2011年3月11日金曜日

11日 金曜日、友引

+ RHSA-2011:0346-1: Moderate: openldap security and bug fix update
http://rhn.redhat.com/errata/RHSA-2011-0346.html

- Linux SCSI target framework (tgt) "iscsi_rx_handler()" Vulnerability
http://secunia.com/advisories/43713/

- Linux Kernel I/O-Warrior USB Device Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46069

RHSA-2011:0345 Moderate: qemu-kvm security update
http://rhn.redhat.com/errata/RHSA-2011-0345.html

RHSA-2011:0347 Moderate: openldap security update
http://rhn.redhat.com/errata/RHSA-2011-0347.html

CentOS alert CESA-2011:0337 (vsftpd)
http://lwn.net/Alerts/432787/

UPDATE: Cisco Security Advisory: Cisco IOS Software H.323 Denial of Service Vulnerabilities
http://www.cisco.com/en/US/products/products_security_advisory09186a0080b4a300.shtml

IRCRASH : RecordPress Multiple Vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35268

Red Hat : [RHSA-2011:0327-01] subversion: Moderate Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35265

Red Hat : [RHSA-2011:0328-01] subversion: Moderate Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35266

Red Hat : [RHSA-2011:0329-01] kernel: Important Advisory
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35267

Debian : [DSA 2186-1] iceweasel security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35269

Debian : [DSA 2187-1] icedove security update
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35270

アクシス、天井取り付け型監視カメラに7万円台の普及価格帯モデルを発表
http://itpro.nikkeibp.co.jp/article/NEWS/20110310/358219/?ST=security

JVNDB-2011-001225 Adobe Shockwave Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001225.html

JVNDB-2011-001224 Adobe Shockwave Player の IML32 モジュールにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001224.html

JVNDB-2011-001223 Adobe Shockwave Player の dirapi.dll モジュールにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001223.html

JVNDB-2011-001222 Adobe Shockwave Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001222.html

JVNDB-2011-001221 Adobe Shockwave Player における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001221.html

JVNDB-2011-001220 Adobe Shockwave Player の compatibility コンポーネントにおける任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001220.html

iOS 4.3 released, numerous security vulnerabilities patched
http://isc.sans.edu/diary/iOS+4+3+released+numerous+security+vulnerabilities+patched/10525

Debian update for iceweasel and xulrunner
http://secunia.com/advisories/43638/

LMS Web Ensino Multiple Vulnerabilities
http://secunia.com/advisories/43651/

Wikiwig "to_p_dict" and "to_r_list" Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/43709/

Debian update for icedove
http://secunia.com/advisories/43656/

SUSE update for gimp
http://secunia.com/advisories/43690/

Icinga Two Cross-Site Scripting Vulnerabilities
http://secunia.com/advisories/43643/

WordPress Lazyest Gallery Plugin "image" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/43661/

Red Hat update for tomcat5
http://secunia.com/advisories/43694/

Red Hat update for tomcat6
http://secunia.com/advisories/43701/

Fedora update for asterisk
http://secunia.com/advisories/43702/

Red Hat update for scsi-target-utils
http://secunia.com/advisories/43706/

JBoss Enterprise Portal Platform Java Double Literal Denial of Service Vulnerability
http://secunia.com/advisories/43704/

JBoss Enterprise SOA Platform Java Double Literal Denial of Service Vulnerability
http://secunia.com/advisories/43705/

Apple TV Multiple Vulnerabilities
http://secunia.com/advisories/43697/

Linux SCSI target framework (tgt) "iscsi_rx_handler()" Vulnerability
http://secunia.com/advisories/43713/

Apple iOS Multiple Vulnerabilities
http://secunia.com/advisories/43698/

Majordomo 2 "_list_file_get()" Directory Traversal Vulnerability
http://secunia.com/advisories/43631/

libvirt Read-Only API Calls Security Bypass Security Issue
http://secunia.com/advisories/43670/

Comtrend CT-5367 "password.cgi" Security Bypass Vulnerability
http://secunia.com/advisories/43653/

unixODBC "SQLDriverConnect()" Buffer Overflow Vulnerability
http://secunia.com/advisories/43679/

Apple Safari Multiple Vulnerabilities
http://secunia.com/advisories/43696/

Fedora update for pywebdav
http://secunia.com/advisories/43703/

DoS/PoC: Linux Kernel < 2.6.37-rc2 TCP_MAXSEG Kernel Panic DoS
http://www.exploit-db.com/exploits/16952/

Apple Safari Code Execution and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2011/0641

Apple iOS Code Execution and Information Disclosure Vulnerabilities
http://www.vupen.com/english/advisories/2011/0640

Redhat Security Update vsftpd Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2011/0639

Redhat Security Update Tomcat Remote Denial of Service Vulnerabilities
http://www.vupen.com/english/advisories/2011/0638

JBoss Enterprise Products Remote Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2011/0637

Redhat Security Update Fixes scsi-target-utils Double Free Vulnerability
http://www.vupen.com/english/advisories/2011/0636

Fedora Security Update Fixes Asterisk Array Overflow Vulnerabilities
http://www.vupen.com/english/advisories/2011/0635

Fedora Security Update Fixes PyWebDAV SQL Injection Vulnerabilities
http://www.vupen.com/english/advisories/2011/0634

Debian Security Update Fixes WebKit Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2011/0633

Debian Security Update Fixes Icedove Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2011/0632

Debian Security Update Fixes Iceweasel Code Execution Vulnerabilities
http://www.vupen.com/english/advisories/2011/0631

Oracle Weblogic CVE-2010-4437 Remote Session Fixation Vulnerability
http://www.securityfocus.com/bid/45852

WebKit Use-After-Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/46822

Cisco IOS CVE-2010-2828 H.323 Unspecified Denial of Service Vulnerability
http://www.securityfocus.com/bid/43392

OpenLDAP Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/46363

QEMU KVM VNC Password Security Bypass Vulnerability
http://www.securityfocus.com/bid/45743

Linux Kernel 'ib_uverbs_poll_cq()' Function Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/46488

Linux Kernel 'ib_uverbs_poll_cq()' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/46073

Linux Kernel TKIP Countermeasures Security Vulnerability
http://www.securityfocus.com/bid/46322

Linux Kernel I/O-Warrior USB Device Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46069

Linux Kernel 'drivers/media/dvb/ttpci/av7110_ca' IOCTL Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45986

Linux Kernel 'ethtool.c' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/45972

Linux Kernel 'blk_rq_map_user_iov()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/45660

Linux Kernel 'drivers/acpi/debugfs.c' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45408

Linux Kernel TCP_MAXSEG Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/44830

Linux Kernel 'posix-cpu-timers.c' Local Race Condition Vulnerability
http://www.securityfocus.com/bid/45028

Linux Kernel 'net/sched/act_police.c' File Memory Leak Local Information Disclosure Vulnerability
http://www.securityfocus.com/bid/42529

Linux Kernel 'inotify_init()' Memory Leak Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/45036

Linux Kernel Unix Sockets Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/45037

Linux Kernel 'l2tp_ip_sendmsg()' and 'pppol2tp_sendmsg()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/44762

Linux Kernel 'install_special_mapping()' Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/45323

Linux Kernel Block Layer Local Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/44793

Linux Kernel 'hci_uart_tty_open()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/45014

Linux Kernel CAN Protocol Information Disclosure Vulnerability
http://www.securityfocus.com/bid/44661

Google Chrome prior to 9.0.597.107 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/46614

Logwatch Log File Special Characters Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/46554

Mail-Box Perl Module Unspecified Security Vulnerability
http://www.securityfocus.com/bid/46779

Lazyest Gallery WordPress Plugin 'image' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/46823

IBM WebSphere Application Server prior to 7.0.0.15 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/46736

Microsoft .NET Runtime Optimization Service Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/46773

WebKit CSS Token Sequences Handling Denial of Service Vulnerability
http://www.securityfocus.com/bid/45722

Google Chrome prior to 9.0.597.84 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/46144

Google Chrome prior to 8.0.552.237 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/45788

WebKit CVE-2010-1783 Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/42035

CubeCart Cross Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/46641

Mozilla Firefox and SeaMonkey JavaScript Non-Local Variables Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46648

Mozilla Firefox/SeaMonkey Cross-Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/46652

Mozilla Firefox and SeaMonkey 'JSON.stringify()' Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46661

Mozilla Firefox SeaMonkey and Thunderbird CVE-2011-0053 Multiple Memory Corruption Vulnerabilities
http://www.securityfocus.com/bid/46645

Mozilla Firefox and SeaMonkey JavaScript String Values Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/46650

Mozilla Firefox and SeaMonkey JavaScript Worker Use-After-Free Memory Corruption Vulnerability
http://www.securityfocus.com/bid/46663

Mozilla Firefox/SeaMonkey 'eval()' Function Security Bypass Vulnerability
http://www.securityfocus.com/bid/46643

pywebdav MySQL Authentication Module SQL Injection Vulnerability
http://www.securityfocus.com/bid/46655

FreeBSD netgraph and bluetooth Local Privilege Escalation Vulnerabilities
http://www.securityfocus.com/bid/32976

Blackberry Browser Multiple Unspecified Information Disclosure and Integer Overflow Vulnerabilities
http://www.securityfocus.com/bid/46833

Apple Mobile Safari for iOS 4.2.1 Unpecified Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/46832

HP Power Manager Unspecified Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/46830

CosmoShop Multiple Cross Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/46828

Nagios 'layer' Parameter Cross-Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/46826

Xinha 'spell-check-savedicts.php' Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/46825

PHP-Nuke 'Submit_News' Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/46824

libvirt Multiple Remote Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/46820

Arthur de Jong 'nss-pam-ldapd' Authentication Bypass Vulnerability
http://www.securityfocus.com/bid/46819

0 件のコメント:

コメントを投稿