2010年6月4日金曜日

4日 金曜日、先勝

HS10-009: Vulnerability in Hitachi Web Server SSL Client Authentication CRLs
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS10-009/index.html

HS10-008: DoS Vulnerability in the Hitachi Web Server SSL function
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS10-008/index.html

HS10-007: DoS Vulnerability in TP1/Message Control
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS10-007/index.html

HS10-006: Stack Overflow Vulnerability in Collaboration - Common Utility
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS10-006/index.html

HS10-005: Vulnerability in CA ARCserve Backup
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS10-005/index.html

HS10-004: Web browsers terminate abnormally when XMAP3 is installed
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS10-004/index.html

HS10-003: Vulnerabilities in EUR Form Products and EUR Products
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS10-003/index.html

HS10-013: JP1/ServerConductor/Deployment Managerにおける不正にシャットダウン/リブートを実行する問題
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-013/index.html

JVNDB-2010-001327 複数の Oracle 製品の Java 2D コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001327.html

JVNDB-2010-001317 複数の Oracle 製品の HotSpot Server コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001317.html

JVNDB-2010-001315 複数の Oracle 製品の Java Runtime Environment コンポーネントにおける脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001315.html

JVNDB-2009-002319 SSL および TLS プロトコルに脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002319.html

JVNDB-2009-001168 JDK および JRE の Java プラグインにおける古い JRE バージョンで動作可能な脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-001168.html

A ARCserve Backup Information Disclosure Vulnerability
http://secunia.com/advisories/40037/

Motorola SURFBoard Cable Modem Directory Traversal
http://www.exploit-db.com/exploits/12865




- Microsoft Security Bulletin Advance Notification for June 2010
http://www.microsoft.com/technet/security/bulletin/ms10-jun.mspx
Critical: 3, Important: 7

DHCP: Fencepost error on zero-length client identifier
https://www.isc.org/software/dhcp/advisories/cve-2010-2156

Postfix 2.7.1 stable release candidate 2
http://mirror.postfix.jp/postfix-release/official/postfix-2.7.1-RC2.RELEASE_NOTES
http://mirror.postfix.jp/postfix-release/official/postfix-2.7.1-RC2.HISTORY

Postfix 2.8 Snapshot 20100603
http://mirror.postfix.jp/postfix-release/experimental/postfix-2.8-20100603.RELEASE_NOTES
http://mirror.postfix.jp/postfix-release/experimental/postfix-2.8-20100603.HISTORY

Storage Foundation 5.1 for Windows (SFW), Storage Foundation 5.1 High Availability for Windows (SFW HA), and Veritas Cluster Server 5.1 for Windows Application Pack 1 (32 bit)
http://seer.entsupport.symantec.com/docs/354940.htm

Storage Foundation 5.1 for Windows (SFW), Storage Foundation 5.1 High Availability for Windows (SFW HA), and Veritas Cluster Server 5.1 for Windows Application Pack 1 (64 bit)
http://seer.entsupport.symantec.com/docs/354939.htm

Veritas Storage Foundation and High Availability Solutions 5.0 Rollup Patch 1a (RP1a) for Windows (SFW and SFW HA) support for Microsoft Exchange 2007 and Service Pack 1
http://seer.entsupport.symantec.com/docs/354923.htm

Veritas Cluster Server (VCS) Application Agent for Exchange 2007 for Storage Foundation High Availability (SFWHA) 5.0 Rollup Patch 2 (RP2) for Windows and VCS for Network Appliance SnapMirror 5.0 RP2
http://seer.entsupport.symantec.com/docs/354922.htm

Veritas Storage Foundation (tm) and High Availability Solutions for Windows 5.0 and Veritas Cluster Server for Network Appliance Snapmirror 5.0 Release Update 1 (RU1) Rollup Patch 2 (RP2) 64 Bit
http://seer.entsupport.symantec.com/docs/354921.htm

Veritas Storage Foundation (tm) and High Availability Solutions for Windows 5.0 and Veritas Cluster Server for Network Appliance Snapmirror 5.0 Release Update 1 (RU1) Rollup Patch 2 (RP2) 32 Bit
http://seer.entsupport.symantec.com/docs/354920.htm

Veritas Storage Foundation (tm) and High Availability Solutions for Windows 5.0 and Veritas Cluster Server for NetApp SnapMirror 5.0 Release Update 1 (RU1) Rollup Patch 1a (RP1a) 64 Bit
http://seer.entsupport.symantec.com/docs/354919.htm

Veritas Storage Foundation (tm) and High Availability Solutions for Windows 5.0 and Veritas Cluster Server for NetApp SnapMirror 5.0 Release Update 1 (RU1) Rollup Patch 1a (RP1a) 32 Bit
http://seer.entsupport.symantec.com/docs/354918.htm

Storage Foundation 5.0 for Windows (SFW) and Storage Foundation HA 5.0 for Windows (SFW-HA) for Windows Vista Client (64 Bit Versions)
http://seer.entsupport.symantec.com/docs/354917.htm

Storage Foundation 5.0 for Windows (SFW), Storage Foundation HA 5.0 for Windows (SFW-HA), and Veritas Cluster Server (VCS) 5.0 for Netapp SnapMirror for Windows Vista Client (32 Bit Versions)
http://seer.entsupport.symantec.com/docs/354916.htm

Gentoo Linux : XEmacs: User-assisted execution of arbitrary code
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32765

Gentoo Linux : GD: User-assisted execution of arbitrary code
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32766

Gentoo Linux : lighttpd: Denial of Service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32767

Ubuntu Security Notice : Linux kernel vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32759

Gentoo Linux : multipath-tools: World-writeable socket
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32760

Gentoo Linux : BIND: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32761

Gentoo Linux : Fetchmail: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32762

Gentoo Linux : Smarty: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32763

Gentoo Linux : Newt: User-assisted execution of arbitrary code
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32764

Independent Researcher : Wing FTP Server - Cross Site Scripting Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32768

Ubuntu Security Notice : Net-SNMP vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32758

eFront Multiple Parameter Cross Site Scripting Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00047.html

[security bulletin] HPSBMA02538 SSRT100136 rev.1 - HP ServiceCenter Running on AIX, HP-UX, L
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00045.html

[security bulletin] HPSBST02536 SSRT100057 rev.1 - HP StorageWorks Storage Mirroring, Remote Una
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00044.html

[security bulletin] HPSBUX02531 SSRT100108 rev.1 - HP-UX Running Apache-based Web Server
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00040.html

[security bulletin] HPSBUX02524 SSRT100089 rev.1 - HP-UX Running Java, Remote Execution of A
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00038.html

[ GLSA 201006-17 ] lighttpd: Denial of Service
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00042.html

[ GLSA 201006-16 ] GD: User-assisted execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00043.html

[ GLSA 201006-15 ] XEmacs: User-assisted execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00041.html

[ GLSA 201006-14 ] Newt: User-assisted execution of arbitrary code
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00039.html

[ GLSA 201006-13 ] Smarty: Multiple vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00037.html

「偽ソフト」の被害が急増、「ガンブラー」攻撃による感染も
Webアクセスだけで感染の危険性、PCを使えなくなる事例も報告
http://itpro.nikkeibp.co.jp/article/Research/20100604/348863/?ST=security

Top 10 Things you may not know about tcpdump
http://isc.sans.org/diary.html?storyid=8896

Microsoft Patch Tuesday June 2010 Pre-Release
http://isc.sans.org/diary.html?storyid=8899

Novell eDirectory Multiple Flaws Let Remote Users Deny Service, Hijack Sessions, and Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Jun/1024055.html

HP StorageWorks Storage Mirroring Unspecified Flaw Lets Remote Users Gain Access
http://securitytracker.com/alerts/2010/Jun/1024054.html

HP ServiceCenter Input Validation Hole Permits Cross-Site Scripting Attacks
http://securitytracker.com/alerts/2010/Jun/1024053.html

HazelPress Lite <= 0.0.4 (Auth Bypass) SQL Injection Vulnerability http://securityreason.com/securityalert/7476

my little forum 2.2.9 contact.php SQL Injection
http://securityreason.com/securityalert/7475

OES (Open Educational System) <= 0.1b Multiple RFI Exploit http://securityreason.com/securityalert/7474

Article friendly 5.14-pro Insecure direct object Referece Vulnerability
http://securityreason.com/securityalert/7473

ARISg5 (Version 5.0) Cross Site Scripting Vulnerability
http://securityreason.com/securityalert/7472

JE Ajax Event Calendar Local File Inclusion Vulnerability
http://securityreason.com/securityalert/7471

HP ServiceCenter Unspecified Cross-Site Scripting Vulnerability
http://secunia.com/advisories/40045/

MoinMoin "template" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/40043/

HP-UX update for Apache
http://secunia.com/advisories/40042/

Gentoo update for lighttpd
http://secunia.com/advisories/40048/

Gentoo update for xemacs
http://secunia.com/advisories/40047/

Gentoo update for gd
http://secunia.com/advisories/40046/

CMS Made Simple Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/40031/

F5 Enterprise Manager OpenSSL Denial of Service
http://secunia.com/advisories/40001/

Novell eDirectory Multiple Vulnerabilities
http://secunia.com/advisories/40041/

TomatoCMS Multiple Vulnerabilities
http://secunia.com/advisories/39680/

Ubuntu update for linux and linux-source-2.6.15
http://secunia.com/advisories/40012/

Horde Groupware / Horde Groupware Webmail Edition Cross-Site Request Forgery
http://secunia.com/advisories/39860/

RPM Package Manager Package Upgrade File Metadata Update Weaknesses
http://secunia.com/advisories/40028/

Gentoo update for newt
http://secunia.com/advisories/40006/

Gentoo update for smarty
http://secunia.com/advisories/40010/

Beanstalkd "put" Command Job Processing Security Issue
http://secunia.com/advisories/40032/

SIMM Management System "page" Local File Inclusion Vulnerability
http://secunia.com/advisories/40009/

HP StorageWorks Storage Mirroring Software Unspecified Unauthorised Access Vulnerability
http://secunia.com/advisories/40044/

Bftpd Anonymous Account "ROOTDIR" Security Issue
http://secunia.com/advisories/40014/

Sudo "secure path" Security Bypass Security Issue
http://secunia.com/advisories/40002/

eFront Multiple Parameter Processing Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1333

Novell eDirectory Buffer Overflow and Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/1332

Horde Groupware and Webmail Cross Site Request Forgery Vulnerability
http://www.vupen.com/english/advisories/2010/1331

SIMM Management System "page" Local File Inclusion Vulnerability
http://www.vupen.com/english/advisories/2010/1330

TCExam "tce_functions_tcecode_editor.php" File Upload Vulnerability
http://www.vupen.com/english/advisories/2010/1329

Sar News for Joomla "id" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2010/1328

Chocky Soft 2005 "numb" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2010/1327

Ticimax E-Ticaret "id" Parameter Remote SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2010/1326

Ecomat CMS SQL Injection and Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1325

JS Jobs for Joomla "cid" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2010/1324

wsCMS "id" and "cid" Parameters Remote SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2010/1323

F5 ARX OpenSSL TLS Connection Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/1322

F5 Enterprise Manager OpenSSL Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/1321

F5 BIG-IP Security Update Fixes Kerberos and OpenSSL Vulnerabilities
http://www.vupen.com/english/advisories/2010/1320

HP StorageWorks Storage Mirroring Unauthorized Access Vulnerability
http://www.vupen.com/english/advisories/2010/1319

HP-UX Security Update Fixes Java Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/1318

Kerio MailServer and WinRoute Firewall File Manipulation Vulnerability
http://www.vupen.com/english/advisories/2010/1317

Gentoo Security Update Fixes Newt Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/1316

Gentoo Security Update Fixes Smarty Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/1315

Ubuntu Security Update Fixes Net-snmp Security Bypass Vulnerability
http://www.vupen.com/english/advisories/2010/1314

Pablo Software Solutions Quick 'n Easy FTP Server LIST Command Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/19067

Novell eDirectory Multiple Remote Vulnerabilities
http://www.securityfocus.com/bid/40541

HP StorageWorks Storage Mirroring Unspecified Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/40539

lighttpd Slow Request Handling Remote Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38036

GD Graphics Library '_gdGetColors' Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/36712

XEmacs Multiple Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/35473

OpenSSL 'dtls1_retrieve_buffered_fragment()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38533

Apache mod_proxy_ftp Remote Command Injection Vulnerability
http://www.securityfocus.com/bid/36254

Apache mod_proxy_ftp Module NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/36260

Apache Subrequest Handling Information Disclosure Vulnerability
http://www.securityfocus.com/bid/38580

OpenSSL 'ssl3_get_record()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/39013

Joomla! Multiple Modules 'search' Parameter Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/40444

Linux Kernel GFS/GFS2 Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/39101

Linux Kernel VM/VFS 'invalidatepage()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/39569

Linux Kernel 'release_one_tty()' Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/39480

Linux Kernel ReiserFS Security Bypass Vulnerability
http://www.securityfocus.com/bid/39344

Linux Kernel 'tipc' Module Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/39120

Linux Kernel 'nameidata' Null Pointer Dereference Vulnerability
http://www.securityfocus.com/bid/39186

Linux Kernel 'proc_oom_score()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/39477

Linux Kernel NFS Automount 'symlinks' Denial of Service Vulnerability
http://www.securityfocus.com/bid/39044

Linux Kernel USB interface Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/39042

Linux Kernel 'tcp_rcv_state_process()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/39016

Linux Kernel 'sctp_rcv_ootb()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38857

Linux Kernel KVM Segment Selector Loading Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38467

Linux Kernel Bluetooth Sysfs File Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/38898

Linux Kernel KVM Multiple Privilege Escalation and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/38158

Linux Kernel Virtual Dynamically-linked Shared Object Access Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38858

Linux Kernel 'azx_position_ok()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/38348

Linux Kernel 'dvb_net_ule()' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/38479

Linux Kernel 'net/ipv6/ip6_output.c' NULL Pointer Dereference Denial of Service Vulnerability
http://www.securityfocus.com/bid/38185

QEMU Virtio Networking Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37201

Linux Kernel RTL8169 NIC 'RxMaxSize' Frame Size Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/37521

PostgreSQL Index Function Session State Modification Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/37333

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/40215

PostgreSQL 'RESET ALL' Unauthorized Access Vulnerability
http://www.securityfocus.com/bid/40304

PostgreSQL JOIN Hashtable Size Integer Overflow Denial Of Service Vulnerability
http://www.securityfocus.com/bid/38619

PostgreSQL 'bitsubstr' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/37973

FeedDemon 'outline' Tag Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/33630

RPCBind Multiple Insecure Temporary File Creation Vulnerabilities
http://www.securityfocus.com/bid/40562

osCSS Remote File Upload Vulnerability
http://www.securityfocus.com/bid/40555

RSA Key Manager Client Metadata SQL Injection Vulnerability
http://www.securityfocus.com/bid/40553

eFront Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/40551

Motorola SBV6120E SURFboard Digital Voice Modem Directory Traversal Vulnerability
http://www.securityfocus.com/bid/40550

MoinMoin 'PageEditor.py' Cross-Site Scripting Vulnerability
http://www.securityfocus.com/bid/40549

Microsoft June 2010 Advance Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/40548

HP ServiceCenter Unspecified Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/40547

SmartISoft phpBazar 'picturelib.php' Remote File Include Vulnerability
http://www.securityfocus.com/bid/40546

Content Management System module for PHProjekt 'path_pre' Remote File Include Vulnerability
http://www.securityfocus.com/bid/40545

TomatoCMS Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/40544

0 件のコメント:

コメントを投稿