2010年2月15日月曜日

15日 月曜日、友引

プレス発表
「CRYPTRECシンポジウム2010」応募暗号説明会開催のお知らせ
http://www.ipa.go.jp/about/press/20100215.html

「日本語で偽のウイルス警告」――19言語に対応した「偽ソフト」出現
米CAが報告、OSに応じてソフト名を変更する機能も
http://itpro.nikkeibp.co.jp/article/NEWS/20100215/344541/?ST=security

早くも出現、「Googleバズ」に便乗するウイルスやスパム
「サービス開始から2日目で出現」、セキュリティ企業各社が報告
http://itpro.nikkeibp.co.jp/article/NEWS/20100215/344540/?ST=security

月例更新でWindows XP機の一部に障害、マルウエアとMS10-015が原因か
http://itpro.nikkeibp.co.jp/article/NEWS/20100215/344538/?ST=security

JVNDB-2009-001876 Linux kernel の e1000_clean_rx_irq 関数における整数アンダーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001876.html

JVNDB-2009-001610 OpenSSL における証明書チェーンの有効性を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001610.html

JVNDB-2009-001190 MIT Kerberos の asn1_decode_generaltime 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001190.html

JVNDB-2005-000883 sudo の Perl スクリプト実行時における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2005/JVNDB-2005-000883.html



 
 
 
+ [ProFTPD-announce] ProFTPD 1.3.2d released!
http://www.proftpd.org/docs/NEWS-1.3.2d
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2d

+ Two Security Vulnerabilities in SAMBA(7) May Allow Unauthorized Access to the Remote Root Filesystem or May Lead to a Denial of Service (DoS) Condition
http://sunsolve.sun.com/search/document.do?assetkey=1-66-271069-1

+ Postfix 2.7 stable release
http://www.postfix.org/announcements/postfix-2.7.0.html
http://mirror.postfix.jp/postfix-release/official/postfix-2.7.0.HISTORY

+ Linux Kernel PI Futex Invalid Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38165

- [ProFTPD-announce] ProFTPD 1.3.3rc4 released!
http://www.proftpd.org/docs/NEWS-1.3.3rc4
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.3rc4

HPSBMA02486 SSRT090049 rev.2 - HP OpenView Network Node Manager (OV NNM) Java Runtime Environment (JRE) and Java Developer Kit (JDK), Remote Execution of Arbitrary Code and Other Vulnerabilities
http://www13.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02000725

Postfix 2.8 Snapshot 20100213
http://mirror.postfix.jp/postfix-release/experimental/postfix-2.8-20100213.HISTORY

DreamCoder for PostgreSQL ver 2.3 released
http://www.postgresql.org/about/news.1180

PostgreSQL Code Factory 10.2 released
http://www.postgresql.org/about/news.1179

Kernel release: 2.6.33-rc8
http://www.linux.org/news/2010/02/12/0001.html

スパイウェアパターン891.00にアップデート後にインターネットにアクセスできなくなる現象についてのお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1369

Timekeeping best practices for Linux guests
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1006427&sliceId=1&docTypeID=DT_KB_1_1

RHSA-2010:0101-1: Important: openoffice.org security update
http://rhn.redhat.com/errata/RHSA-2010-0101.html

iDEFENSE : Microsoft PowerPoint OEPlaceholderAtom Invalid Array Indexing Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31748

iDEFENSE : Microsoft PowerPoint LinkedSlideAtom Heap Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31749

iDEFENSE : Microsoft PowerPoint OEPlaceholderAtom Use-After-Free Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31750

Independent Researcher : Google Buzz and blind CSRF attacks
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31754

Independent Researcher : SHA-3 Candidate Mega Collision Attack!!
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31756

Security-Assessment.com : ActiveX Control Mutliple Stack Overflows
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31752

Debian : New ajaxterm packages fix session hijacking
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31745

Hewlett-Packard : HP DreamScreen, Remote Disclosure of Information
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31746

Hewlett-Packard : HP ProLiant Support Pack 8.30 for Windows, Remote Code Execution, Information Disclosure
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31747

Independent Researcher : SQL injection vulnerability in apemCMS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31753

Independent Researcher : ratseg x86 exploit
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31755

[security bulletin] HPSBMA02486 SSRT090049 rev.2 - HP OpenView Network Node Manager (OV NNM) Jav
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00131.html

cmsmadesimple Multiple Security Issues : XSS+ LFI
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00132.html

iDefense Security Advisory 02.09.10: Microsoft PowerPoint OEPlaceholderAtom Invalid Array Indexing V
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00129.html

iDefense Security Advisory 02.09.10: Microsoft PowerPoint LinkedSlideAtom Heap Overflow Vulnerabilit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00130.html

iDefense Security Advisory 02.09.10: Microsoft PowerPoint OEPlaceholderAtom Use-After-Free V
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00128.html

e-Sentinel Security Advisory - Ref: Session Hijacking iPhone Facebook Application ver 3.1.2
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00126.html

ChemViewX v1.9.5 ActiveX Control Mutliple Stack Overflows
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00125.html

(resend) RE: [WEB SECURITY] Trustwaves SpiderLabs Security Advisory TWSL2010-001
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00127.html

SQL injection vulnerability in apemCMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00124.html

Rogue DHCP server fun
http://isc.sans.org/diary.html?storyid=8233

Network Traffic Analysis in Reverse
http://isc.sans.org/diary.html?storyid=8230

Time to update those IP Bogon Filters (again)
http://isc.sans.org/diary.html?storyid=8227

OpenOffice.org Flaws Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023591.html

OpenOffice VBA Macro Security Controls Can Be Bypassed
http://securitytracker.com/alerts/2010/Feb/1023588.html

Squid HTCP Packet Processing NULL Pointer Dereference Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Feb/1023587.html

Squid HTCP Request Processing Denial of Service Vulnerability
http://secunia.com/advisories/38570/

OpenOffice.org 3 Multiple Vulnerabilities
http://secunia.com/advisories/38568/

OpenOffice.org 2 Multiple Vulnerabilities
http://secunia.com/advisories/38567/

Squid HTCP Request Processing Denial of Service Vulnerability
http://secunia.com/advisories/38561/

Debian update for ajaxterm
http://secunia.com/advisories/38560/

Red Hat update for flash-plugin
http://secunia.com/advisories/38559/

Fedora update for kernel
http://secunia.com/advisories/38557/

CommodityRentals Trade Manager "cid" SQL Injection Vulnerability
http://secunia.com/advisories/38556/

CommodityRentals Video Games Rentals Script "pfid" SQL Injection Vulnerability
http://secunia.com/advisories/38555/

CommodityRentals Vacation Rentals Script "rental_id" SQL Injection Vulnerability
http://secunia.com/advisories/38552/

Adobe Reader/Acrobat Domain Sandbox Bypass Vulnerability
http://secunia.com/advisories/38551/

Adobe Flash Player Domain Sandbox Bypass Vulnerability
http://secunia.com/advisories/38547/

Adobe Products XML Processing Information Disclosure
http://secunia.com/advisories/38543/

Ubuntu update for tomcat6
http://secunia.com/advisories/38541/

Accellion File Transfer Appliance Directory Traversal Vulnerability
http://secunia.com/advisories/38538/

HP DreamScreen Information Disclosure Vulnerability
http://secunia.com/advisories/38536/

HP ProLiant Support Pack Visual C++ Redistributable Vulnerabilities
http://secunia.com/advisories/38533/

Accellion File Transfer Appliance Script Insertion Vulnerability
http://secunia.com/advisories/38522/

Hyleos ChemView v1.9.5.1 ActiveX Control Buffer Overflow Exploit (meta)
http://www.exploit-db.com/exploits/11422

Open & Compact FTPd Pre-Authentication Remote Exploit
http://www.exploit-db.com/exploits/11420

CastRipper 2.50.70 (.asx) Playlist Stack Overflow Exploit
http://www.exploit-db.com/exploits/11413

Juniper Networks Juniper Installer Service Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38232

Adobe Flash Player and AIR (CVE-2010-0187) Unspecified Denial of Service Vulnerability
http://www.securityfocus.com/bid/38200

Adobe Flash Player and AIR Unspecified Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38198

Webmin and Usermin Unspecified Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/37259

Qualiteam X-Cart 'cart.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38205

RSA SecurID WebID Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38207

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

OpenSSL PKCS Padding RSA Signature Forgery Vulnerability
http://www.securityfocus.com/bid/19849

Joomla! EasyBook Component Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/38209

VMware Products Directory Traversal Vulnerability
http://www.securityfocus.com/bid/36842

Joomla! Kide Shoutbox Security Bypass Vulnerability
http://www.securityfocus.com/bid/38206

Joomla! Webee Component SQL Injection and HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/38204

Joomla! JQuarks Component SQL Injection Vulnerability
http://www.securityfocus.com/bid/38203

Cisco Collaboration Server Source Code Disclosure Vulnerabilities
http://www.securityfocus.com/bid/38202

Cisco Collaboration Server 'LoginPage.jhtml' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38201

Ghostscript 'errprintf()' Function PDF Handling Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37410

RadASM '.rap' Project File Stack-Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34042

AlstraSoft Video Share Enterprise Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/25019

Microsoft Internet Explorer XML Handling Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/32721

Sun Java SE November 2009 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/36881

Linux Kernel 'do_pages_move()' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38144

Linux Kernel PI Futex Invalid Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38165

Linux Kernel 'drivers/connector/connector.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38058

Microsoft PowerPoint 'OEPlaceholderAtom' Record Invalid Index Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38103

Microsoft PowerPoint 'LinkedSlideAtom' Heap Overflow Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38101

Microsoft Windows Header MDL Fragmentation Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38062

AjaxTerm 'ajaxterm.js' Session Hijacking Vulnerability
http://www.securityfocus.com/bid/34903

Microsoft Windows #GP Trap Handler Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37864

Microsoft Windows Double Free Memory Corruption Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38044

Microsoft PowerPoint 'OEPlaceholderAtom' Record Corrupt Memory Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38104

EMV Protocol PIN Verification Bypass Vulnerability
http://www.securityfocus.com/bid/38231

Hyleos ChemView ActiveX Control Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/38225

Izumi 'src/page.php' Multiple Remote and Local File Include Vulnerabilities
http://www.securityfocus.com/bid/38223

Mini-stream Software CastRipper '.asx' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38221

OpenOffice Prior to 3.2 Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/38218

Alqatari 'lesson.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38216

AIMP '.m3u' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38215

KDE Screensaver Unlock Dialog Race Condition Lock Bypass Vulnerability
http://www.securityfocus.com/bid/38214

Squid Web Proxy Cache HTCP Request Processing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38212

gnome-screensaver Unlock Dialog Race Condition Lock Bypass Vulnerability
http://www.securityfocus.com/bid/38211

0 件のコメント:

コメントを投稿