No Image

USN-3330-1: Linux kernel (Qualcomm Snapdragon) vulnerabilities

2017-06-20 KENNETH 0

USN-3330-1: Linux kernel (Qualcomm Snapdragon) vulnerabilities Ubuntu Security Notice USN-3330-1 19th June, 2017 linux-meta-snapdragon, linux-snapdragon vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-snapdragon – Linux kernel for Snapdragon processors Details It was discovered that the stack guard page for processes in the Linuxkernel was not sufficiently large enough to prevent overlapping with theheap. An attacker could leverage this with another vulnerability to executearbitrary code and gain administrative privileges (CVE-2017-1000364) Roee Hay discovered that the parallel port printer driver in the Linuxkernel did not properly bounds check passed arguments. A local attackerwith write access to the kernel command line arguments could use this toexecute arbitrary code. (CVE-2017-1000363) A reference count bug was discovered in the Linux kernel ipx protocolstack. A local [ more… ]

No Image

USN-3331-1: Linux kernel (AWS) vulnerabilities

2017-06-20 KENNETH 0

USN-3331-1: Linux kernel (AWS) vulnerabilities Ubuntu Security Notice USN-3331-1 19th June, 2017 linux-aws, linux-meta-aws vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-aws – Linux kernel for Amazon Web Services (AWS) systems Details It was discovered that the stack guard page for processes in the Linuxkernel was not sufficiently large enough to prevent overlapping with theheap. An attacker could leverage this with another vulnerability to executearbitrary code and gain administrative privileges (CVE-2017-1000364) Roee Hay discovered that the parallel port printer driver in the Linuxkernel did not properly bounds check passed arguments. A local attackerwith write access to the kernel command line arguments could use this toexecute arbitrary code. (CVE-2017-1000363) A reference count bug was discovered in the Linux kernel ipx protocolstack. [ more… ]

No Image

USN-3332-1: Linux kernel (Raspberry Pi 2) vulnerabilities

2017-06-20 KENNETH 0

USN-3332-1: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu Security Notice USN-3332-1 19th June, 2017 linux-meta-raspi2, linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-raspi2 – Linux kernel for Raspberry Pi 2 Details It was discovered that the stack guard page for processes in the Linuxkernel was not sufficiently large enough to prevent overlapping with theheap. An attacker could leverage this with another vulnerability to executearbitrary code and gain administrative privileges (CVE-2017-1000364) Roee Hay discovered that the parallel port printer driver in the Linuxkernel did not properly bounds check passed arguments. A local attackerwith write access to the kernel command line arguments could use this toexecute arbitrary code. (CVE-2017-1000363) A reference count bug was discovered in the Linux kernel ipx protocolstack. [ more… ]

No Image

USN-3333-1: Linux kernel (HWE) vulnerabilities

2017-06-20 KENNETH 0

USN-3333-1: Linux kernel (HWE) vulnerabilities Ubuntu Security Notice USN-3333-1 19th June, 2017 linux-hwe, linux-meta-hwe vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the Linux kernel. Software description linux-hwe – Linux hardware enablement (HWE) kernel Details It was discovered that a use-after-free flaw existed in the filesystemencryption subsystem in the Linux kernel. A local attacker could use thisto cause a denial of service (system crash). (CVE-2017-7374) It was discovered that the stack guard page for processes in the Linuxkernel was not sufficiently large enough to prevent overlapping with theheap. An attacker could leverage this with another vulnerability to executearbitrary code and gain administrative privileges (CVE-2017-1000364) Roee Hay discovered that the parallel port printer driver in the Linuxkernel did not properly bounds check passed arguments. A local attackerwith [ more… ]

[도서] Security in Computing

2017-06-20 KENNETH 0

[도서] Security in Computing 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]Security in Computing 찰스 플리거,샤리 로렌스 플리거,조나단 매굴리스 공저/고은혜,유호석 등역 | 에이콘출판사 | 2017년 06월 판매가 45,000원 (10%할인) | YES포인트 2,500원(5%지급) Security in Computing은 오랫동안 IT 전문가와 보안 전문가, 그리고 이 분야를 공부하는 학생으로부터 사랑을 받아왔다. 5판에서는 고전적인 내용에 더해 현대의 최신 기술, 공격, 표준 및 추세를 반영했다. 현시기 Source: [도서] Security in Computing