v

Defining and Calculating Voltage Imbalance

Saving one compressor will cover the cost of a voltage monitor and then some.




v

Nationwide 250 hp Boiler Achieves 5 ppm NOx Performance

Equipped with an Oilon LN30 ultra-low NOx burner and Nationwide’s Eagle PLC-based Control System, the 250 hp package boiler achieved average emissions performance of 5 ppm NOx and 0 ppm CO (corrected to 3% O2) during third-party testing.




v

H2VAC: Using Hydrogen Fuel to Decarbonize Heating and Cooling

Discover how hydrogen fuel is poised to revolutionize HVAC systems by reducing carbon emissions and easing strain on electric grids, driving the industry toward a decarbonized future.




v

Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Xen . org security team on Nov 12

Xen Security Advisory CVE-2024-45819 / XSA-464
version 2

libxl leaks data to PVH guests via ACPI tables

UPDATES IN VERSION 2
====================

Public release.

ISSUE DESCRIPTION
=================

PVH guests have their ACPI tables constructed by the toolstack. The
construction involves building the tables in local memory, which are
then copied into guest memory. While actually used...




v

Xen Security Advisory 463 v2 (CVE-2024-45818) - Deadlock in x86 HVM standard VGA handling

Posted by Xen . org security team on Nov 12

Xen Security Advisory CVE-2024-45818 / XSA-463
version 2

Deadlock in x86 HVM standard VGA handling

UPDATES IN VERSION 2
====================

Public release.

ISSUE DESCRIPTION
=================

The hypervisor contains code to accelerate VGA memory accesses for HVM
guests, when the (virtual) VGA is in "standard" mode. Locking involved
there has an unusual discipline, leaving...




v

CVE-2024-50386: Apache CloudStack: Directly downloaded templates can be used to abuse KVM-based infrastructure

Posted by Daniel Augusto Veronezi Salvador on Nov 12

Severity: important

Affected versions:

- Apache CloudStack 4.0.0 through 4.18.2.4
- Apache CloudStack 4.19.0.0 through 4.19.1.2

Description:

Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the
primary storage for deploying instances. Due to missing validation checks for KVM-compatible templates in CloudStack
4.0.0 through 4.18.2.4 and 4.19.0.0 through 4.19.1.2, an attacker that...




v

Re: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Solar Designer on Nov 12

NIST doesn't appear to provide their own CVSS vectors/scores lately.
However, they republish (with attribution) some third-party ones, this
time from CISA-ADP. The CISA-ADP CVSS vector for this vulnerability
specifies that it not only is network-reachable, but also that it has
High impact not only on Availability, but also on Confidentiality and
Integrity. This results in a CVSSv3.1 score of 9.8. Even merely
correcting the vector not to...




v

Re: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Clemens Lang on Nov 12

Hi,

I think the source for the CISA-ADP data is at [1]. For this specific CVE, the relevant file would be [2]. Their readme
has a section at the bottom, where they encourage feedback:

I’m aware of at last one prior case where a similar case of (IMHO) overblown CVSS scores was discussed in an issue on
this particular GitHub project [3].

Somebody seems to already have opened a ticket for this CVE, too: [4]

[1]:...




v

RE: CVE-2024-36905: Linux kernel: Divide-by-zero on shutdown of TCP_SYN_RECV sockets

Posted by Joel GUITTET on Nov 12

Hello
First thanks to Alexander for reposting because I was not able to do so!
You're right Clemens, I have myself ask the question on this github
(https://github.com/cisagov/vulnrichment/issues/130), but still no information for the moment.
Joel




v

Re: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Andrew Cooper on Nov 12

Data are leaked into the PVShim guest, but it is the shim Xen
(exclusively) which has access to the ACPI tables.

The guest which has been shim'd can't architecturally access the leaked
data.

~Andrew




v

Re: Xen Security Advisory 464 v2 (CVE-2024-45819) - libxl leaks data to PVH guests via ACPI tables

Posted by Demi Marie Obenour on Nov 12

Is this unconditional (perhaps because the relevant data gets zeroed out
by the shim), or does it only apply when the PV guest can't extract data
from the shim's memory? For instance, 32-bit PV guests aren't security
supported anymore, but the PV shim isn't supposed to rely on the
security of the shim itself, only of the rest of the system.




v

CVE-2024-52533: Buffer overflow in socks proxy code in glib < 2.82.1

Posted by Alan Coopersmith on Nov 12

Another CVE was issued by Mitre yesterday for another bug listed on
https://gitlab.gnome.org/Teams/Releng/security/-/wikis/home

https://gitlab.gnome.org/GNOME/glib/-/issues/3461 reports that:
"set_connect_msg() receives a buffer of size SOCKS4_CONN_MSG_LEN but it writes
up to SOCKS4_CONN_MSG_LEN + 1 bytes to it. This is because SOCKS4_CONN_MSG_LEN
doesn't account for the trailing nul character that set_connect_msg() appends...




v

Demand for Frequency Drives on the Uptick

AC drives are an essential part of the HVAC marketplace, and the growth of the market looks to be exceptional over the next few years. According to MarketsandMarkets, the market is expected to grow from an estimated $15.72 billion in 2016 to $22.07 billion by 2021.




v

Honeywell Intl. Inc.: BMS Service

Combining advanced automation and data analytics, Outcome Based Service enables Honeywell service engineers to assess and scrutinize building assets around the clock, promoting the identification of anomalies and misconfigurations.




v

Emerson’s Equipment Evolutions Strengthen HVACR Experience

Emerson continues to evolve its equipment lines in an effort to introduce its technologies to a broader customer base.




v

Commercial HVAC Customers Demand Smart RTUs, Manufacturers Deliver

It is 2018, and this is not your father’s rooftop equipment. The old, reliable system taking up space on the roof has become so much more.




v

See What’s Possible at the New UTC Innovation and Technology Center

United Technologies Corp. (UTC), the parent company of Carrier Corp., recently opened the new UTC Center for Intelligent Buildings in Palm Beach Gardens, Florida.




v

Advanced Refrigeration Technologies Boosting Energy Efficiency in Supermarkets

In supermarkets, where HVAC and refrigeration equipment use 50 to 60 percent of all electricity consumed, new technologies and advanced control strategies have been developed to help boost energy efficiency as well as reduce emissions.




v

Technology Investments For HVAC Contractors Pay in Time Saved

HVAC contractors could invest in all kinds of technology, ranging from tools to management systems, but often, the question lies with the payoff.




v

Aircuity is Approved Vendor for Real-Time Energy Management Program

Aircuity has been named a New York State Energy Research and Development Authority Qualified Vendor for the RTEM program.




v

DOE, Industry Finalize Standards for Commercial HVAC Products

After six meetings, the working group reached consensus and provided recommendations for energy conservation standards, test procedures, and metrics.




v

Portable HVAC Products Provide Specialized Solutions

Since they don’t have to stay in one place, portable cooling units have been known to show up in some pretty unique places. Here’s a closer look at how portable units are serving in some outside-the-box applications.




v

Roof Mount System Secures Solar Racks, HVAC Equipment, and More

OMG Roofing Products has introduced the PowerGrip Plus roof mount system, a watertight structural attachment system used to secure solar racks, HVAC, and other equipment to roofs covered with thermoplastic (TPO and PVC) membranes.




v

Schools Save Energy with CHP

While cogeneration is still largely an industrial process, the market has significant potential for educational institutions coast to coast.




v

Starting Up Idle HVAC Equipment after Summer Vacation

There are things contractors can do to get school equipment back online and ensure it’s operating as efficiently as possible in time for the first school bell this fall.




v

New Products Offer Energy Savings, Comfort

Every year, The NEWS introduces the latest heating equipment that is available for the upcoming winter season. The intent is to help contractors prepare for this busy period by doing the research that will help them to distinguish between brands.




v

Nortek Global HVAC Introduces 3-Phase Light Commercial Air Conditioner

Nortek Global HVAC has introduced a new three-phase electric/electric packaged cooling solution. The company said the Model P8SE delivers 14 SEER cooling in capacity ranges from 3 to 5 tons in even tonnages, making it an energy-efficient choice for strip malls, restaurants, and retail stores.




v

Nortek Global HVAC: Packaged A/C Unit

The Model P8SE light commercial air conditioner is a three-phase electric/electric packaged cooling solution. It delivers 14-SEER cooling in capacities ranging 3-5 ton in even tonnages, making it fit for strip malls, restaurants, and retail stores. 




v

Commercial Cooling Showcase 2016: Summer Heat No Match for HVAC Cooling Equipment

The manufacturers provided all of the data included in the product grid as well as the photo feature. Therefore, any questions should be directed to them via the contact information provided in the photo feature section.




v

Efficiency Standards Prompt Rooftop Innovations

More than half of U.S. commercial building space is cooled by packaged HVAC equipment, according to the U.S. Department of Energy (DOE). So it comes as no surprise that energy efficiency is the biggest trend driving the rooftop market.




v

Commercial Heating Showcase 2016: New HVAC Systems Help Keep the Commercial Market Warm

Each year, The NEWS spotlights the industry’s latest commercial heating products. The manufacturers provided us with a brief description of features included with each product.




v

Now Trending: HVACR

While many educational sessions were presented at the Air-Conditioning, Heating, and Refrigeration (AHR) Expo, perhaps the most popular was the course on global HVAC trends offered by the Building Services Research and Information Association (BSRIA).




v

Serviceability, Flexibility Earn Aaon’s WH Series DDA Gold

Aaon’s focus on serviceability and performance helped the WH Series earn gold in The NEWS’ 2017 Dealer Design Awards HVAC Light Commercial Equipment category.




v

Fujitsu Technical Service Advisors Conference Creates a Unified Front

Fujitsu’s Technical Service Advisors event was held to strengthen manufacturer-distributor relationships and empower in-field technical support staff.




v

Contractors Rank Their Go-to HVAC Tools

We asked our contractor advisory panel to weigh in on their most useful and effective tools used in the field. Here’s what they had to say.




v

The Wireless HVAC Tool Wave

Manufacturers are responding to the demand by offering a wide range of wireless tools they believe will help contractors and technicians do their jobs more accurately and efficiently.




v

Yellow Jacket’s Booth Buzzed with Excitement and Innovation

Just like bees return to the hive every day for sunset, Yellow Jacket has habitually returned to the AHR Expo every January for the past 45 years.




v

Testo Targets Younger Generations with More Innovative Instruments

Last year was a notable one for Testo Inc. as the test and measurement manufacturing company celebrated its 60th anniversary. However, 2018 promises to be just as momentous as Testo US will reach its 35th anniversary milestone.




v

HVAC Pros Discuss Their Favorite Diagnostic Troubleshooting Tools

HVACR technicians are special individuals. They have the intelligence, aptitude, and knack for problem-solving. In fact, they are expected to know how to diagnose and troubleshoot equipment of all types, sizes, and ages.




v

Extech, a division of Flir Systems Inc.: IAQ Meter

This handheld device displays CO, CO2, air temperature, rh, dew point, and wet bulb temperature measurements.




v

Extech, a division of Flir Systems Inc.: Digital Multimeter

Designed for HVAC and refrigeration professionals to view electrical and temperature readings, this product logs data remotely using the ExView® W-Series app on smartphones and tablets via Bluetooth.




v

North Park Innovations Group: System Monitor

This product is a leave-behind HVAC analytic device that technicians can install on each unit, regardless of the brand they service.




v

HVAC Tools Are Becoming More Advanced, Leading to Profit Opportunities

Investing in the right tools will save your employees’ time and avoid delaying repairs in the rush of summer.




v

Tools Roundup for HVACR Pros: Measure, Carry, Flare, and More

This brief year-end tool review rounds up a handful of items that might make the work a little easier in 2021.




v

Remove this email address

Posted by Jose Dominguez via Snort-sigs on Oct 22

Please remove this email address from future notifications




v

Re: Remove this email address

Posted by Joel Esler via Snort-sigs on Oct 23

Thank you for writing in.

Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-sigs

or by sending an email to snort-sigs-leave () lists snort org

Thanks!




v

possible false positive for 'INDICATOR-SHELLCODE x86 setgid 0' can someone confirm

Posted by John via Snort-sigs on Oct 29

When I attempt to download the following xz file, my IPS blocks it with the below populating the snort log. I suspect
this is a false positive unless there is some code in the xz file that is truly malicious. Can someone with more
knowledge about the rule please comment?

Link to file that triggers the match:
http://fl.us.mirror.archlinuxarm.org/armv7h/extra/qt5-base-5.15.15%2Bkde%2Br136-1-armv7h.pkg.tar.xz

Entry from snort log:...




v

Visitors notice

Let your visitors know about news and events on your website as often as possible. You need to keep your website up-to-date so that your visitors will get used to visiting your pages regularly. You can use RSS feeds to deliver new articles directly to your readers.




v

For HVAC Companies, a Phantom Stock Plan Can Revolutionize Retention Packages

Learn how HVAC companies can increase retention by giving their employees a stake in the company’s success through phantom stock plans.




v

Introducing the HVAC Electrify and Decarbonize e-newsletter

ACHR NEWS launches new tools to help readers stay up-to-date on the latest trends.