No Image

USN-5835-1: Cinder vulnerability

2023-01-31 KENNETH 0

USN-5835-1: Cinder vulnerability Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou discovered that Cinder incorrectly handled VMDK image processing. An authenticated attacker could possibly supply a specially crafted VMDK flat image and obtain arbitrary files from the server containing sensitive information. Source: USN-5835-1: Cinder vulnerability

No Image

USN-5835-2: OpenStack Glance vulnerability

2023-01-31 KENNETH 0

USN-5835-2: OpenStack Glance vulnerability Guillaume Espanel, Pierre Libeau, Arnaud Morin, and Damien Rannou discovered that OpenStack Glance incorrectly handled VMDK image processing. An authenticated attacker could possibly supply a specially crafted VMDK flat image and obtain arbitrary files from the server containing sensitive information. Source: USN-5835-2: OpenStack Glance vulnerability

No Image

USN-5833-1: python-future vulnerability

2023-01-31 KENNETH 0

USN-5833-1: python-future vulnerability Sebastian Chnelik discovered that python-future incorrectly handled certain HTTP header field. An attacker could possibly use this issue to cause a denial of service. Source: USN-5833-1: python-future vulnerability

[도서] 마이크로서비스 아키텍처 구축 가이드

2023-01-31 KENNETH 0

[도서] 마이크로서비스 아키텍처 구축 가이드 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]마이크로서비스 아키텍처 구축 가이드 김용욱 저 | 한빛미디어 | 2023년 02월 판매가 28,800원 (10%할인) | YES포인트 1,600원(5%지급) 국내 환경에 최적화된 마이크로서비스 아키텍처 구축 프로세스 마이크로서비스 아키텍처가 세상에 알려진 지 오랜 시간이 지났지만 실무 현장에서는 아직도 마이크로서비스 아키텍처 도입에 대한 많은 의문점을 Source: [도서] 마이크로서비스 아키텍처 구축 가이드

No Image

USN-5832-1: Linux kernel (Raspberry Pi) vulnerabilities

2023-01-31 KENNETH 0

USN-5832-1: Linux kernel (Raspberry Pi) vulnerabilities Kyle Zeng discovered that the sysctl implementation in the Linux kernel contained a stack-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-4378) Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42896) It was discovered that the Xen netback driver in the Linux kernel did not properly handle packets structured in certain ways. An attacker in a guest VM could possibly use this to cause a denial of service (host NIC availability). (CVE-2022-3643) It was discovered that an integer overflow vulnerability existed in the Bluetooth subsystem in the Linux kernel. A physically proximate [ more… ]