No Image

USN-3360-1: Linux kernel vulnerabilities

2017-07-21 KENNETH 0

USN-3360-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3360-1 21st July, 2017 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel Details It was discovered that the Linux kernel did not properly initialize a Wake-on-Lan data structure. A local attacker could use this to expose sensitiveinformation (kernel memory). (CVE-2014-9900) It was discovered that the Linux kernel did not properly restrict access to/proc/iomem. A local attacker could use this to expose sensitiveinformation. (CVE-2015-8944) It was discovered that a use-after-free vulnerability existed in theperformance events and counters subsystem of the Linux kernel for ARM64. Alocal attacker could use this to cause a denial of service (system crash)or possibly execute arbitrary code. (CVE-2015-8955) It was discovered that the SCSI generic (sg) [ more… ]

No Image

USN-3359-1: Linux kernel vulnerabilities

2017-07-21 KENNETH 0

USN-3359-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3359-1 20th July, 2017 linux, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel linux-raspi2 – Linux kernel for Raspberry Pi 2 Details It was discovered that the Linux kernel did not properly initialize a Wake-on-Lan data structure. A local attacker could use this to expose sensitiveinformation (kernel memory). (CVE-2014-9900) Dmitry Vyukov, Andrey Konovalov, Florian Westphal, and Eric Dumazetdiscovered that the netfiler subsystem in the Linux kernel mishandled IPv6packet reassembly. A local user could use this to cause a denial of service(system crash) or possibly execute arbitrary code. (CVE-2016-9755) Alexander Potapenko discovered a race condition in the Advanced Linux SoundArchitecture (ALSA) subsystem in the Linux kernel. A local attacker coulduse this [ more… ]

No Image

USN-3358-1: Linux kernel vulnerabilities

2017-07-21 KENNETH 0

USN-3358-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3358-1 20th July, 2017 linux, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Summary Several security issues were fixed in the Linux kernel. Software description linux – Linux kernel linux-raspi2 – Linux kernel for Raspberry Pi 2 Details It was discovered that the Linux kernel did not properly initialize a Wake-on-Lan data structure. A local attacker could use this to expose sensitiveinformation (kernel memory). (CVE-2014-9900) Alexander Potapenko discovered a race condition in the Advanced Linux SoundArchitecture (ALSA) subsystem in the Linux kernel. A local attacker coulduse this to expose sensitive information (kernel memory).(CVE-2017-1000380) Li Qiang discovered that the DRM driver for VMware Virtual GPUs in theLinux kernel did not properly validate some ioctl arguments. A localattacker could use this to cause a denial of service (system [ more… ]

No Image

RHSA-2017:1793-1: Important: graphite2 security update

2017-07-21 KENNETH 0

RHSA-2017:1793-1: Important: graphite2 security update Red Hat Enterprise Linux: An update for graphite2 is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2017-7771, CVE-2017-7772, CVE-2017-7773, CVE-2017-7774, CVE-2017-7775, CVE-2017-7776, CVE-2017-7777, CVE-2017-7778 Source: RHSA-2017:1793-1: Important: graphite2 security update

[도서] Beyond Bullet Points 3/e

2017-07-21 KENNETH 0

[도서] Beyond Bullet Points 3/e 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]Beyond Bullet Points 3/e 클리프 앳킨슨 저/문은주 역 | 에이콘출판사 | 2017년 07월 판매가 22,500원 (10%할인) | YES포인트 1,250원(5%지급) 이벤트 : 주목 IT 신간&예약판매 사은품 이벤트 공인된 BBP(Beyond Bullet Points) 에반젤리스트 클리프 앳킨슨은 ‘하나의’ ‘단순’ ‘요약’이라는 세 가지 키워드를 이용해 새로운 제작 방식을 제안한다. 인지 과학 전문가들과 멀티미디어 학습 분야 연구자들 Source: [도서] Beyond Bullet Points 3/e