-
SAP GUI chronicle – even you are using NWBC client, can you ignore web browser vulnerability? (17th Feb 2023)
Preface: It was the periodically recurring SAP Security Note #2622660 which patches the latest Chromium vulnerabilities for SAP Business Client. Background: Difference between SAP NWBC and SAP GUI?Web Dynpro is the SAP NetWeaver programming model for user interfaces (UIs).– Using SAP GUI, when you execute WD (Web Dynpro) application, it opens in a browser. -The…
-
CVE-2023-20927 About Android “AndroidManifest[.]xml” (15th Feb 2023)
Preface: When an Android application needs to access sensitive resources on the device, whether it hit design weakness lead to vulnerability occurs. Background: Usually, if we want to add some user permissions, we write the following code in the AndroidManifest[.]xml file: The android system grants these permissions at the installation time but there is one…
-
CVE-2023-21808 – Patched MS zero-day vulnerability (14th Feb 2023)
Preface: .NET is a free, cross-platform, open source developer platform for building many different types of applications. With .NET, you can use multiple languages, editors, and libraries to build web, mobile, desktop, games, IoT, and more. Background: The demand for .NET will continue to increase as long as new and better technologies are developed.NET 6…
-
CVE-2023-0405: Like a newborn. AI in some fields may have design weakness. (14th Feb 2023)
Preface: Today is Valentine’s Day 2023, are you alone? But in the future artificial intelligence will be with you. Background: With an AI content writer, all you need to do is enter your desired topic or keyword into the plugin settings, and then AI will immediately generate an article that reads as if it were…
-
CVE-2022-42292 : Nvidia fixed GeForce Experience design weakness (13th Feb 2023 )
Preface: This design weakness was released 30th Jan 2023. However, this vulnerability is known as CVE-2022-42292 since 10/03/2022. But it already been fixed. Background: The GeForce Experience features a host of performance and configuration tweaks for games, automatic driver updates for your GPU, Nvidia Shadowplay for live streaming, integrated game filters (like Instagram filters but…
-
CVE-2023-23625 Certain versions of Go-unixfs from Ipfs contain vulnerability (9th Feb 2023)
Preface: AI system infrastructure may not have a mature model, it will continue forever, without end. Perhaps this is true sustainability. Since the key component is the computer. So the only thing that slows him down is software or hardware bugs. Background: Cryptocurrency technology fully utilise the concept of Blockchain. Seems the advantage of cryptocurrency…
-
CVE-2023-0286: X.400 address type confusion in X.509 GeneralName. What exactly does it mean? (8th Feb 2023)
Preface: What is the benefits of corrective action. A motivation to maintain sustainability. Background: Background: X.509 describes an approach to providing and managing authentication using asymmetric cryptography, generally referred to as Public Key Infrastructure (PKI).If X.400 defined authentication mechanism using x.509 PKI:It enhance end to end services for content integrity, message origin authentication and message…
-
CVE-2023-23931 – cryptography (7th Feb 2023)
Preface: PyCrypto is no longer under active development (project is dead – 2015). For details, see the link – https://github.com/pycrypto/pycrypto/issues/173“cryptography” is a package which provides cryptographic recipes and primitives to Python developers. The goal is for it to be your “cryptographic standard library”. It supports Python 3.6+ and PyPy3 7.2+. Background: “cryptography” is a package…
-
Who empower knowledge to AI (artificial intelligence). Perhaps the answer is you. (7th Feb 2023)
Preface: Einstein’s formula e=mc2 opened the door to the world of science and the universe. Since the equation involves complex and advanced arithmetic. So no one can simply describe it.Modern civilisation relies on digital computing. Our daily lives involve smartphones, smart cities and countless so-called Internet of Things (IoT) devices. But who empower knowledge to…
-
Whether it is the last round of remediation on CVE-2022-26373? Intel’s Enhanced Indirect Branch Restricted Speculation (eIBRS) – 6th Feb 2023
Preface: CVE-2022-26373 technical detail has released to public on 9th Aug 2022. Till end of Jan, 2023 it still has update on this vulnerability. For example, Red Hat fixed this vulnerability in their product Enterprise Linux 7 on 3rd Nov 2022. Since then it conducting the remediation to their product line. Perhaps the remediation on…