No Image

USN-5619-1: LibTIFF vulnerabilities

2022-09-20 KENNETH 0

USN-5619-1: LibTIFF vulnerabilities It was discovered that LibTIFF was not properly performing the calculation of data that would eventually be used as a reference for bound-checking operations. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-19131) It was discovered that LibTIFF was not properly terminating a function execution when processing incorrect data. An attacker could possibly use this issue to cause a denial of service or to expose sensitive information. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-19144) It was discovered that LibTIFF did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted TIFF file using tiffinfo tool, an attacker could possibly use this issue to cause a denial of service. This issue only affected [ more… ]

No Image

USN-5618-1: Ghostscript vulnerability

2022-09-20 KENNETH 0

USN-5618-1: Ghostscript vulnerability It was discovered the Ghostscript incorrectly handled memory when processing certain inputs. By tricking a user into opening a specially crafted PDF file, an attacker could cause the program to crash. Source: USN-5618-1: Ghostscript vulnerability

[도서] IT 용어 도감 엔지니어편

2022-09-20 KENNETH 0

[도서] IT 용어 도감 엔지니어편 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]IT 용어 도감 엔지니어편 마스이 토시카츠 저/김선숙 역 | 성안당 | 2022년 09월 판매가 16,200원 (10%할인) | YES포인트 900원(5%지급) 『IT용어 도감』[엔지니어편]은 동명의 도서의 같은 저자가 낸 후속편으로 일반 대중 보다는 개발자나 웹 제작자, 회사원에 특화된 조금 더 전문 용어를 다룬다. 한 페이지당 한 용어를 쉬운 일러스트로 해설을 넣어 Source: [도서] IT 용어 도감 엔지니어편

No Image

USN-5617-1: Xen vulnerabilities

2022-09-20 KENNETH 0

USN-5617-1: Xen vulnerabilities It was discovered that memory contents previously stored in microarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY read operations on Intel client and Xeon E3 processors may be briefly exposed to processes on the same or different processor cores. A local attacker could use this to expose sensitive information. (CVE-2020-0543) Julien Grall discovered that Xen incorrectly handled memory barriers on ARM-based systems. An attacker could possibly use this issue to cause a denial of service, obtain sensitive information or escalate privileges. (CVE-2020-11739) Ilja Van Sprundel discovered that Xen incorrectly handled profiling of guests. An unprivileged attacker could use this issue to obtain sensitive information from other guests, cause a denial of service or possibly gain privileges. (CVE-2020-11740, CVE-2020-11741) It was discovered that Xen incorrectly handled grant tables. A malicious guest could possibly use this issue to [ more… ]

No Image

USN-5613-2: Vim regression

2022-09-19 KENNETH 0

USN-5613-2: Vim regression USN-5613-1 fixed vulnerabilities in Vim. Unfortunately that update failed to include binary packages for some architectures. This update fixes that regression. We apologize for the inconvenience. Original advisory details: It was discovered that Vim was not properly performing bounds checks when executing spell suggestion commands. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2022-0943) It was discovered that Vim was using freed memory when dealing with regular expressions through its old regular expression engine. If a user were tricked into opening a specially crafted file, an attacker could crash the application, leading to a denial of service, or possibly achieve code execution. (CVE-2022-1154) It was discovered that Vim was not properly performing checks on name of lambda functions. An attacker could possibly use this issue to cause a [ more… ]