2009年7月22日水曜日

22日 水曜日、赤口

+ MySQL 5.0.84 released
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-84.html

JVNDB-2009-001794 Microsoft Office Excel における Excel ファイルの処理に関する整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001794.html

JVNDB-2009-001793 Microsoft Office Excel における Excel ファイルの処理に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001793.html

JVNDB-2009-001792 Microsoft Office Excel における Excel ファイルの処理に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001792.html

JVNDB-2009-001791 Microsoft Office Excel における Excel ファイルの処理に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001791.html

JVNDB-2009-001790 Microsoft Office Excel における BIFF ファイルの処理に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001790.html

JVNDB-2009-001789 Microsoft Office Excel における Excel ファイルの処理に関するバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001789.html

JVNDB-2009-001788 Microsoft Office Excel における Excel ファイルの処理に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001788.html

JVNDB-2009-001787 Windows 上で稼働している Microsoft IIS の WebDAV 拡張における認証を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001787.html

MySQL 5.0.85 (Not yet released)
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-85.html

RHSA-2009:1162-1: Critical: firefox security update
http://rhn.redhat.com/errata/RHSA-2009-1162.html

RHSA-2009:1163-1: Critical: seamonkey security update
http://rhn.redhat.com/errata/RHSA-2009-1163.html

ソフトウェア等の脆弱性関連情報に関する届出状況
[2009年第2四半期(4月~6月)]
http://www.ipa.go.jp/security/vuln/report/vuln2009q2.html

ワシントン大,機密情報を一定時間後に自然消滅させるツールを公開
http://itpro.nikkeibp.co.jp/article/NEWS/20090722/334208/?ST=security

Firefox 3.0.12 is Available
http://isc.sans.org/diary.html?storyid=6844

Novell Privileged User Manager Bug Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Jul/1022584.html

Wireshark Flaws in IPMI, AFS, Inifiniband, Bluetooth L2CAP, RADIUS, MIOP, and sFlow Dissector Remote Denial of Service
http://securitytracker.com/alerts/2009/Jul/1022583.html

Pango 'pango_glyph_string_set_size()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/34870

OpenSSL DTLS Packets Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/35001

OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/35138







+ HPSBUX02437 SSRT090038 rev.1 - HP-UX Running XNTP, Remote Execution of Arbitrary Code
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01763606-1

+ Linux Kernel SGI GRU Driver Off By One Vulnerability
http://www.securityfocus.com/bid/35753

- Solution 259148: Security Vulnerability in the Solaris Simple Authentication and Security Layer (SASL) Library (see libsasl(3LIB)) Routine sasl_encode64(3SASL) may Allow Unprivileged Users to Crash Applications Using this Function
http://sunsolve.sun.com/search/document.do?assetkey=1-66-259148-1

- RHSA-2009:1164-1: Important: tomcat security update
http://rhn.redhat.com/errata/RHSA-2009-1164.html

ウイルスパターンファイル 6.291.00~6.295.00における誤警告情報
http://www.trendmicro.co.jp/support/news.asp?id=1281

Independent Researcher : One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29861

INFIGO : NASA Common Data Format remote buffer overflow(s)
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29860

FreeBSD : FreeBSD 7.2 (pecoff executable) Local Denial of Service Exploit 23
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29859

Nine:Situations:Group : Adobe related service (getPlus_HelperSvc.exe) local elevation of privileges
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29862

Ubuntu Security Notice : Ruby vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=29858

2008年の国内セキュリティソフト市場規模は1911億円 IDC Japan予測
http://itpro.nikkeibp.co.jp/article/Research/20090722/334200/?ST=security

JVNVU#466161 XML 署名の検証において認証回避が可能な問題
http://jvn.jp/cert/JVNVU466161/index.html

Re[4]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3....
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00149.html

ZDI-09-046: Novell Privileged User Manager Remote DLL Injection Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00151.html

Adobe Acrobat 9.1.2 NOS Local Privilege Escalation Exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00152.html

Re[4]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3....
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00148.html

Re[2]: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3....
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00146.html

Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3....
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00139.html

mChek 3.4 Information Disclosure
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00143.html

[INFIGO-2009-07-09]: NASA Common Data Format remote buffer overflow(s)
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-07/msg00142.html

Common Data Format CDF File Processing Vulnerabilities
http://secunia.com/advisories/35940/

Ubuntu update for Ruby
http://secunia.com/advisories/35937/

Real Time Currency Exchange "Amount" Cross-Site Scripting
http://secunia.com/advisories/35936/

PHP Scripts Now Multiple Products "rank" SQL Injection Vulnerability
http://secunia.com/advisories/35935/

PHP Scripts Now Astrology "day" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/35933/

PHP Scripts Now Riddles Cross-Site Scripting and SQL Injection
http://secunia.com/advisories/35932/

Adobe getPlus DLM Insecure Default Directory Permissions
http://secunia.com/advisories/35930/

AdQuick "red_url" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/35926/

DragDropCart Multiple Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35925/

EZArticles "title" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/35924/

EZodiak "sign" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/35923/

EZWebSearch "language" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/35922/

GejoSoft "photos/tags" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/35921/

MyWeight Multiple Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35919/

Programs Rating "id" Cross-Site Scripting
http://secunia.com/advisories/35918/

EzWebCalendar File Upload Vulnerability
http://secunia.com/advisories/35905/

Acoustica MP3 Audio Mixer M3U Playlist Importing Buffer Overflow
http://secunia.com/advisories/35902/

Netrix CMS "cikkform.php" Security Bypass Vulnerability
http://secunia.com/advisories/35891/

FreeBSD PE COFF Loading Denial of Service Vulnerability
http://secunia.com/advisories/35889/

PHP Scripts Now Hangman Two Vulnerabilities
http://secunia.com/advisories/35888/

MCshoutbox Multiple Vulnerabilities
http://secunia.com/advisories/35885/

Wireshark Multiple Vulnerabilities
http://secunia.com/advisories/35884/

EpicDJ Playlist Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/35878/

EpicVJ Playlist Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/35869/

Audio Lib Player Playlist Processing Buffer Overflow
http://secunia.com/advisories/35867/

YourFreeWorld Ultra Classifieds Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/35857/

Novell Privileged User Manager Library Injection Vulnerability
http://secunia.com/advisories/35840/

America's Army Multiple Vulnerabilities
http://secunia.com/advisories/35809/

World in Conflict Data Type Processing Denial of Service
http://secunia.com/advisories/35802/

MS Office Web Components Spreadsheet ActiveX (OWC10/11) Exploit
http://www.milw0rm.com/exploits/9224

Adobe Acrobat 9.1.2 NOS Local Privilege Escalation Exploit
http://www.milw0rm.com/exploits/9223

WINMOD 1.4 (.lst File) Local Buffer Overflow Exploit (SEH)
http://www.milw0rm.com/exploits/9221

NASA Common Data Format File Handling Memory Corruption Issues
http://www.vupen.com/english/advisories/2009/1971

Wireshark Buffer Overflow and Multiple Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2009/1970

Adobe getPlus Download Manager Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2009/1969

GejoSoft Community URI Handling Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1968

Programs Rating "id" Parameter Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1967

Proxy Site Script "ip" Parameter Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1966

Ultra Classifieds Pro Multiple Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2009/1965

Web TV (YouTube TV) "chn" Parameter Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2009/1964

Audio Lib Player Playlist Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1963

PowerUpload Cookie Handling Authentication Bypass Vulnerability
http://www.vupen.com/english/advisories/2009/1962

MCshoutbox SQL Injection and Arbitrary File Upload Vulnerabilities
http://www.vupen.com/english/advisories/2009/1961

MiniCWB "LANG" Parameter Remote File Inclusion Vulnerabilities
http://www.vupen.com/english/advisories/2009/1960

KMplayer Subtitles File Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1959

Acoustica MP3 Audio Mixer File Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1958

Medieval CUE Splitter CUE File Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1957

EpicDJ Playlist Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1956

EpicVJ Playlist Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1955

Soritong MP3 Player Skin Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1954

Streaming Audio Player Skin Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/1953

Apache Tomcat XML Parser Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35416

Apache Tomcat 'RequestDispatcher' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35263

Apache Tomcat Form Authentication Existing/Non-Existing Username Enumeration Weakness
http://www.securityfocus.com/bid/35196

Apache Tomcat Java AJP Connector Invalid Header Denial of Service Vulnerability
http://www.securityfocus.com/bid/35193

Apache Tomcat Cookie Quote Handling Remote Information Disclosure Vulnerability
http://www.securityfocus.com/bid/27706

ZNC File Upload Directory Traversal Vulnerability
http://www.securityfocus.com/bid/35757

Novell Privileged User Manager Remote Library Injection Vulnerability
http://www.securityfocus.com/bid/35752

NOS getPlus Download Manager Insecure File Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35740

Common Data Format Library Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35754

@Mail 'admin.php' Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/34762

World in Conflict Typecheck Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/35751

Linux Kernel SGI GRU Driver Off By One Vulnerability
http://www.securityfocus.com/bid/35753

McAfee SmartFilter Multiple Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/35756

Sun Java System Web Server '.jsp' File Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35577

Microsoft Office Web Components ActiveX Control 'msDataSourceObject' Code Execution Vulnerability
http://www.securityfocus.com/bid/35642

WordPress Comment Author URI Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/35755

America's Army Multiple Vulnerabilities
http://www.securityfocus.com/bid/35749

Wireshark 1.2.0 Multiple Vulnerabilities
http://www.securityfocus.com/bid/35748

YourFreeWorld Programs Rating Script Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/35746

E-Xoopport MyAnnonces 'lid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35744

Novell NetIdentity Agent 'XTIERRPCPIPE' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/34400

0 件のコメント:

コメントを投稿