-
The ins and outs of CVE-2023-23583 (16th Nov 2023)
Preface: The REP MOVSB/STOSB instruction can enhance fast strings attempts to move as much of the data with larger size load/stores as possible. So, a patch exposes ERMS feature to KVM guests in June 2011. Background: REP is a prefix that makes the processor repeat the following instruction. It decrements the RCX register each time…
-
CVE-2023-34060: Whether it hit this design weakness? (14th Nov 2023)
Preface: Before you start reading. Perhaps below two different url will lure your interest of this article. Please read 1 first, then 2 1:vCenter Server Appliance Web Console (VAMI) is removed from vCenter Server 6.0 – https://kb.vmware.com/s/article/2120477 2:Change VCSA 6.7 SSH port – https://communities.vmware.com/t5/VMware-vCenter-Discussions/Change-VCSA-6-7-SSH-port/td-p/1861744 Ref: The vCenter Server appliance is a preconfigured virtual machine that…
-
CVE-2023-47346: A vulnerability encountered on a 5G freeware. But do not contempt these technical factors. Perhaps it also encounter in other similar technology vendors.(14th Nov 2023)
Preface: The technology trend driven transformation in mobile communication world in global. Not only will mobile devices require more RAM to handle 5G-enabled multimedia applications and tasks, As a result, enhancing memory is key to unlocking the 5G future! Background: The free5GC is an open-source project for 5th generation (5G) mobile core networks. The ultimate…
-
The vendor did not provide details of CVE-2023-22107. Will similar vulnerabilities occur in the following scenarios? (13th Nov 2023)
Preface: When we see new vulnerability information posted on forums or NVD. According to market practice, suppliers have provided patches to customers in advance. Maybe they already received the patch earlier (few weeks ago). But a lot of vulnerability items not intend to disclose the details. Perhaps this is the way. It will reduce the…
-
CVE-2023-46604: Apache ActiveMQ is vulnerable to Remote Code Execution (10th Nov 2023)
Preface: While ActiveMQ is a traditional message broker, Apache Kafka is a distributed streaming platform designed to handle high-velocity, high-volume, and fault-tolerant data streams. It was originally developed at LinkedIn and later donated to the Apache Software Foundation. Background: ActiveMQ is open source, message-oriented middleware (MoM). It was written in Java with a full JMS…
-
One of the milestones in the digital world, especially artificial intelligence technology (9th Nov 2023)
Preface: The Matrix is a 1999 science fiction action film. At that time, virtual machines technology were not yet in a mature stage. IBM mainframe LPAR (Logical partitions (LPARs)) is the only implement in market successful. Even Docker technology hasn’t even been born yet! But the film’s screenwriter seemed to predict the truth. What is…
-
CVE-2023-4272: Mali GPU Kernel Driver exposes sensitive data from freed memory (7th Nov 2023)
Preface: ARM’s Mali GPUs can be found in smartphones from different brands, including Samsung, Xiaomi, and Oppo. Mali GPUs can be seen on MediaTek, HiSilicon Kirin, and Exynos SOCs Background: When memory is freed, all pointers into it become invalid, and its contents might either be returned to the operating system, making the freed space…
-
CVE-2023-20702: Null pointer dereference in 5G RLC (6th Nov 2023)
Preface: A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit. Background: An RLC PDU (Protocol Data Unit) consists of an RLC header and data. From an upper layer, RLC receives an RLC SDU (Service Data Unit). The data…
-
The big data driven AI robots development. This is not a dream. (6th Nov 2023)
Preface: As of today AI tools has ChatGPT, BERT, LaMDA, GPT-3, DALL-E-2, MidJourney, and Stable Diffusion. ChatGPT was released as a freely available research preview, but due to its popularity, OpenAI now operates the service on a freemium model. It allows users on its free tier to access the GPT-3.5-based version. Background: Legged robots, or…
-
Regarding CVE-2023-43018, the focus is on defect remediation (2nd Nov 2023)
Preface: Banking industry core applications large portion running on IBM zSystems. The operations including transactional and batch, maintain systems-of-record (SOR) data. Financial Institutions, government organizations, and others have been operating, maintaining, and updating their COBOL applications for many years. The reason behind is that COBOL remains valid while functioning or competing with other modern languages.…