2010年12月28日火曜日

28日 火曜日、先負

Service Pack 1 未適用のウイルスバスターコーポレートエディション 8.0サポート終了に伴う後継製品へのアップグレードのご案内
http://www.trendmicro.co.jp/support/news.asp?id=1506

集中監視コンソールのインスタンスステータスログで、過去のログが混在することがある
http://www.say-tech.co.jp/support/bom-for-windows/post-57/index.shtml

JVNVU#120541 SSL および TLS プロトコルに脆弱性
http://jvn.jp/cert/JVNVU120541/index.html

JVNVU#568372 NTP におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/cert/JVNVU568372/index.html




+ Apache Ant 1.8.2 Released
http://ant.apache.org/

+ Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability
http://secunia.com/advisories/42747/
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00254.html
http://securitytracker.com/alerts/2010/Dec/1024925.html
http://www.vupen.com/english/advisories/2010/3327
http://www.securityfocus.com/bid/45583

- Perl IO::Socket::SSL 'verify_mode' Security Bypass Vulnerability
http://www.securityfocus.com/bid/45189

FreeBSD-7.4/8.2 first Release Candidate
http://www.freebsd.org/news/newsflash.html#event20101227:01

Debian : [DSA-2137-1] libxml2 - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34591

Independent Researcher : [W-Agora-SA-12/27/2010] W-Agora - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34600

ZDI : [ZDI-10-300] Novell iPrint Client - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34592

ZDI : [ZDI-10-299] Novell iPrint Client - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34593

ZDI : [ZDI-10-298] Novell iPrint Client - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34594

ZDI : [ZDI-10-297] Novell iPrint Client - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34595

ZDI : [ZDI-10-296] Novell iPrint Client - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34596

ZDI : [ZDI-10-295] - Novell iPrint Client - Code Execution Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34597

Mandriva : [MDVSA-2010:259] pidgin - Null Pointer Dereference Issue
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34589

Mandriva : [MDVSA-2010:251-2] firefox - Multiple Issues
http://www.criticalwatch.com/support/security-advisories.aspx?AID=34590

2010年のウイルス感染被害は前年の4割以下に減少---トレンドマイクロのレポートから
http://itpro.nikkeibp.co.jp/article/NEWS/20101227/355702/?ST=security

ファミマTカードの不正利用、米国の実店舗で発生
http://itpro.nikkeibp.co.jp/article/NEWS/20101227/355695/?ST=security

Multiple Vulnerabilities in OpenClassifieds 1.7.0.3
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00244.html

[waraxe-2010-SA#078] - Multiple Vulnerabilities in CruxCMS 3.0.0
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00247.html

Microsoft Windows Fax Services Cover Page Editor (.cov) Memory Corruption poc
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00254.html

Social Engine 4.x (Music Plugin) Arbitrary File Upload Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00255.html

[SECURITY] [DSA 2137-1] Security update for libxml2
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00245.html

Pligg XSS and SQL Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00250.html

[ MDVSA-2010:251-2 ] firefox
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00242.html

Security Advisory - FlexVision Listener Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00253.html

[ MDVSA-2010:251-1 ] firefox
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00256.html

[IMF 2011] 2nd Call - Deadline Extended
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00252.html

[ MDVSA-2010:259 ] pidgin
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00251.html

Django admin list filter data extraction / leakage
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00249.html

MyBB 1.6 <= SQL Injection Vulnerability http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00248.html

Asan Portal (IdehPardaz) Multiple Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00246.html

Secunia Research: Microsoft Word LFO Parsing Double-Free Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00243.html

[security bulletin] HPSBST02619 SSRT100281 rev.2 - HP StorageWorks Storage Mirroring, Remote Exe
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00241.html

Sigma Portal Denial of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2010-12/msg00238.html

Various sites "Owned and Exposed"
http://isc.sans.edu/diary.html?storyid=10156

Novell iPrint Multiple Flaws Let Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Dec/1024926.html

Microsoft Fax Cover Page Editor Memory Corruption Error Lets Remote Users Execute Arbitrary Code
http://securitytracker.com/alerts/2010/Dec/1024925.html

Square CMS "id" SQL Injection Vulnerability
http://secunia.com/advisories/42702/

OpenEMR Script Insertion and SQL Injection Vulnerabilities
http://secunia.com/advisories/42738/

Fedora update for perl-IO-Socket-SSL
http://secunia.com/advisories/42757/

IBM Lotus Mobile Connect Multiple Vulnerabilities
http://secunia.com/advisories/42703/

IBM WebSphere Service Registry and Repository EJB Authentication Bypass
http://secunia.com/advisories/42742/

Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability
http://secunia.com/advisories/42747/

IBM Tivoli Access Manager for e-business Directory Traversal Vulnerability
http://secunia.com/advisories/42727/

ENOVIA "emxFramework.FilterParameterPattern" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/42668/

PECL phar Extension Format String Vulnerabilities
http://secunia.com/advisories/42726/

web@all Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/42736/

Pligg Multiple Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/42740/

CubeCart Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/42728/

Debian update for libxml2
http://secunia.com/advisories/42762/

Pidgin MSN Direct Connection Denial of Service Weakness
http://secunia.com/advisories/42732/

Libxml2 XPath Double Free Vulnerability
http://secunia.com/advisories/42721/

Fedora update for dbus
http://secunia.com/advisories/42760/

Fedora update for eclipse
http://secunia.com/advisories/42761/

Novell Groupwise GWPOA HTTP Request Code Execution Vulnerability
http://www.securiteam.com/securitynews/6E03H200KO.html

Microsoft Excel MSODrawing Improper Exception Handling Code Execution Vulnerability
http://www.securiteam.com/windowsntfocus/6D03G200KA.html

Oracle Sun JRE JPEGImageWriter.writeImage Code Execution Vulnerability
http://www.securiteam.com/securitynews/6F03I200KC.html

Oracle Java ActiveX Plugin Uninitialized Window Handle Code Execution Vulnerability
http://www.securiteam.com/securitynews/6H03K200KS.html

Oracle Java Runtime HeadspaceSoundbank.nGetName BANK Record Size Code Execution Vulnerability
http://www.securiteam.com/securitynews/6I03L200KE.html

Oracle Java IE Browser Plugin docbase Parameter Code Execution Vulnerability
http://www.securiteam.com/securitynews/6G03J200KG.html

RealNetworks RealPlayer Malformed IVR Pointer Index Code Execution Vulnerability
http://www.securiteam.com/securitynews/6J03M200KQ.html

Microsoft Windows Fax Cover Page Editor Buffer Overflow Vulnerability
http://www.vupen.com/english/advisories/2010/3327

Fedora Security Update Fixes perl-IO-Socket-SSL Peer Verification Issue
http://www.vupen.com/english/advisories/2010/3326

Fedora Security Update Fixes D-Bus Nested Variants Stack Overflow
http://www.vupen.com/english/advisories/2010/3325

Fedora Security Update Fixes Eclipse Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/3324

Fedora Security Update Fixes GIT Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/advisories/2010/3323

Fedora Security Update Fixes ImageMagick Untrusted Search Path
http://www.vupen.com/english/advisories/2010/3322

Fedora Security Update Fixes Kernel Remote and Local Vulnerabilities
http://www.vupen.com/english/advisories/2010/3321

Mandriva Security Update Fixes Firefox Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2010/3320

Debian Security Update Fixes Libxml2 XPath Double Free Vulnerability
http://www.vupen.com/english/advisories/2010/3319

Pidgin MSN Use-After-Free Denial of Service Vulnerability
http://www.securityfocus.com/bid/45024

IBM Lotus Mobile Connect Unspecified Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/45361

ImpressCMS 'quicksearch_ContentContent' Parameter HTML Injection Vulnerability
http://www.securityfocus.com/bid/45541

PHP 'ext/phar/stream.c' and 'ext/phar/dirstream.c' Multiple Format String Vulnerabilities
http://www.securityfocus.com/bid/40173

IBM ENOVIA 'emxFramework.FilterParameterPattern' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/45391

Google Chrome prior to 8.0.552.215 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/45170

D-Bus Nested Variants Denial of Service Vulnerability
http://www.securityfocus.com/bid/45377

Mozilla Firefox and SeaMonkey Firebug 'XMLHttpRequestSpy' Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45354

Mozilla Firefox and SeaMonkey Java LiveConnect Script Security Bypass Vulnerability
http://www.securityfocus.com/bid/45355

Mozilla Firefox/Thunderbird/SeaMonkey OS Font Code Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/45352

Mozilla Firefox/Thunderbird/SeaMonkey 'document.write()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45345

Mozilla Firefox/Thunderbird/SeaMonkey CVE-2010-3776 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45347

Mozilla Firefox/Thunderbird/SeaMonkey Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/45353

Mozilla Firefox and SeaMonkey (CVE-2010-3772) Invalid Array Index Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45351

Mozilla Firefox and SeaMonkey 'about:blank' Window Chrome Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45346

Mozilla Firefox and SeaMonkey 'nsDOMAttribute' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45326

Mozilla Firefox/Thunderbird/SeaMonkey CVE-2010-3777 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45348

Mozilla Firefox Pseudo URL Same Origin Policy Security Bypass Vulnerability
http://www.securityfocus.com/bid/45314

Mozilla Firefox/SeaMonkey 'JSSLOT_ARRAY_COUNT' Annotation Integer Overflow Vulnerability
http://www.securityfocus.com/bid/45324

Perl IO::Socket::SSL 'verify_mode' Security Bypass Vulnerability
http://www.securityfocus.com/bid/45189

Redmine Multiple Vulnerabilities
http://www.securityfocus.com/bid/45571

Jetty Web Server Plugin for Eclipse Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/44883

ImageMagick 'configure.c' Configuration File Loading Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45044

DD-WRT '/Info.live.htm' Multiple Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/45598

Sigma Portal 'ShowObjectPicture.aspx' Denial of Service Vulnerability
http://www.securityfocus.com/bid/45588

LiveZilla 'Track' Module 'server.php' Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/45586

IBM WebSphere Service Registry and Repository Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/45585

Libpurple MSN Short Packets Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/45581

Pligg CMS SQL Injection and Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/45580

Kolibri Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/45579

Pligg CMS 'range' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/45578

LoveCMS 'modules.php' Multiple Local File Include Vulnerabilities
http://www.securityfocus.com/bid/45577

Interact 'search_terms' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/45576

OpenEMR Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/45575

Novell iPrint Client Multiple Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/45301

Novell iPrint Client 'ienipp.ocx' ActiveX 'GetDriverSettings()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/44966

Open Classifieds Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/45596

CruxCMS Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/45594

Microsoft Windows Fax Cover Page Editor Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/45583

w-Agora 'search.php' Cross Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/45587

0 件のコメント:

コメントを投稿