2009年5月13日水曜日

13日 水曜日、仏滅

SiteProtector 2.0 Database Service Pack 7.24
http://www-935.ibm.com/services/jp/iss/readme/SiteProtector/ibm_siteprotector_dbsp_7.24_readmej.txt

RealSecure 7.0 Server Sensor XPU 29.050
http://www-935.ibm.com/services/jp/iss/readme/XPressUpdates/RS/rs7ss_x29_050rnj.txt

Proventia Server for Linux XPU 29.050
http://www-935.ibm.com/services/jp/iss/readme/XPressUpdates/proventiaSvr/iss_pam_linux_29_050j.txt

Proventia M, MX Firmware 3.14 以上 / A, G, GX, MS シリーズ Firmware 1.4 以上 XPU 29.050
http://www-935.ibm.com/services/jp/iss/readme/XPressUpdates/proventiaM/proventia_pam_xpu_29_050_readmej.txt
Agent Manager 6.9, Service Pack 7.141, 8.141, Proventia Desktop XPU V8.0.812.2390, V9.0.226.2390, Proventia Server for Windows 2.0.300.2390
http://www-935.ibm.com/services/jp/iss/readme/proventia/readmepd_2390j.txt

InterScan Web Security Suite 3.1 Linux版 Patch 1 (ビルド1131) 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1261

Microsoft Office の PowerPoint の脆弱性(MS09-017) について
http://www.ipa.go.jp/security/ciadr/vul/20090513-ms09-017.html

カスペルスキーとデジタルアーツが統合製品を開発へ
http://itpro.nikkeibp.co.jp/article/NEWS/20090513/329931/?ST=security

Microsoftの月例アップデート,5月は緊急1件,PowerPointの脆弱性に対応
http://itpro.nikkeibp.co.jp/article/NEWS/20090513/329923/?ST=security

2009年5月 Microsoft セキュリティ情報 (緊急 1件) に関する注意喚起
http://www.jpcert.or.jp/at/2009/at090008.txt

JVNTA09-132A Microsoft Office PowerPoint に複数の脆弱性
http://jvn.jp/cert/JVNTA09-132A/index.html

JVNVU#627331 Microsoft Office PowerPoint に任意のコードが実行される脆弱性
http://jvn.jp/cert/JVNVU627331/index.html

JVNVU#970180 Adobe Reader および Acrobat における customDictionaryOpen() と getAnnots() に脆弱性
http://jvn.jp/cert/JVNVU970180/index.html

JVN#73653977 Sun GlassFish Enterprise Server および Sun Java System Application Server におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN73653977/index.html

JVNDB-2009-000027 Sun GlassFish Enterprise Server および Sun Java System Application Server におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000027.html

JVNDB-2009-001212 Microsoft Internet Explorer における初期化されていないメモリに関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001212.html

JVNDB-2009-001211 Microsoft Internet Explorer における初期化されていないメモリに関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001211.html

JVNDB-2009-001210 Microsoft Internet Explorer における初期化されていないメモリに関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001210.html

JVNDB-2009-001209 Microsoft Internet Explorer における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001209.html

JVNDB-2009-001208 Microsoft DirectX の DirectShow における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001208.html

Mac OS X Kernel Workqueue Index Bug Lets Local Users Gain System Privileges
http://www.securitytracker.com/id?1022213

iChat May Use Non-secure Communications for AIM/Jabber Accounts Configured for SSL
http://www.securitytracker.com/id?1022212

Mac OS X CFNetwork Heap Overflow in Processing HTTP Headers Lets Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1022211

Mac OS X Bugs in CoreGraphics and QuickDraw Manager Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1022209

Apple Safari Buffer Overflow in WebKit in Processing SVGList Objects Lets Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1022207

Apple Safari Bug in Processing 'feed:' URLs Lets Remote Users Execute Arbitrary JavaScript
http://www.securitytracker.com/id?1022206

APSB09-06: Security Updates available for Adobe Reader and Acrobat
http://www.adobe.com/support/security/bulletins/apsb09-06.html

Mac OS X 10.5.7 Update
http://support.apple.com/kb/HT3397

Ubuntu update for quagga
http://secunia.com/advisories/35061/

acpid Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34692

Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34740

Adobe Reader 'getAnnots()' JavaScript Function Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34736

Microsoft PowerPoint Invalid Record Type Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34835

Microsoft PowerPoint Notes Container Heap Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34840

QEMU Security Bypass Vulnerability
http://www.securityfocus.com/bid/30604

QEMU VNC 'monitor.c' Insecure Password Vulnerability
http://www.securityfocus.com/bid/33020

QEMU Multiple Local Vulnerabilities
http://www.securityfocus.com/bid/23731

QEMU 'vl.c' Security Bypass Vulnerability
http://www.securityfocus.com/bid/29101

QEMU and KVM VNC Server Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32910

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34656

Mozilla Firefox 'nsTextFrame::ClearTextRun()' Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34743

Mozilla Firefox International Domain Name Subdomain URI Spoofing Vulnerability
http://www.securityfocus.com/bid/33837

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -07 -08 -09 and -11 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/33990

Libpng Library Uninitialized Pointer Arrays Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/33827

Libpng Library Unknown Chunk Handler Vulnerability
http://www.securityfocus.com/bid/28770

FreeType Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34550

FreeType TT_Load_Simple_Glyph() TTF File Integer Overflow Vulnerability
http://www.securityfocus.com/bid/24074
xterm DECRQSS Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/33060

FreeType TTF File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/18326

Ruby Multiple Security Bypass and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/30644

Ruby REXML Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/30802

NTP 'ntpq' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34481

FreeBSD Malformed ICMPv6 Packet Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/31004

Net-SNMP GETBULK Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/32020

MIT Kerberos SPNEGO and ASN.1 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34408

OpenSSL 'EVP_VerifyFinal' Function Signature Verification Vulnerability
http://www.securityfocus.com/bid/33150

MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34409

MIT Kerberos 'NegTokenInit' Token Handling Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34257

IPsec-Tools Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/30657

Quagga Autonomous System Number Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34817

SquirrelMail Prior to 1.4.18 Multiple Vulnerabilities
http://www.securityfocus.com/bid/34916

GNU Enscript 'src/psgen.c' Stack Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31858

Microsoft PowerPoint Invalid Record Type Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34879

Adobe Flash Player Unspecified Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/33890

Adobe Flash Player Invalid Object Reference Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/33880

Microsoft PowerPoint Sound Data (CVE-2009-1128) Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/34837

Microsoft PowerPoint Sound Data (CVE-2009-1129) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34839

Ruby 'regex.c' Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/30682

PHP 'mbstring' Extension Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/32948

PHP 5 'posix_access()' Function 'safe_mode' Bypass Directory Traversal Vulnerability
http://www.securityfocus.com/bid/29797

PCRE Regular Expression Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/30087

Xpdf JBIG2 Processing Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34568

PHP 'chdir()' and 'ftok()' 'safe_mode' Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/29796

CUPS Insufficient 'Host' Header Validation Weakness
http://www.securityfocus.com/bid/34665

PHP FastCGI Module File Extension Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/31612

Microsoft PowerPoint Sound Data (CVE-2009-0227) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34882

Microsoft PowerPoint Paragraph Data Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34833

Microsoft PowerPoint Sound Data (CVE-2009-0223) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34834

PHP 'rfc822_write_address()' Function Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/29829

Multiple Vendor OpenSSL 'DSA_verify' Function Signature Verification Vulnerability
http://www.securityfocus.com/bid/33151

Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/30560

Microsoft PowerPoint Sound Data (CVE-2009-0226) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34881

Apache 'mod_negotiation' HTML Injection and HTTP Response Splitting Vulnerability
http://www.securityfocus.com/bid/27409

PHP Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/30649



[ANNOUNCE] Apache ODE 1.3.2 released
http://ode.apache.org/getting-ode.html

+ マイクロソフト セキュリティ情報 2009 年 5 月のセキュリティ情報
http://www.microsoft.com/japan/technet/security/bulletin/ms09-may.mspx

+ Microsoft Office PowerPoint の脆弱性により、リモートでコードが実行される
http://www.microsoft.com/japan/technet/security/advisory/969136.mspx
http://www.microsoft.com/technet/security/advisory/969136.mspx

- Microsoft Security Bulletin MS09-017 - Critical
Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340)
http://www.microsoft.com/technet/security/Bulletin/MS09-017.mspx
http://www.microsoft.com/japan/technet/security/Bulletin/MS09-017.mspx

+ DeleGate/9.9.3 (STABLE) released
http://www.delegate.org/mail-lists/delegate-en/4446

+ Microsoft Internet Explorer UTF-7 Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/34917

+ PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/34090

The Programming Language with the happiest users
http://use.perl.org/article.pl?sid=09/05/12/1357205&from=rss

Manually moving simple and concatenated volumes to a New Disk Group
http://seer.entsupport.symantec.com/docs/323060.htm

Solution 258768 : SUN ALERT WEEKLY SUMMARY REPORT - Week of 03-May-2009 to 09-May-2009
http://sunsolve.sun.com/search/document.do?assetkey=1-66-258768-1

Syhunt-SA-05/12/2009: Syhunt: A-A-S (Application Access Server) Multiple Security Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29232

FormMail-SA-05/12/2009: Multiple Vulnerabilities in FormMail 1.92 and possibly earlier
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29233

AustralianBanks-SA-05/12/2009: Security Advisory: Banks in Australia
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29234

Bitweaver-SA-05/12/2009: Bitweaver <= 2.6 remote code execution exploit http://www.criticalwatch.com/support/security-advisories.aspx?AID=29235

SUSE-SR:2009:010: security-announce SUSE Security Summary Report
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29230

クラリオンのポータブル型カーナビに「USBウイルス」が混入
主な対策ソフトで検出・駆除可能、単体では発症せず
http://itpro.nikkeibp.co.jp/article/NEWS/20090513/329898/?ST=security

「セキュリティアプライアンスで日本一に」チェック・ポイント杉山社長
http://itpro.nikkeibp.co.jp/article/NEWS/20090512/329876/?ST=security

遠隔操作でノートPCのデータを消す通信カード、アルカテル・ルーセントが発売
http://itpro.nikkeibp.co.jp/article/NEWS/20090512/329774/?ST=security

暗号化した文書を携帯電話のカメラで閲覧、富士通が開発
http://itpro.nikkeibp.co.jp/article/NEWS/20090512/329846/?ST=security

[USN-775-1] Quagga vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00115.html

[USN-776-1] KVM vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00116.html

iDefense Security Advisory 05.12.09: Microsoft PowerPoint PPT95 Import Multiple Stack Buffer Overflow Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00114.html

iDefense Security Advisory 05.12.09: Microsoft PowerPoint PPT95 Import Multiple Stack Buffer Overflow Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00112.html

iDefense Security Advisory 05.12.09: Microsoft PowerPoint PPT 4.0 Importer Multiple Stack Buffer Overflow Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00111.html

iDefense Security Advisory 05.12.09: Microsoft PowerPoint 4.2 Conversion Filter Stack Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00113.html

iDefense Security Advisory 05.12.09: Microsoft PowerPoint 4.2 Conversion Filter Heap Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00110.html

iDefense Security Advisory 05.12.09: Microsoft PowerPoint 4.2 Conversion Filter Stack Buffer Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00109.html

ZDI-09-020: Microsoft Office PowerPoint Notes Container Heap Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00107.html

ZDI-09-019: Microsoft Office PowerPoint OutlineTextRefAtom Parsing Memory Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00106.html

Secunia Research: Microsoft PowerPoint Atom Parsing Buffer Overflows
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00104.html

Sun IDM Arbitrary Commands Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00099.html

CA20090126-01: CA Anti-Virus Engine Detection Evasion Multiple Vulnerabilities [Updated]
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00103.html

Security Advisory: Banks in Australia
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00093.html

The security tools list, new version with more than 200 new tools!
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00098.html

FormMail 1.92 Multiple Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00101.html

xcon2009 is coming
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00091.html

Exploiting IE8 UTF-7 XSS Vulnerability using Local Redirection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00095.html

Bitweaver <= 2.6 /boards/boards_rss.php / saveFeed() remote code execution exploit http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00090.html

Syhunt: A-A-S (Application Access Server) Multiple Security Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-05/msg00094.html

Microsoft PowerPoint 4.2 Conversion Filter Stack Buffer Overflow Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=787

Microsoft PowerPoint 4.2 Conversion Filter Heap Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=788

Microsoft PowerPoint 4.2 Conversion Filter Stack Overflow
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=789

Microsoft PowerPoint PPT 4.0 Importer Multiple Stack Buffer Overflow Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=790

Microsoft PowerPoint PPT95 Import Multiple Stack Buffer Overflow Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=791

Microsoft PowerPoint PPT95 Import Multiple Stack Buffer Overflow Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=792

Microsoft PowerPoint Build List Memory Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=793

Microsoft PowerPoint Notes Container Heap Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=794

Microsoft PowerPoint Notes Container Heap Corruption Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=795

Microsoft PowerPoint Integer Overflow Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=796

SquirrelMail Multiple Vulnerabilities
http://secunia.com/advisories/35073/

Smarty "smarty_function_math()" Template Security Bypass
http://secunia.com/advisories/35072/

IBM AIX update for OpenSSL
http://secunia.com/advisories/35070/

SUSE Update for Multiple Packages
http://secunia.com/advisories/35065/

Bitweaver "version" Directory Traversal Vulnerability
http://secunia.com/advisories/35057/

uTopic "rating" SQL Injection Vulnerability
http://secunia.com/advisories/35051/

openWYSIWYG Directory Traversal and File Upload Vulnerabilities
http://secunia.com/advisories/35050/

eggBlog Directory Traversal and File Upload Vulnerabilities
http://secunia.com/advisories/35047/

CycloMedia CycloScopeLite ActiveX Control "ReturnConnection()" Vulnerability
http://secunia.com/advisories/35046/

OpenSC "pkcs11-tool" RSA Key Generation Security Issue
http://secunia.com/advisories/35035/

A-A-S Application Access Server Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/35034/

Debian update for qemu
http://secunia.com/advisories/35031/

Ubuntu update for moin
http://secunia.com/advisories/35024/

Microsoft PowerPoint Multiple Vulnerabilities
http://secunia.com/advisories/32428/

Symantec System Center Alert Management System Console Arbitrary Program Execution Vulnerability
http://www.securiteam.com/windowsntfocus/5DP0D0AR5E.html

CA ARCserve Backup Apache HTTP Server Multiple Vulnerabilities
http://www.securiteam.com/unixfocus/5CP0C0AR5Y.html

Oracle Database SQL Injection vulnerability in LT.ROLLBACKWORKSPACE
http://www.securiteam.com/unixfocus/5EP0E0AR5Q.html

Quagga Linux Denial of Service Vulnerability
http://www.securiteam.com/unixfocus/5GP0G0AR5I.html

FRISK Software F-prot CAB Bypass / Evasion
http://www.securiteam.com/securitynews/5BP0B0AR5W.html

FRISK Software F-prot CAB Bypass / Evasion
http://www.securiteam.com/securitynews/5FP0F0AR5M.html

Microsoft PowerPoint Has Multiple Buffer Overflows and Memory Corruption Bugs That Let Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id?1022205

A-A-S Application Access Server CSRF Bug Lets Remote Users Execute Arbitrary Commands
http://www.securitytracker.com/id?1022204

Bitweaver Bug in saveFeed() Lets Remote Authenticated Users Execute Arbitrary Commands on the Target System
http://www.securitytracker.com/id?1022203

TYPSoft FTP ABOR Command Bug Lets Remote Users Deny Service
http://www.securitytracker.com/id?1022202

Microsoft Office PowerPoint Multiple Code Execution Vulnerabilities (MS09-017)
http://www.vupen.com/english/advisories/2009/1290

openWYSIWYG Folder Listing and Image Upload Vulnerabilities
http://www.vupen.com/english/advisories/2009/1289

uTopic "rating" Parameter Handling Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/1288

Php Recommend PHP Code Execution and Authentication Bypass Issues
http://www.vupen.com/english/advisories/2009/1287

IBM AIX Security Update Fixes OpenSSL Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/1286

Bitweaver "version" Directory Traversal Code Injection Vulnerability
http://www.vupen.com/english/advisories/2009/1285

ESXi console message: OEM Policy File is dirty. Settings not respected.
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010720&sliceId=1&docTypeID=DT_KB_1_1

Site Recovery Manager Test Failover fails intermittently
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010692&sliceId=1&docTypeID=DT_KB_1_1

VMotion fails after a third-party security tool performs a port scan of the ESX hosts
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010672&sliceId=1&docTypeID=DT_KB_1_1

New alarm to trigger a script or send an email fails
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1010666&sliceId=1&docTypeID=DT_KB_1_1

libxml XML Entity Name Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31126

Microsoft PowerPoint Sound Data (CVE-2009-0227) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34882

Absolute Form Processor XE 'userid' Parameter Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/34706

pecio cms 'index.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/34802

ldns 'rr.c' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34233

PyCrypto ARC2 Module Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33674

OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/33922

X-Forum 'cookie_username' Cookie Parameter Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/34302

GNOME glib Base64 Encoding and Decoding Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34100

Microsoft PowerPoint File Parsing 'OutlineTextRefAtom' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34351

Microsoft PowerPoint Sound Data (CVE-2009-0225) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34880

Microsoft PowerPoint Sound Data (CVE-2009-0226) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34881

Microsoft PowerPoint Sound Data (CVE-2009-1137) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34876

Xpdf JBIG2 Processing Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34568

FreeType Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34550

Evolution Data Server 'ntlm_challenge()' Memory Contents Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34109

Apport Local Arbitrary File Deletion Vulnerability
http://www.securityfocus.com/bid/34776

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34656

Mozilla Firefox International Domain Name Subdomain URI Spoofing Vulnerability
http://www.securityfocus.com/bid/33837

PostgreSQL Conversion Encoding Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/34090

Computer Associates Anti-Virus Engine 'arclib.dll' Multiple Scan Evasion Vulnerabilities
http://www.securityfocus.com/bid/33464

Sun Java System Identity Manager Multiple Vulnerabilities
http://www.securityfocus.com/bid/34191

CastRipper '.m3u' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34915

Sun Java Web Start and Java Plug-in JAR File Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/32892

Sun Java Web Start and Java Plug-in Multiple Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/32620

Sun Java Web Start Multiple Vulnerabilities
http://www.securityfocus.com/bid/30148

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/32608

Sun Java Runtime Environment Multiple Unspecified Same Origin Policy Violation Vulnerabilities
http://www.securityfocus.com/bid/30140

RETIRED: Microsoft May 2009 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/34867

RETIRED: Microsoft April 2009 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/34450

Microsoft PowerPoint Paragraph Data Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34833

OpenSSL Multiple Vulnerabilities
http://www.securityfocus.com/bid/34256

Microsoft Internet Explorer UTF-7 Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/34917

CycloMedia CycloScopeLite ActiveX Control Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/34912

Sun GlassFish Enterprise and Sun Java System Application Server Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/34914

openWYSIWYG 'addons/imagelibrary/insert_image.php' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/34913

openWYSIWYG 'addons/imagelibrary/select_image.php' Directory Traversal Vulnerability
http://www.securityfocus.com/bid/34904

Multiple Symantec Products Intel Common Base Agent Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/34671

RETIRED: eggBlog 'select_image.php' Directory Traversal Vulnerability
http://www.securityfocus.com/bid/34905

GNOME Evolution '~/.evolution/mail/local' File Permission Vulnerability
http://www.securityfocus.com/bid/34921

BigACE 'username' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/34920

Smarty Template Engine 'function.math.php' Security Bypass Vulnerability
http://www.securityfocus.com/bid/34918

SquirrelMail Prior to 1.4.18 Multiple Vulnerabilities
http://www.securityfocus.com/bid/34916

A-A-S Application Access Server Multiple Vulnerabilities
http://www.securityfocus.com/bid/34911

Bitweaver Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/34910

Microsoft PowerPoint Invalid Record Type Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34879

Microsoft PowerPoint Data Out of Bounds Remote Stack Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34841

Microsoft PowerPoint Notes Container Heap Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34840

Microsoft PowerPoint Sound Data (CVE-2009-1129) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34839

Microsoft PowerPoint Sound Data (CVE-2009-1128) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34837

Microsoft PowerPoint Invalid Record Type Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34835

Microsoft PowerPoint Sound Data (CVE-2009-0223) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34834

Microsoft PowerPoint Sound Data (CVE-2009-0222) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34831

Postfix 2.6 Patchlevel 0 released
http://mirror.postfix.jp/postfix-release/official/postfix-2.6.0.HISTORY

Postfix 2.5 Patchlevel 7 released
http://mirror.postfix.jp/postfix-release/official/postfix-2.5.7.HISTORY

Postfix 2.4 Patchlevel 11 released
http://mirror.postfix.jp/postfix-release/official/postfix-2.4.11.HISTORY

Postfix 2.3 Patchlevel 17 released
http://mirror.postfix.jp/postfix-release/official/postfix-2.3.17.HISTORY

0 件のコメント:

コメントを投稿