2009年10月2日金曜日

2日 金曜日、先負

Kernel release: 2.6.31.2-rc1
http://www.linux.org/news/2009/10/02/0002.html

Kernel release: 2.6.30.9-rc1
http://www.linux.org/news/2009/10/02/0001.html

Kernel release: 2.6.27.36-rc1
http://www.linux.org/news/2009/10/01/0008.html

Linux saves Aussie electrical grid
http://www.linux.org/news/2009/10/01/0007.html

openSUSE 11.2 Milestone 8 released
http://www.linux.org/news/2009/10/01/0006.html

Ubuntu 9.10 Beta Released
http://www.linux.org/news/2009/10/01/0005.html

Red Hat Urges Supreme Court to Address Difficulties Posed By Patents to Software
http://www.linux.org/news/2009/10/01/0004.html

NSW Revenue Office bets on Linux agility
http://www.linux.org/news/2009/10/01/0003.html

The OpenBlockS 600 is a Linux server that fits in your palm
http://www.linux.org/news/2009/10/01/0002.html

Putting Linux on Parental Control
http://www.linux.org/news/2009/10/01/0001.html

VMSA-2009-0013 VMware Fusion resolves two security issues
http://lists.vmware.com/pipermail/security-announce/2009/000066.html

米国土安全保障省,今後3年で最大1000人の専門家を雇用へ
http://itpro.nikkeibp.co.jp/article/NEWS/20091002/338070/?ST=security

JVN#84396512 SugarCRM におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN84396512/index.html

JVNDB-2009-000065 SugarCRM におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000065.html

JVNDB-2009-002057 Linux kernel の udp_sendmsg 関数における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002057.html

JVNDB-2009-002056 Linux kernel における proto_ops 構造体の初期化処理に関する権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002056.html

JVNDB-2009-002055 Sun Solaris の pollwakeup 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002055.html

VNDB-2009-002054 Sun Solaris の sendfile および sendfilev 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002054.html

JVNDB-2009-002053 Adobe Flex の SDK におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002053.html

JVNDB-2009-001963 Adobe Flash Player および Adobe AIR におけるクリックジャッキングに関するユーザにリンクを選択させる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001963.html

JVNDB-2009-001962 Adobe Flash Player および Adobe AIR におけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001962.html

JVNDB-2009-001961 Adobe Flash Player および Adobe AIR における Null ポインタの処理に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001961.html

JVNDB-2009-001960 Adobe Flash Player および Adobe AIR におけるヒープベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001960.html

JVNDB-2009-001959 Adobe Flash Player における権限昇格に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001959.html

JVNDB-2009-001941 Adobe Flash に脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001941.html

JVNDB-2009-001889 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001889.html

JVNDB-2009-001888 Apple Safari の WebKit におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001888.html

JVNDB-2009-001733 CUPS の ippReadIO 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001733.html

Samba smbd Processing Flaw Lets Remote Authenticated Users Deny Service
http://securitytracker.com/alerts/2009/Oct/1022976.html

Samba 'mount.cifs' Lets Local Users View Portions of Files on the Target System
http://securitytracker.com/alerts/2009/Oct/1022975.html

NetWare Stack Overflow in 'PKERNEL.NLM' Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2009/Oct/1022974.html

Solaris Bug in Solaris IP(7P) Module and STREAMS Framework Lets Local Users Deny Service
http://securitytracker.com/alerts/2009/Sep/1022973.html





+ OpenSSH 5.3/5.3p1 released
http://www.openssh.com/txt/release-5.3

+ Linux Kernel 64-bit Kernel Register Memory Leak Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36576

[ANN] Apache Felix Web Console version 2.0.0 Released
http://felix.apache.org/apache-felix-web-console.html

[ANNOUNCE] Pg West in two weeks!
http://www.postgresqlconference.org/2009/west/talks

Solution 268448: Multiple Security Vulnerabilities in Firefox Versions Before 3.5.3 May Allow Execution of Arbitrary Code, Access to Unauthorized Data, or Denial of Service (DoS)
http://sunsolve.sun.com/search/document.do?assetkey=1-66-268448-1

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Cisco IOS Tunnels Vulnerability
http://www.cisco.com/warp/public/707/cisco-amb-20090923-tunnels.shtml

InterScan Messaging Hosted Security のWebポータルへログインが行えない現象のご報告
http://www.trendmicro.co.jp/support/news.asp?id=1309

RHSA-2009:1471-1: Important: elinks security update
http://rhn.redhat.com/errata/RHSA-2009-1471.html

RHSA-2009:1472-1: Moderate: xen security and bug fix update
http://rhn.redhat.com/errata/RHSA-2009-1472.html

無料対策ソフト便乗の悪質サイトが早くも出現、目的は偽ソフトの配布
「Security Essentials」で検索すると上位に表示、アクセスすると偽警告
http://itpro.nikkeibp.co.jp/article/NEWS/20091001/338224/?ST=security

[USN-839-1] Samba vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00008.html

Rooted CON 2010 - CFP
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00007.html

[ MDVSA-2009:254 ] graphviz
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00006.html

ZDI-09-067: Novell NetWare NFS Portmapper and RPC Module Stack Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00005.html

[ MDVSA-2009:253 ] backuppc
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00004.html

{PRL} Cerberus FTP server 3.0.6 Pre-Auth DoS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00003.html

{PRL} Novell Edirectory 8.8 SP5 XSS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00002.html

THOTCON 0x1 - Call For Papers is Open -> October 1, 2009
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00001.html

[ MDVSA-2009:178 ] perl-IO-Socket-SSL
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00000.html

Increase in ssh root access attempts
http://isc.sans.org/diary.html?storyid=7213

Lyris ListManager Multiple Vulnerabilities
http://secunia.com/advisories/36926/

Drupal Boost Module Filesystem Directory Creation
http://secunia.com/advisories/36925/

Drupal Organic Groups Script Insertion Vulnerability
http://secunia.com/advisories/36923/

Sun Solaris 8 IP Module and STREAMS Framework Denial of Service
http://secunia.com/advisories/36920/

Novell NetWare RPC CALLIT Buffer Overflow Vulnerability
http://secunia.com/advisories/36916/

Sun Solaris IP Module and STREAMS Framework Denial of Service
http://secunia.com/advisories/36915/

Google Chrome Floating Point Parsing Buffer Overflow
http://secunia.com/advisories/36913/

Drupal Browscap Module Script Insertion Vulnerability
http://secunia.com/advisories/36912/

EMC Captiva PixTools Distributed Imaging ActiveX Control Insecure Methods
http://secunia.com/advisories/36896/

Samba Information Disclosure and Denial of Service
http://secunia.com/advisories/36893/

Red Hat update for openssh
http://secunia.com/advisories/36866/

Red Hat update for kernel
http://secunia.com/advisories/36852/

Lyris ListManager Multiple Vulnerabilities
http://secunia.com/advisories/36823/

Kayako SupportSuite / eSupport Cross-Site Scripting Vulnerability
http://secunia.com/advisories/36807/

EMC Captiva PixTools Distributed Imaging File Creation Vulnerability
http://www.vupen.com/english/advisories/2009/2808

Google Chrome v8 Engine Floating Point Memory Corruption Vulnerability
http://www.vupen.com/english/advisories/2009/2807

Novell NetWare RPC CALLIT Remote Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2009/2806

Sun OpenSolaris Security Update Fixes Firefox Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2009/2805

Sun Solaris IP Module and STREAMS Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/2804

BackupPC 'ClientNameAlias()' Security Bypass Vulnerability
http://www.securityfocus.com/bid/36575

ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36574

OpenOffice EMF File Parser Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/36291

OpenOffice Word Document Table Parsing Multiple Heap Based Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36200

Graphviz Graph Parser Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/31648

Xen pygrub Local Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/36523

Cerberus FTP Server Long Command Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36390

libxml2 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36010

Kayako SupportSuite and eSupport 'functions_ticketsui.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/36568

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36314

Perl IO::Socket::SSL 'verify_hostname_of_cert()' Security Bypass Vulnerability
http://www.securityfocus.com/bid/35587

MIT Kerberos SPNEGO and ASN.1 Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/34408

MIT Kerberos 'asn1_decode_generaltime()' Uninitialized Pointer Memory Corruption Vulnerability
http://www.securityfocus.com/bid/34409

Linux Kernel 64-bit Kernel Register Memory Leak Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36576

Internet Explorer X.509 Certificate Common Name Encoding Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/36577

EMC Captiva PixTools Distributed Imaging ActiveX Control Multiple Insecure Method Vulnerabilities
http://www.securityfocus.com/bid/36566

Newt Text Box Content Processing Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36515

Samba Oplock Break Notification Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36573

Samba setuid 'mount.cifs' Verbose Option Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36572

Samba Misconfigured '/etc/passwd' File Security Bypass Vulnerability
http://www.securityfocus.com/bid/36363

Samba Format String And Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/35472

Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36343

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

Novell NetWare NFS Portmapper and RPC Module Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36564

Novell eDirectory 'dconserv.dlm' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/36567

BlackBerry Device Software Browser Dialog Box Certificate Mismatch Weakness
http://www.securityfocus.com/bid/36528

Google Chrome 'dtoa()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36565

0 件のコメント:

コメントを投稿