2009年11月9日月曜日

9日 月曜日、先勝







JVNDB-2009-002195 IBM AIX の nfs.ext における NFSv4 共有のアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002195.html

JVNDB-2009-002194 IBM AIX の gssd における Kerberized NFSv4 共有のアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002194.html

JVNDB-2009-002193 Linux kernel の md ドライバにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002193.html

JVNDB-2009-002192 Linux kernel の KVM におけるゲスト Kernel メモリを読込/書込される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002192.html

JVNDB-2008-002163 Java Runtime Environment (JRE) における Kerberos 認証に関するサービス運用妨害の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002163.html

JVNDB-2008-002159 Java Runtime Environment (JRE) における JAR ファイルに書き込み可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002159.html

JVNDB-2008-002158 Java Runtime Environment (JRE) における画像処理に関するバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002158.html

JVNDB-2008-002157 Java Runtime Environment (JRE) における GIF ファイルの処理に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002157.html

JVNDB-2008-002149 Java Runtime Environment (JRE) における操作中のユーザのディレクトリの内容をリストされる脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002149.html

JVNDB-2008-002147 Sun Java Web Start および Java Plug-in における任意のファイルを読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002147.html

JVNDB-2008-002145 Sun Java Web Start および Java Plug-in 用 BasicService におけるローカルファイルの内容が別のシステムに送信される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002145.html

JVNDB-2008-002144 Sun Java Web Start および Java Plug-in における JWS キャッシュのパス名およびアプリケーションのユーザ名を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002144.html

JVNDB-2008-002143 Sun Java Web Start および Java Plug-in におけるローカルファイルまたはアプリケーションへのアクセス権限を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002143.html

JVNDB-2008-002142 Sun Java Web Start および Java Plug-in における認証されていないホストへのネットーワーク接続をされる脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-002142.html






- PSN-2009-11-573: SSL/TLS Vulnerability
https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2009-11-573&viewMode=view

+ Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" and "Status.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data
http://sunsolve.sun.com/search/document.do?assetkey=1-66-272230-1
http://www.securityfocus.com/bid/34383

+ Linux kernel 2.4.37.7 released
http://www.kernel.org/pub/linux/kernel/v2.4/ChangeLog-2.4.37.7

- MySQL-SA-11/06/2009: MySQL trick for SQL injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30835

- Php 5.3.0 pdflib extension open_basedir bypass
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00055.html
http://packetstorm.linuxsecurity.com/0911-exploits/php530-bypass.txt
http://www.securityfocus.com/bid/36951

+ OpenSSL TLS Session Renegotiation Plaintext Injection Vulnerability
http://secunia.com/advisories/37291/
http://www.vupen.com/english/advisories/2009/3164

- Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

+ FreeBSD 'fifo_vnops.c' Resource Leak Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36949

[ANNOUNCE] PostgreSQL 8.5 Alpha2 RPMs released
http://developer.postgresql.org/pgdocs/postgres/release-8-5.html

[ANNOUNCE] Free VPS Hosting w/ PostgreSQL - Limited Availability
http://ams.hub.org/signup

[ANNOUNCE] Apache Felix SCR version 1.2.0 Released
http://felix.apache.org/site/apache-felix-service-component-runtime.html

[ANNOUNCE] Apache Directory Studio 1.5 released
http://directory.apache.org/studio/downloads.html

[ANNOUNCE] Apache Lucene java 2.9.1 released
http://lucene.apache.org/java/2_9_1/changes/Changes.html

Linux Kernel release: 2.6.31.6-rc1
http://www.linux.org/news/2009/11/07/0002.html

Linux Kernel release: 2.6.27.39-rc1
http://www.linux.org/news/2009/11/07/0001.html

Document ID: 332631: Volumes are marked as "Missing" after a VxVM restart (including after reboot). The volumes only appear once the diskgroup has been deported, then imported
http://seer.entsupport.symantec.com/docs/332631.htm

Debian : New Linux 2.6.18 packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30825

Gentoo Linux : Horde: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30836

Independent Researcher : MySQL trick for SQL injection
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30835

Mandriva : firefox
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30820

SECURETHOUGHTS : Using Blended Browser Threats involving Chrome to steal files on your computer
http://www.criticalwatch.com/support/security-advisories.aspx?AID=30833

[ GLSA 200911-01 ] Horde: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00056.html

Migration of cert-advisory list subscribers
http://www.derkeiler.com/Mailing-Lists/Cert/2009-11/msg00000.html

Php 5.3.0 pdflib extension open_basedir bypass
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00055.html

[ MDVSA-2009:294 ] firefox
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00053.html

[SECURITY] [DSA 1929-1] New Linux 2.6.18 packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00054.html

Using Blended Browser Threats involving Chrome to steal files on your computer
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00052.html

[SECURITY] [DSA 1928-1] New Linux 2.6.24 packages fix several vulnerabilities

http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2009-11/msg00051.html

iPhone worm in the wild
http://isc.sans.org/diary.html?storyid=7549

Even More Thoughts on Legacy Systems
http://isc.sans.org/diary.html?storyid=7552

FireEye takes on Ozdok and Recovery Ideas
http://isc.sans.org/diary.html?storyid=7555

More Thoughts on Legacy Systems
http://isc.sans.org/diary.html?storyid=7546

New version of OpenSSL released - OpenSSL 0.9.8l
http://isc.sans.org/diary.html?storyid=7543

Fedora update for kernel
http://secunia.com/advisories/37302/

Ubuntu update for libgd2
http://secunia.com/advisories/37301/

Fedora update for kernel
http://secunia.com/advisories/37295/

Debian update for linux-2.6
http://secunia.com/advisories/37293/

GnuTLS TLS Session Renegotiation Plaintext Injection Vulnerability
http://secunia.com/advisories/37292/

OpenSSL TLS Session Renegotiation Plaintext Injection Vulnerability
http://secunia.com/advisories/37291/

Debian update for linux-2.6.24
http://secunia.com/advisories/37282/

Gentoo update for horde
http://secunia.com/advisories/37279/

Google Chrome Two Vulnerabilities
http://secunia.com/advisories/37273/

Citrix NetScaler / Access Gateway Denial of Service Vulnerability
http://secunia.com/advisories/37271/

Ubuntu update for libhtml-parser-perl
http://secunia.com/advisories/37270/

Debian update for linux-2.6
http://secunia.com/advisories/37266/

Ubuntu update for libgd2
http://secunia.com/advisories/37264/

Fedora update for alienarena-data
http://secunia.com/advisories/37259/

Portili Products Multiple Vulnerabilities
http://secunia.com/advisories/37258/

Fedora update for alienarena
http://secunia.com/advisories/37256/

Apple Mac OS X "ptrace()" Denial of Service Vulnerability
http://secunia.com/advisories/37238/

Skeletons in Hyderabad's cyber-closet - PART TWO
http://www.zone-h.org/news/id/4728

BREAKING NEWS: India's mourning its Cyber Crime Squad members
http://www.zone-h.org/news/id/4723

GnuTLS TLS Session Renegotiation Plaintext Injection Vulnerability
http://www.vupen.com/english/advisories/2009/3165

OpenSSL Session Renegotiation Plaintext Injection Vulnerability
http://www.vupen.com/english/advisories/2009/3164

Apple Mac OS X "ptrace()" Local Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/3163

Asterisk Products Cross Site AJAX Request Injection Vulnerability
http://www.vupen.com/english/advisories/2009/3162

Sun OpenSolaris SCTP and SDP Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/3161

Citrix Products Multiple Feature Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2009/3160

Google Chrome Memory Corruption and Script Injection Vulnerabilities
http://www.vupen.com/english/advisories/2009/3159

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

PDFLib 'open_basedir' Restriction Bypass Vulnerability
http://www.securityfocus.com/bid/36951

Alien Arena 'M_AddToServerList()' UDP Packet Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36782

HTML-Parser Invalid HTML Entity Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36807

Linux Kernel Subsystem Connector Missing Capability Check Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/36834

Linux kernel 'O_EXCL' NFSv4 Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36472

Linux Kernel Multiple Protocols Local Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/36176

Linux Kernel 'net/llc/af_llc.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36126

Linux Kernel 'get_random_int' Random Number Generation Weakness
http://www.securityfocus.com/bid/36788

Linux Kernel 2.4 and 2.6 Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36827

Linux Kernel 'pipe.c' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36901

Linux Kernel 'net/ax25/af_ax25.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36635

Linux Kernel 'unix_stream_connect()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36723

Linux Kernel 2.4 and 2.6 Multiple Local Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/36304

Linux Kernel eCryptfs Lower Dentry Null Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36639

Linux Kernel AppleTalk Driver IP Over DDP Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36379

Linux Kernel 'kernel/signal.c' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/35929

Linux Kernel PA-RISC EEPROM Driver Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36004

Linux Kernel 64-bit Kernel Register Memory Leak Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36576

Linux Kernel '/drivers/net/r8169.c' Out-of-IOMMU Error Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36706

Linux Kernel r128 Driver CCE Initialization NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/36824

Linux Kernel 'clear_child_tid()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/35930

Linux Kernel Keyring 'refcount' Local Integer Underflow Vulnerability
http://www.securityfocus.com/bid/36793

Linux Kernel KVM 'kvm_dev_ioctl_get_supported_cpuid()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/36803

Mozilla Firefox CVE-2009-3379 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36875

Mozilla Firefox CVE-2009-3378 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36873

Mozilla Firefox CVE-2009-3377 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/36872

Mozilla Firefox and SeaMonkey Proxy Auto-Configuration File Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36856

Mozilla Firefox and SeaMonkey Download Filename Spoofing Vulnerability
http://www.securityfocus.com/bid/36867

Mozilla Firefox CVE-2009-3380 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/36871

Mozilla Firefox XPCOM Utility Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36857

Mozilla Firefox and SeaMonkey 'libpr0n' GIF Parser Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36855

Mozilla Firefox 'document.getSelect' Cross Domain Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36858

Mozilla Firefox Download Manager World Writable File Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/36852

Mozilla Firefox Form History Information Disclosure Vulnerability
http://www.securityfocus.com/bid/36853

Mozilla Firefox JavaScript Web-Workers Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36854

Mozilla Firefox Floating Point Conversion Heap Overflow Vulnerability
http://www.securityfocus.com/bid/36851

Citrix NetScaler and Access Gateway Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36948

Mod_Perl Path_Info Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/23192

Apache mod_perl 'Apache::Status' and 'Apache2::Status' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/34383

Google Chrome prior to 3.0.195.32 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36947

FreeBSD 'fifo_vnops.c' Resource Leak Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36949

Multiple Horde Products Cross-Site Scripting Vulnerabilities and File Overwrite Vulnerability
http://www.securityfocus.com/bid/36382

0 件のコメント:

コメントを投稿