No Image

USN-4075-1: Exim vulnerability

2019-07-26 KENNETH 0

USN-4075-1: Exim vulnerability exim4 vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Exim could be made to run programs as an administrator if it received specially crafted network traffic. Software Description exim4 – Exim is a mail transport agent Details Jeremy Harris discovered that Exim incorrectly handled sort expansions. In environments where sort expansions are used, a remote attacker could possibly use this issue to execute arbitrary code as root. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 exim4-daemon-heavy – 4.92-4ubuntu1.2 exim4-daemon-light – 4.92-4ubuntu1.2 Ubuntu 18.04 LTS exim4-daemon-heavy – 4.90.1-1ubuntu1.3 exim4-daemon-light – 4.90.1-1ubuntu1.3 Ubuntu 16.04 LTS exim4-daemon-heavy – 4.86.2-2ubuntu2.4 exim4-daemon-light – 4.86.2-2ubuntu2.4 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update [ more… ]

No Image

USN-4074-1: VLC vulnerabilities

2019-07-25 KENNETH 0

USN-4074-1: VLC vulnerabilities vlc vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Summary Several security issues were fixed in VLC. Software Description vlc – multimedia player and streamer Details It was discovered that the VLC CAF demuxer incorrectly handled certain files. If a user were tricked into opening a specially-crafted CAF file, a remote attacker could use this issue to cause VLC to crash, resulting in a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-19857) It was discovered that the VLC Matroska demuxer incorrectly handled certain files. If a user were tricked into opening a specially-crafted MKV file, a remote attacker could use this issue to cause VLC to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2019-12874) It was discovered that the VLC [ more… ]

No Image

USN-4073-1: libEBML vulnerability

2019-07-25 KENNETH 0

USN-4073-1: libEBML vulnerability libebml vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary libEBML could be made to crash if it opened a specially crafted file. Software Description libebml – library for the EBML format Details It was discovered that libEBML incorrectly handled certain media files. If a user were tricked into opening a specially crafted media file, libEBML could possibly be made to crash, resulting in a denial of service. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libebml4v5 – 1.3.5-2ubuntu0.1 Ubuntu 16.04 LTS libebml4v5 – 1.3.3-1ubuntu0.1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2019-13615 Source: USN-4073-1: libEBML vulnerability

AWS Snowball 및 Snowball Edge, 대용량 데이터 이동 서비스 서울 리전 출시

2019-07-25 KENNETH 0

AWS Snowball 및 Snowball Edge, 대용량 데이터 이동 서비스 서울 리전 출시 AWS의 대용량 데이터 이동 장치 서비스인 AWS Snowball 및 Snowball Edge가 서울 리전에 출시되었습니다. Snowball 및 Snowball Edge는 안전하고 견고한 장치를 사용하여 데이터 마이그레이션, 에지 컴퓨팅, 기계 학습 및 분석을 위해 Amazon S3로의 페타 바이트 단위로 데이터를 이동하는 전송 서비스입니다. AWS Snowball 및 AWS Snowball Edge는 기존 저장소에서 네트워크 대역폭이 충분하지 않을 때, 대용량 데이터 세트를 클라우드로 이전하는데 도움이 됩니다. AWS Snowball Edge는 원격 위치, 인터넷 연결이 끊어진 환경 등에서 엣지 컴퓨팅을 위해 특정 Amazon EC2 인스턴스를 실행할 수 있게 해줍니다. AWS 클라우드에서 애플리케이션 개발 및 테스트 한 다음, Snowball Edge 장치에 배포하여 이미지 분석 또는 기계 학습을위한 데이터를 수집하고 사전 처리 할 수 있습니다. 데이터 저장 및 추가 처리를 위해 저장 장치를 AWS로 다시 보낼 수 있습니다. 데이터 이전 작업 생성하기 이제 AWS Snowball 이전 작업을 관리 [ more… ]

No Image

USN-4072-1: Ansible vulnerabilities

2019-07-25 KENNETH 0

USN-4072-1: Ansible vulnerabilities ansible vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Several security issues were fixed in Ansible. Software Description ansible – Configuration management, deployment, and task execution system Details It was discovered that Ansible failed to properly handle sensitive information. A local attacker could use those vulnerabilities to extract them. (CVE-2017-7481) (CVE-2018-10855) (CVE-2018-16837) (CVE-2018-16876) (CVE-2019-10156) It was discovered that Ansible could load configuration files from the current working directory containing crafted commands. An attacker could run arbitrary code as result. (CVE-2018-10874) (CVE-2018-10875) It was discovered that Ansible fetch module had a path traversal vulnerability. A local attacker could copy and overwrite files outside of the specified destination. (CVE-2019-3828) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu [ more… ]