2010年8月20日金曜日

20日 金曜日、大安

BIND 9.5.3b1 is now available.
http://ftp.isc.org/isc/bind9/9.5.3b1/9.5.3b1

[courier-announce] Cone build 20100819 released
http://www.courier-mta.org/download.php#cone

Trend Micro NAS Security サポート開始のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1455

Trend Micro Security (for Mac) 1.5 Service Pack 2 公開のお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1452

Can VMware put a dent in Microsoft Exchange?
http://www.infoworld.com/t/email/can-vmware-put-dent-in-microsoft-exchange-294

VMware Zimbra Offers Business a Microsoft Exchange Alternative
http://www.channelinsider.com/c/a/Microsoft/VMware-Zimbra-Offers-Business-a-Microsoft-Exchange-Alternative-499467/

VMware Takes Zimbra to the Cloud
http://www.serverwatch.com/virtualization/article.php/3898186/VMware-Takes-Zimbra-to-the-Cloud.htm

Zimbra Appliance: VMWare executes on cloud-based email
http://www.zdnet.com/blog/forrester/zimbra-appliance-vmware-executes-on-cloud-based-email/490

JVN#91740962 Winny におけるバッファオーバーフローの脆弱性
http://jvn.jp/jp/JVN91740962/index.html

JVN#21471805 Winny におけるバッファオーバーフローの脆弱性
http://jvn.jp/jp/JVN21471805/index.html

JVN#25393522 Winny におけるノード情報の処理に関する脆弱性
http://jvn.jp/jp/JVN25393522/index.html

JVN#54336184 Winny における BBS 情報の処理に関する脆弱性
http://jvn.jp/jp/JVN54336184/index.html

JVNDB-2010-000030 Winny におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000030.html

JVNDB-2010-000029 Winny におけるバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000029.html

JVNDB-2010-000028 Winny におけるノード情報の処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000028.html

JVNDB-2010-000027 Winny における BBS 情報の処理に関する脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000027.html

Red Hat Virtual Desktop Server Manager (VDSM) SSL Connection Handling Flaw Lets Remote Users Deny Service
http://securitytracker.com/alerts/2010/Aug/1024347.html




+- Tomcat 7.0.2 Beta Released
http://tomcat.apache.org/
http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

+ MySQL 5.1.50 released
http://dev.mysql.com/doc/refman/5.1/en/news-5-1-50.html

+ vsftpd 2.3.2 released
http://vsftpd.beasts.org/
ftp://vsftpd.beasts.org/users/cevans/untar/vsftpd-2.3.2/Changelog

- FreeBSD mbufs() sendfile Cache Poisoning Privilege Escalation
http://www.exploit-db.com/exploits/14688/

- Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/42251
CVE-2010-1892

[ANNOUNCE] Apache IvyDE 2.1.0 released
http://ant.apache.org/ivy/ivyde/history/latest-milestone/release-notes.html

Google Chrome 5.0.375.127 released
http://googlechromereleases.blogspot.com/2010/08/stable-channel-update_19.html

APSB10-17 Security updates available for Adobe Reader and Acrobat
http://www.adobe.com/support/security/bulletins/apsb10-17.html

LSI SAS1064E and LSI SAS1068E Controllers Revisions B2 and B3 may Cause a System Panic
http://sunsolve.sun.com/search/document.do?assetkey=1-77-1168826.1-1

Linuxオプション5.0プロセス数監視の初期値について
http://www.say-tech.co.jp/support/linux/linux50/index.shtml

Acros Security : [ASPR #2010-08-18-1] Remote Binary Planting in Apple iTunes for Windows
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33476

Independent Researcher : Medium security hole in Rekonq web browser
http://www.criticalwatch.com/support/security-advisories.aspx?AID=33477

US-CERT Technical Cyber Security Alert TA10-231A -- Adobe Reader and Acrobat Vulnera
http://www.derkeiler.com/Mailing-Lists/Cert/2010-08/msg00002.html

Flock Browser 3.0.0.3989 Malformed Bookmark XSS and script insertion
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00212.html

[security bulletin] HPSBMA02424 SSRT080125 rev.3 - HP OpenView Network Node Manager (OV NNM), Re
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00216.html

[security bulletin] HPSBST02536 SSRT100057 rev.2 - HP StorageWorks Storage Mirroring, Remote Una
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00214.html

[SECURITY] [DSA 2093-1] New ghostscript packages fix several vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00210.html

NSOADV-2010-005: SonicWALL E-Class SSL-VPN ActiveX Control format string overflow
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00211.html

MUSE v4.9.0.006 (.pls) Local Universal Buffer Overflow [SEH]
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00213.html

MUSE v4.9.0.006 (.m3u) Local Buffer Overflow Exploit
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-08/msg00215.html

新たな「Androidウイルス」出現、ゲームに見せかけて位置情報を送信
監視用の有料アプリも用意、ただし危険性は低い
http://itpro.nikkeibp.co.jp/article/NEWS/20100819/351279/?ST=security

9割のSMBはデータ・バックアップ・ソフトを導入済み、課題は管理者のスキル不足---シマンテック
http://itpro.nikkeibp.co.jp/article/Research/20100819/351282/?ST=security

JVNDB-2010-001844 Autonomy KeyView Filter SDK の kvolefio.dll における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001844.html

JVNDB-2010-001843 w3m のistream.c における X.509 証明書の処理に関する任意の SSL サーバになりすまされる脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001843.html

JVNDB-2010-001842 Apache HTTP Server の mod_cache および mod_dav モジュールにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001842.html

JVNDB-2010-001841 Mozilla Firefox の layout/generic/nsObjectFrame.cpp における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001841.html

Change is Good. Change is Bad. Change is Life.
http://isc.sans.edu/diary.html?storyid=9424

Casper the unfriendly ghost
http://isc.sans.edu/diary.html?storyid=9430

Open-Realty "select_users_lang" Local File Inclusion Vulnerability
http://secunia.com/advisories/41024/

Wyse ThinOS LPD Service Buffer Overflow
http://secunia.com/advisories/40997/

Joomla JGrid Component File Inclusion and SQL Injection Vulnerabilities
http://secunia.com/advisories/40987/

DotNetNuke Syndication Handler Denial of Service Vulnerability
http://secunia.com/advisories/41043/

Drupal Simplenews Content Selection Module Cross-Site Scripting Vulnerability
http://secunia.com/advisories/41046/

IBM Tivoli Storage Manager FastBack Multiple Vulnerabilities
http://secunia.com/advisories/41044/

SonicWALL SSL-VPN Format String Flaw in ActiveX Control Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Aug/1024346.html

Microsoft SRV2.SYS SMB Negotiate ProcessID Function Table Dereference (MS09-050)
http://securityreason.com/securityalert/7674

OpenSSL "ssl3_get_key_exchange()" Use-after-free Vulnerability
http://securityreason.com/securityalert/7673

SWFTools Two Integer Overflow Vulnerabilities
http://securityreason.com/securityalert/7672

Adobe Acrobat and Reader Multiple Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/2123

Apache CouchDB Admin Interface Cross Site Request Forgery
http://www.vupen.com/english/advisories/2010/2122

Linux-PAM "pam_xauth" Module Privilege Escalation Weakness
http://www.vupen.com/english/advisories/2010/2121

Fedora Security Update Fixes ZNC Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2010/2120

Fedora Security Update Fixes OpenConnect Certificate Validation Issue
http://www.vupen.com/english/advisories/2010/2119

Fedora Security Update Fixes Drupal Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2118

Fedora Security Update Fixes Freeciv Code Execution and File Disclosure
http://www.vupen.com/english/advisories/2010/2117

Fedora Security Update Fixes ClamAV Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/2116

SuSE Security Update Fixes Kernel Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2010/2115

Debian Security Update Fixes Ghostscript Multiple Vulnerabilities
http://www.vupen.com/english/advisories/2010/2114

Tuniac 100723 Denial of Service Vulnerability
http://www.exploit-db.com/exploits/14689/

SonicWALL E-Class SSL-VPN ActiveX Control Format String Overflow
http://www.exploit-db.com/exploits/14687/

Tuniac '.m3u' File Version 100723 Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/42569

Databay MAXcms Multiple File Include Vulnerabilities
http://www.securityfocus.com/bid/42534

MediaCoder Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/38405

Adobe Acrobat and Reader Font Parsing Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/42203

CMS Made Simple 'modules/Printing/output.php' CMS Local File Include Vulnerability
http://www.securityfocus.com/bid/36005

Adobe ColdFusion CVE-2010-2861 Directory Traversal Vulnerability
http://www.securityfocus.com/bid/42342

Microsoft Windows TCP/IP IPv6 Extension Header Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/42251

Ghostscript 'iscan.c' PDF Handling Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/41593

Ghostscript PostScript Infinite Recursion Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/40107

FreeBSD mbuf Handling Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/41577

Open-Realty 'title' Parameter HTML Injection Vulnerability
http://www.securityfocus.com/bid/41947

Flock Browser Malformed Bookmark Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/42556

SonicWALL E-Class SSL-VPN Format String Vulnerability
http://www.securityfocus.com/bid/42548

0 件のコメント:

コメントを投稿