No Image

USN-5956-1: PHPMailer vulnerabilities

2023-03-15 KENNETH 0

USN-5956-1: PHPMailer vulnerabilities Dawid Golunski discovered that PHPMailer was not properly escaping user input data used as arguments to functions executed by the system shell. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 ESM. (CVE-2016-10033, CVE-2016-10045) It was discovered that PHPMailer was not properly escaping characters in certain fields of the code_generator.php example code. An attacker could possibly use this issue to conduct cross-site scripting (XSS) attacks. This issue was only fixed in Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2017-11503) Yongxiang Li discovered that PHPMailer was not properly converting relative paths provided as user input when adding attachments to messages, which could lead to relative image URLs being treated as absolute local file paths and added as attachments. An attacker could possibly use this issue to access unauthorized resources and [ more… ]

No Image

USN-5955-1: Emacs vulnerability

2023-03-15 KENNETH 0

USN-5955-1: Emacs vulnerability It was discovered that Emacs did not properly manage certain files when using htmlfontify functionality. A local attacker could possibly use this issue to cause a denial of service, or possibly execute arbitrary commands. Source: USN-5955-1: Emacs vulnerability

2023년 AWS 스타트업 지원 프로그램 ‘정글’에 참여하세요!

2023-03-15 KENNETH 0

2023년 AWS 스타트업 지원 프로그램 ‘정글’에 참여하세요! 2020년 시작했던 AWS의 ‘정글’ 프로그램이 다시 돌아왔습니다! 중소벤처기업부·창업진흥원과 협력으로 진행하는 2023년 정글 프로그램은 국내 헬스케어, 생명과학, ESG (환경, 지속가능성) 스타트업들을 위하여 최대 3억의 사업화 자금과 비즈니스/기술 성장을 위한 다양한 교육과 멘토링, 크레딧, 판로개척 지원 등을 제공합니다. 이 글에서 본 프로그램에 대한 상세 개요 및 지원 항목들을 살펴보도록 하겠습니다. 프로그램 소개 ‘정글 프로그램’ 은 중소벤처기업부의 2023년 글로벌 기업 협업 프로그램의 일환으로서 업력 7년 이내의 국내 헬스케어, 생명과학, ESG (환경, 지속 가능성) 스타트업들을 선발합니다. 약 25개 내외 기업들을 선정하여AWS 의 기술 노하우와 국내·외 네트워크를 활용하여 해당 스타트업들이 차기 유니콘 기업으로 성장할 수 있도록 지원하고자 합니다. 선정 절차는 K-Startup 홈페이지에서 3월 28일 (화) 18:00 까지 스타트업 기업을 모집하여 총 2단계의 평가 과정을 거치게 됩니다 (서류평가 후 발표평가). 최종 선발된 25개 내외사의 경우 선발 시점부터 올해 말까지 약 7개월여간 AWS 가 제공하는 다양한 프로그램들을 경험하게 됩니다. 프로그램 [ more… ]

No Image

USN-5952-1: OpenJPEG vulnerabilities

2023-03-15 KENNETH 0

USN-5952-1: OpenJPEG vulnerabilities Sebastian Poeplau discovered that OpenJPEG incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-6851, CVE-2020-8112) It was discovered that OpenJPEG incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-15389, CVE-2020-27814, CVE-2020-27823, CVE-2020-27824, CVE-2020-27841, CVE-2020-27845) It was discovered that OpenJPEG incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could [ more… ]

No Image

USN-5954-1: Firefox vulnerabilities

2023-03-15 KENNETH 0

USN-5954-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2023-25750, CVE-2023-25752, CVE-2023-28162, CVE-2023-28176, CVE-2023-28177) Lukas Bernhard discovered that Firefox did not properly manage memory when invalidating JIT code while following an iterator. An attacker could potentially exploits this issue to cause a denial of service. (CVE-2023-25751) Rob Wu discovered that Firefox did not properly manage the URLs when following a redirect to a publicly accessible web extension file. An attacker could potentially exploits this to obtain sensitive information. (CVE-2023-28160) Luan Herrera discovered that Firefox did not properly manage cross-origin iframe when dragging a URL. An attacker could potentially exploit this issue to perform spoofing attacks. (CVE-2023-28164) Khiem [ more… ]