-
About NVIDIA GPU vulnerabilities -22nd Nov 2021
Preface: NVIDIA, the inventor of the Graphics Processing Unit (GPU) brings visual computing excellence to the embedded world. High performance meets low power with the NVIDIA Tegra processor – get ready for HD video, crisp graphics and unprecedented 3D capabilities, all in one power efficient package. Background: GPUDirect Storage kernel driver nvidia-fs.ko is a kernel…
-
Vulnerabilities discovered so far in GCC c++filt v2.26.Is it all solved now? (18-11-2021)
Preface: Not limited to traditional Linux, Apple also has cplus-dem[.]c open source. Background: What is GCC used for? GCC stands for GNU Compiler Collections which is used to compile mainly C and C++ language. It can also be used to compile Objective C and Objective C++. File (cplus-dem.c) lives in both GCC and libiberty. Cplus-dem[.]cis…
-
CVE-2021-43997 – Amazon FreeRTOS encounter vulnerability (18th Nov, 2021)
Preface: Amazon now “owns” FreeRTOS, in the sense that the company will provide all support going forward. FreeRTOS includes a kernel and a growing set of software libraries suitable for use across industry sectors and applications. To support a growing number of use cases, AWS provides software libraries that offer enhanced functionality including connectivity, security,…
-
Security Focus on SMU Mailbox (CVE-2021-26331) -16th Nov 2021
Preface: Quick way to understand difference in between Ryzen and EPYC (see below): About Ryzen: Some said, Ryzen CPUs are best suited for gaming PCs.However, AMD has announced its newest range of mobile chips,the Ryzen 5000 mobile series, which it claims will be used in 1500 devices during 2021. About EPYC: AMD and Google Cloud…
-
Review of major events (from windows 7 to AMD display driver design weakness) 15th Nov, 2021
Preface: Long time ago, digital world try to avoid malware infection. Malware has few different types. Memory-resident malware, also known as fileless malware, is a type of malicious software that writes itself directly onto a computer’s system memory. This behavior leaves very few signs of infection, making it difficult for traditional tools and non-experts to…
-
CVE-2021-22101 – If someone can run out of resources, this is similar to a denial of service technique! (11-11-2021)
Preface: Who cares about spending all your money, maybe just yourself! Who cares about running out of your system resources, perhaps it is the system owner. Background: VMware Tanzu Application Service is a modern application platform for enterprises that want to continuously deliver and run microservices across clouds. Release new features and updates to production…
-
VMware – Security advisory to address a privilege escalation vulnerability in vCenter Server and Cloud Foundation – 10th Nov, 2021
Preface: Every Windows system is vulnerable to a particular NTLM relay attack that could allow attackers to escalate privileges from User to Domain Admin. Background: If your administration portal is a web application which protected by IWA (Integrated Windows Authentication). When client send a request to web server doing handshaking, the web server will be…
-
Are you struggling with weaknesses in the SAP design – CVE-2021-40501? 9th Nov, 2021
Preface: In the digital world, it always has unexpected problems. Background: SAP kernel is the core component of any SAP system. It includes executable files on the SAP server, which are used to connect to the system and execute SAP programs. In the SAP system environment, remote function call (RFC) is one of the main…
-
“excessive resource usage” in jsonrpc whether Citrix announcement (CTX 330728 ) security focus? (9th Nov 2021)
Preface: The Citrix ADC NITRO protocol allows you to configure and monitor the Citrix ADC appliance programmatically by usingRepresentational State Transfer (REST) interfaces. Therefore, NITRO applications can be developed in any programming language.Additionally, for applications that must be developed in Java or .NET or Python, NITRO APIs are exposed through relevant librariesthat are packaged as…
-
Siemens Security Advisory by Siemens ProductCERT – 9th Nov 2021
Preface: Directory traversal (path traversal) happens when the attacker is able to read files on the web server outside of the directory of the website. Directory traversal is only possible if the website developer makes mistakes. Background: SIMATIC PCS 7 Web can be used to operate and monitor aplant via Intranet or Internet. Extensive configuration…