-
CISA Urges Beware of BlackBerry (QNX RTOS) Vulnerabilities – 17th Aug 2021
Preface: BlackBerry OS was discontinued after the release of BlackBerry 10. BlackBerry 10 is based on QNX, a Unix-like operating system that was originally developed by QNX Software Systems until the company was acquired by BlackBerry in April 2010. It supports the application framework Qt (version 4.8) and in some later models features an Android…
-
CVE-2021-38197 – vulnerability encountered in “go-unarr”. Not suggest to use until it fix. (16th Aug, 2021)
Preface: Gobot is a framework for robotics, drones, and the Internet of Things (IoT), written in the Go programming language. The design goal of the decompression library is for embedded devices, because the flash memory capacity is limited and the processing speed is slow. Background: Package unarr is a decompression library for RAR, TAR, ZIP…
-
A vulnerability in the XML data compression tool (Xml) jeopardizing the Schneider Control Expert software (16th Aug, 2021)
Preface: Since xml data is irregular and verbose, it can impact both query processing and data exchange. Background: XMill is a tool for compressing XML data efficiently. It is based on a regrouping strategy that leverages the effect of highly-efficient compression techniques in compressors such as gzip (Please refer to attached diagram for details). The…
-
The Qixi Festival (GMT+8, 14th Aug, 2021)
Preface: It is no doubt that coincide often appears myth stories handed down from ancient times. The coincides is related to the astronomical phenomenon. Mythological background: Legend has it that since the Northern and Southern Dynasties, the seventh day of the lunar calendar is the daywhen Altair(牛郎) and Vega(織女) meet once a year. It is…
-
CVE-2021-34484 – Was the error that occurred a return? 12th Aug 2021
Preface: Type the following command and hit Enter. mklink /J “path to junction link” “path to target folder”. The junction link is thus created. Background: By creating a new folder structure, changing the user’s shell folder registry key, and placing a connection point in the hierarchy,you can open any other UsrClass[.]dat file on the system…
-
Cyber Security Focus SAP Security Patch Day-August 2021. About CVE-2021-33690 (August 10, 2021)
Preface: Software Development Life Cycle is the application of standard business practices to building software applications. It’s typically divided into six to eight steps: Planning, Requirements, Design, Build, Document, Test, Deploy, Maintain. Background: The SAP NetWeaver development infrastructure combines the features and advantages of a local development environment (usually provided in a Java environment) and…
-
A vulnerability exists in Dream Security (Korea)’s PKI Security product. Remind us to pay attention to the baseline design. 9th Aug 2021
Preface: Public key infrastructure (PKI) governs the issuance of digital certificates to protect sensitive data, provide unique digital identities for users, devices and applications and secure end-to-end communications. Technical background: From a technical point of view, application software is installed on the host and provides functions (listening to data on open ports or sending data to the…
-
CVE-2021-38203 – About btrfs design defect (9th Aug 2021)
Preface: The following companies use Btrfs in production: Facebook (testing in production as of 2014/04, deployed on millions of servers as of 2018/10) Jolla (smartphone) Lavu (iPad) point of sale solution. Background: Btrfs is an advanced file system, jointly developed by an organization, and now specific Synology NAS models support this file system.Btrfs is now…
-
Security Focus – Host header tampering leading to server-side request on internal restricted service (5-8-2021)
Preface: HTTP Host header attacks exploit vulnerable websites that handle the value of the Host header in an unsafe way. Background: After the initial configuration of Workspace ONE Access is complete, administrator can go to the Workspace ONE Access console pages to install certificates, manage passwords, and download log files. You can also update the…
-
CVE-2021-33403 – Lancer Token Ethereum ERC20 Token integer overflow (4-8-2021)
Preface: As of 4th Aug, 2021. There are 8106 unique holders of Lancer Token now on total amount 151 377 339,14 LNC. Background: One of the most significant Ethereum tokens is known as ERC-20. ERC-20 tokens are issued on the Ethereum network. As of October 2019, more than 200,000 ERC-20-compatible tokens exist on Ethereum’s main…