2010年3月15日月曜日

15日 月曜日、赤口

+ [Zlib-announce] zlib 1.2.4 released
http://zlib.net/
http://zlib.net/ChangeLog.txt

- マイクロソフト セキュリティ アドバイザリ (981374): Internet Explorer の脆弱性により、リモートでコードが実行される
http://www.microsoft.com/japan/technet/security/advisory/981374.mspx

Trend Micro InterScan Messaging Hosted Security の製品名表記変更のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1381

Trend Micro Deep Security 7 サポート開始のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1380

JVNDB-2009-002504 MySQL で使用される yaSSL における複数のスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002504.html

JVNDB-2009-002480 Linux kernel の handle_dr 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002480.html

JVNDB-2009-002446 NTP におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002446.html

Joomla! 'com_races' Component 'raceId' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38712

Joomla! 'com_seek' Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38711




+ PHP xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38708

+ Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38702

[ANNOUNCE] Apache Harmony 5.0M13 and Apache Harmony 6.0M1
http://harmony.apache.org/download.cgi

[ANN] Apache Continuum 1.3.6 (Beta) Released
http://continuum.apache.org/docs/1.3.6/release-notes.html

squid-3.0.STABLE25 released
http://www.squid-cache.org/Versions/v3/3.0/
http://www.squid-cache.org/Versions/v3/3.0/squid-3.0.STABLE25-RELEASENOTES.html

Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" and "Status.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data
http://sunsolve.sun.com/search/document.do?assetkey=1-66-272230-1

ALERT WEEKLY SUMMARY REPORT
http://sunsolve.sun.com/search/document.do?assetkey=1-66-275470-1

Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Execution
http://www.microsoft.com/technet/security/advisory/981374.mspx

Linux Kernel release: 2.6.32.10-rc1
http://www.linux.org/news/2010/03/13/0001.html

Linux Kernel release: 2.6.33.1-rc1
http://www.linux.org/news/2010/03/12/0001.html

Document ID: 347230: Rescan operations performed within the Veritas Enterprise Administrator (VEA) console or from the vxassist command line utility take a considerable amount of time to complete in environments utilizing a large number of disks and/or volumes.
http://seer.entsupport.symantec.com/docs/347230.htm

Document ID: 347177: Configuring Veritas Cluster Server 5.1.x for Windows (VCS) running on a Windows 2008 server with Symantec Endpoint 11.0 (SEP) Maintenance Release 5 (MR5) installed will fail
http://seer.entsupport.symantec.com/docs/347177.htm

Debian : New moin packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31993

iDEFENSE : Multiple Vendor WebKit HTML Element Use After Free Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31998

Ubuntu Security Notice : MoinMoin vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31989

Apple : Safari 4.0.5
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31990

Debian : New Linux 2.6.26 packages fix several issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31991

Debian : New egroupware packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31992

Mandriva : Security Announce ncpfs
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31988

VUPEN Security Research - Apple Safari ColorSync Profile Integer Overflow Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00113.html

[XSS] I found a xss in phpmyadmin 3.3.0 when we create new database in interface!
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00112.html

[SECURITY] [DSA 2014-1] New moin packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00110.html

[USN-911-1] MoinMoin vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00108.html

iDefense Security Advisory 03.11.10: Multiple Vendor WebKit HTML Element Use After Free Vulnerabilit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00109.html

[SECURITY] [DSA 2013-1] New egroupware packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00111.html

[ MDVSA-2010:061 ] ncpfs
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00107.html

[SECURITY] [DSA 2012-1] New Linux 2.6.26 packages fix several issues
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00114.html

ZDI-10-027: Skype Protocol Handler datapath Argument Injection Remote Code Execution Vulnera
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00116.html

ZDI-10-028: Skype URI Processing Arbitrary XML File Deletion Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00115.html

RHEA-2010:0138-1: tzdata enhancement update
http://rhn.redhat.com/errata/RHEA-2010-0138.html

DST Issue in Windows 7 Ultimate?
http://isc.sans.org/diary.html?storyid=8431

Evil Sports Sites
http://isc.sans.org/diary.html?storyid=8425

eGroupWare Input Validation Flaws Permit Command Execution and Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Mar/1023709.html

Apple Safari Bug in PubSub May Let Remote Feeds Bypass the Cookie Blocking Mechanism
http://securitytracker.com/alerts/2010/Mar/1023707.html

Perforce Multiple Flaws Let Remote Users Deny Service, Obtain Information, Create Accounts, and Access the System
http://securitytracker.com/alerts/2010/Mar/1023692.html

dl Download Ticket Service "t" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38898/

IBM AIX Sendmail SSL Certificate NULL Character Spoofing Vulnerability
http://secunia.com/advisories/38883/

IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
http://secunia.com/advisories/38909/

Unbound Memory Alignment Denial of Service
http://secunia.com/advisories/38888/

Debian update for linux-2.6
http://secunia.com/advisories/38905/

Debian update for moin
http://secunia.com/advisories/38903/

Ubuntu update for MoinMoin
http://secunia.com/advisories/38874/

Eros Webkatalog "id" SQL Injection Vulnerability
http://secunia.com/advisories/38900/

IBM ENOVIA SmarTeam V5 "errMsg" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38878/

Fedora update for cups
http://secunia.com/advisories/38927/

Debian update for egroupware
http://secunia.com/advisories/38924/

ATutor Multiple Script Insertion Vulnerabilities
http://secunia.com/advisories/38906/

Apple Safari Multiple Vulnerabilities
http://secunia.com/advisories/38932/

Apple Safari Code Execution and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2010/0599

IBM ENOVIA SmarTeam "errMsg" Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/0598

Debian Security Update Fixes Egroupware Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/0597

Debian Security Update Fixes Kernel Security Bypass and DoS Issues
http://www.vupen.com/english/advisories/2010/0596

Fedora Security Update Fixes NSS TLS Plaintext Injection Vulnerability
http://www.vupen.com/english/advisories/2010/0595

Fedora Security Update Fixes CUPS Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0594

Fedora Security Update Fixes Samba Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/0593

Ubuntu Security Update Fixes Moin Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0592

Ubuntu Security Update Fixes dpkg Directory Traversal Vulnerability
http://www.vupen.com/english/advisories/2010/0591

Slackware Security Update Fixes Pidgin Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/0590

Mandriva Security Update Fixes ncpfs Two Local Vulnerabilities
http://www.vupen.com/english/advisories/2010/0589

MicroWorld eScan Antivirus http://www.exploit-db.com/exploits/11720

Yahoo Player v1.0 (.m3u) Buffer Overflow Exploit (direct EIP overwrite)
http://www.exploit-db.com/exploits/11713

Microsoft Internet Explorer 'iepeers.dll' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38615

MoinMoin Multiple Unspecified Security Vulnerabilities
http://www.securityfocus.com/bid/38023

Linux Kernel Subsystem Connector Missing Capability Check Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/36834

Linux Kernel PI Futex Invalid Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38165

Cisco Digital Media Manager Default Credentials Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/38503

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Ipswitch WS_FTP Professional HTTP Server Response Format String Vulnerability
http://www.securityfocus.com/bid/36297

FreeBSD and OpenBSD 'ftpd' NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38559

Sendmail NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/37543

SAP Business One 2005 License Manager 'NT_Naming_Service.exe' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35933

Cisco Unified Communications Manager SCCP (CVE-2010-0587) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38496

RETIRED: Apple Safari Prior to 4.0.5 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/38671

Cisco Unified Communications Manager SCCP (CVE-2010-0588) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38501

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

ARWScripts Fonts Site Script 'f' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/38709

PHP xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38708

phpMyAdmin 'db_create.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38707

eZoneScripts Game Room Script Admin Upload Remote File Upload Vulnerability
http://www.securityfocus.com/bid/38705

Red Hat Enterprise Linux 'ptrace()' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38702

Unbound 'sock_list' Structure Allocation Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38701

dl Download Ticket Service 'index.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38700

Easynet4u Forum Host 'topic.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38697

Joomla! 'com_family' Component 'categoryid' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38695

Joomla! 'com_leader' Component 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38694

Joomla! 'com_start' Component 'mitID' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38693

0 件のコメント:

コメントを投稿