2010年2月19日金曜日

19日 金曜日、赤口

JVNVU#472363 IPv6 実装における Forward Information Base のアップデートに関する問題
http://jvn.jp/cert/JVNVU472363/index.html

JVNDB-2010-001060 GNU gzip における複数の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001060.html

JVNDB-2010-001059 Rockwell Automation Allen-Bradley MicroLogix PLC に複数の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001059.html

JVNDB-2010-001058 Microsoft Internet Explorer において任意のコードが実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001058.html

JVNDB-2008-001046 MySQL で使用される yaSSL におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001046.html

JVNDB-2008-001045 MySQL で使用される yaSSL における複数のバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001045.html

MS10-015 may cause Windows XP to blue screen (but only if you have malware on it)
http://isc.sans.org/diary.html?storyid=8266

IPAフォントの派生フォント「Takaoフォント」リリース
http://sourceforge.jp/magazine/10/02/18/117208

Asterisk Scripting Support Lets Remote Users Inject Data into Dialplans
http://securitytracker.com/alerts/2010/Feb/1023637.html

IBM Cognos Express Default Management Account Lets Remote User Access the System
http://securitytracker.com/alerts/2010/Feb/1023636.html

New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
http://www.securityfocus.com/bid/38307

PortWise SSL VPN 'reloadFrame' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38308






+ MySQL Community Server 5.1.44 has been released
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-44.html

+ SYM10-002: Security Advisories Relating to Symantec Products - Symantec Event Manipulation Potential Scan Bypass
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_00
http://securitytracker.com/alerts/2010/Feb/1023621.html
http://secunia.com/advisories/38653/
http://www.vupen.com/english/advisories/2010/0410

+ SYM10-004: Security Advisories Relating to Symantec Products - Symantec Client Proxy Buffer Overflow in Older Product Versions
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_02
http://securitytracker.com/alerts/2010/Feb/1023624.html
http://secunia.com/advisories/38651/
http://www.vupen.com/english/advisories/2010/0412

++ Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
http://www.cisco.com/warp/public/707/cisco-sa-20100217-asa.shtml

[ANNOUNCE] dataPro version 1.6.1 released
http://www.vive.net/products/datapro.htm

Samba3-HOWTOの日本語訳を公開しました。
http://www.samba.gr.jp/project/translation/Samba3-HOWTO/

Call for Papers: 12th German Perl Workshop 2010
http://use.perl.org/article.pl?sid=10/02/18/1726218&from=rss

EMS SQL Manager for PostgreSQL version 4.7 released
http://www.postgresql.org/about/news.1182

iTuple and haxTuple: open source ERP, now on the iPhone and with bug derby prizes
http://www.postgresql.org/about/news.1181

340485: Volumes controlled by Veritas Cluster Services or Storage Foundation for Windows High Availability will cause system hang during large file copy in certain instances.
http://seer.entsupport.symantec.com/docs/340485.htm

Mandriva : pidgin
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31801

Secunia : Mozilla Firefox Memory Corruption Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31813

Cisco : Multiple Vulnerabilities in Cisco Security Agent
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31807

Cisco : Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31808

Cisco : Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerabi
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31809

Debian : New kdelibs packages fix arbitrary code execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31804

Independent Researcher : Rising Online Virus Scanner ActiveX Control DoS (Stack overflow)
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31810

Justin C. Klein Keane : Drupal Help Injection Module XSS Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31811

Mandriva : netpbm
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31799

Mandriva : gnome-screensaver
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31800

ProCheckUp : Cross-Site Scriting on Portwise SSL VPN v4.6
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31812

Red Hat : Critical: firefox security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31805

Red Hat : Critical: seamonkey security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31806

Ubuntu Security Notice : Firefox 3.0 and Xulrunner 1.9 vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31802

Ubuntu Security Notice : Firefox 3.5 and Xulrunner 1.9.1 vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31803

[SECURITY] [DSA 1999-1] New xulrunner packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00164.html

[ MDVSA-2010:034-1 ] kernel
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00162.html

ZDI-10-018: IBM Cognos Server Backdoor Account Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00160.html

[ MDVSA-2010:041 ] pidgin
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00168.html

Secunia Research: Mozilla Firefox Memory Corruption Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00158.html

[USN-895-1] Firefox 3.0 and Xulrunner 1.9 vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00166.html

[ MDVSA-2010:040 ] gnome-screensaver
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00161.html

[ MDVSA-2010:039 ] netpbm
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00165.html

Cross-Site Scriting on Portwise SSL VPN v4.6
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00156.html

Cisco Security Advisory: Cisco Firewall Services Module Skinny Client Control Protocol Inspection De
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00159.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Applian
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00157.html

Circumventing Critical Security in Windows XP
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00163.html

Pixel Portal Sql Injection Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00155.html

RHSA-2010:0115-1: Moderate: pidgin security update
http://rhn.redhat.com/errata/RHSA-2010-0115.html

Mozilla Thunderbird Use-After-Free Error in HTML Parser Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023633.html

Mozilla Thunderbird Browser Engine Bugs Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023632.html

Symantec Client Security Buffer Overflow in SYMLTCOM.dll ActiveX Control Lets Remote Users Execute Arbitrary Code in Certain Limited Cases
http://securitytracker.com/alerts/2010/Feb/1023631.html

Norton System Works Buffer Overflow in SYMLTCOM.dll ActiveX Control Lets Remote Users Execute Arbitrary Code in Certain Limited Cases
http://securitytracker.com/alerts/2010/Feb/1023630.html

Norton Anti-Virus Buffer Overflow in SYMLTCOM.dll ActiveX Control Lets Remote Users Execute Arbitrary Code in Certain Limited Cases
http://securitytracker.com/alerts/2010/Feb/1023629.html

Norton Internet Security Buffer Overflow in SYMLTCOM.dll ActiveX Control Lets Remote Users Execute Arbitrary Code in Certain Limited Cases
http://securitytracker.com/alerts/2010/Feb/1023628.html

Symantec Client Security Buffer Overflow in Client Proxy ActiveX Control Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023625.html

Symantec AntiVirus Buffer Overflow in Client Proxy ActiveX Control Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Feb/1023624.html

Symantec Endpoint Protection Event Management Flaw Lets Remote Users Bypass On-Demand Scanning
http://securitytracker.com/alerts/2010/Feb/1023623.html

Symantec Client Security Event Management Flaw Lets Remote Users Bypass On-Demand Scanning
http://securitytracker.com/alerts/2010/Feb/1023622.html

Symantec AntiVirus Event Management Flaw Lets Remote Users Bypass On-Demand Scanning
http://securitytracker.com/alerts/2010/Feb/1023621.html

Mozilla Firefox Content-Type Header Processing Error Permits Cross-Domain Scripting Attacks
http://securitytracker.com/alerts/2010/Feb/1023615.html

Drupal Content Distribution Module Multiple Vulnerabilities
http://secunia.com/advisories/38652/

Joomla! Core Design Scriptegrator Plugin "files[]" File Inclusion Vulnerability
http://secunia.com/advisories/38637/

DotNetNuke Role Expiration Privilege Escalation Security Issue
http://secunia.com/advisories/38634/

New-CMS Script Insertion and Cross-Site Request Forgery Vulnerabilities
http://secunia.com/advisories/38631/

OmniDocs SQL Injection Vulnerability
http://secunia.com/advisories/38527/

Mozilla Firefox Unspecified Code Execution Vulnerability
http://secunia.com/advisories/38608/

IBM Lotus Notes Unspecified Buffer Overflow Vulnerability
http://secunia.com/advisories/38622/

Novell Products Kerberos KDC Integer Underflow Vulnerabilities
http://secunia.com/advisories/38612/

Google Gadget ActiveX Control ATL Templates Vulnerability
http://secunia.com/advisories/38496/

Cisco Security Agent Multiple Vulnerabilities
http://secunia.com/advisories/38619/

Symantec Products "SYMLTCOM.dll" ActiveX Control Buffer Overflow
http://secunia.com/advisories/38654/

Pidgin Multiple Denial of Service Weaknesses
http://secunia.com/advisories/38563/

Enomaly ECP Community Edition "vmfeed" Module Multiple Security Issues
http://secunia.com/advisories/38589/

Symantec Products Scanning Bypass Weakness
http://secunia.com/advisories/38653/

Cisco PIX 500 Series Multiple Vulnerabilities
http://secunia.com/advisories/38636/

Cisco Firewall Services Module Denial of Service Vulnerability
http://secunia.com/advisories/38621/

Cisco ASA 5500 Series Multiple Vulnerabilities
http://secunia.com/advisories/38618/

Ubuntu update for firefox and xulrunner
http://secunia.com/advisories/38663/

Ubuntu update for firefox and xulrunner
http://secunia.com/advisories/38649/

Symantec Products Client Proxy ActiveX Control Buffer Overflow
http://secunia.com/advisories/38651/

Red Hat update for seamonkey
http://secunia.com/advisories/38661/

Nikira Fraud Management System "message" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38564/

KDE KRunner Lock Module Race Condition Weakness
http://secunia.com/advisories/38600/

Drupal iTweak Upload Module Script Insertion Vulnerability
http://secunia.com/advisories/38633/

Red Hat update for firefox
http://secunia.com/advisories/38655/

Debian update for kdelibs
http://secunia.com/advisories/38624/

Mozilla Thunderbird Multiple Vulnerabilities
http://secunia.com/advisories/38657/

Mozilla SeaMonkey Multiple Vulnerabilities
http://secunia.com/advisories/38656/

Mozilla Firefox Multiple Vulnerabilities
http://secunia.com/advisories/37242/

Erotik Auktionshaus "id" SQL Injection Vulnerability
http://secunia.com/advisories/38614/

Multiple File Attachments Mail Form Arbitrary File Upload Security Issue
http://secunia.com/advisories/38630/

Linux Kernel USB Information Disclosure and Denial of Service
http://secunia.com/advisories/38601/

Cisco ASA 5500 Authentication Bypass and Denial of Service Issues
http://www.vupen.com/english/advisories/2010/0415

Novell Products Kerberos AES / RC4 Integer Underflow Vulnerabilities
http://www.vupen.com/english/advisories/2010/0414

Pidgin Security Update Fixes Multiple Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/0413

Symantec Products Client Proxy Remote Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0412

Symantec Products "SYMLTCOM.dll" Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0411

Symantec Products Event Manipulation Scan Bypass Weakness
http://www.vupen.com/english/advisories/2010/0410

KDE KRunner Lock Module Race Condition Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/0409

Mozilla Products Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0405

Easy~Ftp Server v1.7.0.2 (HTTP) Remote BOF Exploit
http://www.exploit-db.com/exploits/11500

gitWeb v1.5.2 Remote Command Execution
http://www.exploit-db.com/exploits/11497

SYM10-005: Security Advisories Relating to Symantec Products - Symantec IM Manager Local-Access Cross-site Scripting
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100218_00

SYM10-003: Security Advisories Relating to Symantec Products - Input validation errors in SYMLTCOM.dll can lead to a buffer overflow.
http://www.symantec.com/business/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2010&suid=20100217_01

Expat UTF-8 Character XML Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36097

FFmpeg Version 0.5 Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/36465

Linux Kernel 'hfc_usb.c' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37036

Linux Kernel 'drivers/scsi/gdth.c' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37068

Linux Kernel AppleTalk Driver IP Over DDP Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36379

Linux Kernel 'unix_stream_connect()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/36723

Linux Kernel 'ebtables' Security Bypass Vulnerability
http://www.securityfocus.com/bid/37762

Linux e1000 Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/37519

Linux Kernel r128 Driver CCE Initialization NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/36824

Linux Kernel 'megaraid_sas' Driver Insecure File Permission Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37019

Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/38286

Mozilla Firefox and SeaMonkey Web Workers Array Data Type Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38285

Mozilla Firefox/Thunderbird/SeaMonkey HTML Parser Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38287

Mozilla Firefox and SeaMonkey 'showModalDialog' method Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38289

Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38288

Multiple Adobe Products Unspecified Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38198

Adobe Acrobat and Reader CVE-2010-0188 Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38195

Pidgin Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38294

Mozilla Firefox Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38298

Adobe BlazeDS Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38197

Joomla! Core Design Scriptegrator Component Local File Include Vulnerability
http://www.securityfocus.com/bid/38296

Microsoft Windows #GP Trap Handler Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37864

Microsoft Windows Double Free Memory Corruption Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38044

IBM Cognos Express Hardcoded Credentials Security Bypass Vulnerability
http://www.securityfocus.com/bid/38084

Python Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/30491

Python zlib Module Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/28715

Python ImageOP Module Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/25696

MIT Kerberos AES and RC4 Decryption Integer Underflow Vulnerabilities
http://www.securityfocus.com/bid/37749

Multiple RealNetworks Products Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/37880

CubeCart 'productId' SQL Injection Vulnerability
http://www.securityfocus.com/bid/37065

Multiple RealNetworks Products Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/37880

CubeCart 'productId' SQL Injection Vulnerability
http://www.securityfocus.com/bid/37065

Google Desktop Gadget ActiveX Control ATL Templates Security Vulnerability
http://www.securityfocus.com/bid/38060

Netpbm XPM File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38164

Drupal iTweak Upload Module HTML Injection Vulnerability
http://www.securityfocus.com/bid/38292

XlentProjects SphereCMS 'archive.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38309

New-CMS Multiple Local File Include and HTML-Injection Vulnerabilities
http://www.securityfocus.com/bid/38307

Newgen Software OmniDocs 'ForceChangePassword.jsp' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38304

OSClass Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/38302

IBM Lotus Notes Unspecified Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38300

DotNetNuke Role Expiration Security Bypass Vulnerability
http://www.securityfocus.com/bid/38299

DigiDNA FileApp Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38297

Joomla! 'com_otzivi' Component 'controller' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/38295

Symantec IM Manager Console HTML Injection Vulnerability
http://www.securityfocus.com/bid/38241

0 件のコメント:

コメントを投稿