2020年2月10日 星期一

Cloudflare: Introducing the GraphQL Analytics API: exactly the data you need, all in one place


REF: https://blog.cloudflare.com/introducing-the-graphql-analytics-api-exactly-the-data-you-need-all-in-one-place/

[USN-4252-1] tcpdump vulnerabilities

---------- Forwarded message ---------
From: Marc Deslauriers
Date: Jan 28, 2020 12:27AM

Multiple security issues were discovered in tcpdump. A remote attacker
could use these issues to cause tcpdump to crash, resulting in a denial of
service, or possibly execute arbitrary code.

References:
  https://usn.ubuntu.com/4252-1
  CVE-2017-16808, CVE-2018-10103, CVE-2018-10105, CVE-2018-14461,
  CVE-2018-14462, CVE-2018-14463, CVE-2018-14464, CVE-2018-14465,
  CVE-2018-14466, CVE-2018-14467, CVE-2018-14468, CVE-2018-14469,
  CVE-2018-14470, CVE-2018-14879, CVE-2018-14880, CVE-2018-14881,
  CVE-2018-14882, CVE-2018-16227, CVE-2018-16228, CVE-2018-16229,
  CVE-2018-16230, CVE-2018-16300, CVE-2018-16451, CVE-2018-16452,
  CVE-2018-19519, CVE-2019-1010220, CVE-2019-15166, CVE-2019-15167

One open source chat tool to rule them all

Person using a laptop
REF: https://opensource.com/article/20/1/open-source-chat-tool

MagicSoft Playout ver 7.4.12

MagicSoft Playout ver 7.4.12 was released and it adds the possibility to assign colors to playlist entries ( related to program type and parental rating ).

REF: https://www.magicsoft.tv/news.html

Announcing deeper insights and new monitoring capabilities from Cloudflare Analytics


REF: https://blog.cloudflare.com/announcing-deeper-insights-and-new-monitoring-capabilities/

[USN-4239-1] PHP vulnerabilities

---------- Forwarded message ---------
From: Leonidas S. Barbosa
Date: Jan 15, 2020 10:34PM

It was discovered that PHP incorrectly handled certain files. An attacker
could possibly use this issue to cause a denial of service. This issue only affected
Ubuntu 14.04 ESM, 16.04 LTS, 18.04 LTS, 19.04 and 19.10. (CVE-2019-11045)

It was discovered that PHP incorrectly handled certain inputs. An attacker
could possibly use this issue to expose sensitive information.
(CVE-2019-11046)

It was discovered that PHP incorrectly handled certain images. An attacker
could possibly use this issue to access sensitive information.
(CVE-2019-11047, CVE-2019-11050)

References:
  https://usn.ubuntu.com/4239-1
  CVE-2019-11045, CVE-2019-11046, CVE-2019-11047, CVE-2019-11050

Cloudflare: Delegated Credentials for TLS


REF: https://blog.cloudflare.com/keyless-delegation/