No Image

USN-5855-3: ImageMagick regression

2023-04-01 KENNETH 0

USN-5855-3: ImageMagick regression USN-5855-2 fixed vulnerabilities in ImageMagick. Unfortunately an additional mitigation caused a regression. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that ImageMagick incorrectly handled certain PNG images. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause ImageMagick to stop responding, resulting in a denial of service, or possibly obtain the contents of arbitrary files by including them into images. Source: USN-5855-3: ImageMagick regression

No Image

Announcing Windows 11 Insider Preview Build 22621.1537 and 22624.1537

2023-04-01 KENNETH 0

Announcing Windows 11 Insider Preview Build 22621.1537 and 22624.1537 Hello Windows Insiders, today we are releasing Windows 11 Insider Preview Build 22621.1537 and Build 22624.1537 (KB5022910) to the Beta Channel. Build 22624.1537 = New features rolling out. Build 22621.1537 = New features off by default. REMINDER: Insiders who were previously on Build 22623 will automatically get moved to Build 22624 via an enablement package. The enablement package artificially increments the build number for the update with new features getting rolled out and turned on to make it easier to differentiate from devices with the update with features off by default. This approach is being used for the Beta Channel only and is not indicative of any changes or plans for final feature rollouts. Insiders who landed in the group with new features turned off by default (Build 22621.xxxx) can check for [ more… ]

No Image

USN-5991-1: Linux kernel (GCP) vulnerabilities

2023-03-31 KENNETH 0

USN-5991-1: Linux kernel (GCP) vulnerabilities It was discovered that the System V IPC implementation in the Linux kernel did not properly handle large shared memory counts. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2021-3669) It was discovered that a use-after-free vulnerability existed in the SGI GRU driver in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3424) Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-36280) Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not properly perform reference counting in some situations, leading to a use- after-free vulnerability. [ more… ]

No Image

USN-5990-1: musl vulnerabilities

2023-03-31 KENNETH 0

USN-5990-1: musl vulnerabilities It was discovered that musl did not handle certain i386 math functions properly. An attacker could use this vulnerability to cause a denial of service (crash) or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, and Ubuntu 18.04 LTS. (CVE-2019-14697) It was discovered that musl did not handle wide-character conversion properly. A remote attacker could use this vulnerability to cause resource consumption (infinite loop), denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 14.04 ESM, Ubuntu 16.04 ESM, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2020-28928) Source: USN-5990-1: musl vulnerabilities

지속 가능한 효율적이고 비용 최적화 된 AWS 기반 애플리케이션 구축하기

2023-03-31 KENNETH 0

지속 가능한 효율적이고 비용 최적화 된 AWS 기반 애플리케이션 구축하기 오늘날, 그 어느 때보다도, 거의 모든 조직에서 지속 가능성과 비용 절감이 최우선 고려 사항입니다. 클라우드 전환을 통한 탄소 감축 기회와 관련한 조사에 따르면 AWS의 인프라는 미국 기업 데이터 센터의 중앙값보다 3.6배 더 에너지 효율적이며 유럽 평균보다 최대 5배 더 에너지 효율적인 것으로 나타났습니다. 즉, 단순히 AWS로 이전하는 것만으로는 오늘날의 고객들이 설정하는 환경, 사회, 지배 구조(ESG) 및 클라우드 재무관리(CFM) 목표를 충족시키기에 충분하지 않습니다. 지구의 자원들을 지속적으로 사용하려면 클라우드에서 실행되는 애플리케이션을 효율성을 염두에 두고 구축해야 합니다. 그 이유는 클라우드 지속 가능성은 AWS와 고객의 공동 책임이기 때문입니다. AWS는 클라우드의 지속 가능성 최적화에 책임을 지고 효율적인 인프라, 모든 고객의 요구사항을 충족할 수 있는 충분한 옵션, 그리고 이를 효과적으로 관리할 수 있는 도구를 구축합니다. AWS 고객으로서 전체 리소스 요구 사항을 최소화하고 소비해야 하는 것을 최대한 활용하여 솔루션을 구축해야 합니다. 대부분의 AWS서비스 요금은 하드웨어 사용과 관련이 [ more… ]