No Image

USN-2950-2: libsoup update

2016-04-28 KENNETH 0

USN-2950-2: libsoup update Ubuntu Security Notice USN-2950-2 27th April, 2016 libsoup2.4 update A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Summary This update fixes libsoup NTLM authentication. Software description libsoup2.4 – HTTP client/server library for GNOME Details USN-2950-1 fixed vulnerabilities in Samba. The updated Samba packagesintroduced a compatibility issue with NTLM authentication in libsoup. Thisupdate fixes the problem. We apologize for the inconvenience. Original advisory details: Jouni Knuutinen discovered that Samba contained multiple flaws in the DCE/RPC implementation. A remote attacker could use this issue to perform a denial of service, downgrade secure connections by performing a man in the middle attack, or possibly execute arbitrary code. (CVE-2015-5370) Stefan Metzmacher discovered that Samba contained multiple flaws in the NTLMSSP authentication implementation. A remote attacker could use this issue to [ more… ]

No Image

USN-2955-1: Oxide vulnerabilities

2016-04-28 KENNETH 0

USN-2955-1: Oxide vulnerabilities Ubuntu Security Notice USN-2955-1 27th April, 2016 oxide-qt vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Summary Several security issues were fixed in Oxide. Software description oxide-qt – Web browser engine for Qt (QML plugin) Details A use-after-free was discovered when responding synchronously topermission requests. An attacker could potentially exploit this to causea denial of service via application crash, or execute arbitrary code withthe privileges of the user invoking the program. (CVE-2016-1578) An out-of-bounds read was discovered in V8. If a user were tricked in toopening a specially crafted website, an attacker could potentially exploitthis to cause a denial of service via renderer crash. (CVE-2016-1646) A use-after-free was discovered in the navigation implementation inChromium in some circumstances. If a user were tricked in to opening [ more… ]

No Image

USN-2934-1: Thunderbird vulnerabilities

2016-04-28 KENNETH 0

USN-2934-1: Thunderbird vulnerabilities Ubuntu Security Notice USN-2934-1 27th April, 2016 thunderbird vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Several security issues were fixed in Thunderbird. Software description thunderbird – Mozilla Open Source mail and newsgroup client Details Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, DanielHolbert, Jesse Ruderman, and Randell Jesup discovered multiple memorysafety issues in Thunderbird. If a user were tricked in to opening aspecially crafted message, an attacker could potentially exploit these tocause a denial of service via application crash, or execute arbitrary codewith the privileges of the user invoking Thunderbird. (CVE-2016-1952) Nicolas Golubovic discovered that CSP violation reports can be used tooverwrite local files. If a user were tricked in to opening a speciallycrafted website in a browsing context with [ more… ]

Using DNS for Service Discovery with NGINX and NGINX Plus

2016-04-28 KENNETH 0

Using DNS for Service Discovery with NGINX and NGINX Plus One of the great advantages of a microservices architecture is how quickly and easily you can scale service instances. With multiple service instances you need a load balancer and some way to quickly inform it of changes to the set of available service instances. This is known as service discovery. NGINX Plus provides two options for integrating with service discovery systems: the on-the-fly reconfiguration API and Domain Name System (DNS) re-resolution. This blog post focuses on the latter. When you scale service instances (we’ll call them backends in this blog post) by adding or removing virtual machines (VMs) or containers, the configuration of the load balancer must be changed to reflect every change to the set of backends. Scaling can occur multiple times per day, per hour, or even per minute, depending [ more… ]

[도서] 시작하세요! 하둡 프로그래밍

2016-04-28 KENNETH 0

[도서] 시작하세요! 하둡 프로그래밍 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]시작하세요! 하둡 프로그래밍 정재화 저 | 위키북스 | 2016년 05월 판매가 37,800원 (10%할인) | YES포인트 2,100원(5%지급) 빅 데이터의 핵심 플랫폼인 하둡은 대규모 데이터의 분산 처리를 위한 오픈소스 프레임워크다. 더그 커팅이 구글의 논문을 바탕으로 만든 하둡은 초기에는 검색 엔진에서 사용하기 위한 기술로 개발됐지만 지금은 전 Source: [도서] 시작하세요! 하둡 프로그래밍