2010年4月5日月曜日

5日 月曜日、仏滅

++ jetty 6.1.23 released
http://jetty.codehaus.org/jetty/
http://svn.codehaus.org/jetty/jetty/branches/jetty-6.1/VERSION.txt

+? jetty 7.0.2 released
http://www.eclipse.org/projects/project-plan.php?projectid=rt.jetty
http://svn.codehaus.org/jetty/jetty/branches/jetty-7/VERSION.txt

コンピュータウイルス・不正アクセスの届出状況[3月分および第1四半期]について
http://www.ipa.go.jp/security/txt/2010/04outline.html

JVNDB-2010-001208 複数の Mozilla 製品におけるにおけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001208.html

JVNDB-2010-001207 Mozilla Firefox における同一生成元ポリシーを回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001207.html

JVNDB-2010-001206 Mozilla Thunderbird/SeaMonkey における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001206.html

Oracle Java SE and Java for Business CVE-2010-0847 Remote Java 2D Vulnerability
http://www.securityfocus.com/bid/39071




+ Linux kernel 2.6.33.2, 2.6.32.11, 2.6.31.13, 2.6.27.46 released
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.33.2
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.32.11
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.31.13
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.27.46

[ANN] Apache Vysper 0.5 released
http://mina.apache.org/vysper/apache-vysper-05-release.html

MySQL Workbench 5.2.17 Beta 7 Available
http://wb.mysql.com/

[ANNOUNCEMENT] HttpComponents HttpCore 4.1-beta1 Released
http://www.apache.org/dist/httpcomponents/httpcore/RELEASE_NOTES.txt

[ANNOUNCE] Apache Tika 0.7 released
http://www.apache.org/dist/lucene/tika/CHANGES-0.7.txt

[ANNOUNCEMENT] Apache Commons Math 2.1 Released
http://commons.apache.org/math/

ALERT WEEKLY SUMMARY REPORT
http://sunsolve.sun.com/search/document.do?assetkey=1-66-275470-1

HPSBMA02490 SSRT090222 rev.2 - HP SOA Registry Foundation, Remote Unauthorized Access to Data, Cross Site Scripting (XSS), Privilege Escalation
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02037890

Document ID: 348286: Upgrading to Storage Foundation HA (SFW-HA) 5.1 SP1 returns error to uninstall or upgrade previous conflicting products
http://seer.entsupport.symantec.com/docs/348286.htm

Document ID: 347698: "An error occurred while executing the test. The given key was not present in the dictionary" is reported by the cluster validation tool in Microsoft Windows Failover Cluster when a Volume Manager Disk Group resource is present - Vertas Storage Foundation for Windows
http://seer.entsupport.symantec.com/docs/347698.htm

Independent Researcher : Vulnerability Centreon IT & Network Monitoring v2.1.5
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32179

RHBA-2010:0340-1: net-snmp bug fix update
http://rhn.redhat.com/errata/RHBA-2010-0340.html

Nmap 5.30BETA1 Released With 37 New Scripts, Nping, and New Apple Vulnerability
http://seclists.org/nmap-hackers/2010/3

Financial Management of Cyber Risk
http://isc.sans.org/diary.html?storyid=8575

Apple QuickTime and iTunes Security Update
http://isc.sans.org/diary.html?storyid=8566

Foxit Reader Security Update
http://isc.sans.org/diary.html?storyid=8569

Oracle Java SE and Java for Business Critical Patch Update Advisory
http://isc.sans.org/diary.html?storyid=8572

Mozilla Firefox Memory Re-use Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Apr/1023817.html

IBM WEBi Input Validation Flaw Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Mar/1023802.html

Vulnerability Note VU#570177: Foxit Reader vulnerable to arbitrary command execution
http://www.kb.cert.org/vuls/id/570177

Vulnerability Note VU#507652: Oracle Sun Java fails to properly validate Java applet signatures
http://www.kb.cert.org/vuls/id/507652

Mozilla Firefox DOM Node Moving Use-After-Free Vulnerability
http://secunia.com/advisories/39175/

Slackware update for seamonkey
http://secunia.com/advisories/39241/

Slackware update for openssl
http://secunia.com/advisories/39239/

Zabbix PHP Frontend "user" SQL Injection Vulnerability
http://secunia.com/advisories/39119/

Mozilla Firefox Node Scope Confusion Use-after-free Vulnerability
http://www.vupen.com/english/advisories/2010/0779

Apple AirPort Utility MAC Address ACLs Bypass Weakness
http://www.vupen.com/english/advisories/2010/0778

Libnids "ip_fragment.c" Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0777

Ubuntu Security Update Fixes Libnss-db Information Disclosure Issue
http://www.vupen.com/english/advisories/2010/0776

Turbolinux Security Update Fixes Thunderbird Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/0775

Turbolinux Security Update Fixes Squid Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/0774

Slackware Security Update Fixes SeaMonkey Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/0773

Slackware Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/0772

Slackware Security Update Fixes OpenSSL Denial of Service Issues
http://www.vupen.com/english/advisories/2010/0771

SuSE Security Update Fixes Code Execution and Security Bypass Issues
http://www.vupen.com/english/advisories/2010/0770

SuSE Security Update Fixes Kernel Code Execution and DoS Issues
http://www.vupen.com/english/advisories/2010/0769

PHP 6.0 Dev str_transliterate() 0Day Buffer Overflow Exploit
http://www.exploit-db.com/exploits/12051

Easy Ftp Server v1.7.0.2 MKD Remote Post-Authentication BoF Exploit
http://www.exploit-db.com/exploits/12044

eZip Wizard 3.0 (.zip) SEH
http://www.exploit-db.com/exploits/12059

ZipCentral (.zip) 0day SEH Exploit
http://www.exploit-db.com/exploits/12053

Apple Safari ImageIO TIFF Image Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38673

Apple Safari TIFF Image Uninitialized Memory Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38677

Apple Safari Prior to 4.0.5 Integer Overflow Vulnerability
http://www.securityfocus.com/bid/38674

Apple Safari BMP Image Uninitialized Memory Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38676

LibTIFF 'LZWDecodeCompat()' Remote Buffer Underflow Vulnerability
http://www.securityfocus.com/bid/35451

Sendmail NULL Character CA SSL Certificate Validation Security Bypass Vulnerability
http://www.securityfocus.com/bid/37543

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

Foxit Reader Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/39109

Netpbm XPM File Remote Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38164

Oracle Java SE and Java for Business CVE-2010-0087 Remote Vulnerability
http://www.securityfocus.com/bid/39068

Mozilla Firefox 'multipart/x-mixed-replace' Image Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38921

Mozilla Firefox and SeaMonkey Web Workers Array Data Type Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/38285

Apple QuickTime FLC Encoded '.fli' Movie File Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39152

Apple QuickTime QDM2 and QDCA Encoded Audio Content (CVE-2010-0059) Memory Corruption Vulnerability
http://www.securityfocus.com/bid/39160

Apple QuickTime FlashPix Encoded File 'NumberOfTiles' Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/39155

Apple QuickTime M-JPEG Data '.mov' File Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39154

Apple QuickTime MPEG Movie File 'genl' Atom Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39166

Apple QuickTime RLE Encoded '.mov' File Remote Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39165

Apple QuickTime CoreMedia H.263 Encoded '.3g2' Movie Files Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/39167

Microsoft Internet Explorer CTimeAction Object Memory Corruption Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/39030

Microsoft Internet Explorer 'Tabular Data Control' ActiveX Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/39025

Mozilla Firefox Use-After-Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/38952

Jabber Studio JabberD Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/17155

eDisplay Personal FTP server Multiple Commands Remote Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/38860

PHP xmlrpc Extension Multiple Remote Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38708

Google Chrome Invalid FTP Server Response Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/39183

0 件のコメント:

コメントを投稿