No Image

USN-6167-1: QEMU vulnerabilities

2023-06-19 KENNETH 0

USN-6167-1: QEMU vulnerabilities It was discovered that QEMU did not properly manage the guest drivers when shared buffers are not allocated. A malicious guest driver could use this issue to cause QEMU to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-1050) It was discovered that QEMU did not properly check the size of the structure pointed to by the guest physical address pqxl. A malicious guest attacker could use this issue to cause QEMU to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS and Ubuntu 22.10. (CVE-2022-4144) It was discovered that QEMU did not properly manage memory in the ACPI Error Record Serialization Table [ more… ]

[도서] 원리가 보이는 파이썬 빅데이터 분석 기초와 실습

2023-06-19 KENNETH 0

[도서] 원리가 보이는 파이썬 빅데이터 분석 기초와 실습 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]원리가 보이는 파이썬 빅데이터 분석 기초와 실습 천세학 저 | 한빛아카데미 | 2023년 06월 판매가 28,000원 (0%할인) | YES포인트 0원(0%지급) 원리를 이해하며 배우는 파이썬 빅데이터 분석 첫째, 핵심 원리가 보이는 다양한 예제! 쉽고 간결한 예제로 파이썬 프로그래밍 기초와 데이터 분석 기본 문법의 핵심 원리를 이해할 수 있습니다. 둘째, 분석과 시 Source: [도서] 원리가 보이는 파이썬 빅데이터 분석 기초와 실습

No Image

USN-6175-1: Linux kernel vulnerabilities

2023-06-17 KENNETH 0

USN-6175-1: Linux kernel vulnerabilities Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-32233) Gwangun Jung discovered that the Quick Fair Queueing scheduler implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-31436) Reima Ishii discovered that the nested KVM implementation for Intel x86 processors in the Linux kernel did not properly validate control registers in certain situations. An attacker in a guest VM could use this to cause a denial of service (guest crash). (CVE-2023-30456) It was discovered that the Broadcom [ more… ]

No Image

USN-6174-1: Linux kernel (OEM) vulnerabilities

2023-06-17 KENNETH 0

USN-6174-1: Linux kernel (OEM) vulnerabilities Jordy Zomer and Alexandra Sandulescu discovered that the Linux kernel did not properly implement speculative execution barriers in usercopy functions in certain situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2023-0459) It was discovered that the Human Interface Device (HID) support driver in the Linux kernel contained a type confusion vulnerability in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-1073) It was discovered that the NTFS file system implementation in the Linux kernel did not properly handle a loop termination condition, leading to an out-of-bounds read vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-26606) Source: USN-6174-1: Linux kernel (OEM) vulnerabilities

No Image

USN-6173-1: Linux kernel (OEM) vulnerabilities

2023-06-17 KENNETH 0

USN-6173-1: Linux kernel (OEM) vulnerabilities Gwangun Jung discovered that the Quick Fair Queueing scheduler implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-31436) It was discovered that the Broadcom FullMAC USB WiFi driver in the Linux kernel did not properly perform data buffer size validation in some situations. A physically proximate attacker could use this to craft a malicious USB device that when inserted, could cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-1380) Ruihan Li discovered that the bluetooth subsystem in the Linux kernel did not properly perform permissions checks when handling HCI sockets. A physically proximate attacker could use this to cause a denial of service (bluetooth communication). (CVE-2023-2002) It was discovered that [ more… ]