2011年10月19日水曜日

19日 水曜日、先勝


RHSA-2011:1379-1: Moderate: krb5 security update
http://rhn.redhat.com/errata/RHSA-2011-1379.html





+ J2SE JDK/JRE 1.6.0_29 released
http://www.oracle.com/technetwork/java/javase/6u29-relnotes-507960.html

+ Oracle Critical Patch Update Advisory - October 2011
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html

+ Oracle Java SE Critical Patch Update Advisory - October 2011
http://www.oracle.com/technetwork/topics/security/javacpuoct2011-443431.html

+ Critical: java-1.6.0-openjdk security update
http://rhn.redhat.com/errata/RHSA-2011-1380.html

- SA46468: HP Data Protector Multiple Unspecified Vulnerabilities
http://secunia.com/advisories/46468/

- PHP Prior to 5.3.7 Multiple NULL Pointer Dereference Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/49249

- PHP CVE-2011-2202 Security Bypass Vulnerability
http://www.securityfocus.com/bid/48259

- PHP 'socket_connect()' Function Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/47950

BIND 9.9.0a3 released
https://www.isc.org/software/bind/990a3

UPDATE: Cisco IOS Software Data-Link Switching Vulnerability
http://www.cisco.com/warp/public/707/cisco-sa-20110928-dlsw.shtml

UPDATE: Cisco IOS Software IP Service Level Agreement Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20110928-ipsla

ウイルスバスター for Mac プログラムアップデートのお知らせ
http://www.trendmicro.co.jp/support/news.asp?id=1634

[ MDVSA-2011:156 ] tomcat5
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00113.html

Dolphin <= 7.0.7 (member_menu_queries.php) Remote PHP Code Injection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00112.html

Site@School 2.4.10 SQL Injection & XSS vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00111.html

[PT-2011-14] SQL injection vulnerability in BoonEx Dolphin
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2011-10/msg00110.html

「セサミストリート」でアダルト動画!?YouTubeで乗っ取り発覚
不適切な動画が20分間掲載、プロフィルも改ざん
http://itpro.nikkeibp.co.jp/article/NEWS/20111019/371021/?ST=security

Critical Control 12 : Malware Defense
http://isc.sans.edu/diary.html?storyid=11830

ClamAV Recursion Level Handling Vulnerability
http://secunia.com/advisories/46455/

TYPO3 phpMyAdmin Extension Cross-Site Scripting Vulnerability
http://secunia.com/advisories/46463/

Joomla! Information Disclosure Vulnerabilities
http://secunia.com/advisories/46421/

SUSE update for cups
http://secunia.com/advisories/46409/

SUSE update for cups
http://secunia.com/advisories/46448/

SUSE update for libopenssl
http://secunia.com/advisories/46452/

SUSE update for libopenssl
http://secunia.com/advisories/46453/

GNUBoard URL SQL Injection Vulnerability
http://secunia.com/advisories/46443/

SUSE update for php5
http://secunia.com/advisories/46425/

SUSE update for kdelibs4
http://secunia.com/advisories/46439/

SUSE update for wireshark
http://secunia.com/advisories/46449/

SUSE update for libreoffice
http://secunia.com/advisories/46450/

SUSE update for popt
http://secunia.com/advisories/46451/

SUSE update for tomcat6
http://secunia.com/advisories/46454/

Microsoft Office Publisher Document Insertion Buffer Overflow Vulnerability
http://secunia.com/advisories/46438/

Ubuntu update for php5
http://secunia.com/advisories/46374/

Piwik Multiple Unspecified Vulnerabilities
http://secunia.com/advisories/46461/

Asterisk SIP Channel Driver Uninitialised Variables Denial of Service Vulnerability
http://secunia.com/advisories/46420/

WordPress WP Photo Album Plus Plugin "wppa-album" SQL Injection Vulnerability
http://secunia.com/advisories/46467/

HP Data Protector Multiple Unspecified Vulnerabilities
http://secunia.com/advisories/46468/

Oracle Fusion Middleware Bugs Let Remote Users Partially Access and Modify Data and Remote and Local Users Partially Deny Service
http://www.securitytracker.com/id/1026206

Piwik Data Processing Multiple Unspecified Remote Vulnerabilities
http://www.vupen.com/english/ADV-2011-2204.php

Microsoft Publisher "Pubconv.dll" Document Insertion Memory Corruption
http://www.vupen.com/english/ADV-2011-2203.php

HP Data Protector Notebook Extension Multiple Remote Code Execution
http://www.vupen.com/english/ADV-2011-2202.php

phpMyAdmin "phpmyadmin.css.php" Remote Path Disclosure Vulnerability
http://www.vupen.com/english/ADV-2011-2201.php

phpMyAdmin Setup Interface Data Processing Cross Site Scripting
http://www.vupen.com/english/ADV-2011-2200.php

Check Point UTM-1 Edge and Safe@Office WebUI Multiple Vulnerabilities
http://www.vupen.com/english/ADV-2011-2199.php

Microsys Promotic Directory Traversal and Buffer Overflow Vulnerabilities
http://www.vupen.com/english/ADV-2011-2198.php

OPC Systems .NET Remote Procedural Call Denial of Service Vulnerability
http://www.vupen.com/english/ADV-2011-2197.php

Honeywell TEMA Remote Installer ActiveX Code Execution Vulnerability
http://www.vupen.com/english/ADV-2011-2196.php

atvise webMI HTTP Requests Processing Multiple Remote Vulnerabilities
http://www.vupen.com/english/ADV-2011-2195.php

IRAI AUTOMGEN Project File Processing Buffer Overflow Vulnerability
http://www.vupen.com/english/ADV-2011-2194.php

Asterisk SIP Channel Driver Unitialized Variable Denial of Service Vulnerability
http://www.vupen.com/english/ADV-2011-2193.php

Joomla! Data Processing Multiple Information Disclosure Vulnerabilities
http://www.vupen.com/english/ADV-2011-2192.php

Drupal Cumulus Module Data Processing Cross Site Scripting Vulnerability
http://www.vupen.com/english/ADV-2011-2191.php

Drupal Certificate Login Module Remote SQL Injection Vulnerability
http://www.vupen.com/english/ADV-2011-2190.php

OneOrZero AIMS Authentication Bypass and SQL Injection Vulnerabilities
http://www.vupen.com/english/ADV-2011-2189.php

D-Link DIR-685 Xtreme N Storage Router WPA/WPA2 Encryption Issue
http://www.vupen.com/english/ADV-2011-2188.php

GoAhead Webserver Multiple Parameter Cross Site Scripting Vulnerabilities
http://www.vupen.com/english/ADV-2011-2187.php

REMOTE: Apple Safari Webkit libxslt Arbitrary File Creation
http://www.exploit-db.com/exploits/17993

Oracle Sun Products Suite CVE-2011-2292 Local Solaris Vulnerability
http://www.securityfocus.com/bid/50268

Oracle PeopleSoft CVE-2011-3529 Remote PeopleSoft Enterprise HRMS Vulnerability
http://www.securityfocus.com/bid/50267

Oracle Sun Products Suite CVE-2011-2286 Remote Vulnerability
http://www.securityfocus.com/bid/50265

Oracle Sun Products Suite CVE-2011-3507 Remote Oracle Communications Unified Vulnerability
http://www.securityfocus.com/bid/50264

Oracle PeopleSoft Products CVE-2011-2315 Remote PeopleSoft Enterprise PeopleTools Vulnerability
http://www.securityfocus.com/bid/50263

Oracle Sun Products Suite CVE-2011-3536 Local Vulnerability
http://www.securityfocus.com/bid/50262

Oracle Sun Product Suite CVE-2011-3537 Local Vulnerability
http://www.securityfocus.com/bid/50259

Oracle Sun Products Suite CVE-2011-3506 Remote Oracle OpenSSO Vulnerability
http://www.securityfocus.com/bid/50252

Oracle PeopleSoft Products CVE-2011-3533 Remote PeopleSoft Enterprise HRMS Vulnerability
http://www.securityfocus.com/bid/50249

Oracle Sun Solaris CVE-2011-3542 Local Vulnerability
http://www.securityfocus.com/bid/50244

Oracle PeopleSoft Products CVE-2011-3527 Remote PeopleSoft Enterprise HRMS Vulnerability
http://www.securityfocus.com/bid/50241

Oracle E-Business Suite CVE-2011-3519 Remote Oracle Applications Framework Vulnerability
http://www.securityfocus.com/bid/50233

Oracle Supply Chain Products Suite CVE-2011-3532 Remote Oracle Agile Product Supplier Collaboration
http://www.securityfocus.com/bid/50227

Oracle E-Business Suite CVE-2011-2303 Remote Oracle Application Object Library Vulnerability
http://www.securityfocus.com/bid/50225

Oracle E-Business Suite CVE-2011-2302 Remote Oracle Application Object Library Vulnerability
http://www.securityfocus.com/bid/50221

Oracle Database Server CVE-2011-3511 Remote Database Vault Vulnerability
http://www.securityfocus.com/bid/50219

Oracle Fusion Middleware CVE-2011-3523 Remote Oracle Web Services Manager Vulnerability
http://www.securityfocus.com/bid/50209

Oracle Fusion Middleware CVE-2011-2319 Remote Oracle WebLogic Server Vulnerability
http://www.securityfocus.com/bid/50206

Oracle Fusion Middleware CVE-2011-2255 Remote Oracle WebLogic Portal Vulnerability
http://www.securityfocus.com/bid/50205

RETIRED: Oracle October 2011 Critical Patch Update Multiple Vulnerabilities
http://www.securityfocus.com/bid/50119

Apache HTTP Server CVE-2011-3192 Denial Of Service Vulnerability
http://www.securityfocus.com/bid/49303

Symantec IM Manager Code Injection Vulnerability
http://www.securityfocus.com/bid/49742

Apple Mac OS X FlashPix Files CVE-2011-3222 Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/50100

Oracle Solaris CVE-2011-2312 'ZFS' Sub Component Local Vulnerability
http://www.securityfocus.com/bid/50269

X.Org X11 Local Privilege Escalation Vulnerability and Memory Leak Vulnerability
http://www.securityfocus.com/bid/50002

RETIRED: Oracle Java SE Critical Patch Update October 2011 Advance Notification
http://www.securityfocus.com/bid/50118

SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability
http://www.securityfocus.com/bid/49778

Oracle Linux CVE-2011-2306 Oracle Validation Security Vulnerability
http://www.securityfocus.com/bid/50194

PHP Versions Prior to 5.3.7 Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/49241

Multiple Cisco Products CVE-2011-2738 Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/49627

Apache Tomcat 'sendfile' Request Attributes Information Disclosure Vulnerability
http://www.securityfocus.com/bid/48667

Apache Tomcat HTTP DIGEST Authentication CVE-2011-1184 Multiple Security Weaknesses
http://www.securityfocus.com/bid/49762

Apache Tomcat 'MemoryUserDatabase' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/48456

Apache Tomcat AJP Protocol Security Bypass Vulnerability
http://www.securityfocus.com/bid/49353

Quagga Multiple Remote Security Vulnerabilities
http://www.securityfocus.com/bid/49784

ClamAV Recursion Level Handling Denial of Service Vulnerability
http://www.securityfocus.com/bid/50183

rpm-python RPM File Handling Remote Memory Corruption Vulnerability
http://www.securityfocus.com/bid/49799

Joomla! 'com_jfuploader' Arbitrary File Upload Vulnerability
http://www.securityfocus.com/bid/44559

phpMyAdmin Setup Interface Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/50175

PHP 'ZipArchive::addGlob' and 'ZipArchive::addPattern' Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/49252

PHP Prior to 5.3.7 Multiple NULL Pointer Dereference Denial Of Service Vulnerabilities
http://www.securityfocus.com/bid/49249

PHP Versions Prior to 5.3.3/5.2.14 Multiple Vulnerabilities
http://www.securityfocus.com/bid/41991

PHP CVE-2011-2202 Security Bypass Vulnerability
http://www.securityfocus.com/bid/48259

PHP 'socket_connect()' Function Stack Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/47950

WebKit 'libxslt' Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/48840

Avaya Identity Engines Ignition Server Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/50271

Oracle Solaris CVE-2011-3539 Local Solaris Vulnerability
http://www.securityfocus.com/bid/50270

Oracle Solaris CVE-2011-2311 ZFS Component Local Vulnerability
http://www.securityfocus.com/bid/50266

Oracle Sun Products CVE-2011-3522 Local SPARC T3, Netra SPARC T3, Sun Fire, Sun Blade Vulnerability
http://www.securityfocus.com/bid/50261

Oracle Siebel CRM CVE-2011-2316 Siebel Apps - Marketing Remote Vulnerability
http://www.securityfocus.com/bid/50260

Oracle Sun Products CVE-2011-2327 Local Oracle Communications Unified Vulnerability
http://www.securityfocus.com/bid/50258

Oracle Solaris CVE-2011-2304 Remote Vulnerability
http://www.securityfocus.com/bid/50257

Oracle Siebel CRM CVE-2011-3518 Siebel Core - UIF Client Remote Vulnerability
http://www.securityfocus.com/bid/50256

Oracle Sun Solaris CVE-2011-3535 Remote Vulnerability
http://www.securityfocus.com/bid/50255

Oracle Solaris CVE-2011-2313 Local Solaris Vulnerability
http://www.securityfocus.com/bid/50254

Oracle PeopleSoft Products CVE-2011-3528 Remote PeopleSoft Enterprise HRMS Vulnerability
http://www.securityfocus.com/bid/50253

Oracle Sun Solaris CVE-2011-3534 Remote Vulnerability
http://www.securityfocus.com/bid/50251

Oracle Java SE CVE-2011-3561 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50250

Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50248

Oracle PeopleSoft CVE-2011-3520 PeopleSoft Enterprise PeopleTools Remote Vulnerability
http://www.securityfocus.com/bid/50247

Oracle Java SE CVE-2011-3553 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50246

Oracle Industry Applications CVE-2011-3538 Remote Sun Ray Vulnerability
http://www.securityfocus.com/bid/50245

Oracle Java SE CVE-2011-3547 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50243

Oracle Java SE CVE-2011-3558 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50242

Oracle Industry Applications CVE-2011-2309 Remote Health Sciences - Oracle Clinical, Remote Data Cap
http://www.securityfocus.com/bid/50240

Oracle Java SE CVE-2011-3546 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50239

Oracle PeopleSoft CVE-2011-3530 PeopleSoft Enterprise HRMS Remote Vulnerability
http://www.securityfocus.com/bid/50238

Oracle Java SE CVE-2011-3555 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50237

Oracle Java SE CVE-2011-3560 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50236

Oracle Sun Solaris CVE-2011-3515 Local Vulnerability
http://www.securityfocus.com/bid/50235

Oracle Java SE CVE-2011-3557 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50234

Oracle E-Business Suite CVE-2011-2308 Oracle Application Object Library Remote Vulnerability
http://www.securityfocus.com/bid/50232

Oracle Java SE CVE-2011-3556 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50231

Oracle Siebel CRM CVE-2011-3526 Remote Siebel Core - UIF Server Vulnerability
http://www.securityfocus.com/bid/50230

Oracle Java SE CVE-2011-3516 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50229

Oracle Waveset CVE-2011-2310 Remote Vulnerability
http://www.securityfocus.com/bid/50228

Oracle Java SE CVE-2011-3550 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50226

Oracle Java SE CVE-2011-3551 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50224

Oracle Java SE CVE-2011-3549 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50223

Oracle Database CVE-2011-2322 Remote Database Vault Vulnerability
http://www.securityfocus.com/bid/50222

Oracle Java SE CVE-2011-3545 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50220

Oracle Java SE CVE-2011-3544 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50218

Oracle E-Business Suite CVE-2011-3513 Oracle Application Object Library Remote Vulnerability
http://www.securityfocus.com/bid/50217

Oracle Java SE CVE-2011-3554 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50216

Oracle Java SE and Java for Business CVE-2011-3521 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50215

Oracle Sun Solaris CVE-2011-3543 Remote Vulnerability
http://www.securityfocus.com/bid/50214

Oracle Fusion Middleware CVE-2011-3510 Remote Oracle Business Intelligence Enterprise Edition Vulner
http://www.securityfocus.com/bid/50213

Oracle Fusion Middleware CVE-2011-2237 Remote Oracle Web Services Manager Vulnerability
http://www.securityfocus.com/bid/50212

Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50211

Oracle Fusion Middleware CVE-2011-2318 Oracle WebLogic Server Local Vulnerability
http://www.securityfocus.com/bid/50210

Oracle OpenSSO CVE-2011-3517 Remote Vulnerability
http://www.securityfocus.com/bid/50208

Oracle Fusion Middleware CVE-2011-3541 Oracle Outside In Technology Local Vulnerability
http://www.securityfocus.com/bid/50207

Oracle Database CVE-2011-3512 Remote Core RDBMS Vulnerability
http://www.securityfocus.com/bid/50203

Oracle Fusion Middleware CVE-2011-2314 Oracle Containers for J2EE Remote Vulnerability
http://www.securityfocus.com/bid/50202

Oracle Sun Solaris CVE-2011-3508 Remote Vulnerability
http://www.securityfocus.com/bid/50201

Oracle Database CVE-2011-2301 Oracle Text Local Vulnerability
http://www.securityfocus.com/bid/50199

Oracle Fusion Middleware CVE-2011-2320 Remote WebLogic Server Vulnerability
http://www.securityfocus.com/bid/50198

Oracle Database CVE-2011-3525 Remote Application Express Vulnerability
http://www.securityfocus.com/bid/50197

X.Org X11 File Read Permission Information Disclosure Vulnerability
http://www.securityfocus.com/bid/50196

Site@School 'index.php' Cross Site Scripting and SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/50195

X.Org X11 File Enumeration Information Disclosure Vulnerability
http://www.securityfocus.com/bid/50193

PAM 'update-motd' Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/50192

Joomla NoNumber! Extension Manager Plugin Local File Include and PHP code Injection Vulnerabilities
http://www.securityfocus.com/bid/50191

TYPO3 T3blog Extension Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/50190

Check Point UTM-1 Edge and Safe Multiple Unspecified Security Vulnerabilities
http://www.securityfocus.com/bid/50189

Joomla! Unspecified Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/50188

Boonex Dolphin 'member_menu_queries.php' PHP Code Injection Vulnerability
http://www.securityfocus.com/bid/50185

Piwik Prior to 1.6 Multiple Unspecified Security Vulnerabilities
http://www.securityfocus.com/bid/50182

HP Data Protector Unspecified Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/50181

0 件のコメント:

コメントを投稿