2009年9月15日火曜日

15日 火曜日、先負

+ Solution 266908: Security vulnerability in Solaris Pidgin (see pidgin(1)), Versions Prior to 2.5.9 may Lead to Execution of Arbitrary Code or a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-266908-1
http://secunia.com/advisories/36708/

Botnet discovered on Linux servers
http://www.linux.org/news/2009/09/14/0002.html

Linux Mint Xfce Community Edition Released
http://www.linux.org/news/2009/09/14/0001.html

JVNDB-2009-002005 Apple Mac OS におけるファイルディスクリプタの共有に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002005.html

JVNDB-2009-002004 Apple Mac OS の kernel におけるバッファーオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002004.html

JVNDB-2009-002003 Apple Mac OS の MobileMe におけるセッションをハイジャックされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002003.html

JVNDB-2009-002002 Apple Mac OS のログインウィンドウにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002002.html

Debian update for iceweasel
http://secunia.com/advisories/36757/

Debian update for xulrunner
http://secunia.com/advisories/36692/

Apple Xsan Screensharing Local Credentials Disclosure Weakness
http://www.vupen.com/english/advisories/2009/2644

Sun Solaris "w" Utility Heap Overflow Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2009/2643

Linux Kernel 'sock_sendpage()' NULL Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36038

nginx HTTP Request Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36384

GNU Troff pdfroff Insecure Temporary File Creation and Arbitrary File Access Vulnerabilities
http://www.securityfocus.com/bid/36381

Multiple Vendor BIOS Keyboard Buffer Password Persistence Weakness
http://www.securityfocus.com/bid/15751





+ dovecot 1.1.19, 1.2.5 released
http://www.dovecot.org/
http://www.dovecot.org/list/dovecot-news/2009-September/000136.html
http://www.dovecot.org/list/dovecot-news/2009-September/000137.html

+ iptables 1.4.5 released
http://www.iptables.org/projects/iptables/downloads.html#iptables-1.4.5
http://www.iptables.org/projects/iptables/files/changes-iptables-1.4.5.txt

+ Linux Kernel AppleTalk-IP Memory Leak Denial of Service
http://secunia.com/advisories/36707/
http://www.securityfocus.com/bid/36379

+ HPSBUX02458 SSRT090104 rev.1 - HP-UX Running bootpd, Remote Denial of Service (DoS)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&docId=emr_na-c01866324-1

[ANNOUNCE] Apache Felix FileInstall 2.0.0
http://felix.apache.org/site/apache-felix-file-install.html

HPSBST02459 SSRT080134 rev.1 - HP StorageWorks Remote Management Interface (RMI) for MSL Tape Libraries and 1/8 G2 Tape Autoloaders, Denial of Service (DoS)
http://www13.itrc.hp.com/service/cki/docDisplay.do?docLocale=en&docId=emr_na-c01868405-1

EMS SQL Manager for PostgreSQL 4.6 released
http://www.postgresql.org/about/news.1138

Slackware Linux : mozilla-firefox
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30375

Gentoo Linux : ZNC: Directory traversal
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30380

Gentoo Linux : Wireshark: Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30381

Gentoo Linux : HTMLDOC: User-assisted execution of arbitrary code
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30376

Gentoo Linux : irssi: Execution of arbitrary code
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30377

Gentoo Linux : Horde: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30378

Gentoo Linux : Lynx: Arbitrary command execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30379

ニュースレターに見せかける迷惑メール、対策製品の回避が目的
宣伝文句は一切無し、リンクをクリックするとバイアグラ販売サイトへ
http://itpro.nikkeibp.co.jp/article/NEWS/20090915/337217/?ST=security

[TKADV2009-007] Apple iPhone OS AudioCodecs Heap Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00117.html

[USN-831-1] OpenEXR vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00115.html

[USN-830-1] OpenSSL vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00116.html

[SECURITY] [DSA 1886-1] New iceweasel packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00114.html

[SECURITY] [DSA 1885-1] New xulrunner packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00113.html

[SECURITY] [DSA 1884-1] New nginx packages fix arbitrary code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00112.html

[ECHO_ADV_111$2009] Joomla Hotel Booking System Component XSS/SQL Injection Multiple Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00111.html

[SECURITY] [DSA 1883-2] New nagios2 packages fix regression
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00110.html

[ GLSA 200909-17 ] ZNC: Directory traversal
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00108.html

[ GLSA 200909-16 ] Wireshark: Denial of Service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00107.html

War FTP Daemon Remote Denial Of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00104.html

[ GLSA 200909-15 ] Lynx: Arbitrary command execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00103.html

[ GLSA 200909-14 ] Horde: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00102.html

[ GLSA 200909-13 ] irssi: Execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00101.html

[ GLSA 200909-12 ] HTMLDOC: User-assisted execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00100.html

nullcon Goa 2010 Call For Papers
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00099.html

vBulletin 3.8.2 Denial of Service Exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-09/msg00098.html

Horde Groupware / Groupware Webmail Edition Two Vulnerabilities
http://secunia.com/advisories/36729/

Fedora update for postgresql
http://secunia.com/advisories/36727/

Fedora update for firefox and xulrunner
http://secunia.com/advisories/36725/

Fedora update for firefox and xulrunner
http://secunia.com/advisories/36724/

Fedora update for ikiwiki
http://secunia.com/advisories/36723/

Fedora update for puppet
http://secunia.com/advisories/36722/

Sun Solaris 8 "w" Utility Privilege Escalation
http://secunia.com/advisories/36720/

Sun Solaris "w" Utility Privilege Escalation
http://secunia.com/advisories/36719/

Bugzilla Information Disclosure Weakness and SQL Injection Vulnerabilities
http://secunia.com/advisories/36718/

Slackware update for mozilla-firefox
http://secunia.com/advisories/36709/

Lvinux Kernel AppleTalk-IP Memory Leak Denial of Service
http://secunia.com/advisories/36707/

Serendipity Freetag Plugin SQL Injection Vulnerability
http://secunia.com/advisories/36706/

Image voting "show" SQL Injection Vulnerability
http://secunia.com/advisories/36705/

Dovecot CMU Sieve Plugin Buffer Overflow Vulnerabilities
http://secunia.com/advisories/36698/

Xerver HTTP Server Restricted Extensions Security Bypass
http://secunia.com/advisories/36681/

Horde Application Framework Multiple Vulnerabilities
http://secunia.com/advisories/36665/

Gentoo update for horde
http://secunia.com/advisories/36653/

Gentoo update for irssi
http://secunia.com/advisories/36652/

Gentoo update for htmldoc
http://secunia.com/advisories/36651/

Gentoo update for wireshark
http://secunia.com/advisories/36650/

Gentoo update for znc
http://secunia.com/advisories/36641/

Stanford WebAuth Password Disclosure Security Issue
http://secunia.com/advisories/36640/

Graffiti CMS File Upload Vulnerability
http://secunia.com/advisories/36635/

Horde Products File Overwrite and Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2009/2642

CMU Sieve Plugin for Dovecot Buffer Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2009/2641

Bugzilla SQL Injection and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2009/2640

Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2009/2639

Oracle Secure Backup Server 10.3.0.1.0 Auth Bypass/RCI Exploit
http://www.milw0rm.com/exploits/9652

Mozilla Firefox 2.0.0.16 UTF-8 URL Remote Buffer Overflow Exploit
http://www.milw0rm.com/exploits/9663

IPSwitch IMAP Server <= 9.20 Remote Buffer Overflow Exploit http://www.milw0rm.com/exploits/9662

Techlogica HTTP Server 1.03 Arbitrary File Disclosure Exploit
http://www.milw0rm.com/exploits/9660

MP3 Studio 1.0 (.m3u File) Local Buffer Overflow Exploit
http://www.milw0rm.com/exploits/9661

Portable E.M Magic Morph 1.95b .MOR File Stack Buffer Overflow PoC
http://www.milw0rm.com/exploits/9659

Invisible Browsing 5.0.52 (.ibkey) Local Buffer Overflow Exploit
http://www.milw0rm.com/exploits/9655

Solaris Heap Overflow in w(1) Utility Lets Local Users Gain Root Privileges
http://securitytracker.com/alerts/2009/Sep/1022901.html

CUPS Heap Overflow in USB Backend Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2009/Sep/1022898.html

RHBA-2009:1439-1: imlib bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1439.html

RHBA-2009:1440-1: autofs5 bug fix update
http://rhn.redhat.com/errata/RHBA-2009-1440.html

Multiple Vendor FTP Server Long Command Handling Security Vulnerability
http://www.securityfocus.com/bid/31289

Sun Solaris sendfile(3EXT) and sendfilev(3EXT) Local Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36083

Debian devscripts 'uscan' Input Validation Vulnerability
http://www.securityfocus.com/bid/36227

Qt NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36203

OpenEXR Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/35838

WarFTPD Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/20944

Joomla! AlphaUserPoints Component 'username2points' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/36383

Fedora 'puppet' Package Insecure File Permissions Vulnerability
http://www.securityfocus.com/bid/36378

Multiple Vendor BIOS Keyboard Buffer Password Persistence Weakness
http://www.securityfocus.com/bid/15751

Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36299

Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36377

Apple iPhone and iPod Touch MP3 and AAC File Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36338

Ventrilo Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/36365

Webservice-DIC yoyaku_41 Remote Arbitrary Command Injection Vulnerability
http://www.securityfocus.com/bid/36362

CUPS USB backend Local Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36350

Nicecoder iDesk 'download.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/36348

Zoom Player Pro Malformed MIDI File Integer Overflow Vulnerability
http://www.securityfocus.com/bid/36347

Mozilla Firefox/Thunderbird/SeaMonkey MFSA 2009 -14 through -22 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/34656

Apple Xsan Admin Error Message Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36385

Multiple Horde Products Cross-Site Scripting Vulnerabilities and File Overwrite Vulnerability
http://www.securityfocus.com/bid/36382

Oracle Secure Backup CVE-2009-1978 Arbitrary Command Execution Vulnerability
http://www.securityfocus.com/bid/35678

Oracle Secure Backup CVE-2009-1977 Remote Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35672

Nagios Unspecified Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/29140

Nagios Prior to 2.11 Unspecified Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/28250

Nagios Unspecified Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/26152

Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36343

Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36189

Microsoft Windows Telnet NTLM Credential Reflection Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35993

Microsoft IIS FTPd Globbing Functionality Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36273

ZNC File Upload Directory Traversal Vulnerability
http://www.securityfocus.com/bid/35757

Xerox WorkCentre Web Services Extensible Interface Platform Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/36177

Serendipity Freetag Plugin SQL Injection Vulnerability
http://www.securityfocus.com/bid/36376

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36314

ikiwiki 'teximg' Plugin Insecure TeX Commands Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36181

CamlImages PNG Image Parsing Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35556

Wireshark 1.2.0 Multiple Vulnerabilities
http://www.securityfocus.com/bid/35748

Lynx URI Handlers Arbitrary Command Execution Vulnerability
http://www.securityfocus.com/bid/15395

Oracle January 2009 Critical Patch Update Multiple Vulnerabilities
http://www.securityfocus.com/bid/33177

Irssi 'WALLOPS' Message Off By One Heap Memory Corruption Vulnerability
http://www.securityfocus.com/bid/35399

Horde 'Passwd' Module Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/35573

HTMLDOC 'html' File Handling Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35727

Horde IMP Webmail Client Cross Site Scripting And HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/33492

Horde XSS Filter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/33367

Horde Products Local File Include and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/33491

Altiris eXpress NS SC Download ActiveX Control Arbitrary File Download Vulnerability
http://www.securityfocus.com/bid/36346

FreeBSD 'kqueue' Unspecified NULL Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36375

Joomla! Hotel Booking System Multiple Cross Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/36380

Linux Kernel AppleTalk Driver IP Over DDP Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36379

nginx HTTP Request Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36384

0 件のコメント:

コメントを投稿