached – 1.5.6-0ubuntu1.2 Ubuntu 16.04 LTS memcached – 1.4.25-2ubuntu1.5 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-15026 Source: USN-4125-1: Memcached vulnerability

Amazon CloudWatch Container Insight를 통한 컨테이너 기반 앱 모니터링 기능 출시

2019-09-09 KENNETH 0

Amazon CloudWatch Container Insight를 통한 컨테이너 기반 앱 모니터링 기능 출시 컨테이너 기반 애플리케이션과 마이크로서비스의 도입이 확대되면서 모니터링 및 관리 작업 부담도 커지고 있습니다. 컨테이너에서 모니터링 데이터를 안정적으로 수집하고 성능 또는 기타 문제를 분석하는 것을 돕기 위해  지난 7월 뉴욕에서 개최된 AWS Summit에서 Amazon ECS and AWS Fargate에 대해 Amazon CloudWatch Container Insights를 기능을 미리 보기로 공개하였습니다. 이제 CloudWatch Container Insights는 기존 클러스터까지 모니터링할 수 있는 기능을 추가하여 정식 출시합니다. 신규 클러스터와 기존 클러스터 인프라 및 컨테이너화된 애플리케이션의 컴퓨팅 사용률과 오류에 대한 분석 정보를 Kubernetes, Amazon Elastic Container Service for Kubernetes, Amazon ECS, AWS Fargate 등의 컨테이너 관리 서비스에서 즉각적으로 손쉽게 얻을 수 있습니다. Amazon CloudWatch를 활성화하면 클러스터에서 실행 중인 모든 컨테이너를 검색하여 컨테이너 스택의 모든 계층에서 성능 및 운영 데이터를 수집합니다. 또한 환경에서 발생하는 변경 사항을 지속적으로 모니터링하고 업데이트하므로, 컨테이너 지표와 로그를 수집하고 모니터링하고 분석하고 그에 대응하는 데 필요한 [ more… ]