2009年10月26日月曜日

26日 月曜日、大安

JVN#75368899 IPv6 を実装した複数の製品にサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN75368899/index.html

JVNDB-2009-000068 IPv6 を実装した複数の製品にサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000068.html

JVNDB-2009-002145 HP HP-UX の bootpd におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002145.html

JVNDB-2009-002143 Sun Solaris の "w" ユーティリティにおけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002143.html

JVNDB-2009-002142 x86 システム上で稼働している Linux kernel の KVM サブシステムにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002142.html

JVNDB-2009-002141 i386 プラットフォーム上で稼働している Linux kernel の KVM サブシステムにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002141.html

JVNDB-2009-002140 IBM Lotus Domino Web Access におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002140.html

Cyber Security Awareness Month - Day 25 - Port 80 and 443
http://isc.sans.org/diary.html?storyid=7450




+ Linux kernel 2.6.31.5 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.5

+ Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 May Allow Execution of Arbitrary Code or Cause Denial of Service (DoS) - Adobe Security Bulletin APSB09-15
http://sunsolve.sun.com/search/document.do?assetkey=1-66-270669-1

+ Oracle: Critical Patch Update - October 2009 (日本語サイト)
http://support.oracle.co.jp/krown_external/oisc_showDoc.do?id=137451

+ Linux Kernel 'proc' World Writeable File Security Bypass Vulnerability
http://www.securityfocus.com/bid/36806

+ ProFTPD mod_tls Module NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36804

+ Linux Kernel KVM 'kvm_dev_ioctl_get_supported_cpuid()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/36803

+ Linux Kernel KVM 'update_cr8_intercept()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36805

Postfix 2.7 Snapshot 20091023
http://mirror.postfix.jp/postfix-release/experimental/postfix-2.7-20091023.HISTORY

Devel-NYTProf-2.10_94 released
http://search.cpan.org/~timb/Devel-NYTProf-2.10_94/

Debian : New mapserver packages fix serveral vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30712

Gentoo Linux : Pidgin: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30714

「アフィリエイトで配布、月に3000万円稼ぐ会員も」――偽ソフトの実体
シマンテックが説明会、「業績優秀者には高級車のボーナス」
http://itpro.nikkeibp.co.jp/article/Research/20091023/339090/?ST=security

/proc filesystem allows bypassing directory permissions on Linux
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00178.html

[SECURITY] [DSA 1915-1] New Linux 2.6.26 packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00177.html

HP Quality Centre Weak password Obfuscation
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00176.html

[security bulletin] HPSBUX02466 SSRT090192 rev.1 - HP-UX Running Tomcat Servlet Engine, Remo
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00171.html

[security bulletin] HPSBUX02465 SSRT090192 rev.1 - HP-UX Running Apache-based Web Server
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00172.html

[USN-850-2] poppler regression
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00174.html

[ GLSA 200910-02 ] Pidgin: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00170.html

[SECURITY] [DSA 1914-1] New mapserver packages fix serveral vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-10/msg00173.html

Cyber Security Awareness Month - Day 24 - The Small Services
http://isc.sans.org/diary.html?storyid=7447

Windows 7 - How is it doing?
http://isc.sans.org/diary.html?storyid=7441

What's with tcp/0?
http://isc.sans.org/diary.html?storyid=7444

Cyber Security Awareness Month - Day 23 port 179 TCP - Border Gateway Protocol
http://isc.sans.org/diary.html?storyid=7435

TwonkyMedia Server Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/37136/

Snort Bug in Monitoring IPv6 Data Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Oct/1023076.html

Pegasus Mail ERR POP Command Buffer Overflow Lets Remote Users Deny Service
http://securitytracker.com/alerts/2009/Oct/1023075.html

Linux Kernel tc_fill_tclass() Discloses Potentially Sensitive Kernel Memory to Local Users
http://securitytracker.com/alerts/2009/Oct/1023073.html

Snort IPv6 Packets Processing Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/3014

squidGuard URL Processing Multiple Filter Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2009/3013

EMC RepliStor Packets Processing Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/3012

IBM HTTP Server "mod_proxy_ftp" Command Injection and DoS Issues
http://www.vupen.com/english/advisories/2009/3011

DM Albums for WordPress "delete_album" Directory Traversal Issue
http://www.vupen.com/english/advisories/2009/3010

TYPO3 Multiple Code Injection and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2009/3009

HTML-Parser Invalid HTML Entity Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36807

Linux Kernel 'proc' World Writeable File Security Bypass Vulnerability
http://www.securityfocus.com/bid/36806

ProFTPD mod_tls Module NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36804

Linux Kernel KVM 'kvm_dev_ioctl_get_supported_cpuid()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/36803

TYPO3 Core Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36801

Alien Arena 'M_AddToServerList()' UDP Packet Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36782

Linux Kernel KVM 'update_cr8_intercept()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36805

Linux Kernel KVM 'kvm_emulate_hypercall()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36512

Linux kernel 'O_EXCL' NFSv4 Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36472

Linux Kernel eCryptfs Lower Dentry Null Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36639

Linux Kernel '/drivers/net/r8169.c' Out-of-IOMMU Error Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36706

Linux Kernel AppleTalk Driver IP Over DDP Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36379

Linux Kernel 'net/llc/af_llc.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36126

Linux Kernel 64-bit Kernel Register Memory Leak Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36576

Linux Kernel with SELinux 'mmap_min_addr' Low Memory NULL Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/36051

Linux Kernel 'net/ax25/af_ax25.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36635

GNU 'w(1)' Utility Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36369

Microsoft Windows LSASS NTLM Implementation Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36593

Neon NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36079

Neon 'ne_xml*' expat XML Parsing Denial of Service Vulnerability
http://www.securityfocus.com/bid/36080

Cyrus IMAP Server SIEVE Script Local Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36296

Dovecot Sieve Plugin Multiple Unspecified Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/36377

squidGuard Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/36800

DM Albums Multiple File Deletion Vulnerabilities
http://www.securityfocus.com/bid/36799

Pidgin 'msn_slplink_process_msg()' NULL Pointer Dereference Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36071

Pidgin 'protocols/jabber/auth.c' JABBER Server XMPP Specifications Man In The Middle Vulnerability
http://www.securityfocus.com/bid/36368

Pidgin Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35067

Pidgin OSCAR Protocol Web Message Denial of Service Vulnerability
http://www.securityfocus.com/bid/35530

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Apache mod_proxy_ftp Remote Command Injection Vulnerability
http://www.securityfocus.com/bid/36254

Pegasus Mail POP3 Response Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36797

Avast! Insecure File Permissions Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36798

Avast! Insecure Program File Permissions Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36796

Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36343

Mozilla Firefox Error Page Address Bar URI Spoofing Vulnerability
http://www.securityfocus.com/bid/35803

MapServer Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/34306

Websense Email Security Cross Site Scripting and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/36741

Snort Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/36795

MapServer HTTP Request Processing Integer Overflow Vulnerability
http://www.securityfocus.com/bid/36802

0 件のコメント:

コメントを投稿