No Image

USN-5897-1: OpenJDK vulnerabilities

2023-02-28 KENNETH 0

USN-5897-1: OpenJDK vulnerabilities Juraj Somorovsky, Marcel Maehren, Nurullah Erinola, and Robert Merget discovered that the DTLS implementation in the JSSE subsystem of OpenJDK did not properly restrict handshake initiation requests from clients. A remote attacker could possibly use this to cause a denial of service. (CVE-2023-21835) Markus Loewe discovered that the Java Sound subsystem in OpenJDK did not properly validate the origin of a Soundbank. An attacker could use this to specially craft an untrusted Java application or applet that could load a Soundbank from an attacker controlled remote URL. (CVE-2023-21843) Source: USN-5897-1: OpenJDK vulnerabilities

[도서] 머신러닝 for 키즈와 함께하는 AI 인공지능 실습

2023-02-28 KENNETH 0

[도서] 머신러닝 for 키즈와 함께하는 AI 인공지능 실습 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]머신러닝 for 키즈와 함께하는 AI 인공지능 실습 박영희 저 | 광문각출판미디어 | 2023년 03월 판매가 19,000원 (0%할인) | YES포인트 0원(0%지급) 본 교재는 인공지능 분야의 다양한 주제를 다루고 있으며, 예제와 실습 문제를 통해 학습자들이 직접 코드를 작성하고 테스트해 볼 수 있도록 구성되었다. 이 교재를 통해, 학생들은 머신러닝 for 키즈를 이용하여 Source: [도서] 머신러닝 for 키즈와 함께하는 AI 인공지능 실습

No Image

USN-5896-1: Rack vulnerabilities

2023-02-28 KENNETH 0

USN-5896-1: Rack vulnerabilities It was discovered that Rack was not properly parsing data when processing multipart POST requests. If a user or automated system were tricked into sending a specially crafted multipart POST request to an application using Rack, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-30122) It was discovered that Rack was not properly escaping untrusted data when performing logging operations, which could cause shell escaped sequences to be written to a terminal. If a user or automated system were tricked into sending a specially crafted request to an application using Rack, a remote attacker could possibly use this issue to execute arbitrary code in the machine running the application. (CVE-2022-30123) Source: USN-5896-1: Rack vulnerabilities

No Image

USN-5888-1: Python vulnerabilities

2023-02-28 KENNETH 0

USN-5888-1: Python vulnerabilities It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2015-20107) Hamza Avvan discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2021-28861) It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2022-37454, CVE-2022-42919) It was discovered that Python incorrectly handled certain inputs. If a user or an automated system were tricked into running a specially crafted input, [ more… ]

AWS Telco Network Builder – 통신 네트워크 배포 및 관리 서비스 출시

2023-02-28 KENNETH 0

AWS Telco Network Builder – 통신 네트워크 배포 및 관리 서비스 출시 100여 년의 시간 동안 통신 산업은 표준화되고 규제되었으며, 그 과정에서 메소드와 기술, 다양한 용어(흥미로운 두문자어로 가득 차 있음)가 개발되었습니다. 업계에서는 고객에게 최상의 음성 및 데이터 서비스를 제공한다는 명목으로 이 엄청난 유산을 존중하는 동시에 신기술을 활용해야 합니다. 오늘은 AWS Telco Network Builder (TNB)에 대한 이야기를 하려고 합니다. 이 새로운 서비스는 통신 서비스 공급자(CSP)가 AWS에서 공용 및 사설 통신 네트워크를 배포 및 관리할 수 있도록 설계되었습니다. 기존 표준, 관행 및 데이터 형식을 사용하므로 CSP가 AWS의 성능, 규모 및 유연성을 더 쉽게 활용할 수 있습니다. 오늘날 CSP는 종종 코드를 가상 머신에 배포합니다. 그러나 미래를 대비하면서 이들은 추가적인 유연성을 모색하고 있으며 컨테이너를 점점 더 많이 사용하고 있습니다. AWS TNB는 이러한 전환의 일환으로 패키징 및 배포를 위해 Kubernetes와 Amazon Elastic Kubernetes Service(EKS)를 사용합니다. 개념 및 용어 서비스에 대해 자세히 알아보기 전에 이 업계에서 [ more… ]