-
About CVE-2023-36054 – design weakness causes Kerberos administration daemon (kadmind) crash! (8th Aug 2023)
Preface: Kerberos runs as a third-party trusted server known as the Key Distribution Center (KDC). Each user and service on the network is a principal. The KDC has three main components: An authentication server that performs the initial authentication and issues ticket-granting tickets for users. Background: Kerberos implementations also exist for other operating systems such…
-
About CVE-2023-33170 – allowing an attacker to try more passwords in dotNET application (updating 7th Aug 2023)
Preface: NET 5 and [.] NET 6 are supported on multiple operating systems, including Windows, Linux, Android, iOS /tvOS, and macOS. The only difference is that[ .] NET 6 is further supported on Windows Arms64 and macOS Apple Silicon while . Background: ASP[.]NET Core 6 is built on top of the [.] NET Core runtime…
-
RHSA-2023:4466 – Security Advisory: RedHat remedy fixed CVE-2022-40899 matter. (3rd Aug 2023)
Preface: future 0.18.2 – Easy, safe support for Python 2/3 compatibility “future“ is the missing compatibility layer between Python 2 and Python 3. It allows you to use a single, clean Python 3.x-compatible codebase to support both Python 2 and Python 3 with minimal overhead. Background: Red Hat Satellite 6 is the evolution of Red…
-
CVE-2023-37464: Mis-config Javascript Object Signing and Encryption [JOSE]. (2nd Aug 2023)
Preface: Encryption uses a key to ensure the ciphertext cannot be deciphered by anyone but the authorized recipient. Signing of data works to authenticate the sender of the data and tends to implement a form of encryption in its process. Background: JSON Object Signing and Encryption (JOSE) is the set of software technologies standardized by…
-
CVE-2023-20583 is Low Risk. But what is a software-based power side channel on an AMD CPU? (2nd Aug 2023)
Preface: AMD explain this design flaw. Do you have any queries? Background: Ryzen is multi-core X86 (64) microprocessors. AMD made its own as an extension of the x86 instruction set. In some AMD processors using frequency scaling . CPU Frequency Scaling is a feature that enables the operating system to scale the CPU frequency up…
-
About CVE-2023-31116: Design weakness of Samsung Exynos Modem 5123 and 5300 (1st Aug 2023)
Preface: RCS enables more dynamic and secure conversations than SMS and MMS. It allows users to share high-resolution photos and videos up to 100MB in size. Background: About one year ago, Google’s next-generation flagship Pixel 7 series appears in the Android 13 developer preview, using Samsung’s baseband chip, model g5300b. RCS is the successor to…
-
Important: CVE-2023-24540 burdens the OpenShift API for Data Protection (OADP), resulting in a security vulnerability (31st Jul 2023)
Preface: Not all valid JavaScript whitespace characters are considered to be whitespace. Templates containing whitespace characters outside of the character set “\t\n\f\r\u0020\u2028\u2029” in JavaScript contexts that also contain actions may not be properly sanitized during execution (CVE-2023-24540) Background: OpenShift API for Data Protection (OADP) enables you to back up and restore application resources, persistent volume…
-
Drones are similar to radio-controlled aircraft, but GPS and (5G or 4G) empowerment are leading the way. (29th Jul 2023)
Preface: Do you think Chinese meaning of intelligence and clever have similar meanings? if you ask me. Perhaps I would say that clever refers to the sensitivity of the ears and eyes. Intelligence is about your brain. Maybe you have other explanations. When you watch a sci-fi movie, the AI core sends out drones to…
-
Time-honored brands face ordeal. Caused by CVE-2023-35078! (26th Jul 2023)
Preface: The company was founded in 2007. MobileIron, he is early pioneer in mobile security and management for smartphones and tablet computers, such as iPhone, iPad, Android…etc. Background: Core supports a number of application program interfaces (APIs): The MobileIron V2 API is a RESTful API you use to send HTTPS requests to get data from…
-
About Apple Neural Engine (CVE-2023-38136) 26th Jul 2023
Preface: We can only use the Neural Engine through Core ML. Core ML is the foundation for domain-specific frameworks and functionality. You can build and train a model with the Create ML app bundled with Xcode. Models trained using Create ML are in the Core ML model format and are ready to use in your…