No Image

USN-2890-2: Linux kernel (Wily HWE) vulnerabilities

2016-02-02 KENNETH 0

Ubuntu Security Notice USN-2890-2 1st February, 2016 linux-lts-wily vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 14.04 LTS Summary Several security issues were fixed in the kernel. Software description linux-lts-wily – Linux hardware enablement kernel from Wily Details It was discovered that a use-after-free vulnerability existed in theAF_UNIX implementation in the Linux kernel. A local attacker could usecrafted epoll_ctl calls to cause a denial of service (system crash) orexpose sensitive information. (CVE-2013-7446) It was discovered that the KVM implementation in the Linux kernel did notproperly restore the values of the Programmable Interrupt Timer (PIT). Auser-assisted attacker in a KVM guest could cause a denial of service inthe host (system crash). (CVE-2015-7513) It was discovered that the Linux kernel keyring subsystem contained a racebetween read and revoke operations. A local attacker could use this tocause a [ more… ]

No Image

USN-2890-3: Linux kernel (Raspberry Pi 2) vulnerabilities

2016-02-02 KENNETH 0

Ubuntu Security Notice USN-2890-3 1st February, 2016 linux-raspi2 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Summary Several security issues were fixed in the kernel. Software description linux-raspi2 – Linux kernel for Raspberry Pi 2 Details It was discovered that a use-after-free vulnerability existed in theAF_UNIX implementation in the Linux kernel. A local attacker could usecrafted epoll_ctl calls to cause a denial of service (system crash) orexpose sensitive information. (CVE-2013-7446) It was discovered that the KVM implementation in the Linux kernel did notproperly restore the values of the Programmable Interrupt Timer (PIT). Auser-assisted attacker in a KVM guest could cause a denial of service inthe host (system crash). (CVE-2015-7513) It was discovered that the Linux kernel keyring subsystem contained a racebetween read and revoke operations. A local attacker could use this tocause a denial [ more… ]

[도서] 인터넷방송개론

2016-02-02 KENNETH 0

분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]인터넷방송개론 김기수 저 | 정일 | 2016년 02월 판매가 22,500원 (10%할인) | YES포인트 250원(1%지급) 이 책은 전체적으로 5부 19장으로 구성되어 있으며 내용을 간단히 소개하면 다음과 같다. 제1부에서는 인터넷방송의 이해를 위하여 인터넷, 방송과 디지털방송의 기본적인 내용을 소개하였으며, 제2부에서는 인터넷 Source: yes24.com-computer-internet

No Image

RHSA-2016:0095-1: Moderate: redis security advisory

2016-02-02 KENNETH 0

Red Hat Enterprise Linux: Updated redis packages that fix a security issue are now available for Red Hat Enterprise Linux OpenStack Platform 6.0. Red Hat Product Security has rated this update as having Moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. CVE-2015-8080 Source: rhn-errata

No Image

USN-2884-1: OpenJDK 7 vulnerabilities

2016-02-02 KENNETH 0

Ubuntu Security Notice USN-2884-1 1st February, 2016 openjdk-7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 15.04 Ubuntu 14.04 LTS Summary Several security issues were fixed in OpenJDK 7. Software description openjdk-7 – Open Source Java implementation Details Multiple vulnerabilities were discovered in the OpenJDK JRE relatedto information disclosure, data integrity, and availability. Anattacker could exploit these to cause a denial of service, exposesensitive data over the network, or possibly execute arbitrary code.(CVE-2016-0483, CVE-2016-0494) A vulnerability was discovered in the OpenJDK JRE related to dataintegrity. An attacker could exploit this to expose sensitive dataover the network or possibly execute arbitrary code. (CVE-2016-0402) It was discovered that OpenJDK 7 incorrectly allowed MD5 to be usedfor TLS connections. If a remote attacker were able to perform aman-in-the-middle attack, this flaw could be exploited to exposesensitive [ more… ]