2009年6月17日水曜日

17日 水曜日、大安

The latest snapshot for the stable Linux kernel tree is: 2.6.30-git10
http://www.kernel.org/pub/linux/kernel/v2.6/snapshots/patch-2.6.30-git10.log

MySQL 5.1.36 (Not yet released)
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-36.html

MySQL 6.0.12 (Not yet released)
http://dev.mysql.com/doc/refman/6.0/en/news-6-0-12.html

CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29594

CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29595

IVIZ-09-003: CA ARCserve Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29592

IVIZ-09-004: CA ARCserve Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29593

MDVSA-2009:133: irssi
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29582

TZO-40-2009: Clamav generic bypass (RAR, CAB, ZIP)
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29591

APPLE-SA-2009-06-15-1: Java for Mac OS X 10.5 Update 4
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29584

APPLE-SA-2009-06-15-2: Java for Mac OS X 10.4 Release 9
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29585

Netgear-SA-06/15/2009: Netgear DG632 Router Authentication Bypass Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29589

Netgear-SA-06/15/2009: Netgear DG632 Router Remote DoS Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29590

DSF-02-2009: Zoki Catalog SQL Injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29605

RHSA-2009:1100-01: Moderate: wireshark security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29586

RHSA-2009:1101-01: Moderate: cscope security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29587

RHSA-2009:1102-01: Moderate: cscope security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29588

USN-788-1: Tomcat vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29583

waraxe-2009-SA#074: Multiple Vulnerabilities in TorrentTrader Classic 1.09
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29596

[Press Release] 2009年度IPA情報セキュリティセミナー開催について
http://www.ipa.go.jp/security/event/2009/isec-semi/press.html

Google出身者が設立したDasient,ホスト型のアンチマルウエア・サービス開始
http://itpro.nikkeibp.co.jp/article/NEWS/20090617/332067/?ST=security

専門家グループ,GoogleにWebサービスのHTTPS通信デフォルト化を要求
http://itpro.nikkeibp.co.jp/article/NEWS/20090617/332065/?ST=security

JPCERT/CC WEEKLY REPORT 2009-06-17
http://www.jpcert.or.jp/wr/2009/wr092301.html




+ iptables 1.4.4 released
http://www.iptables.org/news.html#2009-06-16
http://www.iptables.org/projects/iptables/files/changes-iptables-1.4.4.txt

+ RHSA-2009:1106-1: Important: kernel security and bug fix update
http://rhn.redhat.com/errata/RHSA-2009-1106.html

+ RHSA-2009:1107-1: Moderate: apr-util security update
http://rhn.redhat.com/errata/RHSA-2009-1107.html

+ RHSA-2009:1108-1: Moderate: httpd security update
http://rhn.redhat.com/errata/RHSA-2009-1108.html

+ Linux Kernel Buffer Overflow in CIFS nativeFileSystem Field Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/May/1022160.html
https://rhn.redhat.com/errata/RHSA-2009-1081.html
http://www.securityfocus.com/bid/34453

+ Sun Solaris Print Job Denial of Service
http://secunia.com/advisories/35480/
http://www.securityfocus.com/bid/35400

- Solution 247386: Part II - Multiple Printing Regressions in Solaris 10 Kernel Patches 127127-11 and 127128-11
http://sunsolve.sun.com/search/document.do?assetkey=1-66-247386-1

+ Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
http://www.securityfocus.com/bid/35115

+ Microsoft Windows Print Spooler Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35209

[ANNOUNCE] PostGIS 1.4.0 Beta 1
http://postgis.refractions.net/

[ANNOUNCEMENT] Apache Commons Pool 1.5.1 Released
http://commons.apache.org/pool/

[ANNOUNCE] PostgreSQL 8.4 Release Candidate 1 Now Available
http://www.postgresql.org/developer/beta
http://www.postgresql.org/about/news.1097

MySql Connector/Net 6.0.4 has been released
http://dev.mysql.com/downloads/connector/net/6.0.html

Ubuntu aims at healing Linux's usability wounds
http://www.linux.org/news/2009/06/16/0005.html

SCO vs. Linux: New investor rescues SCO from bankruptcy
http://www.linux.org/news/2009/06/16/0004.html

Run your Linux like a Mac
http://www.linux.org/news/2009/06/16/0003.html

Microsoft's Windows 7 price gamble opens door to Linux
http://www.linux.org/news/2009/06/16/0002.html

The Linux UI future; more complex than ever
http://www.linux.org/news/2009/06/16/0001.html

Postgres Plus Advanced Server 8.3R2 Released
http://www.postgresql.org/about/news.1099

RHBA-2009:1103-1: cman bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1103.html

RHBA-2009:1104-1: openais bug-fix update
http://rhn.redhat.com/errata/RHBA-2009-1104.html

RHEA-2009:1105-1: tzdata enhancement update
http://rhn.redhat.com/errata/RHEA-2009-1105.html

Cannot log in to an ESX 4 host with vSphere Web Access
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011921&sliceId=1&docTypeID=DT_KB_1_1

[SECURITY] [DSA 1816-1] New apache2 packages fix privilege escalation
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00176.html

WinAppDbg version 1.2 is out!
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00172.html

ZDI-09-043: Apple Java CColorUIResource Pointer Derference Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00174.html

phpMyTourney adminfunctions.php Remote File Include Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00171.html

[ MDVSA-2009:133 ] irssi
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00170.html

Official release of "Keykeriki" open source wireless keyboard sniffer
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00169.html

CA20090615-02: CA Service Desk Tomcat Cross Site Scripting Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00167.html

CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities (Updated)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00168.html

CA20090615-01: CA ARCserve Backup Message Engine Denial of Service Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00166.html

[TZO-40-2009] Clamav generic bypass (RAR,CAB,ZIP)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00165.html

Re[2]: [Full-disclosure] Netgear DG632 Router Remote DoS Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00164.html

[TZO-33-2009] Fprot generic bypass (TAR)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00163.html

「IPSを止めないで」,イスラエルCheck Point副社長が強調
http://itpro.nikkeibp.co.jp/article/NEWS/20090616/331990/?ST=security

squid-3.0.STABLE16 released
http://www.squid-cache.org/Versions/v3/3.0/squid-3.0.STABLE16-RELEASENOTES.html

Linux Kernel Buffer Overflow in CIFS nativeFileSystem Field Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/May/1022160.html

NETGEAR DG632 Router Discloses File Source Contents to Remote Users
http://securitytracker.com/alerts/2009/Jun/1022404.html

NETGEAR DG632 Router Web Interface Can Be Crashed By Remote Users
http://securitytracker.com/alerts/2009/Jun/1022403.html

HP OpenView SNMP Emanate Master Agent Unspecified Flaw Grants Access to Remote Users
http://securitytracker.com/alerts/2009/Jun/1022400.html

Elvin Multiple Vulnerabilities
http://secunia.com/advisories/35486/

TYPO3 References Database SQL Injection Vulnerability
http://secunia.com/advisories/35485/

TYPO3 FrontEnd MP3 Player Extension SQL Injection
http://secunia.com/advisories/35484/

TYPO3 Modern Guestbook / Commenting System Cross-Site Scripting
http://secunia.com/advisories/35483/

Fedora update for gupnp
http://secunia.com/advisories/35482/

Sun Solaris Print Job Denial of Service
http://secunia.com/advisories/35480/

TYPO3 Virtual Civil Services Extension SQL Injection
http://secunia.com/advisories/35479/

SkyBlueCanvas Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35478/

Webmedia Explorer Multiple Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35477/

Zoki Catalog "search_text" SQL Injection Vulnerability
http://secunia.com/advisories/35476/

F-Secure Messaging Security Gateway Mail Relay Vulnerability
http://secunia.com/advisories/35475/

CA Service Desk Tomcat Cross-Site Scripting Vulnerability
http://secunia.com/advisories/35474/

CA ARCserve Backup Message Engine Denial of Service
http://secunia.com/advisories/35473/

GUPnP Empty Message Denial of Service Vulnerability
http://secunia.com/advisories/35472/

Fedora update for drupal-views
http://secunia.com/advisories/35471/

Fedora update for mingw32-libpng
http://secunia.com/advisories/35470/

Fedora update for firefox and xulrunner
http://secunia.com/advisories/35468/

Sophos Products CAB Archive Handling Security Bypass
http://secunia.com/advisories/35467/

Joomla Jumi Component "fileid" SQL Injection Vulnerability
http://secunia.com/advisories/35465/

Red Hat update for wireshark
http://secunia.com/advisories/35464/

HP OpenView SNMP Emanate Master Agent HMAC Authentication Spoofing
http://secunia.com/advisories/35463/

Red Hat update for cscope
http://secunia.com/advisories/35462/

Fedora update for coccinelle
http://secunia.com/advisories/35459/

Ubuntu update for tomcat6
http://secunia.com/advisories/35455/

iJoomla RSS Feeder "cat" SQL Injection Vulnerability
http://secunia.com/advisories/35454/

McAfee 3.6.0.608 naPolicyManager.dll ActiveX Arbitrary Data Write Vuln
http://www.milw0rm.com/exploits/8970

Green Dam 3.17 URL Processing Buffer Overflow Exploit (meta)
http://www.milw0rm.com/exploits/8969

XOOPS <= 2.3.3 Remote File Disclosure Vulnerability (.htaccess) http://www.milw0rm.com/exploits/8974

solaris/x86 portbind/tcp shellcode generator
http://www.milw0rm.com/shellcode/8973

linux/x86 setreuid(geteuid(),geteuid()),execve("/bin/sh",0,0) 34 bytes
http://www.milw0rm.com/shellcode/8972

Mozilla Firefox and SeaMonkey Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35388

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34240

Linux Kernel 'drivers/char/agp/generic.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34673

Mozilla Firefox/Thunderbird/SeaMonkey Malicious Proxy HTTPS Man In The Middle Vulnerability
http://www.securityfocus.com/bid/35380

IBM WebSphere Application Server 'IsSecurityEnabled' Flag Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35406

Linux Kernel NFS 'MAY_EXEC' Security Bypass Vulnerability
http://www.securityfocus.com/bid/34934

Linux Kernel CIFS 'decode_unicode_ssetup()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34612

Xen 'hypervisor_callback()' Guest Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34957

IBM WebSphere Application Server Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35405

'nfs-utils' Package for Red Hat Enterprise Linux 5 TCP Wrappers Security Bypass Vulnerability
http://www.securityfocus.com/bid/30466

Mozilla Firefox/Thunderbird/SeaMonkey XUL Scripts Content-Policy Check Security Bypass Vulnerability
http://www.securityfocus.com/bid/35377

Apache APR-util 'apr_brigade_vprintf' Off By One Vulnerability
http://www.securityfocus.com/bid/35251

Apache APR-util 'xml/apr_xml.c' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35253

Apache APR-util 'apr_strmatch_precompile()' Integer Underflow Vulnerability
http://www.securityfocus.com/bid/35221

Mozilla Firefox/Thunderbird/SeaMonkey 'file://' URI Security Bypass Vulnerability
http://www.securityfocus.com/bid/35386

NTP 'ntpq' Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34481

NTP 'ntpd' Autokey Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35017

Mozilla Firefox and SeaMonkey JavaScript Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35373

Mozilla Firefox/SeaMonkey 'file://' URI Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35391

Mozilla Firefox 'NPObject' Access Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35360

McAfee Policy Manager 'naPolicyManager.dll' Arbitrary File Overwrite Vulnerability
http://www.securityfocus.com/bid/35404

Mozilla Firefox/Thunderbird/SeaMonkey Double Frame Construction Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35371

Mozilla Firefox/Thunderbird/SeaMonkey Null Owner Document Arbitrary Code Execution Vulnerability
http://www.securityfocus.com/bid/35383

CUPS 'cups/ipp.c' NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35169

Mozilla Firefox/Thunderbird/SeaMonkey Multiple JavaScript Engine Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35372

CUPS PDF File Multiple Heap Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35195

CUPS Scheduler Directory Services Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35194

Mozilla Firefox/Thunderbird/SeaMonkey Multiple Browser Engine Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35370

util-linux-ng 'login' Remote Log Injection Weakness
http://www.securityfocus.com/bid/28983

IBM DB2 Universal Database Server 8.2 Prior To Fixpak 17 Multiple Vulnerabilities
http://www.securityfocus.com/bid/31058

Libpng 1-bit Interlaced Images Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35233

Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
http://www.securityfocus.com/bid/35115

Xvid Video Codec DirectShow Initialization Logic Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35158

Xvid Video Codec Macroblock Number Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35156

TYPO3 Modern Guestbook / Commenting System Extension Unspecified Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35397

TYPO3 Virtual Civil Services Extension Unspecified SQL Injection Vulnerability
http://www.securityfocus.com/bid/35395

TYPO3 FrontEnd MP3 Player Extension Unspecified SQL Injection Vulnerability
http://www.securityfocus.com/bid/35394

TYPO3 References database Extension Unspecified SQL Injection Vulnerability
http://www.securityfocus.com/bid/35392

Apache Tomcat 'HttpServletResponse.sendError()' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/30496

Drupal Views Module Multiple Security Bypass and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/35304

Apple Mac OS X International Components for Unicode Invalid Byte Sequence Handling Vulnerability
http://www.securityfocus.com/bid/34974

iJoomla RSS Feeder Component 'cat' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35379

Wireshark PN-DCP Data Format String Vulnerability
http://www.securityfocus.com/bid/34291

Wireshark Prior to 1.0.7 Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34457

Wireshark PCNFSD Dissector Denial of Service Vulnerability
http://www.securityfocus.com/bid/35081

Sun Java Runtime Environment Aqua Look and Feel Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35381

RETIRED: Sun Java Runtime Environment Aqua Look and Feel Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35401

Sun Java Runtime Environment and Java Development Kit Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/32608

'Compress::Raw::Zlib' Perl Module Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35307

Mutt 'mutt_ssl.c' X.509 Certificate Chain Security Bypass Vulnerability
http://www.securityfocus.com/bid/35288

Microchip MPLAB IDE '.mcp' File Handling Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34897

EMC AlphaStor Server Agent Multiple Stack Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/29399

Linux Kernel 'exit_notify()' CAP_KILL Verification Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/34405

Linux Kernel nfsd 'CAP_MKNOD' Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/34205

Linux Kernel CIFS Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34453

Linux Kernel '/ipc/shm.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/34020

Linux Kernel Frame Size Integer Overflow Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/34654

ClamAV Embedded Archive File Scan Evasion Vulnerability
http://www.securityfocus.com/bid/35398

Computer Associates ARCserve Backup Message Engine Denial of Service Vulnerability
http://www.securityfocus.com/bid/35396

Microsoft Excel Malformed Shared String Table Record Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35245

RETIRED: Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009-24 through 32 Multiple Vulnerabilities
http://www.securityfocus.com/bid/35326

Cscope 'find.c' Stack Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34832

Cscope Multiple Stack Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/34805

Cscope Include Filename Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/18050

Cscope 'cscope.lists' Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/19686

Cscope Reffile Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/19687

F-Secure Messaging Security Gateway Email Relay Vulnerability
http://www.securityfocus.com/bid/35389

Microsoft Windows Print Spooler Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35209

Coccinelle Insecure Temporary File Creation Vulnerability
http://www.securityfocus.com/bid/34848

XOOPS 'module_icon.php' Local File Include Vulnerability
http://www.securityfocus.com/bid/35407

Multiple Sophos Products CAB File Scan Evasion Vulnerability
http://www.securityfocus.com/bid/35402

Sun Solaris 'lp' Client Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/35400

0 件のコメント:

コメントを投稿