2010年4月1日木曜日

1日 木曜日、赤口

+ RHSA-2010:0339-1: Important: java-1.6.0-openjdk security update
http://rhn.redhat.com/errata/RHSA-2010-0339.html

- Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow DNS Cache Poisoning
http://sunsolve.sun.com/search/document.do?assetkey=1-66-273169-1

CHAR(10) - Clustering, HA and Replication Conference
http://www.postgresql.org/about/news.1191

PostgreSQL PHP Generator 10.3 released
http://www.postgresql.org/about/news.1190

VMSA-2010-0005: VMware products address vulnerabilities in WebAccess
http://www.vmware.com/security/advisories/VMSA-2010-0005.html

Google、ベトナム人ユーザー狙うサイバー攻撃を警告、既に数万台が感染
http://itpro.nikkeibp.co.jp/article/NEWS/20100401/346515/?ST=security

JVN#38687002 Compiere におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN38687002/index.html

JVN#57963254 Compiere におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN57963254/index.html

JVN#41842181 PrettyFormMail におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN41842181/index.html

JVNDB-2010-000009 Compiere におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000009.html

JVNDB-2010-000008 Compiere におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000008.html

JVNDB-2010-000007 PrettyFormMail におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000007.html

JVNDB-2010-001130 複数の Mozilla 製品の HTML パーサにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001130.html

JVNDB-2010-001128 複数の Mozilla 製品のブラウザエンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001128.html

JVNDB-2009-002454 複数の Mozilla 製品における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002454.html

JVNDB-2009-002304 Mozilla Firefox におけるダウンロードファイルを置き換えられる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002304.html

JVNDB-2009-002303 Mozilla Firefox/SeaMonkey における意図しないファイルをダウンロードさせられる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002303.html

JVNDB-2009-002299 Mozilla Firefox の ブラウザエンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002299.html

JVNDB-2009-002109 Mozilla Firefox の JavaScript エンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002109.html

JVNDB-2009-002106 Mozilla Firefox のブラウザエンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002106.html

JVNDB-2009-002101 Mozilla Firefox における任意の PKCS11 モジュールをインストール/削除させる脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002101.html

JVNDB-2009-002100 Mozilla Firefox における XUL ツリー要素に関する任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002100.html

JVNDB-2009-001970 Mozilla Firefox におけるドメイン名の処理に関するサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001970.html

JVNDB-2009-001936 Mozilla Firefox/Thunderbird の JavaScript エンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001936.html

JVNDB-2009-001933 Mozilla Firefox/Thunderbird の base64 デコード関数における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001933.html

JVNDB-2009-001932 Mozilla Firefox/Thunderbird のブラウザエンジンにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001932.html

We are experiencing e-mail issues
http://isc.sans.org/diary.html?storyid=8551

Apple AirPort Base Station Lets Remote Users Access Restricted Networks
http://securitytracker.com/alerts/2010/Mar/1023801.html

【リアルタイム更新中】エイプリルフールに便乗しているサイトまとめ2010年版
http://gigazine.net/index.php?/news/comments/20100401_matome_april_fool/

Wireshark 1.2.7, 1.0.12, and 1.3.4 Released
http://www.wireshark.org/news/20100331.html










+ DeleGate 9.9.7 released
http://www.delegate.org/mail-lists/delegate-en/4780

+? Secunia Research: Sun Java JDK/JRE Soundbank Resource Name Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00260.html

+? Secunia Research: Sun Java JDK/JRE Soundbank Resource Parsing Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00253.html

「Red Hat Enterprise Linux 5.5」リリース、最新プロセッサをサポート
http://itpro.nikkeibp.co.jp/article/NEWS/20100331/346451/

[ANNOUNCE] Apache PDFBox 1.1.0 released
http://pdfbox.apache.org/download.html

Squid 3.1.1 released
http://www.squid-cache.org/Versions/v3/3.1/RELEASENOTES.html

Linux kernel 2.6.34-rc3 released
http://www.kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.34-rc3

RHEA-2010:0336-1: tzdata enhancement update
http://rhn.redhat.com/errata/RHEA-2010-0336.html

Debian : New moin packages fix cross-site scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32144

Debian : New icedove packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32145

iDEFENSE : Oracle Java Runtime Environment Image FIle Buffer Overflow Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32154

Independent Researcher : Trustwave's SpiderLabs Security Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32153

Secunia : Sun Java JDK/JRE Soundbank Resource Parsing Buffer Overflow
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32155

Apple : QuickTime 7.6.6
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32142

Apple : iTunes 9.1
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32143

Hewlett-Packard : Insight Control for Linux (IC-Linux) Remote Execution of Arbitrary Code, Local Unauthorized Elevatio
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32159

Hewlett-Packard : HP SOA Registry Foundation, Remote Unauthorized Access to Data, Cross Site Scripting (XSS), Privileg
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32160

Hewlett-Packard : HP Secure Web Server for OpenVMS (based on Apache) CSWS, Remote Denial of Service (DoS), Unauthorize
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32163

iDEFENSE : Microsoft Internet Explorer 'onreadystatechange' Use After Free Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32152

Independent Researcher : Possible VT-x enabled Intel CPU Crash Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32156

Independent Researcher : Apache ActiveMQ Persistent Cross-Site Scripting (XSS) Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32157

Independent Researcher : OXID eShop Enterprise: Session Fixation and XSS Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32161

Microsoft Internet Explorer の脆弱性 (MS10-018) に関する注意喚起
http://www.jpcert.or.jp/at/2010/at100007.txt

JPCERT/CC WEEKLY REPORT
http://www.jpcert.or.jp/wr/2010/wr101201.html

JVNDB-2009-002524 Linux kernel の ext4_decode_error 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002524.html

[Suspected Spam]Vulnerabilities in NoCMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00261.html

[SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00264.html

[SECURITY] CVE-2008-2370: Apache CouchDB Timing Attack Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00254.html

Elevation of Privilege Vulnerability in iTunes for Windows
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00252.html

Multiple XSS vulnerabilities in OSSIM 2.2.1
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00256.html

OpenDcHub 0.8.1 Remote Code Execution Exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00255.html

BitComet <= 1.19 Remote DOS Exploit http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00262.html

Secunia Research: Sun Java JDK/JRE Soundbank Resource Name Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00260.html

Secunia Research: Sun Java JDK/JRE Soundbank Resource Parsing Buffer Overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00253.html

[SECURITY] [DSA 2025-1] New icedove packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00258.html

[SECURITY] [DSA 2024-1] New moin packages fix cross-site scripting
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00259.html

iDefense Security Advisory 03.30.10: Oracle Java Runtime Environment Image FIle Buffer Overflow Vuln
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00263.html

Trustwaves SpiderLabs Security Advisory TWSL2010-002
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-03/msg00257.html

KVM virtio-net Driver TCP Processing Bug Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Mar/1023798.html

QuickTime Movie/PICT/BMP File Processing Errors Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Mar/1023790.html

iTunes Installation Race Condition Lets Local Users Gain System Privileges
http://securitytracker.com/alerts/2010/Mar/1023787.html

iTunes MP4 Podcast Infinite Loop Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Mar/1023786.html

Apache ActiveMQ Input Validation Flaw Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Mar/1023778.html

PDF Arbitrary Code Execution - vulnerable by design.
http://isc.sans.org/diary.html?storyid=8545

Yamamah "calbums" SQL Injection Vulnerability
http://secunia.com/advisories/39205/

Joomla DW Graph Component "controller" File Inclusion Vulnerability
http://secunia.com/advisories/39200/

CompleteFTP Server Directory Traversal Vulnerability
http://secunia.com/advisories/39191/

Apache CouchDB Insecure Timing Vulnerability
http://secunia.com/advisories/39146/

Free MP3 CD Ripper Buffer Overflow Vulnerability
http://secunia.com/advisories/39193/

Centreon "host_id" SQL Injection Vulnerability
http://secunia.com/advisories/39236/

Red Hat update for brltty
http://secunia.com/advisories/39231/

Irmin CMS "_Root_Path" File Inclusion Vulnerability
http://secunia.com/advisories/39214/

Open DC Hub "myinfo()" Buffer Overflow Vulnerability
http://secunia.com/advisories/39199/

Red Hat update for firefox
http://secunia.com/advisories/38566/

OXID eShop Script Insertion and Session Fixation Vulnerabilities
http://secunia.com/advisories/39224/

BitComet Client DHT Processing Denial of Service Vulnerability
http://secunia.com/advisories/39213/

React Forum "action" File Inclusion Vulnerability
http://secunia.com/advisories/39211/

KimsQ Multiple Remote File Inclusion Vulnerabilities
http://secunia.com/advisories/39156/

Red Hat update for seamonkey
http://secunia.com/advisories/39117/

Apache ActiveMQ Script Insertion and Cross-Site Request Forgery
http://secunia.com/advisories/39223/

Peik CMS Information Disclosure Security Issue
http://secunia.com/advisories/39221/

Red Hat update for kernel
http://secunia.com/advisories/39230/

Debian update for moin
http://secunia.com/advisories/39190/

P30vel Hosting Script Security Bypass
http://secunia.com/advisories/39168/

Mozilla SeaMonkey Multiple Vulnerabilities
http://secunia.com/advisories/39243/

Mozilla Thunderbird Multiple Vulnerabilities
http://secunia.com/advisories/39242/

Mozilla Firefox Multiple Vulnerabilities
http://secunia.com/advisories/39240/

Mozilla Firefox Multiple Vulnerabilities
http://secunia.com/advisories/39136/

MoinMoin Despam Script Insertion Vulnerability
http://secunia.com/advisories/39188/

Novell ZENworks Configuration Management Two Vulnerabilities
http://secunia.com/advisories/39212/

Debian update for icedove
http://secunia.com/advisories/39184/

huroncms Two SQL Injection Vulnerabilities
http://secunia.com/advisories/39148/

HP-UX AudFilter Denial of Service Vulnerability
http://secunia.com/advisories/39228/

HP Insight Control Suite For Linux Two Vulnerabilities
http://secunia.com/advisories/39227/

Avaya Products OpenSSL "bn_wexpand()" Vulnerability
http://secunia.com/advisories/39222/

eSSL eTimeTrack Information Disclosure Security Issue
http://secunia.com/advisories/39073/

Red Hat update for pam_krb5
http://secunia.com/advisories/39237/

Red Hat update for sendmail
http://secunia.com/advisories/39234/

Red Hat update for automake
http://secunia.com/advisories/39233/

Red Hat update for openldap
http://secunia.com/advisories/39232/

Red Hat update for squid
http://secunia.com/advisories/39229/

SUSE Update for Multiple Packages
http://secunia.com/advisories/39176/

Red Hat update for curl
http://secunia.com/advisories/39174/

Sun Java JDK / JRE Multiple Vulnerabilities
http://secunia.com/advisories/37255/

Apple iTunes Multiple Vulnerabilities
http://secunia.com/advisories/39135/

SUSE update for kernel
http://secunia.com/advisories/39178/

Apple QuickTime Multiple Vulnerabilities
http://secunia.com/advisories/39133/

Novell ZENworks Configuration Management Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/0753

WebSphere Application Server Information Disclosure and DoS Issues
http://www.vupen.com/english/advisories/2010/0752

HP-UX AudFilter Rules Unspecified Local Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0751

HP Insight Control for Linux Code Execution and Privilege Escalation
http://www.vupen.com/english/advisories/2010/0750

HP SOA Registry Foundation Code Execution and Privilege Escalation
http://www.vupen.com/english/advisories/2010/0749

Mozilla Products Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0748

Sun Java JDK and JRE Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/0747

Apple QuickTime File Handling Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/0746

Apple iTunes Code Execution and Privilege Escalation Vulnerabilities
http://www.vupen.com/english/advisories/2010/0745

OpenDcHub 0.8.1 Remote Code Execution Exploit
http://www.exploit-db.com/exploits/11986

WM Downloader 3.0.0.9 (.asx) Local Buffer Overflow
http://www.exploit-db.com/exploits/11981

RETIRED: Apple QuickTime Multiple Arbitrary Code Execution Vulnerabilities
http://www.securityfocus.com/bid/39087

Apache 'mod_isapi' Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38494

Apple iPhone Malformed Characters Denial of Service Vulnerability
http://www.securityfocus.com/bid/38758

iBoutique 'index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/31159

SMEStorage 'com_smestorage' Component for Joomla! Local File Include Vulnerability
http://www.securityfocus.com/bid/38911

Apple iPhone Malformed VML Data Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38990

WebKit Right-to-Left Displayed Text Handling Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38689

SuperNews 'index.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/38988

Jenkins Software RakNet Remote Integer Underflow Vulnerability
http://www.securityfocus.com/bid/38974

Retired: Microsoft Internet Explorer MS10-018 Advanced Notification
http://www.securityfocus.com/bid/39021

Mozilla Firefox Unspecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38952

Astaro Security Linux 'index.fpl' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/38893

RETIRED: VMware WebAccess Multiple Vulnerabilities
http://www.securityfocus.com/bid/39037

OpenSSL 'bn_wexpend()' Error Handling Unspecified Vulnerability
http://www.securityfocus.com/bid/38562

Mozilla NSS NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/35888

Mozilla Firefox and Thunderbird Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/35769

Mozilla Firefox and Seamonkey Regular Expression Parsing Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/35891

Mozilla Firefox MFSA 2009-47, -48, -49, -50, -51 Multiple Vulnerabilities
http://www.securityfocus.com/bid/36343

Mozilla Thunderbird Multiple Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38831

HP OpenView Network Node Manager 'OvWebHelp.exe' Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37340

Multiple Mini-stream Software Products '.asx' File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/34864

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Linux Kernel 'net/mac80211/' Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/37170

cURL/libcURL CURLOPT_ENCODING Option Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38162

GNU Automake Insecure Directory Permissions Vulnerability
http://www.securityfocus.com/bid/37378

QEMU Virtio Networking Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37201

pam_krb5 Existing/Non-Existing Username Enumeration Weakness
http://www.securityfocus.com/bid/35112

Red Hat Sendmail Localhost.Localdomain Email Spoofing Vulnerability
http://www.securityfocus.com/bid/23742

Squid Header-Only Packets Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37522

Squid Web Proxy Cache Authentication Header Parsing Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/36091

OpenLDAP X.509 Certificate NULL Character Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/36844

Apple Mac OS X QuickDraw Manager Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/36985

Apple Mac OS X APPLE-SA-2010-03-29-1 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/39020

Apple QuickTime BMP File Memory Corruption Vulnerability
http://www.securityfocus.com/bid/39141

Apple AirPort Base Station MAC Address ACL Remote Security Bypass Vulnerability
http://www.securityfocus.com/bid/39134

GNU libnss_db Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/39132

Drupal Taxonomy Breadcrumb Module Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/39130

Open DC Hub 'MyInfo' Message Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39129

iSCSI Enterprise Target and tgt Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/39127

Apache ActiveMQ 'createDestination.action' HTML Injection Vulnerability
http://www.securityfocus.com/bid/39119

Centreon 'main.php' SQL Injection Vulnerability
http://www.securityfocus.com/bid/39118

CouchDB Message Digest Verification Security Bypass Vulnerability
http://www.securityfocus.com/bid/39116

BitComet DHT Packet Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/39112

MoinMoin 'Despam' Action Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/39110

Joomla! DW Graph Component 'controller' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/39108

0 件のコメント:

コメントを投稿