今回は、「電気回路の基礎」についての説明です。 電気回路のイメージ 電気回路の構成要素を言葉で説明すると以下のようになります。 量記号と単位が被っている項目があり、言葉だけだとイメージしづらいかと思います。ですので、図で […]
[ecdsa] Improper Verification of Cryptographic Signature in Pure-Python ECDSA
A flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. Without this verification, a malformed signature could be accepted, making the signature malleable. Without proper veri…
[Twisted] Improper Input Validation in Twisted
In Twisted Web through 20.3.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a p…
[Twisted] HTTP Request Smuggling in Twisted
In Twisted Web through 20.3.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipeline…
[safety] Malicious package may avoid detection in python auditing
Python Auditing Vulnerability
Demonstrates how a malicious package can insert a load-time poison pill to avoid detection by tools like Safety.
Tools that are designed to find vulnerable packages can not ever run in the same python environment that they…
モバイルSuica 利用者が意外と知らない「機種変更前サーバ退避」2分でできる 旧端末でやっておくこと
スマホでピッてやって電車に乗れて、買い物もできるおサイフケータイ。携帯電話キャリアは5G(第5世代移…
COVID-19: Resources to help people learn on YouTube
As more and more families find themselves at home, we know people are learning how to adjust to this situation. Beyond helping people find authoritative sources of news and information, we also want to be a helpful learning resource to families across …
[docutils] python-docutils allows insecure usage of temporary files
python-docutils allows insecure usage of temporary files
References
https://nvd.nist.gov/vuln/detail/CVE-2009-5042
https://security-tracker.debian.org/tracker/CVE-2009-5042
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=560755
https://github.com/ad…
SONY製オーディオプレイヤーの設定方法 ~iTunesによるプレイリスト管理~
SONY製のオーディオプレイヤー。 ウォークマン、デジタルオーディオプレーヤー、ポータブルオーディオプレイヤーなど呼び方は様々です。以下、ウォークマンで呼び方は統一しますね。そのウォークマンの種類の内の1つであるNW-A […]
[requests-kerberos] Improper Authentication in requests-kerberos
python-requests-Kerberos through 0.5 does not handle mutual authentication
References
https://nvd.nist.gov/vuln/detail/CVE-2014-8650
https://github.com/requests/requests-kerberos/issues/35
https://github.com/requests/requests-kerberos/pull/36
https://…