2010年2月25日木曜日

25日 木曜日、赤口

sk42723: Check Point response to Sockstress TCP DoS attacks (CVE-2008-4609)
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk42723&src=securityAlerts

Restarting the Management agents on an ESX or ESXi Server
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1003490&sliceId=1&docTypeID=DT_KB_1_1

脆弱性対策情報データベースのソフトウェアインタフェースを公開
http://www.ipa.go.jp/security/vuln/press/201002_myjvn_api.html

セキュリティ設定共通化手順SCAP概説
http://www.ipa.go.jp/security/vuln/SCAP.html

JVN#73331060 tDiary 付属のプラグイン tb-send.rb におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN73331060/index.html

JVNTA10-021A Internet Explorer に複数の脆弱性
http://jvn.jp/cert/JVNTA10-021A/index.html

JVNDB-2010-000005 tDiary 付属のプラグイン tb-send.rb におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000005.html

JVNDB-2003-000401 Sun ONE/iPlanet Web Server における HTTP リクエストを非表示にされる脆弱性
http://jvndb.jvn.jp/ja/contents/2003/JVNDB-2003-000401.html

JVNDB-2003-000400 Sun ONE/iPlanet Web Server におけるログファイルに任意のテキストを挿入される脆弱性
http://jvndb.jvn.jp/ja/contents/2003/JVNDB-2003-000400.html

JVNDB-2010-001085 IBM WebSphere Application Server の Single Sign-on 機能における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001085.html

JVNDB-2010-001060 GNU gzip における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001060.html

JVNDB-2010-001006 Linux kernel の e1000e ドライバにおけるイーサネットフレームの処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001006.html

JVNDB-2009-002473 PHP の htmlspecialchars 関数におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002473.html

JVNDB-2009-002447 GNU Libtool の libltdl における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002447.html

JVNDB-2009-002396 Apple Safari の WebKit における任意の Web サイトにリクエストされる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002396.html

JVNDB-2009-002395 Apple Safari の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002395.html

JVNDB-2009-001505 Linux kernel の icmp_send 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001505.html

JVNDB-2009-001292 Linux Kernel の audit_syscall_entry 関数におけるシステムコール監査設定を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001292.html

US-CERT Technical Cyber Security Alert TA10-055A -- Malicious Activity Associated with "Aurora" Internet Explorer Exploit
http://www.derkeiler.com/Mailing-Lists/Cert/2010-02/msg00001.html

Pass The Hash
http://isc.sans.org/diary.html?storyid=8296

Vulnerability Note VU#166739: APC Network Management Card web interface vulnerable to cross-site scripting and cross-site request forgery
http://www.kb.cert.org/vuls/id/166739

TIBCO Administrator Unspecified Flaw Lets Remote Authenticated Users Gain Elevated Privileges
http://securitytracker.com/alerts/2010/Feb/1023653.html

WebKit Style Tag Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38398

OpenInferno OI.Blogs Multiple Local File Include Vulnerabilities
http://www.securityfocus.com/bid/38402

Softbiz Auktios Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38399







+ sudo "sudoedit" Privilege Escalation Security Issue
http://secunia.com/advisories/38659/
+ Todd Miller Sudo 'sudoedit' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38362
+ Sudo "sudoedit" Command Local Privilege Escalation Vulnerability
http://www.vupen.com/english/advisories/2010/0450
+ Sudoedit may allow users to run any command
http://www.sudo.ws/sudo/alerts/sudoedit_escalate.html

+ sudo 1.6.9p21, 1.7.2p4 released
http://www.sudo.ws/sudo/news.html
http://www.ring.gr.jp/archives/misc/sudo/?C=M;O=D

+ ProFTPD 1.3.2e, 1.3.3 released
http://www.proftpd.org/
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2e
http://www.proftpd.org/docs/RELEASE_NOTES-1.3.3

+ Samba 3.4.6 Available for Download
http://news.samba.org/releases/3.4.6/
http://samba.org/samba/history/samba-3.4.6.html

+ Linux kernerl 2.6.33 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33
http://www.linux.org/news/2010/02/24/0001.html

+- RHSA-2009:1455-3: Moderate: kernel security and bug fix update
http://rhn.redhat.com/errata/RHSA-2009-1455.html

+ Linux Kernel TSB I-TLB Load Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38393

Package: Courier 0.64.1 released
https://sourceforge.net/projects/courier/files/courier/0.64.1/courier-0.64.1.tar.bz2/download

Package: maildrop 2.4.2 released
https://sourceforge.net/projects/courier/files/maildrop/2.4.2/maildrop-2.4.2.tar.bz2/download

Security Risk with Fix Available: Web Content Management login page vulnerable to cross site scripting attacks, also affects WebSphere Portal and Quickr services for WebSphere Portal
http://www-01.ibm.com/support/docview.wss?uid=swg21421469

Installing VMware Tools
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=340&sliceId=2&docTypeID=DT_KB_1_1

RHBA-2010:0120-1: coreutils bug fix update
http://rhn.redhat.com/errata/RHBA-2010-0120.html

RHBA-2010:0121-2: dump bug fix update
http://rhn.redhat.com/errata/RHBA-2010-0121.html

Independent Researcher : Rbot Owner Reaction Command Execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31855

Ubuntu Security Notice : OpenOffice.org vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31851

VUPEN Security : Symantec Products "SYMLTCOM.dll" Buffer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31858

プレス発表
官民連携による「情報セキュリティ啓発活動」の実施について
http://www.ipa.go.jp/about/press/20100224.html

ESA-2010-003: EMC HomeBase Server Arbitrary File Upload Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00223.html

iDefense Security Advisory 02.23.10: Multiple Vendor NOS Microsystems getPlus Downloader Input Valid
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00219.html

[USN-904-1] Squid vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00220.html

SQL injection vulnerability in LiveChatNow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00221.html

Rbot Owner Reaction Command Execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-02/msg00222.html

大学生を狙ったフィッシング詐欺が増加中
RSAセキュリティが警告、米大学のポータルなどに見せかける
http://itpro.nikkeibp.co.jp/article/NEWS/20100225/345032/?ST=security

「画像をゆがめて、件名は空白に」――新たな「画像スパム」出現
目的は迷惑メール対策ソフトの回避、編集部でも多数確認
http://itpro.nikkeibp.co.jp/article/NEWS/20100225/345039/?ST=security

PUBLIC ADVISORY: 02.23.10: Multiple Vendor NOS Microsystems getPlus Downloader Input Validation Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=856

Joomla SQL Reports Component "user_id" SQL Injection Vulnerability
http://secunia.com/advisories/38678/

SilverStripe Multiple Vulnerabilities
http://secunia.com/advisories/38697/

Fedora update for cronie
http://secunia.com/advisories/38741/

cronie "crontab" Race Condition Security Issue
http://secunia.com/advisories/38700/

Ubuntu update for openoffice.org
http://secunia.com/advisories/38695/

WorkSimple Multiple Security Issues
http://secunia.com/advisories/38725/

Avaya Products Multiple Vulnerabilities
http://secunia.com/advisories/38696/

Avaya CMS Solaris Python Multiple Vulnerabilities
http://secunia.com/advisories/38675/

Sawmill Unspecified Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38730/

Blue Coat Products TLS Session Renegotiation Plaintext Injection
http://secunia.com/advisories/38728/

TIBCO Administrator Unspecified Security Bypass Vulnerability
http://secunia.com/advisories/38732/

Softbiz Jobs and Recruitment Script Cross-Site Scripting and Request Forgery
http://secunia.com/advisories/38693/

OI.Blogs Multiple Local File Inclusion Vulnerabilities
http://secunia.com/advisories/38726/

TYPO3 Multiple Vulnerabilities
http://secunia.com/advisories/38668/

CA eHealth Performance Manager Cross-Site Scripting Weakness
http://secunia.com/advisories/38694/

Adobe getPlus DLM Unauthorised Installation Vulnerability
http://secunia.com/advisories/38729/

Red Hat update for JBoss Enterprise Web Server
http://secunia.com/advisories/38687/

EMC HomeBase Server Directory Traversal Vulnerability
http://secunia.com/advisories/38660/

Google Picasa JPEG Processing Integer Overflow Vulnerability
http://secunia.com/advisories/38435/

Adobe Download Manager Flaw Lets Remote Users Download and Install Arbitrary Software
http://securitytracker.com/alerts/2010/Feb/1023651.html

CA eHealth Performance Manager Input Validation Hole Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Feb/1023648.html

EMC HomeBase Server Directory Traversal Flaw Lets Remote Users Upload Arbitrary Files
http://securitytracker.com/alerts/2010/Feb/1023647.html

TIBCO Administrator "tibreposerver5.jar" Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/0463

TYPO3 Multiple Cross-Site Scripting and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0462

Google Picasa JPEG Image Processing Integer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/0461

CA eHealth Performance Manager Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/0460

MediaCoder v0.7.3.4605 Local Buffer Overflow Exploit
http://www.exploit-db.com/exploits/11573

Mozilla Firefox v3.6 URL Spoofing Vulnerability
http://www.exploit-db.com/exploits/11561

NOS getPlus Downloader Domain Validation Arbitrary File Download Vulnerability
http://www.securityfocus.com/bid/38313

EMC HomeBase Server Directory Traversal Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38380

SavySoda WiFiFTP 'APPE' Command Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38365

IETF and W3C XML Digital Signature Specification HMAC Truncation Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/35671

OpenOffice VBA Macro Restrictions Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/38245

OpenOffice Prior to 3.2 Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/38218

Squid Web Proxy Cache HTCP Request Processing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38212

WikyBlog Multiple Remote Input Validation Vulnerabilities
http://www.securityfocus.com/bid/38386

MySmartBB Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/38385

phpCOIN Multiple Remote Input Validation Vulnerabilities
http://www.securityfocus.com/bid/12686

GNU gzip LZW Compression Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/37886

Google Picasa JPEG Image Processing Integer Overflow Vulnerability
http://www.securityfocus.com/bid/38384

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

shortCMS 'printview.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38403

OpenInferno OI.Blogs Multiple Local File Include Vulnerabilities
http://www.securityfocus.com/bid/38402

HD FLV Player Component for Joomla! 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38401

PHP F1 Max's Photo Album 'admin.php' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/38400

Softbiz Auktios Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38399

Apple Safari Style Tag Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38398

Weekly Archive by Node Type Module Weekly Summary Security Bypass Vulnerability
http://www.securityfocus.com/bid/38397

TIBCO Administrator 'TIBRepoServer5.jar' Security Bypass Vulnerability
http://www.securityfocus.com/bid/38396

Kojoney 'urllib.urlopen()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38395

SilverStripe Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/38394

Linux Kernel TSB I-TLB Load Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38393

Bispage Content Manager Admin Page SQL Injection Vulnerability
http://www.securityfocus.com/bid/38392

cronie 'crontab' Symbolic Link Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38391

Softbiz Jobs 'moredetails.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38390

Zhang Boyang FTP Server Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38389

Sawmill Unspecified Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38387

0 件のコメント:

コメントを投稿