2009年5月11日月曜日

11日 月曜日、友引

MySQL Workbench 5.2.0 alpha released
http://dev.mysql.com/downloads/workbench/5.2.html

[ANNOUNCE] Apache Derby 10.5.1.1 released
http://db.apache.org/derby/derby_downloads.html

[FreeBSD-Announce] FreeBSD supported branches update
http://security.freebsd.org/

[ANNOUNCE] Contest: PostgreSQL Website Redesign
http://wiki.postgresql.org/wiki/Website_Overhaul_Requirements

[ANNOUNCE] Postgres monitoring tool check_postgres version 2.8.0
http://bucardo.org/check_postgres/

[ANNOUNCE] Jopr 2.2 has been released
http://www.jboss.org/jopr/

[ANNOUNCE] New version of PostgreSQL 8.3 Live CD released
http://yum.pgsqlrpms.org/livecd.php

[ANNOUNCE] pgAdmin v.1.10.0 Beta 3 now available
http://www.postgresql.org/ftp/pgadmin3/release/v1.10.0-beta3/

[ANNOUNCE] Npgsql 2.0.5 released!
http://pgfoundry.org/frs/shownotes.php?release_id=1366

[ANNOUNCE] PgUS recieves official public charity 501c3 status!
https://www.postgresql.us/determination_letter

[ANNOUNCE] PGDay.EU 2009
http://www.pgday.eu/

[ANNOUNCE] Slony-I Releases - 2.0.2 and 1.2.16
http://slony.info/

+ [courier-announce] courier-imap 4.5.0 released
http://www.courier-mta.org/download.php#imap

[courier-announce] Courier 0.62.0 released
http://www.courier-mta.org/download.php

Package: maildrop released
http://prdownloads.sourceforge.net/courier/maildrop-2.1.0.tar.bz2

The latest snapshot for the stable Linux kernel tree is: 2.6.30-rc5-git1
http://git.kernel.org/?p=linux%2Fkernel%2Fgit%2Ftorvalds%2Flinux-2.6.git;a=summary

Postfix 2.7 Snapshot 20090510
http://mirror.postfix.jp/postfix-release/experimental/postfix-2.7-20090510.HISTORY

弊社サポートページメンテナンスのお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1257

Trend Micro InterScan Web Security Suite 3.1 Solaris 版 公開とサポート開始のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1248

「ビジネスパートナー選定時に情報セキュリティ対策を意識する」企業は7割超
http://itpro.nikkeibp.co.jp/article/Research/20090511/329750/?ST=security

カリフォルニア大学バークレー校で,最大16万人分の個人情報に不正アクセス
http://itpro.nikkeibp.co.jp/article/NEWS/20090511/329737/?ST=security

富士通とウィルコム、電源オフでもデータを消せるPC紛失・盗難対策を発表
内蔵のPHS端末を利用して遠隔操作をする技術をウィルコムと開発
http://itpro.nikkeibp.co.jp/article/NEWS/20090507/329666/?ST=security

JVN#03114223 SKIPユーザグループ製 SKIP における SQL インジェクションの脆弱性
http://jvn.jp/jp/JVN03114223/index.html

JVN#43233160 SKIPユーザグループ製 SKIP におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN43233160/index.html

JVNDB-2009-000026 SKIPユーザグループ製 SKIP における SQL インジェクションの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000026.html

JVNDB-2009-000025 SKIPユーザグループ製 SKIP におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000025.html

JVNDB-2009-001201 PHP の JSON_parser 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001201.html

JVNDB-2009-001200 PHP の php_zip_make_relative_path 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001200.html

JVNDB-2009-001199 Sun Solaris の xscreensaver における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001199.html

JVNDB-2009-001198 Apache Tomcat の JK Connector における重要な情報が取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001198.html

Pango Heap Allocation Size Calculations Integer Overflow
http://www.securiteam.com/unixfocus/5WP012KR5W.html

HP OpenView Network Node Manager (OV NNM) Denial of Service (DoS)
http://www.securiteam.com/unixfocus/5XP022KR5G.html

libwmf Packages Vulnerable to Denial of Service
http://www.securiteam.com/unixfocus/5YP032KR5G.html

HPUX Running Useradd(1M) Local Unauthorized Access
http://www.securiteam.com/unixfocus/5ZP042KR5W.html



NTP 4.2.4p7-RC6 Released
http://www.ntp.org/downloads.html

+ Linux 2.6.29.3 Released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.29.3

+ Linux 2.6.27.23 Released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.23

+ RHSA-2009:0476-01: Important: pango security update
http://rhn.redhat.com/errata/RHSA-2009-0476.html

Changes in MySQL 6.0.11 (Not yet released)
http://dev.mysql.com/doc/refman/6.0/en/news-6-0-11.html

The latest prepatch for the stable Linux kernel tree is: 2.6.30-rc5
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.30-rc5

PHP: TestFest 2009
http://www.php.net/archive/2009.php#id2009-05-09-1

ISSKK(http://www.isskk.co.jp/)サイト移行・統合のお知らせ
http://www.isskk.co.jp/isskktoibm.html

Collecting diagnostic information for VMware Converter
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010633&sliceId=1&docTypeID=DT_KB_1_1

Claroline-SA-05/08/2009: Claroline v.1.8.11 Cross-Site Scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29208

RHSA-2009:0476-01: Important: pango security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29203

「USBウイルス」の感染報告が9カ月連続で最多、「ダウンアド」も増加中
トレンドマイクロが2009年4月の報告状況、異なる亜種の出現に注意
http://itpro.nikkeibp.co.jp/article/Research/20090508/329700/?ST=security

偽のWindows 7 RC版に注意、インストールするとウイルス感染
別のウイルスを次々とダウンロード、PCを乗っ取られる恐れあり
http://itpro.nikkeibp.co.jp/article/NEWS/20090508/329690/?ST=security

[SECURITY] [DSA 1797-1] New xulrunner packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00072.html

[TZO-21-2009] Fprot CAB bypass / evasion
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00074.html

[TZO-20-2009] AVG ZIP evasion / bypass
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00070.html

Changes : [TZO-17-2009]Trendmicro multiple bypass/evasions
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00073.html

speaker Bill Blunden on Rootkits...
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00069.html

Universal XSS in all Google Services
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00071.html

Vpopmail/QmailAdmin Users Quota Multiple Integer Overflows
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00068.html

[security bulletin] HPSBUX02366 SSRT080120 rev.2 - HPUX Running useradd(1M), Local Unauthorized
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00067.html

Claroline v.1.8.11 Cross-Site Scripting
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00066.html

Simple Customer profile.php Security Bypass Vulnerability
http://secunia.com/advisories/35030/

Job Script Job Board Software Password Change Vulnerability
http://secunia.com/advisories/35029/

Ubuntu update for mpfr
http://secunia.com/advisories/35028/

Ubuntu update for Pango
http://secunia.com/advisories/35027/

Ubuntu update for libmodplug
http://secunia.com/advisories/35026/

Debian update for libwmf
http://secunia.com/advisories/35025/

Pango Glyph String Parsing Integer Overflow Vulnerability
http://secunia.com/advisories/35021/

Red Hat update for pango
http://secunia.com/advisories/35018/

webSPELL File Inclusion and SQL Injection Vulnerability
http://secunia.com/advisories/35016/

Chinagames iGame CGAgent ActiveX Control Buffer Overflow
http://secunia.com/advisories/35005/

Techno Dreams Job Career Package Cookie Security Bypass
http://secunia.com/advisories/34996/

TCPDB Administrative Pages Security Bypass
http://secunia.com/advisories/34966/

Claroline Input Validation Flaw in 'notfound.php' Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2009/May/1022198.html

Pango Integer Overflow in pango_glyph_string_set_size() May Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/May/1022196.html

RHBA-2009:0477-1 gfs2-utils bug-fix update
http://rhn.redhat.com/errata/RHBA-2009-0477.html

RHSA-2009:0476-1 Important: pango security update
http://rhn.redhat.com/errata/RHSA-2009-0476.html

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34656

Mozilla Firefox International Domain Name Subdomain URI Spoofing Vulnerability
http://www.securityfocus.com/bid/33837

Multiple AVG Products RAR/ZIP Files Scan Evasion Vulnerability
http://www.securityfocus.com/bid/34895

Oracle April 2009 Critical Patch Update Multiple Vulnerabilities
http://www.securityfocus.com/bid/34461

MagpieRSS Cross Site Scripting And HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/34891

Dokeos 'whoisonline.php' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34633

RTWebalbum 'AlbumId' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/34888

LuxBum 'manager.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34889

TinyWebGallery '/admin/_include/init.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/34892

Realty Web-Base 'admin/admin.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34886

Battle Blog 'uploadform.asp' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/34887

Recipe Script 'admin/index.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34885

OpenSC 'pkcs11-tool' Inseure Key Generation Vulnerability
http://www.securityfocus.com/bid/34884

Claroline 'claroline/linker/notfound.php' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/34883

Pango 'pango_glyph_string_set_size()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34870

GNU screen Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/34521

URUWorks ViPlay3 '.vpl' File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34877

ST-Gallery 'example.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34875

JobScript 'changepassword.php' Remote Password Change Vulnerability
http://www.securityfocus.com/bid/34874

Simple Customer 'profile.php' Remote Password Change Vulnerability
http://www.securityfocus.com/bid/34872

VideoScript.us YouTube Video Script 'admin/index.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34868

Microsoft .NET Framework PE Loader Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/24778

Microsoft .Net Framework Multiple Null Byte Injection Vulnerabilities
http://www.securityfocus.com/bid/24791

Multiple Symantec Products Intel Common Base Agent Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/34671

Sorinara Streaming Audio Player '.pla' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34861

Linux Kernel 'ptrace_attach()' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34799

Microsoft .NET Framework JIT Compiler Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/24811

Mozilla Firefox 'nsTextFrame::ClearTextRun()' Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34743

HP-UX 'useradd' Local Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/34748

Chinagames ActiveX Control 'CreateChinagames()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34871

TCPDB 'user/index.php' Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/34866

Techno Dreams Job Career Package Cookie Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/34865

Sorinara Soritong MP3 Player '.m3u' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34863

webSPELL 'getlang.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/34862

PHP 'mb_ereg_replace()' String Evaluation Vulnerability
http://www.securityfocus.com/bid/34873

Multiple Mini-stream Software Products '.asx' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34864

libwmf WMF Image File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34792

HP OpenView Network Node Manager 'ovalarmsrv.exe' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34738

Multiple Mini-stream Software Products '.ram' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34860

MPFR Library 'printf.c' Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/33945

libmodplug 'load_pat.c' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34747

libmodplug 's3m' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/30801

Grabit 'NZB' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34807

BaoFeng Storm ActiveX Control 'SetAttributeValue()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34869

BaoFeng Storm ActiveX Control 'OnBeforeVideoDownload()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34789

Aladdin eSafe Unspecified Archive File Scan Evasion Vulnerability
http://www.securityfocus.com/bid/34726

acpid Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34692

Memcached and MemcacheDB ASLR Information Disclosure Weakness
http://www.securityfocus.com/bid/34756

Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34405

Linux Kernel 'locks_remove_flock()' Local Race Condition Vulnerability
http://www.securityfocus.com/bid/33237

Linux Kernel 'ecryptfs_write_metadata_to_contents()' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34216

Linux Kernel Audit System 'audit_syscall_entry()' System Call Security Bypass Vulnerability
http://www.securityfocus.com/bid/33951

Linux Kernel 'NFS filename' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34390

Linux Kernel 'sock.c' SO_BSDCOMPAT Option Information Disclosure Vulnerability
http://www.securityfocus.com/bid/33846

Linux Kernel 'dell_rbu' Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/33428

Linux Kernel Cloned Process 'CLONE_PARENT' Local Origin Validation Weakness
http://www.securityfocus.com/bid/33906

Linux Kernel 'keyctl_join_session_keyring()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/33339

Linux Kernel 'parisc_show_stack()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/32636

Linux Kernel Frame Size Integer Overflow Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34654

Linux Kernel 'FWD-TSN' Chunk Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33113

Linux Kernel 'ib700wdt.c' Buffer Underflow Vulnerability
http://www.securityfocus.com/bid/33003

Linux Kernel '/ipc/shm.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34020

Linux Kernel MIPS Untrusted User Application Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/32716

Linux Kernel CIFS Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34453

Linux Kernel 64 Bit ABI System Call Parameter Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/33275

Linux Kernel 'drivers/char/agp/generic.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34673

Linux Kernel 'qdisc_run()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/32985

razorCMS 'Create New Page' Form HTML Injection Vulnerability
http://www.securityfocus.com/bid/34854

ldns 'rr.c' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34233

Kayako SupportSuite Ticket Notes HTML Injection Vulnerability
http://www.securityfocus.com/bid/34853

FreePBX Multiple Cross Site Scripting and Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/34857

Verlihub Control Panel Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/34856

32bit FTP 'CWD' Response Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34838

Drupal Taxonomy Vocabulary 'Help text' HTML Injection Vulnerability
http://www.securityfocus.com/bid/34893

0 件のコメント:

コメントを投稿