No Image

USN-5504-1: Firefox vulnerabilities

2022-07-06 KENNETH 0

USN-5504-1: Firefox vulnerabilities Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the browser UI, bypass CSP restrictions, bypass sandboxed iframe restrictions, obtain sensitive information, bypass the HTML sanitizer, or execute arbitrary code. (CVE-2022-2200, CVE-2022-34468, CVE-2022-34470, CVE-2022-34473, CVE-2022-34474, CVE-2022-34475, CVE-2022-34476, CVE-2022-34477, CVE-2022-34479, CVE-2022-34480, CVE-2022-34481, CVE-2022-34484, CVE-2022-34485) It was discovered that Firefox could be made to save an image with an executable extension in the filename when dragging and dropping an image in some circumstances. If a user were tricked into dragging and dropping a specially crafted image, an attacker could potentially exploit this to trick the user into executing arbitrary code. (CVE-2022-34482, CVE-2022-34483) It was discovered that a compromised server could trick Firefox into an addon downgrade in [ more… ]

[도서] 코딩스쿨 터틀과 햄스터로 시작하는 로봇 코딩 첫걸음

2022-07-05 KENNETH 0

[도서] 코딩스쿨 터틀과 햄스터로 시작하는 로봇 코딩 첫걸음 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]코딩스쿨 터틀과 햄스터로 시작하는 로봇 코딩 첫걸음 정일주, 전가현 공저 | 교학사 | 2022년 07월 판매가 8,100원 (10%할인) | YES포인트 450원(5%지급) Source: [도서] 코딩스쿨 터틀과 햄스터로 시작하는 로봇 코딩 첫걸음

No Image

USN-5503-1: GnuPG vulnerability

2022-07-05 KENNETH 0

USN-5503-1: GnuPG vulnerability Demi Marie Obenour discovered that GnuPG incorrectly handled injection in the status message. A remote attacker could possibly use this issue to forge signatures. Source: USN-5503-1: GnuPG vulnerability

No Image

USN-5502-1: OpenSSL vulnerability

2022-07-05 KENNETH 0

USN-5502-1: OpenSSL vulnerability Alex Chernyakhovsky discovered that OpenSSL incorrectly handled AES OCB mode when using the AES-NI assembly optimized implementation on 32-bit x86 platforms. A remote attacker could possibly use this issue to obtain sensitive information. Source: USN-5502-1: OpenSSL vulnerability

[도서] 웹 개발자를 위한 웹 보안

2022-07-05 KENNETH 0

[도서] 웹 개발자를 위한 웹 보안 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]웹 개발자를 위한 웹 보안 말콤 맥도널드 저/장지나 역 | 에이콘출판사 | 2022년 07월 판매가 22,500원 (10%할인) | YES포인트 1,250원(5%지급) 웹 개발자가 알아야 할 공격과 방어를 다룬다! 매년 크게 바뀌지 않는 웹 취약점으로부터 웹사이트를 방어하기 위한 실질적인 방안을 이해하기 쉽게 설명한다. 웹 개발자라면 꼭 알아야 하는 필수 지식이며 예시 Source: [도서] 웹 개발자를 위한 웹 보안