-
About CVE-2023-21666: memory leak vulnerability (3rd May 2023)
Preface: The product does not sufficiently track and release allocated memory after it has been used. Such design weakness will belongs to CWE-401. Background: Snapdragon Heterogeneous Compute SDK: provides developers with the ability to allocate work to any of the three processors on Snapdragon. The SDK provides C++ API’s for the Kryo CPU and Adreno…
-
About CVE-2023-46365: Hard Code value vs access privileges control! (2nd May 2023)
Preface: In order to avoid vulnerabilities, cloud service providers have their hands full! Background: It will be open-sourced under the name of StreamX in April 2021, renamed StreamPark in August 2022, and then formally become an incubation project of the Apache Open Source Software Foundation through voting in September.StreamPark is a streaming application development framework.…
-
About CVE-2023-1786: cloud-init impact Oracle Linux 8 & 9. Fix log file permissions. (27th Apr 2023)
Preface: Open source software fosters collaboration. As such, open source software will continue to play a key role in modern software development. Background: cloud-init is a software package that automates the initialization of cloud instances during system boot. You can configure cloud-init to perform a variety of tasks. Cloud-init is a service used for customizing…
-
About CVE-2023-30841 – Metal Kubed (27th Apr 2023)
Preface: If a website is hacked, cyber criminals don’t get access to your password. Instead, they just get access to the encrypted “hash” created by your password. Talking about hash algotithms, For example, MD5, SHA1, and so on.The length of a hash is always a constant, irrespective of the length of the input. For example,…
-
About CVE‑2023‑25512, CVE‑2023‑25513 & CVE‑2023‑25514 vulnerabilities – NVIDIA CUDA Toolkit (25th Apr 2023)
Preface: In next generation of computing technology, perhaps this so called next generation has came. Any software or hardware design weakness will affected our daily life. It looks that man kind does not have choice, an intangible force push the world to that zone. The situations similar gravity in our earth. Background: Parallel processing is…
-
About CVE-2023-21930: JSSE design weakness (24th Apr 2023)
Preface: The goal is to make internal adjustment to the design of security classes (including the SecurityManager and ClassLoader classes) to reduce the risks of creating subtle security holes in future programming. Background: The Java Secure Socket Extension (JSSE) enables secure Internet communications. It provides a framework and an implementation for a Java version of…
-
About CVE-2023-27536 – Amazon provides alert on “libcurl” design weakness (23rd Apr 2023)
Preface: cURL command is an important Linux tool, commonly used for data transfer and connection troubleshooting. Background: EC2 Instance – Amazon Elastic Compute Cloud (Amazon EC2) provides scalable computing capacity in the Amazon Web Services (AWS) Cloud. Using Amazon EC2 eliminates your need to invest in hardware up-front so that you can develop and deploy…
-
About CVE-2023-2194: Design weakness found in the Linux kernel’s SLIMpro I2C device driver (21st Apr 2023)
Preface: Every day on earth, there is a vulnerable presence in the digital world. This penguin make your life easily, sometimes it was not good. But this is the life cycle of our digital world. Background: This driver (X-Gene SLIMpro I2C Driver) provides support for X-Gene SLIMpro I2C device access using the APM X-Gene SLIMpro…
-
Oracle April 2023 Critical Patch Update Addresses 231 CVEs (19th Apr 2023)
Preface: WebLogic was a company (from 1995 to 1998) credited with creating the first J2EE application server, the WebLogic Application Server. Background: Oracle Fusion Middleware provides the WebLogic Management Framework, which provides heterogeneous management capabilities for Oracle Fusion Middleware products that require basic administrative capabilities.Fusion Middleware Control is a Web-based administration console used to manage…
-
Maybe you need to know – Amazon Linux 2 Security Advisory (19th Apr 2023)
Preface: Is it legal to modify Linux kernel? Yes, it is completely legal to edit the Linux kernel since it is under General Public License – GNU. Background: With Amazon Linux 2, you get an application environment that offers long term support with access to the latest innovations in the Linux ecosystem. Amazon Linux 2…