No Image

USN-3161-3: Linux kernel (Raspberry Pi 2) vulnerabilities

2016-12-21 KENNETH 0

USN-3161-3: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu Security Notice USN-3161-3 20th December, 2016 linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-raspi2 – Linux kernel for Raspberry Pi 2 Details Tilman Schmidt and Sasha Levin discovered a use-after-free condition in theTTY implementation in the Linux kernel. A local attacker could use this toexpose sensitive information (kernel memory). (CVE-2015-8964) It was discovered that the Video For Linux Two (v4l2) implementation in theLinux kernel did not properly handle multiple planes when processing aVIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial ofservice (system crash) or possibly execute arbitrary code. (CVE-2016-4568) CAI Qian discovered that shared bind mounts in a mount namespaceexponentially added entries without restriction to the Linux kernel's [ more… ]

No Image

USN-3161-4: Linux kernel (Qualcomm Snapdragon) vulnerabilities

2016-12-21 KENNETH 0

USN-3161-4: Linux kernel (Qualcomm Snapdragon) vulnerabilities Ubuntu Security Notice USN-3161-4 20th December, 2016 linux-snapdragon vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-snapdragon – Linux kernel for Snapdragon Processors Details Tilman Schmidt and Sasha Levin discovered a use-after-free condition in theTTY implementation in the Linux kernel. A local attacker could use this toexpose sensitive information (kernel memory). (CVE-2015-8964) It was discovered that the Video For Linux Two (v4l2) implementation in theLinux kernel did not properly handle multiple planes when processing aVIDIOC_DQBUF ioctl(). A local attacker could use this to cause a denial ofservice (system crash) or possibly execute arbitrary code. (CVE-2016-4568) CAI Qian discovered that shared bind mounts in a mount namespaceexponentially added entries without restriction to the Linux kernel's mounttable. A [ more… ]

No Image

USN-3162-1: Linux kernel vulnerabilities

2016-12-21 KENNETH 0

USN-3162-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-3162-1 20th December, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details CAI Qian discovered that shared bind mounts in a mount namespaceexponentially added entries without restriction to the Linux kernel's mounttable. A local attacker could use this to cause a denial of service (systemcrash). (CVE-2016-6213) It was discovered that the KVM implementation for x86/x86_64 in the Linuxkernel could dereference a null pointer. An attacker in a guest virtualmachine could use this to cause a denial of service (system crash) in theKVM host. (CVE-2016-8630) Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementationin the Linux kernel contained a buffer overflow when handling fragmentedpackets. A remote attacker could use [ more… ]

No Image

USN-3162-2: Linux kernel (Raspberry Pi 2) vulnerabilities

2016-12-21 KENNETH 0

USN-3162-2: Linux kernel (Raspberry Pi 2) vulnerabilities Ubuntu Security Notice USN-3162-2 20th December, 2016 linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Summary Several security issues were fixed in the kernel. Software description linux-raspi2 – Linux kernel for Raspberry Pi 2 Details CAI Qian discovered that shared bind mounts in a mount namespaceexponentially added entries without restriction to the Linux kernel's mounttable. A local attacker could use this to cause a denial of service (systemcrash). (CVE-2016-6213) Andreas Gruenbacher and Jan Kara discovered that the filesystemimplementation in the Linux kernel did not clear the setgid bit during asetxattr call. A local attacker could use this to possibly elevate groupprivileges. (CVE-2016-7097) Marco Grassi discovered that the driver for Areca RAID Controllers in theLinux kernel did not properly validate control messages. A local attackercould use this [ more… ]

[도서] Do it! HTML5+CSS3 웹 표준의 정석

2016-12-21 KENNETH 0

[도서] Do it! HTML5+CSS3 웹 표준의 정석 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]Do it! HTML5+CSS3 웹 표준의 정석 고경희 저 | 이지스퍼블리싱 | 2017년 01월 판매가 25,200원 (10%할인) | YES포인트 1,400원(5%지급) 이벤트 : IT모바일 2016 대표도서 2017 기대도서 이벤트 : IT모바일 2016 대표도서 2017 기대도서 웹 분야 1위 도서! HTML 5.1 최종 표준안으로 전면 개정! 대학, 학원 강의 인기 교재! 문과생도, 중학생도 쉽게 배우는 책! 웹 분야 1위 도서인 『Do it! HTML5+CSS3 웹 표준의 정석』이 전면 개정판으로 돌아왔 Source: [도서] Do it! HTML5+CSS3 웹 표준의 정석