2010年3月3日水曜日

3日 水曜日、赤口

+ DBI 1.611 released
http://search.cpan.org/~timb/DBI/Changes

InterScan Messaging Hosted SecurityにおけるMTA(Mail Transfer Agent)不具合のご報告
http://www.trendmicro.co.jp/support/news.asp?id=1378

Microsoft、プライバシ保護技術「U-Prove」のプレビュー版を公開
http://itpro.nikkeibp.co.jp/article/NEWS/20100303/345278/?ST=security

JPCERT/CC WEEKLY REPORT 2010-03-03
http://www.jpcert.or.jp/wr/2010/wr100801.html

JVNDB-2010-001112 Microsoft Windows の Microsoft Paint における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001112.html

JVNDB-2010-001111 Microsoft Windows の kernel における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001111.html

JVNDB-2010-001110 Microsoft Windows の KDC におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001110.html

JVNDB-2010-001109 Microsoft Windows の SMB 実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001109.html

JVNDB-2010-001108 Microsoft Windows の SMB 実装におけるアクセス権を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001108.html

JVNDB-2010-001107 Microsoft Windows の SMB 実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001107.html

JVNDB-2010-001106 Microsoft Windows の SMB 実装における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001106.html

JVNDB-2010-001105 Microsoft Windows の Client/Server Run-time Subsystem における権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001105.html

JVNDB-2010-001104 Microsoft Windows の Hyper-V サーバ実装におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001104.html

JVNDB-2008-001801 IPv6 NDP 実装における Neighbor Discovery メッセージの送信元検証処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-001801.html

コンピュータウイルス・不正アクセスの届出状況[2月分]について
http://www.ipa.go.jp/security/txt/2010/03outline.html

IBM Informix Dynamic Server Buffer Overflows in 'librpc.dll' Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Mar/1023669.html

BaoFeng Storm ActiveX Control 'OnBeforeVideoDownload()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34789

Symantec AntiVirus Scan Evasion Vulnerability
http://www.securityfocus.com/bid/38219




+ BIND 9.6.2 released
https://www.isc.org/files/release-notes/962.html

+ Vulnerability Note VU#576029: libpng stalls on highly compressed ancillary chunks
http://www.kb.cert.org/vuls/id/576029
http://www.securityfocus.com/bid/38478

+ Linux Kernel 'dvb_net_ule()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38479

MySQL Connector/Net 6.3 Alpha 2 has been released
http://dev.mysql.com/downloads/connector/net/6.3.html

- DBI-1.610_90 Development release
http://search.cpan.org/~timb/DBI-1.610_90/

- IBM Lotus Domino 'readme.nsf' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38481

MicroOLAP Database Designer for PostgreSQL with enhanced WineHQ support released
http://www.postgresql.org/about/news.1184

Samba 3.3.11 対応の日本語マニュアル ver 0.5.5 を公開しました。
http://sourceforge.jp/forum/forum.php?forum_id=22264

定期サーバメンテナンスのお知らせ(2010年3月12日)
http://www.trendmicro.co.jp/support/news.asp?id=1377

iDEFENSE : IBM Lotus Domino Web Access ActiveX Stack Buffer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31897

Slackware Linux : gzip
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31886

Slackware Linux : openssl
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31887

Slackware Linux : seamonkey
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31888

「架空の引き落としでだます」、セゾンカードをかたるフィッシング
偽メールに「取り消しはこちらまで」のURL、アクセスすると偽サイト
http://itpro.nikkeibp.co.jp/article/NEWS/20100302/345264/?ST=security

ガンブラー対策でセキュリティ企業などがコミュニティ設立
http://itpro.nikkeibp.co.jp/article/NEWS/20100302/345254/?ST=security

JVNVU#612021 Internet Explorer において VBScript および Windows Help を使用する際に任意のコードが実行される脆弱性
http://jvn.jp/cert/JVNVU612021/index.html

CPNI-957037 SSH 通信において一部データが漏えいする可能性
http://jvn.jp/niscc/CPNI-957037/index.html

NSOADV-2010-004: McAfee LinuxShield remote/local code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00025.html

ZDI-10-024: Novell eDirectory SOAP Request Parsing Denial of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00024.html

[SECURITY] [DSA 2006-1] New sudo packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00023.html

[ MDVSA-2010:053 ] apache
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00026.html

Luxology Modo 401 .LXO Integer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00022.html

Sparta Systems TrackWise TeamAccess module Multiple Cross Site Scripting Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00016.html

1024CMS Blind SQL Injection Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00012.html

iDefense Security Advisory 03.02.10: IBM Lotus Domino Web Access ActiveX Stack Buffer Overflow Vulne
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00017.html

[xss] i found a Cross Site Scripting Vulnerability about Discuz! uid Parameter
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00018.html

Eshbel Priority MarketGate module Cross Site Scripting Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00015.html

Todd Miller Sudo local root exploit discovered by Slouching
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00020.html

ZDI-10-023: Multiple Vendor librpc.dll Signedness Error Remote Code Execution Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00013.html

ZDI-10-022: IBM Informix librpc.dll Multiple Remote Code Execution Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00011.html

[ MDVSA-2010:052 ] sudo
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00014.html

PUBLIC ADVISORY: 03.01.10: IBM Lotus Domino Web Access ActiveX Stack Buffer Overflow Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=857

Updates for your consumption this morning (Bind, Opera)
http://isc.sans.org/diary.html?storyid=8335

Panda Cloud Antivirus 1.0.1リリース
http://pandajapanblogs.blogspot.com/2010/03/panda-cloud-antivirus-101.html

Uploadify Arbitrary File Upload Security Issue
http://secunia.com/advisories/38773/

TrendNet TV-IP110W Missing Authentication Check Security Issue
http://secunia.com/advisories/38479/

1024 CMS "id" SQL Injection Vulnerability
http://secunia.com/advisories/38775/

IBM AIX NTP Mode 7 Request Denial of Service
http://secunia.com/advisories/38764/

PHP Trouble Ticket "id" SQL Injection Vulnerability
http://secunia.com/advisories/38763/

IBM Informix Dynamic Server RPC Implementation Vulnerabilities
http://secunia.com/advisories/38731/

Fedora update for sunbird
http://secunia.com/advisories/38770/

Fedora update for thunderbird
http://secunia.com/advisories/38772/

Red Hat update for systemtap
http://secunia.com/advisories/38817/

Red Hat update for systemtap
http://secunia.com/advisories/38765/

Fedora update for openldap
http://secunia.com/advisories/38769/

Fedora update for puppet
http://secunia.com/advisories/38766/

IBM AIX Security Update Fixes NTP Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0510

EMC Legato Networker RPC Library Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/0509

IBM Informix Dynamic Server Remote Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/0508

ProSSHD v1.2 20090726 Buffer Overflow Exploit
http://www.exploit-db.com/exploits/11618

Internet Explorer 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
http://www.exploit-db.com/exploits/11615

Novell eDirectory eMBox SOAP Request Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38157

Todd Miller Sudo 'sudoedit' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38362

Todd Miller Sudo 'runas_default' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38432

Microsoft Windows Double Free Memory Corruption Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38044

Microsoft Windows #GP Trap Handler Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37864

Microsoft Windows Client/Server Run-time Subsystem Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38098

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

OpenSSL 'dtls1_retrieve_buffered_fragment()' DTLS Packet Denial of Service Vulnerability
http://www.securityfocus.com/bid/35138

OpenSSL DTLS Packets Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/35001

OpenSSL 'zlib' Compression Memory Leak Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/31692

GNU gzip LZW Compression Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/37886

PHP Advanced Transfer Manager Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/15074

NTP mode 7 MODE_PRIVATE Packet Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37255

Mozilla Firefox CVE-2010-0159 Multiple Remote Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/38286

Mozilla Firefox and SeaMonkey Web Workers Array Data Type Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38285

Mozilla Firefox and SeaMonkey SVG Document Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38288

Mozilla Firefox and SeaMonkey 'showModalDialog' method Cross Domain Scripting Vulnerability
http://www.securityfocus.com/bid/38289

Mozilla Firefox/Thunderbird/SeaMonkey HTML Parser Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38287

OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36844

Domino Web Access ActiveX Control URL Handling Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38457

McAfee LinuxShield 'nailsd' Daemon Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38489

ProSSHD 'scp_get()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38487

Phptroubleticket 'vedi_faq.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38486

My Little Forum 'contact.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38485

Discuz! 'uid' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38484

Sparta Systems TrackWise EQMS Multiple Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/38483

TrendNet TV-IP110W Missing Authentication Check Security Bypass Vulnerability
http://www.securityfocus.com/bid/38482

IBM Lotus Domino 'readme.nsf' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38481

MarketGate Package for Eshbel Priority ERP 'Referer' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38480

Linux Kernel 'dvb_net_ule()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38479

Libpng 'png_decompress_chunk()' Function Denial of Service Vulnerability
http://www.securityfocus.com/bid/38478

1024 CMS 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38476

Luxology Modo 401 'valet4.dll' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/38460

0 件のコメント:

コメントを投稿