2010年3月4日木曜日

4日 木曜日、先勝

[courier-announce] Cone 0.81 released
http://www.courier-mta.org/download.php#cone

OSC 2010 Tokyo/Springのセミナー資料を公開しました。
http://wiki.samba.gr.jp/mediawiki/index.php?title=%E3%82%A4%E3%83%99%E3%83%B3%E3%83%88#.E3.82.AA.E3.83.BC.E3.83.97.E3.83.B3.E3.82.BD.E3.83.BC.E3.82.B9.E3.82.AB.E3.83.B3.E3.83.95.E3.82.A1.E3.83.AC.E3.83.B3.E3.82.B92010_Tokyo.2FSpring

Timekeeping best practices for Linux guests
http://kb.vmware.com/selfservice/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=1006427&sliceId=1&docTypeID=DT_KB_1_1

JVNVU#576029 libpng における圧縮された補助チャンクの処理に脆弱性
http://jvn.jp/cert/JVNVU576029/index.html

JVNDB-2010-001118 KVM の pit_ioport_read 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001118.html

JVNDB-2010-001117 KVM の x86 エミュレータにおける権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001117.html

JVNDB-2010-001116 KVM の x86 エミュレータにおける権限昇格の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001116.html

JVNDB-2010-001115 QEMU の usb_host_handle_control 関数におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001115.html

JVNDB-2010-001114 RealNetworks HelixPlayer および RealPlayer におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001114.html

JVNDB-2010-001113 RealNetworks HelixPlayer および RealPlayer の Unescape 関数におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001113.html

salefale-dot-com is bad
http://isc.sans.org/diary.html?storyid=8350

CUPS lppasswd Format String Bug Lets Local Users Gain Elevated Privileges
http://securitytracker.com/alerts/2010/Mar/1023678.html

Oracle Siebel Customer Relationship Management Input Validation Hole Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Mar/1023676.html

MiNBank 'minsoft_path' Parameter Multiple Remote File Include Vulnerabilities
http://www.securityfocus.com/bid/31492

Microsoft Office Web Components ActiveX Control Stack Buffer Overflow Code Execution Vulnerability
http://www.securityfocus.com/bid/35992





+ RHSA-2010:0129-1: Moderate: cups security update
http://rhn.redhat.com/errata/RHSA-2010-0129.html
http://www.securityfocus.com/bid/38510

+ SA38776: Apache HTTP Server Multiple Vulnerabilities
http://secunia.com/advisories/38776/
http://www.vupen.com/english/advisories/2010/0511

- DBI 1.611 released
http://search.cpan.org/~timb/DBI/Changes

- Multiple Security Vulnerabilities in the Common Unix Printing System (CUPS) Web Interface in OpenSolaris May Lead to Cross-Site Scripting (XSS) and HTTP Response Splitting Attacks
http://sunsolve.sun.com/search/document.do?assetkey=1-66-271169-1

PSN-2010-02-661: 2010-03 Security Bulletin: NS-Remote SafeNet Security Fixes
https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2010-02-661&viewMode=view

PSN-2010-02-660: 2010-03 Security Bulletin: Secure Access (SA) product ? Cross site scripting issue on end user edit bookmarks page
https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2010-02-660&viewMode=view

PSN-2010-02-659: 2010-03 Security Bulletin: Secure Access (SA) and Unified Access Control (UAC) products - OpenSSL
https://www.juniper.net/alerts/viewalert.jsp?actionBtn=Search&txtAlertNumber=PSN-2010-02-659&viewMode=view

Sun Storage 7000 2009.Q3 Software Release May Result in an Incorrect Diagnosis of CPU Correctable Error
http://sunsolve.sun.com/search/document.do?assetkey=1-66-278130-1

Mozilla Developer Preview Now Available With Out-of-Process Plugins
http://developer.mozilla.org/devnews/index.php/2010/03/03/mozilla-developer-preview-now-available-with-out-of-process-plugins/

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities
http://www.cisco.com/warp/public/707/cisco-sa-20100303-cucm.shtml

Multiple Vulnerabilities in Cisco Digital Media Manager
http://www.cisco.com/warp/public/707/cisco-sa-20100303-dmm.shtml

Cisco Security Advisory: Cisco Digital Media Player Remote Display Unauthorized Content Injection Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20100303-dmp.shtml

Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Cisco Unified Communications Manager Denial of Service Vulnerabilities
http://www.cisco.com/en/US/products/products_applied_mitigation_bulletin09186a0080b1b926.html

ウイルスパターンファイル 6.891.80の緊急配信のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1379

Document ID: 346617: After rebooting the first starting node of a Microsoft Cluster using dynamic disk(s) for quorum, the Cluster Service fails or is delayed due to a quorum online time-out.
http://seer.entsupport.symantec.com/docs/346617.htm

Document ID: 340500: Diskgroup import and deport may take an extensively long amount of time, and VxVDS.exe consumes 100% CPU
http://seer.entsupport.symantec.com/docs/340500.htm

Independent Researcher : plenitude String Crash(0day) Exploit
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31906

Independent Researcher : (plenitude String )Denial of Service Exploit
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31907

SuSE : security-announce SUSE Security Announcement: Linux kernel
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31901

AmnPardaz Security Research Team : Blind SQL Injection Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31908

Core Security Technologies : Luxology Modo 401 .LXO Integer Overflow
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31903

Debian : New sudo packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=31902

「スクリプトを無効にしても防げない」、新たな「ガンブラー」出現
正規サイトに不正な設定ファイルをアップ、ユーザーを悪質サイトに誘導
http://itpro.nikkeibp.co.jp/article/NEWS/20100304/345314/?ST=security

イーディーコントライブ、ウイルス対策ソフトを搭載したUSBメモリー
http://itpro.nikkeibp.co.jp/article/NEWS/20100304/345313/?ST=security

Cisco Security Advisory: Cisco Digital Media Player Remote Display Unauthorized Content Injection Vu
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00034.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Digital Media Manager
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00033.html

CORRECTION: CORE-2009-0913 - Luxology Modo 401 .LXO Integer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00036.html

[ GLSA 201003-01 ] sudo: Privilege escalation
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00032.html

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00027.html

MS10-015 re-released
http://isc.sans.org/diary.html?storyid=8341

Reports about large number of fake Amazon order confirmations
http://isc.sans.org/diary.html?storyid=8344

What is your firewall log telling you - Part #2
http://isc.sans.org/diary.html?storyid=8347

Cisco Digital Media Player Lets Remote Users Inject Arbitrary Video and Data Content
http://securitytracker.com/alerts/2010/Mar/1023672.html

Cisco Digital Media Manager Lets Remote Users Access the System and Remote Authenticated Users Modify the Configuration and View Passwords
http://securitytracker.com/alerts/2010/Mar/1023671.html

Cisco Unified Communications Manager SIP/SCCP/CTI Processing Bugs Let Remote Users Deny Service
http://securitytracker.com/alerts/2010/Mar/1023670.html

Slackware update for openssl
http://secunia.com/advisories/38761/

DFD Cart Cross-Site Scripting and Cross-Site Request Forgery Vulnerabilities
http://secunia.com/advisories/38635/

SUSE update for kernel
http://secunia.com/advisories/38779/

Apache HTTP Server Multiple Vulnerabilities
http://secunia.com/advisories/38776/

ARISg "errmsg" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38793/

Modo 401 LXO Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/38784/

TYPO3 Calendar Base Extension SQL Injection Vulnerability
http://secunia.com/advisories/38745/

Oracle Siebel CRM Cross-Site Scripting Vulnerability
http://secunia.com/advisories/38806/

McAfee LinuxShield "nailsd" Authentication Security Issue
http://secunia.com/advisories/38782/

libpng Ancillary Chunks "Decompression Bomb" Denial of Service
http://secunia.com/advisories/38774/

Debian update for sudo
http://secunia.com/advisories/38762/

McAfee LinuxShield Statistics Server Authentication Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/0518

Libpng PNG Compressed Ancillary Chunks Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0517

Oracle Siebel CRM "start.swe" Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/0516

Apache "mod_proxy_ajp" Request Handling Denial of Service Issue
http://www.vupen.com/english/advisories/2010/0511

SLAED CMS Remote File Upload Vulnerability
http://www.securityfocus.com/bid/38450

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

CUPS File Descriptors Handling Use-After-Free Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38510

Apple Safari 'background' attribute Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38447

SystemTap '__get_argv()' and '__get_compat_argv()' Local Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/38120

Luxology Modo 401 'valet4.dll' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/38460

Todd Miller Sudo 'runas_default' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38432

Todd Miller Sudo 'sudoedit' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38362

Linux Kernel 'do_pages_move()' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38144

Linux Kernel 'drivers/connector/connector.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38058

Linux Kernel 64bit Personality Handling Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38027

Linux Kernel 'ebtables' Security Bypass Vulnerability
http://www.securityfocus.com/bid/37762

Linux Kernel 'print_fatal_signal()' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/37724

Linux e1000e Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/37523

Cisco Unified Communications Manager SCCP (CVE-2010-0587) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38496

Linux e1000 Driver 'Jumbo Frame' Handling Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/37519

Linux Kernel PI Futex Invalid Pointer Dereference Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38165

Linux Kernel 'megaraid_sas' Driver Insecure File Permission Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37019

CUPS 'kerberos' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/36958

BaoFeng Storm ActiveX Control 'OnBeforeVideoDownload()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34789

CUPS 'lppasswd' Tool Localized Message String Security Weakness
http://www.securityfocus.com/bid/38524

Drupal Workflow Module Comment Field HTML Injection Vulnerability
http://www.securityfocus.com/bid/38520

Opera Web Browser 'Content-Length' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38519

Adobe Flash Player Local File Access Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38517

HazelPress 'login.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38516

Drupal eTracker Module URI Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/38514

Drupal AddThis Button Module HTML Injection Vulnerability
http://www.securityfocus.com/bid/38513

Drupal Internationalization Module PHP Filter PHP Code Execution Vulnerability
http://www.securityfocus.com/bid/38512

Project Man 'login.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/38511

ProMan Multiple Remote and Local File Include Vulnerabilities
http://www.securityfocus.com/bid/38509

PhpCDB 'lang_global' Parameter Multiple Local File Include Vulnerabilities
http://www.securityfocus.com/bid/38507

Uiga Church Portal 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/38506

DFD Cart Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/38505

Cisco Digital Media Player Video or Data Content Injection Vulnerability
http://www.securityfocus.com/bid/38504

Cisco Digital Media Manager Default Credentials Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/38503

Cisco Digital Media Manager Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38502

Cisco Unified Communications Manager SCCP (CVE-2010-0588) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38501

Cisco Digital Media Manager (CVE-2010-0571) Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38500

Cisco Unified Communications Manager SIP Message (CVE-2010-0591) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38498

Cisco Unified Communications Manager CTI Manager Service Denial of Service Vulnerability
http://www.securityfocus.com/bid/38497

Cisco Unified Communications Manager SIP Message (CVE-2010-0590) Denial of Service Vulnerability
http://www.securityfocus.com/bid/38495

0 件のコメント:

コメントを投稿