2009年6月2日火曜日

2日 火曜日、友引

IBM WebSphere MQ Buffer Overflow Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jun/1022311.html

OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/33922

OpenSC 'pkcs11-tool' Inseure Key Generation Vulnerability
http://www.securityfocus.com/bid/34884

Apple QuickTime PSD Image Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35168







+ HPSBUX02429 SSRT090058 rev.2 - HP-UX Running Java, Remote Execution of Arbitrary Code and Other Vulnerabilities
http://www13.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&docId=emr_na-c01745133-2

+ RHSA-2009:1076-1: Low: Red Hat Enterprise Linux 2.1 - End Of Life
http://rhn.redhat.com/errata/RHSA-2009-1076.html

+ Apache mod_dav / svn Remote Denial of Service Exploit
http://www.milw0rm.com/exploits/8842

Interactive Ideas gets a lift from Linux sales
http://www.linux.org/news/2009/06/01/0004.html

Tiny Core Linux 2.0 RC4 released
http://www.linux.org/news/2009/06/01/0003.html

Developers take a shift from Windows to Linux
http://www.linux.org/news/2009/06/01/0002.html

Linux market share growing, growing, growing
http://www.linux.org/news/2009/06/01/0001.html

Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090325-sip.shtml

Cisco Security Advisory: Cisco IOS Software Multiple Features IP Sockets Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090325-ip.shtml

Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted UDP Packet Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090325-udp.shtml

Cisco Security Advisory: Cisco IOS Software WebVPN and SSLVPN Vulnerabilities
http://www.cisco.com/warp/public/707/cisco-sa-20090325-webvpn.shtml

Cisco Security Advisory: Cisco IOS Software Mobile IP and Mobile IPv6 Vulnerabilities
http://www.cisco.com/warp/public/707/cisco-sa-20090325-mobileip.shtml

Cisco Security Advisory: Cisco IOS Software Secure Copy Privilege Escalation Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20090325-scp.shtml

DSA 1807-1 : New cyrus-sasl2/cyrus-sasl2-heimdal packages fix arbitrary code execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29417

RHSA-2009:1076-01: Low: Red Hat Enterprise Linux 2.1 - End Of Life
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29416

BASE - 3-SA-05/31/2009: Persistent Cross Site Scripting Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29414

MDVSA-2009:125: wireshark
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29418

MDVSA-2009:124: apache
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29419

Craigsphone-SA-05/30/2009: Low-Hanging Fruit Craigsphone Transcoder Open URL Redirection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29415

Linksys-SA-05/29/2009: WAG54G2 Web Management Console Local Arbitrary Shell Command Injection Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29411

SonicWALL-SA-: SSL-VPN Appliance Format String Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29412

TZO-28-2009: Avira Antivir generic RAR,CAB,ZIP
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29413

The esxupdate -l query command does not provide the correct baseline (1011522)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011522&sliceId=1&docTypeID=DT_KB_1_1

Single sign on (SSO) does not work correctly when the HP RGS display protocol is used to connect (1011492)
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011492&sliceId=1&docTypeID=DT_KB_1_1

Do not create View Composer linked clones using either a linked clone or a full clone of a linked clone as the Master VM
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1011485&sliceId=1&docTypeID=DT_KB_1_1

新たな「Webウイルス」出現、2万件以上の正規サイトに埋め込まれる
「Glumbler」ウイルスとは別物、対策ソフトを使っていても被害の恐れ
http://itpro.nikkeibp.co.jp/article/NEWS/20090601/331097/?ST=security

The father of all bombs - another webdav fiasco
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00019.html

[USN-778-1] cron vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00016.html

Zemana Antilogger 1.9.2 DoS attack
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00015.html

[SECURITY] [DSA 1808-1] New drupal6 packages fix insufficient input sanitising
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00012.html

ZDI-09-024: Safenet SoftRemote IKE Service Remote Stack Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00014.html

ACSAC 2009 submissions due June 8 and June 10 (extended)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00013.html

[SECURITY] [DSA 1807-1] New cyrus-sasl2/cyrus-sasl2-heimdal packages fix arbitrary code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00005.html

MULTIPLE SQL INJECTION VULNERABILITIES -- Online Grades & Attendance v-3.2.6 -->
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00010.html

[ MDVSA-2009:125 ] wireshark
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00002.html

FRHACK 2009 Final Call For Papers extended
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00009.html

[ MDVSA-2009:124 ] apache
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00007.html

CFP 26C3 / 26th Chaos Communication Congress
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00001.html

FIREFOX URL space character SPOOF
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00004.html

OCS Inventory NG 1.02 - Multiple SQL Injections
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00006.html

ICQ 6.5 URL Search Hook/ICQToolBar.dll .URL file processing Windows Explorer remote buffer overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00003.html

ASMAX AR 804 gu Web Management Console Arbitrary Shell Command Injection Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00008.html

Linksys WAG54G2 Web Management Console Local Arbitrary Shell Command Injection Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-06/msg00000.html

Fedora update for opensc
http://secunia.com/advisories/35309/

Fedora update for ntp
http://secunia.com/advisories/35308/

Fedora update for php
http://secunia.com/advisories/35306/

Mp3 Tag Assistant Professional Buffer Overflow Vulnerability
http://secunia.com/advisories/35305/

IBM WebSphere MQ Buffer Overflow Vulnerability
http://secunia.com/advisories/35303/

Sun Solaris libpng Multiple Vulnerabilities
http://secunia.com/advisories/35302/

IBM WebSphere Application Server Multiple Vulnerabilities
http://secunia.com/advisories/35301/

AIMP MP3 ID3 Tags Buffer Overflow Vulnerability
http://secunia.com/advisories/35295/

Xvid Multiple Vulnerabilities
http://secunia.com/advisories/35274/

Traidnt Up "trupuser" and "truppassword" SQL Injection Vulnerabilities
http://secunia.com/advisories/35273/

Arab Portal "X-Forwarded-For" SQL Injection Vulnerability
http://secunia.com/advisories/35257/

ASMAX AR 804 gu Web Management Console Arbitrary Command Exec
http://www.milw0rm.com/exploits/8846

Roxio CinePlayer 3.2 (IAManager.dll) Remote BOF Exploit (heap spray)
http://www.milw0rm.com/exploits/8835

Linksys WAG54G2 Web Management Console Arbitrary Command Exec
http://www.milw0rm.com/exploits/8833

Apple QuickTime PICT Image Heap Overflow Vulnerability
http://www.securityfocus.com/bid/35164

Apple QuickTime MS ADPCM Audio File Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35163

Apple QuickTime PSD Image Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35168

Apple QuickTime User Atom Data Size Uninitialized Memory Access Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35162

Apple QuickTime FLC Compression File Heap Overflow Vulnerability
http://www.securityfocus.com/bid/35161

Apple QuickTime Sorenson 3 Video File Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35159

IBM AIX Setlocale Function Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/19578

UltraISO CCD and IMG File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34363

Apple Mac OS X PICT Image Handling Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34938

Ston3D S3DPlayer Web and Standalone 'system.openURL()' Remote Command Injection Vulnerability
http://www.securityfocus.com/bid/35105

Autonomy KeyView Module 'wp6sr.dll' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34086

Microsoft PowerPoint Sound Data (CVE-2009-1129) Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34839

Vixie Cron PAM_Limits Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/18108

eliteCMS Arbitrary File Upload and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/35155

eliteCMS 'page' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/30990

SafeNet SoftRemote IKE Service Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35154

Asmax Ar-804gu Router 'script' Remote Arbitrary Shell Command Injection Vulnerability
http://www.securityfocus.com/bid/35153

OCS Inventory NG Server Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/35152

ZeusCart 'maincatid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35151

ICQ 'ICQToolBar.dll' Denial of Service Vulnerability
http://www.securityfocus.com/bid/35150

Cyrus SASL 'sasl_encode64()' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34961

aMule 'wxExecute()' Arbitrary Command Execution Vulnerability
http://www.securityfocus.com/bid/34683

Arab Portal 'X-Forwarded-for' Header SQL Injection Vulnerability
http://www.securityfocus.com/bid/35149

Wireshark PCNFSD Dissector Denial of Service Vulnerability
http://www.securityfocus.com/bid/35081

Linksys WAG54G2 Web Management Console Remote Arbitrary Shell Command Injection Vulnerability
http://www.securityfocus.com/bid/35142

OpenSSL 'zlib' Compression Memory Leak Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/31692

IBM Access Support ActiveX Control 'GetXMLValue()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34228

Apache 'mod_proxy_ftp' Wildcard Characters Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/30560

Apache 'Options' and 'AllowOverride' Directives Security Bypass Vulnerability
http://www.securityfocus.com/bid/35115

Microsoft IIS Unicode Requests to WebDAV Multiple Authentication Bypass Vulnerabilities
http://www.securityfocus.com/bid/34993

Joomla! JVideo! Component 'user_id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35146

Roxio CinePlayer SonicDVDDashVRNav.DLL ActiveX Control Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/23412

Apple QuickTime Clipping Region (CRGN) Atom Types Heap Overflow Vulnerability
http://www.securityfocus.com/bid/35167

Apple QuickTime Image Description Atom Sign Extension Vulnerability
http://www.securityfocus.com/bid/35166

Apple QuickTime JP2 Image Handling Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35165

Joomla! Juser Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35160

Xvid Video Codec DirectShow Initialization Logic Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35158

Apple iTunes 'itms:' URI Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35157

Xvid Video Codec Macroblock Number Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35156

0 件のコメント:

コメントを投稿