No Image

USN-2946-1: Linux kernel vulnerabilities

2016-04-06 KENNETH 0

USN-2946-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-2946-1 6th April, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details Venkatesh Pottem discovered a use-after-free vulnerability in the Linuxkernel's CXGB3 driver. A local attacker could use this to cause a denial ofservice (system crash) or possibly execute arbitrary code. (CVE-2015-8812) Xiaofei Rex Guo discovered a timing side channel vulnerability in the LinuxExtended Verification Module (EVM). An attacker could use this to affectsystem integrity. (CVE-2016-2085) David Herrmann discovered that the Linux kernel incorrectly accounted filedescriptors to the original opener for in-flight file descriptors sent overa unix domain socket. A local attacker could use this to cause a denial ofservice (resource exhaustion). (CVE-2016-2550) It was discovered that the Linux [ more… ]

No Image

USN-2946-2: Linux kernel (Trusty HWE) vulnerabilities

2016-04-06 KENNETH 0

USN-2946-2: Linux kernel (Trusty HWE) vulnerabilities Ubuntu Security Notice USN-2946-2 6th April, 2016 linux-lts-trusty vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 12.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-trusty – Linux hardware enablement kernel from Trusty for Precise Details Venkatesh Pottem discovered a use-after-free vulnerability in the Linuxkernel's CXGB3 driver. A local attacker could use this to cause a denial ofservice (system crash) or possibly execute arbitrary code. (CVE-2015-8812) Xiaofei Rex Guo discovered a timing side channel vulnerability in the LinuxExtended Verification Module (EVM). An attacker could use this to affectsystem integrity. (CVE-2016-2085) David Herrmann discovered that the Linux kernel incorrectly accounted filedescriptors to the original opener for in-flight file descriptors sent overa unix domain socket. A local attacker could use this to cause a denial ofservice (resource [ more… ]

No Image

USN-2947-1: Linux kernel vulnerabilities

2016-04-06 KENNETH 0

USN-2947-1: Linux kernel vulnerabilities Ubuntu Security Notice USN-2947-1 6th April, 2016 linux vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Summary Several security issues were fixed in the kernel. Software description linux – Linux kernel Details Ralf Spenneberg discovered that the usbvision driver in the Linux kerneldid not properly sanity check the interfaces and endpoints reported by thedevice. An attacker with physical access could cause a denial of service(system crash). (CVE-2015-7833) Venkatesh Pottem discovered a use-after-free vulnerability in the Linuxkernel's CXGB3 driver. A local attacker could use this to cause a denial ofservice (system crash) or possibly execute arbitrary code. (CVE-2015-8812) Xiaofei Rex Guo discovered a timing side channel vulnerability in the LinuxExtended Verification Module (EVM). An attacker could use this to affectsystem integrity. (CVE-2016-2085) It was discovered that the extended Berkeley Packet Filter [ more… ]

Globo.com’s Live Video Platform for FIFA World Cup ’14- Part II – DVR and Microservices

2016-04-06 KENNETH 0

Globo.com’s Live Video Platform for FIFA World Cup ’14- Part II – DVR and Microservices The following is adapted from a presentation given by Leandro Moreira and Juarez Bochi of Globo.com at nginx.conf 2015, held in San Francisco in September. This blog post is the second of two parts, and is focused on using NGINX to build microservices. The first part, focused on delivery and caching, can be found here. You can watch the video of the complete talk on YouTube. Table of Contents 19:02 DVR 20:24 DVR Challenges – Failover 21:06 DVR Challenges – Storage 22:11 Redis as a Datastore 23:20 Brazil’s General Election 24:12 From Redis to Cassandra 25:11 Waiting Room 27:40 Waiting Room Architecture 29:02 FIFA 2014 World Cup Results 31:00 Recap and Next Steps 31:58 NGINX + Lua is Amazing 33:17 Open Source Software Development 33:55 [ more… ]

No Image

RHSA-2016:0598-1: Moderate: jboss-ec2-eap security, bug fix, and enhancement update

2016-04-06 KENNETH 0

RHSA-2016:0598-1: Moderate: jboss-ec2-eap security, bug fix, and enhancement update Red Hat Enterprise Linux: A jboss-ec2-eap update is now available for Red Hat JBoss Enterprise Application Platform 6.4.7 on Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2014-0230, CVE-2016-2094 Source: RHSA-2016:0598-1: Moderate: jboss-ec2-eap security, bug fix, and enhancement update