No Image

USN-5954-2: Firefox regressions

2023-03-27 KENNETH 0

USN-5954-2: Firefox regressions USN-5954-1 fixed vulnerabilities in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-25750, CVE-2023-25752, CVE-2023-28162, CVE-2023-28176, CVE-2023-28177) Lukas Bernhard discovered that Firefox did not properly manage memory when invalidating JIT code while following an iterator. An attacker could potentially exploits this issue to cause a denial of service. (CVE-2023-25751) Rob Wu discovered that Firefox did not properly manage the URLs when following a redirect to a publicly accessible web extension file. An attacker could potentially exploits this to obtain sensitive information. (CVE-2023-28160) Luan Herrera discovered that [ more… ]

AWS Clean Rooms 정식 출시 – 원본 데이터 공유 없이 서드 파티 파트너와 협업 가능

2023-03-27 KENNETH 0

AWS Clean Rooms 정식 출시 – 원본 데이터 공유 없이 서드 파티 파트너와 협업 가능 광고 및 마케팅, 소매, 소비재(CPG), 여행 및 숙박, 미디어 및 엔터테인먼트, 금융 서비스 등 다양한 업종에서 비즈니스 파트너의 데이터로 자사 데이터를 보완하며 자사 비즈니스를 다각적으로 파악할 방안을 모색하는 기업들의 사례가 갈수록 늘어나고 있습니다. 마케팅 사용 사례를 예로 들어 보겠습니다. 브랜드, 퍼블리셔 및 파트너가 캠페인의 연관성을 높이고 소비자에게 더 효과적으로 접근하려면 여러 채널과 애플리케이션에 저장된 데이터 세트를 활용해 협업해야 합니다. 그와 동시에, 이들 기업은 민감한 소비자 정보를 보호하고 원시 데이터가 공유되지 않도록 하기를 원합니다. 데이터 클린 룸을 이용하면 여러 기업이 비공개 환경에서 집합적 데이터를 분석할 수 있으므로 이러한 과제를 해결하는 데 도움이 될 수 있습니다. 하지만 데이터 클린 룸을 구축하기는 쉽지 않습니다. 데이터 클린 룸을 구축하려면 복잡한 프라이버시 통제, 각 공동 작업자의 데이터를 보호하기 위한 특수 도구, 개발에만 수개월의 시간을 투자해야 하는 맞춤형 분석 도구가 필요합니다. [ more… ]

No Image

Weather from Microsoft Start named the most accurate global forecast provider

2023-03-25 KENNETH 0

Weather from Microsoft Start named the most accurate global forecast provider Following the last few years of record-breaking natural disasters, it’s clear that weather prediction accuracy isn’t just for making daily decisions when going outdoors – it can save lives. From deadly risk of hurricanes to lightning storms to flooding, there’s a critical need for a high-accuracy weather forecast tool. To meet the needs of our users, we decided to build our own weather forecast system in Microsoft Start. Using industry-leading machine learning, AI and other innovative technologies over the last two years, Microsoft built one of the world’s leading weather forecasting capabilities. In a new, independent study commissioned by Microsoft and conducted by ForecastWatch comparing the top global weather providers, Weather from Microsoft Start was named the most accurate weather forecasting service. * ForecastWatch analyzed Weather from Microsoft Start’s [ more… ]

No Image

USN-5971-1: Graphviz vulnerabilities

2023-03-24 KENNETH 0

USN-5971-1: Graphviz vulnerabilities It was discovered that graphviz contains null pointer dereference vulnerabilities. Exploitation via a specially crafted input file can cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-10196) It was discovered that graphviz contains null pointer dereference vulnerabilities. Exploitation via a specially crafted input file can cause a denial of service. These issues only affected Ubuntu 14.04 ESM and Ubuntu 18.04 LTS. (CVE-2019-11023) It was discovered that graphviz contains a buffer overflow vulnerability. Exploitation via a specially crafted input file can cause a denial of service or possibly allow for arbitrary code execution. These issues only affected Ubuntu 14.04 ESM, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-18032) Source: USN-5971-1: Graphviz vulnerabilities

No Image

USN-5970-1: Linux kernel vulnerabilities

2023-03-24 KENNETH 0

USN-5970-1: Linux kernel vulnerabilities It was discovered that the KVM VMX implementation in the Linux kernel did not properly handle indirect branch prediction isolation between L1 and L2 VMs. An attacker in a guest VM could use this to expose sensitive information from the host OS or other guest VMs. (CVE-2022-2196) It was discovered that a race condition existed in the Xen network backend driver in the Linux kernel when handling dropped packets in certain circumstances. An attacker could use this to cause a denial of service (kernel deadlock). (CVE-2022-42328, CVE-2022-42329) Gerald Lee discovered that the USB Gadget file system implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-4382) José Oliveira and [ more… ]