2020年1月30日 星期四

RHSA-2020:0122 - java-11-openjdk security update

Description

The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit.
Security Fix(es):
  • OpenJDK: Use of unsafe RSA-MD5 checkum in Kerberos TGS (Security, 8229951) (CVE-2020-2601)
  • OpenJDK: Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604)
  • OpenJDK: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590)
  • OpenJDK: Incorrect isBuiltinStreamHandler causing URL normalization issues (Networking, 8228548) (CVE-2020-2593)
  • OpenJDK: Excessive memory usage in OID processing in X.509 certificate parsing (Libraries, 8234037) (CVE-2020-2654)
  • OpenJDK: Incorrect handling of unexpected CertificateVerify TLS handshake messages (JSSE, 8231780) (CVE-2020-2655)
  • OpenJDK: Incorrect exception processing during deserialization in BeanContextSupport (Serialization, 8224909) (CVE-2020-2583)
REF: https://access.redhat.com/errata/RHSA-2020:0122

Cloudflare Analytics - Unlock the power of your data

insights option 2x
REF: https://www.cloudflare.com/analytics/

2020年1月28日 星期二

RHSA-2020:0124 - git security update

Description

Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need to have permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection.
Security Fix(es):
  • git: Remote code execution in recursive clones with nested submodules (CVE-2019-1387)
REF: https://access.redhat.com/errata/RHSA-2020:0124

Cloudflare: A cost-effective and extensible testbed for transport protocol development


REF: https://blog.cloudflare.com/a-cost-effective-and-extensible-testbed-for-transport-protocol-development/

[USN-4235-1] nginx vulnerability

---------- Forwarded message ---------
From: Marc Deslauriers
Date: Jan 14, 2020 1:10AM

Bert JW Regeer and Francisco Oca Gonzalez discovered that nginx incorrectly
handled certain error_page configurations. A remote attacker could possibly
use this issue to perform HTTP request smuggling attacks and access
resources contrary to expectations.

References:
  https://usn.ubuntu.com/4235-1
  CVE-2019-20372

CISO essentials: How to empower your defenders and security operations with AI

This graph describes how the Microsoft Intelligent Security Graph connects different signals in order to protect all Microsoft solutions from possible threats.
REF: https://discover.microsoft.com/enhancing-security-through-ai-guide/

2020年1月24日 星期五

[USN-4230-1] ClamAV vulnerability

---------- Forwarded message ---------
From: Marc Deslauriers
Date: Jan 8, 2020 11:04PM

It was discovered that ClamAV incorrectly handled certain MIME messages. A
remote attacker could possibly use this issue to cause ClamAV to crash,
resulting in a denial of service.

References:
  https://usn.ubuntu.com/4230-1
  CVE-2019-15961