2010年6月8日火曜日

8日 火曜日、大安

bind 9.7.1rc1
http://ftp.isc.org/isc/bind9/9.7.1rc1/9.7.1rc1

ServerProtect for Windows 5.7 用 Patch 2 build 1108 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1423

ServerProtect for Windows 5.8 用 Patch 1 build 1240 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1422

ダメージクリーンナップエンジン 6.3 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1417

JVNDB-2010-001228 OpenSSL の kssl_keytab_is_available 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001228.html

JVNDB-2010-001227 OpenSSL の ssl3_get_record 関数におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001227.html

Perl Safe Module (Safe::reval and Safe::rdo) Can Be Bypassed
http://securitytracker.com/alerts/2010/Jun/1024062.html

Apple Mac OS X 2009-003 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/35954




+ RHSA-2010:0458-2: Moderate: perl security update
http://rhn.redhat.com/errata/RHSA-2010-0458.html

+ RHSA-2010:0457-1: Moderate: perl security update
http://rhn.redhat.com/errata/RHSA-2010-0457.html

+ Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
http://www.securityfocus.com/bid/40302

- (参考)Lotus Domino LDAP タスクのバッファーオーバーフローに関する脆弱性について
http://www-06.ibm.com/jp/domino04/lotus/support/faqs/faqs.nsf/all/734092

About the security content of Safari 5.0 and Safari 4.1
http://support.apple.com/kb/HT4196

jetty 7.1.3.v20100526 released
http://svn.codehaus.org/jetty/jetty/branches/jetty-7/VERSION.txt

PostgreSQL 9.0 Beta 2 Now Available
http://www.postgresql.org/about/news.1210

UPDATE: Cisco Security Advisory: Multiple Vulnerabilities in Cisco Network Building Mediator
http://www.cisco.com/warp/public/707/cisco-sa-20100526-mediator.shtml

UPDATE: Cisco Security Advisory: Cisco Small Business Video Surveillance Cameras and Cisco 4-Port Gigabit Security Routers Authentication Bypass Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20100421-vsc.shtml

ウイルスバスター チャットサポート システム障害について
http://www.trendmicro.co.jp/support/news.asp?id=1425

VEA GUI shows more paths than attached for some LUNs
http://seer.entsupport.symantec.com/docs/355288.htm

Storage Agent crashes when adding a LUN.
http://seer.entsupport.symantec.com/docs/355286.htm

SFW commands fail (error V-77-57616-2 Server Initialization failed) when user name contains special characters
http://seer.entsupport.symantec.com/docs/354934.htm

RHBA-2010:0456-1: xen bug fix update
http://rhn.redhat.com/errata/RHBA-2010-0456.html

RHSA-2010:0459-1: Moderate: openoffice.org security update
http://rhn.redhat.com/errata/RHSA-2010-0459.html

Debian : New mysql-dfsg-5.0 packages fix several vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32789

Independent Researcher : Google Apps CSRF vector, email disruption
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32794

Independent Researcher : Core FTP mini-sftp-server Several DoS and Directory Traversal Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32795

Debian : New zonecheck packages fix cross-site scripting
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32788

Debian : New OpenOffice.org packages fix arbitrary code execution
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32787

MustLive : DoS attacks on email clients via protocol handlers
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32793

Secunia : XSS, SQL injection vulnerability in WMSCMS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32791

Debian : New bind9 packages fix cache poisoning
http://www.criticalwatch.com/support/security-advisories.aspx?AID=32786

JVNDB-2010-001505 Java の window drawing 実装における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001505.html

JVNDB-2010-001504 Apple Mac OS X 上で稼働する Java における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001504.html

JVNDB-2010-001503 rpc.pcnfsd の _msgout 関数における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001503.html

JVNDB-2010-001502 Microsoft Windows の Canonical Display Driver における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001502.html

JVNDB-2010-001501 MIT Kerberos 5 の GSS-API ライブラリにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001501.html

JVNDB-2009-002450 PostgreSQL におけるインデックスの処理に関する権限を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-002450.html

[security bulletin] HPSBUX02451 SSRT090137 rev.3 - HP-UX Running BIND, Remote Denial of Serv
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00058.html

[SECURITY] [DSA 2057-1] New mysql-dfsg-5.0 packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00064.html

Core FTP mini-sftp-server Several DoS and Directory Traversal Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00059.html

[SECURITY] [DSA 2056-1] New zonecheck packages fix cross-site scripting
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00063.html

Core FTP Server(SFTP module) open and stat Commands Remote Denial of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00065.html

[SECURITY] [DSA 2055-1] New OpenOffice.org packages fix arbitrary code execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00062.html

XSS vulnerability in CuteSITE CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00066.html

XSS vulnerability in boastMachine
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00068.html

XSRF (CSRF) in CuteSITE CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00067.html

SQL injection vulnerability in CuteSITE CMS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00061.html

SQL injection vulnerability in boastMachine
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00069.html

[SECURITY] [DSA 2054-1] New bind9 packages fix cache poisoning
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-06/msg00060.html

Internet Storm Center panel tonight at SANSFIRE
http://isc.sans.edu/diary.html?storyid=8920

Vulnerability Note VU#486225: Adobe Flash ActionScript AVM2 newfunction vulnerability
http://www.kb.cert.org/vuls/id/486225

OpenOffice.org Python Scripting Bug Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Jun/1024060.html

RSA Key Manager Input Validation Flaw Lets Remote Users Inject SQL Commands
http://securitytracker.com/alerts/2010/Jun/1024059.html

TCExam 10.1.007 Arbitrary Upload
http://securityreason.com/securityalert/7484

Joomla Component My Car 1.0 Multiple Vulnerabilities
http://securityreason.com/securityalert/7483

clearsite Remote File Include Vulnerability
http://securityreason.com/securityalert/7482

Zeeways Script Multiple Vulnerabilities
http://securityreason.com/securityalert/7481

Symphony CMS 2.0.7 Local File Inclusion Vulnerability
http://securityreason.com/securityalert/7480

Joomla Search Log Component "search" SQL Injection Vulnerability
http://secunia.com/advisories/40055/

Joomla DJ-ArtGallery Component "cid[]" Two Vulnerabilities
http://secunia.com/advisories/40073/

WordPress Gigya Socialize Plugin Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/40074/

Freeciv Lua Shell Command Execution Security Issue
http://secunia.com/advisories/40078/

moziloCMS Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/40091/

Debian update for bind9
http://secunia.com/advisories/40086/

Debian update for openoffice.org
http://secunia.com/advisories/40084/

Debian update for zonecheck
http://secunia.com/advisories/40083/

Battlefield 2142 Packet Processing Infinite Loop Vulnerability
http://secunia.com/advisories/40056/

Battlefield 2 Packet Processing Infinite Loop Vulnerability
http://secunia.com/advisories/40053/

VUPlayer <=2.49 .M3u Universal buffer overflow exploit w/ DEP bypass http://www.exploit-db.com/exploits/13756/

Audio Converter 8.1 0day Stack Buffer Overflow PoC exploit
http://www.exploit-db.com/exploits/13760/

Easy CD-DA Recorder 2007 SEH Buffer Overflow
http://www.exploit-db.com/exploits/13761/

Gigya Socialize for WordPress Cross Site Scripting Vulnerability
http://www.vupen.com/english/advisories/2010/1364

Search Log for Joomla "search" Parameter SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2010/1363

e2eTech Design "id" Parameter Multiple SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2010/1362

WmsCMS Multiple SQL Injection and Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1361

iScripts eSwap SQL Injection and Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1360

iScripts EasyBiller "planid" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2010/1359

PHP Car Rental Script "id" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2010/1358

IdevSpot TextAds "page" Parameter Remote SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2010/1357

WebBiblio "page" Parameter Local File Inclusion Vulnerability
http://www.vupen.com/english/advisories/2010/1356

ReVou SQL Injection and Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1355

Debian Security Update Fixes ZoneCheck Cross Site Scripting Issues
http://www.vupen.com/english/advisories/2010/1354

Debian Security Update Fixes OpenOffice.org Code Execution Vulnerability
http://www.vupen.com/english/advisories/2010/1353

Debian Security Update Fixes BIND Cache Poisoning Vulnerabilities
http://www.vupen.com/english/advisories/2010/1352

ZoneCheck Multiple Parameter Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/1351

OpenOffice.org Code Execution and Security Bypass Vulnerabilities
http://www.vupen.com/english/advisories/2010/1350

Audiotran '.pls' File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/40478

OpenOffice Python Scripting IDE Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/40599

Perl Safe Module 'reval()' and 'rdo()' Restriction-Bypass Vulnerabilities
http://www.securityfocus.com/bid/40302

Perl Safe Module 'reval()' and 'rdo()' CVE-2010-1447 Restriction-Bypass Vulnerabilities
http://www.securityfocus.com/bid/40305

Perl 'rmdir()' Local Race Condition Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/12767

Adobe Flash Player, Acrobat Reader, and Acrobat 'authplay.dll' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/40586

RSA Key Manager C Client Metadata SQL Injection Vulnerability
http://www.securityfocus.com/bid/40553

ZoneCheck 'zc.cgi' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/40404

Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
http://www.securityfocus.com/bid/36935

ISC BIND 9 Remote Dynamic Update Message Denial of Service Vulnerability
http://www.securityfocus.com/bid/35848

Oracle MySQL DROP TABLE MyISAM Symbolic Link Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/40257

Oracle MySQL 'COM_FIELD_LIST' Command Packet Security Bypass Vulnerability
http://www.securityfocus.com/bid/40109

Oracle MySQL 'COM_FIELD_LIST' Command Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/40106

Oracle MySQL Malformed Packet Handling Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/40100

IBM Informix Dynamic Server 'librpc.dll' Multiple Buffer Overflow Vulnerabilities
http://www.securityfocus.com/bid/38471

HP OpenView Network Node Manager (CVE-2010-1551) '_OVParseLLA()' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/40067

HP OpenView Network Node Manager 'getnnmdata.exe' Code Execution Vulnerability
http://www.securityfocus.com/bid/40072

Hexjector 'hexjector.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/40509

D.R. Software Audio Converter '.pls' File Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/40618

Core FTP Server Directory Traversal and Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/40609

EA Battlefield 2 and Battlefield 2142 Multiple Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/40605

SubStation Alpha '.rt' File Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/40604

ZoneCheck Multiple Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/40601

Freeciv Lua Runtime Environment Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/40598

Sphider 'en' Parameter Remote Command Execution Vulnerability
http://www.securityfocus.com/bid/40589

JForum 'bookmarks' Module Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/40600

iScripts eSwap SQL Injection and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/40597

ReVou Search Field Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/40596

WebBiblio Subject Gateway System 'page' Parameter Local File Include Vulnerability
http://www.securityfocus.com/bid/40594

WmsCms Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/40593

IDevSpot TextAds 'page' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/40592

WmsCms Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/40591

Joomla! 'com_searchlog' Component 'search' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/40588

0 件のコメント:

コメントを投稿