2009年8月27日木曜日

27日 木曜日、友引

JVNDB-2009-000058 bingo!CMS core および bingo!CMS におけるクロスサイトリクエストフォージェリの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000058.html

JVNDB-2009-001941 Adobe Flash に脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001941.html

JVNDB-2009-001940 Mozilla Firefox の XPCCrossOriginWrapper の処理におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001940.html

JVNDB-2009-001939 Mozilla Firefox の Flash オブジェクトの処理における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001939.html

JVNDB-2009-001938 Mozilla Firefox の setTimeout 関数における任意の JavaScript を実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001938.html

JVNDB-2009-001937 Mozilla Firefox の SVG 要素の処理における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001937.html

once:radix release 1.5
http://www.postgresql.org/about/news.1126

SYM09-012: Security Advisories Relating to Symantec Products - Norton AntiVirus and Symantec Client Security Email Denial of Service Vulnerability
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_01

SYM09-011: Security Advisories Relating to Symantec Products - Symantec Altiris Deployment Solution Multiple Vulnerabilities
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_00

参考)Lotus Notes の Microsoft Excel ファイルビューアーにおけるバッファーオーバーフローの潜在的な脆弱性の問題
http://www-06.ibm.com/ibm/jp/security/info/lotus/si20090826a.html

JVN#68640473 bingo!CMS core および bingo!CMS におけるクロスサイトリクエストフォージェリの脆弱性
http://jvn.jp/jp/JVN68640473/index.html

Symantec Altiris Deployment Solution Multiple Flaws Let Remote Users Modify the Configuration, Execute Arbitrary Commands, and Deny Service
http://securitytracker.com/alerts/2009/Aug/1022779.html

GnuTLS NULL Character Flaw in Common Name Field Lets Remote Users Spoof Certficiates
http://securitytracker.com/alerts/2009/Aug/1022777.html

Solaris Print Service Lets Remote and Local Users Deny Service
http://securitytracker.com/alerts/2009/Aug/1022776.html

Cisco Unified Communications Manager SIP and SCCP Processing Bugs Let Remote Users Deny Service
http://securitytracker.com/alerts/2009/Aug/1022775.html




+ Postfix 2.6.4, 2.5.8, 2.4.12, 2.3.18 released
http://mirror.postfix.jp/postfix-release/index.html
http://mirror.postfix.jp/postfix-release/official/postfix-2.6.4.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-2.5.8.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-2.4.12.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-2.3.18.HISTORY

+ Solution 264608: A Security Vulnerability in the Solaris Print Service (in.lpd(1M)) May Lead to a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-264608-1
http://secunia.com/advisories/36445/
http://www.vupen.com/english/advisories/2009/2417
http://www.securityfocus.com/bid/36148

+ Multiple Symantec Products Email Handling Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34670
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2009&suid=20090826_01

+ Linux Kernel 'net/appletalk/ddp.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36150

[ANNOUNCE] Apache Mina SSHD 0.2.0 released
http://mina.apache.org/sshd/sshd-020.html

[ANNOUNCE] Apache Jackrabbit 2.0 alpha9 released
http://jackrabbit.apache.org/downloads.html

[ANNOUNCE] Apache Derby 10.5.3.0 released
http://db.apache.org/derby/derby_downloads.html

Solution 265688: Solaris 10 BIND Patches, T-patches and IDRs may Fail to Install in Deferred-Activation Patching (DAP) Context as a Result of Having Malformed pkgmap Files Caused by a pkgmk(1) Regression
http://sunsolve.sun.com/search/document.do?assetkey=1-66-265688-1

Solution 247746: HIPER - S0C4 Abends May Occur After Running Consolidate/Export by VTV or Export by Management Class if Patch 132510-01 (L1H13WK) or Patch 132512-01 (L1H13WL) Are Applied
http://sunsolve.sun.com/search/document.do?assetkey=1-66-247746-1

The latest Linux Next version of the Linux kernel is: next-20090826
http://git.kernel.org/?p=linux/kernel/git/next/linux-next.git;a=summary

The latest snapshot 2.6 version of the Linux kernel is: 2.6.31-rc7-git4
http://www.kernel.org/pub/linux/kernel//v2.6/snapshots/patch-2.6.31-rc7-git4.bz2

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities
http://www.cisco.com/warp/public/707/cisco-sa-20090826-cucm.shtml

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Cisco Unified Communications Manager Denial of Service Vulnerabilities
http://www.cisco.com/warp/public/707/cisco-amb-20090826-cucm.shtml

Document ID: 330268: Harddisks in failing status and mirror won't resynchronize.
http://seer.entsupport.symantec.com/docs/330268.htm

Microsoft : Microsoft Security Bulletin Major Revisions
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30242

Positive Technologies : CA Internet Security Suite Denial of Service Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30247

Debian : New dhcp3 packages fix arbitrary code execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30243

Hewlett-Packard : HP Tru64 UNIX or HP Tru64 Internet Express Running BIND Server, Denial of Service (DoS)
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30250

iDEFENSE : Autonomy KeyView Excel File SST Parsing Integer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30244

Independent Researcher : EesySec Personal Firewall Remote Buffer Overflow Exploit
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30249

Independent Researcher : HyperVM File Permissions Local Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30251

Louhi Networks Oy : Xerox WorkCentre multiple models Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30248

NGSSoftware : Oracle PL/SQL Injection Flaw in REPCAT_RPC.VALIDATE_REMOTE_RC
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30245

NGSSoftware : Oracle 11g (11.1.0.6) Password Policy and Compliance
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30246

「15万台が感染、国内でも被害多数」、ウイルスツール「Zeus」の脅威
アンダーグラウンドで“大人気”、個人情報を盗むウイルスを簡単作成
http://itpro.nikkeibp.co.jp/article/NEWS/20090827/336060/?ST=security

[USN-826-1] Mono vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00250.html

[SECURITY] [DSA 1874-1] New nss packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00249.html

[SECURITY] [DSA 1873-1] New xulrunner packages fix spoofing vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00248.html

[MORNINGSTAR-2009-01] Multiple security issues in Open Auto Classifieds version <= 1.5.9 http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00247.html

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00246.html

[PT-2009-05] CA Internet Security Suite Denial of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-08/msg00244.html

RHSA-2009:1232-1: Moderate: gnutls security update
http://rhn.redhat.com/errata/RHSA-2009-1232.html

RHBA-2009:1231-1: system-config-lvm bug-fix update
http://rhn.redhat.com/errata/RHBA-2009-1231.html

Malicious CD ROMs mailed to banks
http://isc.sans.org/diary.html?storyid=7024

Oracle Secure Backup Administration Server Multiple Command Injection Vulnerabilities
http://www.securiteam.com/unixfocus/5XP0L1PS0K.html

Cisco Firewall Services Module Denial of Serevice Vulnerability
http://www.securiteam.com/unixfocus/5ZP0N1PS0O.html

VMware libpng and Apache HTTP Server Arbitrary Code and DOS vulnerability
http://www.securiteam.com/unixfocus/5YP0M1PS0M.html

Radvision Scopia Cross Site Scripting Vulnerabilities
http://www.securiteam.com/securitynews/5BP0P1PS0S.html

ScribeFire Firefox Extension Code Injection Vulnerability
http://www.securiteam.com/securitynews/5AP0O1PS0Q.html

Cisco Access Points Disclose Potentially Sensitive Information and May Let Remote Users Hijack APs
http://securitytracker.com/alerts/2009/Aug/1022774.html

Google Chrome Javascript Memory Access Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022773.html

Symantec Data Loss Prevention Buffer Overflow in Autonomy KeyView Module Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022772.html

Symantec Mail Security Buffer Overflow in Autonomy KeyView Module Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022771.html

Symantec Brightmail Appliance Buffer Overflow in Autonomy KeyView Module Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Aug/1022770.html

ProShow Producer PSH Parsing Buffer Overflow Vulnerability
http://secunia.com/advisories/36466/

EMO Breeder Manager "idd" SQL Injection Vulnerability
http://secunia.com/advisories/36464/

Fedora update for dhcp
http://secunia.com/advisories/36457/

Cerberus FTP Server Command Processing Denial of Service
http://secunia.com/advisories/36456/

IBM Java Active Template Library Vulnerabilities
http://secunia.com/advisories/36453/

IBM Java 6 Multiple Vulnerabilities
http://secunia.com/advisories/36452/

IBM Java Multiple Vulnerabilities
http://secunia.com/advisories/36451/

ProFTP FTP Messages Buffer Overflow Vulnerability
http://secunia.com/advisories/36446/

Sun Solaris Print Service Denial of Service
http://secunia.com/advisories/36445/

Autonomy KeyView SDK XLS Processing Buffer Overflow
http://secunia.com/advisories/36422/

Symantec Products KeyView XLS Processing Buffer Overflow
http://secunia.com/advisories/36421/

Radvision SCOPIA "page" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/36420/

Google Chrome Multiple Vulnerabilities
http://secunia.com/advisories/36417/

Linux Kernel <= 2.6.30 atalk_getname() 8-bytes Stack Disclosure Exploit http://www.milw0rm.com/exploits/9521

IBM Java Multiple Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/2423

EMO Breader Manager "idd" Parameter SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2009/2422

ProShow Producer "psh" File Handling Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/2421

Google Chrome V8 Javascript Engine Memory Read Vulnerability
http://www.vupen.com/english/advisories/2009/2420

Cisco Lightweight Access Points Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2419

Sun Solaris Print Service Unspecified Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2417

Symantec Products KeyView XLS Handling Integer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/2416

Autonomy KeyView SDK XLS Handling Integer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/2415

OpenSC PKCS#11 Implementation Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/33922

'mod_auth_mysql' Package Multibyte Character Encoding SQL Injection Vulnerability
http://www.securityfocus.com/bid/33392

Microsoft OWC ActiveX Control 'BorderAround()' Heap Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35991

Drupal Go - url redirects Multiple HTML Injection and Arbitrary Code Execution Vulnerabilities
http://www.securityfocus.com/bid/36164

PunBB 'pun_user[language]' Parameter Multiple Local File Include Vulnerabilities
http://www.securityfocus.com/bid/32360

Sun Virtual Desktop Infrastructure (VDI) Secure LDAP Vulnerability
http://www.securityfocus.com/bid/36043

Linux Kernel 'cmp_ies()' Remote Null Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36052

PunBB Reputation Module 'poster' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/35844

WordPress Comment Author URI Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/35755

Apple Mac OS X 2009-003 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35954

Microsoft Office Web Components ActiveX Control 'msDataSourceObject()' Code Execution Vulnerability
http://www.securityfocus.com/bid/35642

WordPress Prior to Version 2.8.3 'wp-admin' Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/35935

Microsoft Office Web Components ActiveX Control Memory Allocation Code Execution Vulnerability
http://www.securityfocus.com/bid/35990

Cerberus FTP Server 'ALLO' Command Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36134

Mono 'System.Web' HTTP Header Injection Vulnerability
http://www.securityfocus.com/bid/30867

Mono Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/30471

Drupal Ajax Table Module Security Bypass and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/36165

IBM WebSphere Application Server 'CSIv2' Security Bypass Vulnerability
http://www.securityfocus.com/bid/36163

Multiple Symantec Products Email Handling Denial Of Service Vulnerability
http://www.securityfocus.com/bid/34670

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

Mozilla Firefox Error Page Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35803

Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35891

Simple CMS 'index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/36162

TotalCalendar SQL Injection and Local File Include Vulnerabilities
http://www.securityfocus.com/bid/36161

Computer Associates Internet Security Suite 'vetmonnt.sys' Denial of Service Vulnerability
http://www.securityfocus.com/bid/36077

Sun OpenSSO Enterprise XML Document Processing Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35977

IBM WebSphere Application Server SCA Security Bypass Vulnerability
http://www.securityfocus.com/bid/36159

IBM WebSphere Application Server Single Sign On Security Bypass Vulnerability
http://www.securityfocus.com/bid/36158

IBM WebSphere Application Server Migration Component Trace Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36156

IBM WebSphere Application Server for z/OS File Permission Vulnerability
http://www.securityfocus.com/bid/36157

IBM WebSphere Application Server 'ibm-portlet-ext.xmi' Security Bypass Vulnerability
http://www.securityfocus.com/bid/36155

IBM WebSphere Application Server wsadmin Security Bypass Vulnerability
http://www.securityfocus.com/bid/36153

IBM Websphere Server Weak Password Obfuscation Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36154

Symantec Altiris Deployment Solution File Transfer Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/36113

Symantec Altiris Deployment Solution Authentication Handshake Race Condition Security Vulnerability
http://www.securityfocus.com/bid/36112

Symantec Altiris Deployment Solution 'Aclient' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36111

Symantec Altiris Deployment Solution 'DBManager' Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/36110

Cisco Unified Communications Manager Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/36152

IBM WebSphere Commerce Unspecified Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36151

Linux Kernel 'net/appletalk/ddp.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36150

Sun Java Runtime Environment Audio System Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/35939

Sun Java Runtime Environment JPEG Image Handling Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35942

Sun Java Runtime Environment XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/35958

Sun Java Runtime Environment Unpack200 JAR Unpacking Utility Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35944

Sun JRE/JDK Java Web Start ActiveX Control ATL Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/35945

Sun Java Runtime Environment Proxy Mechanism Implementation Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/35943

JNLPAppletLauncher Arbitrary File Creation Vulnerability
http://www.securityfocus.com/bid/35946

GnuTLS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35952

Sun Solaris Print Service (in.lpd(1M)) Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36148

libxml2 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36010

Google Chrome V8 JavaScript Engine Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36149

0 件のコメント:

コメントを投稿