No Image

Apache Struts2 보안 업데이트 권고

2016-04-29 KENNETH 0

출처 : http://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=24223   □ 개요 o Apache Struts 2에서 원격 코드 실행 취약점 등을 보완한 보안 업데이트 발표[1][2] o 영향 받는 버전의 사용자는 최신버전으로 업데이트 권고 □ 설명 o 원격 코드 실행 취약점(CVE-2016-3081, CVE-2016-3082) [3][4] □ 영향 받는 버전 o Struts 2.0.0 ~ Struts 2.3.28 (2.3.20.3 및 2.3.24.3 제외) □ 해결 방안 o Struts 2.3.20.3, 2.3.24.3, 2.3.28.1로 업데이트 □ 기타 문의사항 o 한국인터넷진흥원 인터넷침해대응센터: 국번 없이 118 [참고사이트] [1 ]http://struts.apache.org/download.cgi#struts23281 [2] http://struts.apache.org/docs/version-notes-23281.html [3] http://struts.apache.org/docs/s2-031.html [4] http://struts.apache.org/docs/s2-032.html

No Image

RHBA-2016:0700-1: glusterfs bug fix update

2016-04-28 KENNETH 0

RHBA-2016:0700-1: glusterfs bug fix update Red Hat Enterprise Linux: Updated glusterfs packages that fix one bug are now available for Red Hat Enterprise Linux 6.6 Extended Update Support. Source: RHBA-2016:0700-1: glusterfs bug fix update

No Image

RHSA-2016:0699-1: Low: Red Hat Enterprise Developer Toolset Version 3.x Six-Month Retirement Notice

2016-04-28 KENNETH 0

RHSA-2016:0699-1: Low: Red Hat Enterprise Developer Toolset Version 3.x Six-Month Retirement Notice This is the Six-Month notification for the retirement of Red Hat Developer Toolset Version 3.x. This notification applies only to those customers subscribed to the channel for Red Hat Developer Toolset Version 3.x. Source: RHSA-2016:0699-1: Low: Red Hat Enterprise Developer Toolset Version 3.x Six-Month Retirement Notice

No Image

USN-2936-1: Firefox vulnerabilities

2016-04-28 KENNETH 0

USN-2936-1: Firefox vulnerabilities Ubuntu Security Notice USN-2936-1 27th April, 2016 firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software description firefox – Mozilla Open Source web browser Details Christian Holler, Tyson Smith, Phil Ringalda, Gary Kwong, Jesse Ruderman,Mats Palmgren, Carsten Book, Boris Zbarsky, David Bolter, Randell Jesup,Andrew McCreight, and Steve Fink discovered multiple memory safety issuesin Firefox. If a user were tricked in to opening a specially craftedwebsite, an attacker could potentially exploit these to cause a denial ofservice via application crash, or execute arbitrary code with theprivileges of the user invoking Firefox. (CVE-2016-2804, CVE-2016-2806,CVE-2016-2807) An invalid write was discovered when using the JavaScript .watch() [ more… ]