2011年4月1日金曜日

1日 金曜日、大安

[ANNOUNCE] Apache Whirr 0.4.0-incubating released
http://www.apache.org/dyn/closer.cgi/incubator/whirr/

Apache Solr 3.1.0
http://www.apache.org/dyn/closer.cgi/lucene/solr

Apache Lucene 3.1.0
http://www.apache.org/dyn/closer.cgi/lucene/java

[ANNOUNCEMENT] Apache Chemistry OpenCMIS 0.3.0 released
http://chemistry.apache.org/

CESA-2011:0392 (libtiff)
http://lwn.net/Alerts/436364/

JVNDB-2011-001340 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001340.html

JVNDB-2011-001339 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001339.html

JVNDB-2011-001338 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001338.html

JVNDB-2011-001337 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001337.html

JVNDB-2011-001336 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001336.html

JVNDB-2011-001335 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001335.html

JVNDB-2011-001334 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001334.html

JVNDB-2011-001333 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001333.html

JVNDB-2011-001332 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001332.html

JVNDB-2011-001331 複数の Apple 製品の WebKit における任意のコードを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-001331.html

JVNDB-2010-002612 PHP の fopen_wrappers.c における open_basedir 制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002612.html

JVNDB-2010-002104 Samba の sid_parse および dom_sid_parse 関数におけるスタックベースのバッファオーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002104.html

JVNDB-2010-002130 PHP の phar 拡張における重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002130.html

JVNDB-2010-001644 Apache HTTP Server の mod_proxy_http における重要なレスポンスを取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001644.html

JVNDB-2010-001842 Apache HTTP Server の mod_cache および mod_dav モジュールにおけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-001842.html

JVNDB-2010-002541 MIT Kerberos 5 における GSS トークンを偽造される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002541.html

JVNDB-2010-002540 MIT Kerberos 5 における KRB-SAFE メッセージを偽造される脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002540.html

JVNDB-2010-002117 bzip2 および libbzip2 の BZ2_decompress 関数における整数オーバーフローの脆弱性
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-002117.html

JVNDB-2006-000997 PHP におけるアクセス制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2006/JVNDB-2006-000997.html

Happy Open Source Intelligence Analysts Day: April 1st
http://isc.sans.edu/diary.html?storyid=10639

Websense warns about Lizamoon
http://isc.sans.edu/diary.html?storyid=10633

IBM AIX LDAP Bug Lets Remote Users Bypass Authentication
http://www.securitytracker.com/id/1025273




+ HPSBUX02645 SSRT100387 rev.1 - HP-UX Apache Web Server, Remote Information Disclosure, Cross-Site Scripting (XSS), Denial of Service (DoS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02752210&admit=109447626+1301615736486+28353475

+ HPSBUX02639 SSRT100293 rev.1 - HP-UX Running XNTP, Remote Denial of Service (DoS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02737553

+ HPSBUX02646 SSRT100396 rev.1 - HP-UX, Local Denial of Service (DoS)
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02753287

+ Linux kernel 2.6.35.12 released
http://www.kernel.org/pub/linux/kernel/v2.6/longterm/v2.6.35/ChangeLog-2.6.35.12

+ Linux Kernel OCFS2 Sparse Writes Information Disclosure Weakness
http://secunia.com/advisories/43966/

+- Apache MPM-ITK Module Security Weakness
http://www.securityfocus.com/bid/46953

HPSBMA02650 SSRT100429 rev.1 - HP Operations for UNIX, Remote Cross Site Scripting (XSS), Unauthorized Access
http://www11.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02770049

「スマホ」向けのセキュリティ基盤サービス、ベリサインとアイキューブドが提供開始
http://itpro.nikkeibp.co.jp/article/NEWS/20110331/358980/?ST=security

JVNVU#706148 ISC BIND におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/cert/JVNVU706148/index.html

JVNVU#837744 ISC BIND named validator に脆弱性
http://jvn.jp/cert/JVNVU837744/index.html

PUBLIC ADVISORY: 03.31.11 RealNetworks Helix DNA Server RTSP Stack Buffer Overflow
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=899

Debian : [DSA-2208-1] bind9: denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35462

Debian : [DSA-2208-2] bind9: denial of service
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35463

Mandriva : [MDVSA-2011:056] openldap
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35461

Ubuntu Security Notice : [USN-1099-1] GDM vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35460

Cisco : Cisco Secure Access Control System Unauthorized Password Change Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35464

Cisco : Cisco Network Access Control Guest Server System Software Authentication Bypass Vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35465

Debian : [DSA 2206-1] mahara: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35451

Debian : [DSA-2207-1] tomcat5.5: Multiple vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35452

High-Tech Bridge SA : [HTB22905] Path disclosure in Wordpress
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35453

High-Tech Bridge SA : [HTB22904] Path disclosure in bbPress
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35454

High-Tech Bridge SA : [HTB22903] XSS in Spitfire CMS
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35455

Independant Researcher : "WESPA PHP Newsletter v3.0" Remote Admin Password Change With install path
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35456

Independant Researcher : "Simple PHP Newsletter" Remote Admin Password Change With install path
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35457

Mandriva : [MDVSA-2011:055] openldap
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35459

Ubuntu Security Notice : [USN-1094-1] Libvirt vulnerability
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35449

Ubuntu Security Notice : [USN-1095-1] Quagga vulnerabilities
http://www.criticalwatch.com/support/security-advisories.aspx?AID=35450

Websense warns about Lizamoon
http://isc.sans.edu/diary.html?storyid=10633

Cisco Secure Access Control System Password Change Vulnerability
http://secunia.com/advisories/43924/

SUSE update for libxml2
http://secunia.com/advisories/43936/

Cisco NAC Guest Server RADIUS Authentication Bypass Security Issue
http://secunia.com/advisories/43925/

Debian update for bind9
http://secunia.com/advisories/43767/

PHPBoost Backup Disclosure Weakness
http://secunia.com/advisories/43949/

Tracks "todos/tag/" Cross-Site Scripting Vulnerability
http://secunia.com/advisories/43909/

Linux Kernel OCFS2 Sparse Writes Information Disclosure Weakness
http://secunia.com/advisories/43966/

Drupal Translation Management Module Multiple Vulnerabilities
http://secunia.com/advisories/43950/

SUSE update for java-1_5_0-ibm
http://secunia.com/advisories/43957/

SUSE update for fuse
http://secunia.com/advisories/43958/

Innominate mGuard Multiple Vulnerabilities
http://secunia.com/advisories/43946/

Ubuntu update for gdm
http://secunia.com/advisories/43918/

EMC Data Protection Advisor Collector arbitrary code execution
http://securityreason.com/securityalert/8169

Andy's PHP Knowledgebase 0.95.2 (viewusers.php) SQL Injection
http://securityreason.com/securityalert/8168

HP Diagnostics, Remote Cross Site Scripting (XSS)
http://securityreason.com/securityalert/8167

Symantec LiveUpdate Administrator CSRF vulnerability
http://securityreason.com/securityalert/8166

IBM AIX LDAP Bug Lets Remote Users Bypass Authentication
http://www.securitytracker.com/id/1025273

Andy PHP Knowledgebase "pdfa" Parameter SQL Injection Vulnerability
http://www.vupen.com/english/advisories/2011/0823

jHTTPd Web Server HTTP Request Remote Directory Traversal Vulnerability
http://www.vupen.com/english/advisories/2011/0822

Cisco Secure Access Control System Unauthorized Password Change
http://www.vupen.com/english/advisories/2011/0821

Cisco Network Access Control Guest Server Authentication Bypass
http://www.vupen.com/english/advisories/2011/0820

Pure-FTPd STARTTLS Plaintext Command Injection Vulnerability
http://www.vupen.com/english/advisories/2011/0819

Mandriva Security Update Fixes OpenLDAP Unauthorized Access and DoS
http://www.vupen.com/english/advisories/2011/0818

Debian Security Update Fixes BIND Denial of Service Vulnerability
http://www.vupen.com/english/advisories/2011/0817

libxml2 'XPATH' Expressions Memory Corruption Vulnerability
http://www.securityfocus.com/bid/45617

Apache MPM-ITK Module Security Weakness
http://www.securityfocus.com/bid/46953

Mono 'loader.c' Library Loading Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/44810

Mono/Moonlight Generic Type Argument Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/45051

Multiple Vendors STARTTLS Implementation Plaintext Arbitrary Command Injection Vulnerability
http://www.securityfocus.com/bid/46767

Asterisk Manager Interface Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/46897

Asterisk TCP/TLS Server NULL Pointer Dereference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/46898

Pligg CMS Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/46998

Quagga BGP Daemon Null Pointer Deference Denial Of Service Vulnerability
http://www.securityfocus.com/bid/46942

Quagga BGP Daemon 'AS_PATHLIMIT' Denial Of Service Vulnerability
http://www.securityfocus.com/bid/46943

OpenLDAP Multiple Security Bypass Vulnerabilities
http://www.securityfocus.com/bid/46363

OpenLDAP 'modrdn' NULL OldDN Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/46831

Linux Kernel Econet Protocol Multiple Local Vulnerabilities
http://www.securityfocus.com/bid/45072

Linux Kernel Ptrace (CVE-2010-3301) Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/43355

Linux Kernel CVE-2010-2240 Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/42505

Linux Kernel Local Address Limit Override Security Weakness
http://www.securityfocus.com/bid/45159

bzip2 'BZ2_decompress' Function Integer Overflow Vulnerability
http://www.securityfocus.com/bid/43331

0 件のコメント:

コメントを投稿