-
CVE-2022-29245 – SSH.NET from Sshnet fixes a security flaw in X25519 key exchange that could allow an attacker to eavesdrop on communications to decrypt them.(31st May 2022)
Preface: Login with key is safer than password login, and password login is easily intercepted. Background: Net Framework is a software development platform developed by Microsoft for building and running Windows applications. The . Net framework consists of developer tools, programming languages, and libraries to build desktop and web applications. It is also used to…
-
CVE-2022-1934 Mruby/mruby prior to 3.2 contain Use After Free vulnerability (31st May 2022)
Preface: mruby or mruby/c, mruby / c is an implementation of mruby that inherits the features of Ruby and consumes less memory than the conventional mruby (lightweight Ruby for embedded systems developed in Fukuoka). Dassai|Asahishuzo – (日本獺祭(旭酒造)) also uses mruby/c to develop winery-related monitoring equipment. Background: mruby is a Fukuoka-developed programming language for embedded software.…
-
About macOS Monterey 12.3 (26th May 2022)
Preface: A CVE with similar symptoms occurred in March 2022.CVE-2022-22633 – A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 8.5, iOS 15.4 and iPadOS 15.4, macOS Big Sur 11.6.5, macOS Monterey 12.3. Opening a maliciously crafted PDF file may lead to an unexpected application termination or arbitrary…
-
CVE-2022-1348:This flaw affects logrotate versions before 3.20.0 (28th May 2022)
Preface: Log management allows you to monitor requests at any level (API, database, etc.) and see which are underperforming. Log management is based on log files.Log files are important data points for security and surveillance, providing a full history of events over time. Beyond operating systems, log files are found in applications, web browsers, hardware,…
-
CVE-2022-29246 – Certain versions of Usbx from Azure-rtos contain vulnerabilities, please be aware! 24-May-2022
Preface: The main difference is that FreeRTOS has traditionally been completely open source (MIT license) whereas ThreadX has traditionally been completely commercial / proprietary. Therefore, FreeRTOS is dominating the embedded RTOS market, with something like 20% of new projects using it. Background: Azure RTOS USBX is a high-performance USB host, device, and on-the-go (OTG) embedded…
-
CVE-2022-1467 Who is the one created the vulnerability? (24-05-2022)
Preface:If the operating system itself contains unknown technical matter. When 3rd party application installed, a vulnerability merely encounter on the specified software. Do you think operating system vendor should do the remedy? Or third party vendor take the responsibility? Background: Cybersecurity related to functional safety will be included Powergrid, public facilities and manufacturing industry. SCADA…
-
When you read the news, it mentions unknown things in the universe and you will want to know more.(22nd May 2022)
Preface: How fast are the Voyager computers? Official Reply from NASA: Not very fast compared to today’s standards. The master clock runs at 4 MHz but the CPU’s clock runs at only 250 KHz. A typical instruction takes 80 microseconds, that is about 8,000 instructions per second. To put this in perspective, a 2013 top-of-the-line…
-
This CVE reference number (CVE-2022-21500) whether awaken known design weakness on EBS 12.2. (19th May 2022)
Preface: If a company or organization suffers a data breach, a significant concern is what PII might be exposed—the personal data of the customers that do business or otherwise interact with the entity. Exposed PII can be sold on the dark web and used to commit identity theft, putting breach victims at risk. Background: Within…
-
About CVE-2022-1734 – When Linux finds a vulnerability, how will it affect the IoT or IIoT world. 18 May 2022
Preface: A system on a chip (SoC), is an integrated circuit that integrates all or most components of a computer or other electronic system. A SoC chip may have several GPIO components. Linux doesn’t usually run on Cortex-M, 8051, AVR, or other popular microcontroller architectures. Instead, we use application processors — popular ones are the…
-
Guidelines 04/2022 on the calculation of administrative fines under the GDPR (16 May 2022)
What is the definition of data mishandling in the digital world, it is difficult to define a scope. There may be gaps in definition in different situations. Whether a different angle of justice occurs depends on the undefined element.The European Data Protection Board welcomes comments on the Guidelines 04/2022 on the calculation of administrative fines…