2012年3月1日木曜日

1日 木曜日、仏滅


+ BIND 9.9.0 is now available
https://www.isc.org/software/bind
https://kb.isc.org/article/AA-00631

+ OpenLDAP 2.4.30 released
http://www.openldap.org/software/release/announce.html
http://www.openldap.org/software/release/changes.html


++ Linux Kernel 3.0.23, 3.2.9 released
http://www.kernel.org/pub/linux/kernel/v3.0/ChangeLog-3.0.23
http://www.kernel.org/pub/linux/kernel/v3.0/ChangeLog-3.2.9


? Linux Kernel 'apparmor_setprocattr()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/50172

- Linux Kernel PTE Pages OOM Score Denial of Service Vulnerability
http://www.securityfocus.com/bid/48477

- Linux Kernel '/mm/oom_kill.c' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/50459

- Linux Kernel 'icmp_send()' NULL Pointer Dereference Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/47872

- Linux Kernel TOMOYO LSM CVE-2011-2518 Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/52202

nginx-1.1.16 development version released
http://nginx.org/en/download.html

[ANNOUNCE] Apache Whirr 0.7.1 released
http://www.apache.org/dyn/closer.cgi/whirr/
https://issues.apache.org/jira/browse/WHIRR/fixforversion/12319942

[ANNOUNCE] Apache Directory LDAP API 1.0.0-M11 released
http://directory.apache.org/api/

[ANNOUNCE] ApacheDS 2.0.0-M6 released
http://directory.apache.org/apacheds/2.0/downloads.html

[ANNOUNCE] Apache Directory Studio 2.0 M3 released
http://directory.apache.org/studio/update/2.x/

Cisco Cius Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cius

Cisco Unified Communications Manager Skinny Client Control Protocol Vulnerabilities
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cucm

Multiple Vulnerabilities in Cisco Unity Connection
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-cuc

Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-wlc

Cisco TelePresence Video Communication Server Session Initiation Protocol Denial of Service Vulnerabilities
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120229-vcs

Cisco Small Business SRP 500 Series Multiple Vulnerabilities
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120223-srp500

賞金総額100万ドル、Chromeの脆弱性発見コンテストを開催
重大な脆弱性報告で賞金最高6万ドル
http://itpro.nikkeibp.co.jp/article/NEWS/20120301/383941/?ST=security

[SECURITY] [DSA 2422-1] file security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00191.html

[SECURITY] [DSA 2421-1] moodle security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00190.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Wireless LAN Controllers
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00187.html

Cisco Security Advisory: Cisco Unified Communications Manager Skinny Client Control Protocol Vulnera
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00186.html

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unity Connection
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00188.html

Cisco Security Advisory: Cisco TelePresence Video Communication Server Session Initiation Protocol
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00189.html

[ MDVSA-2012:027 ] postgresql8.3
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00184.html

Cisco Security Advisory: Cisco Cius Denial of Service Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00185.html

[ MDVSA-2012:026 ] postgresql
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00183.html

Multiple XSS in Dotclear
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-02/msg00182.html

COX Network Outage
http://isc.sans.edu/diary.html?storyid=12682

ISC Feature of the Week: 404Project Reports
http://isc.sans.edu/diary.html?storyid=12685

Cisco Security Advisories - 29FEB2011
http://isc.sans.edu/diary.html?storyid=12688

Cisco TelePresence Video Communication Server Bugs Let Remote Users Deny Service
http://www.securitytracker.com/id/1026751

Cisco Unity Connection Flaws Let Remote Users Deny Service and Remote Authenticated Users Gain Elevated Privileges
http://www.securitytracker.com/id/1026750

Cisco Unified Communications Manager Lets Remote Users Deny Service and Inject SQL Commands
http://www.securitytracker.com/id/1026749

Cisco Cius Unspecified Flaw Lets Remote Users Deny Service
http://www.securitytracker.com/id/1026748

Cisco Wireless LAN Controller Bugs Let Remote Users View/Modify the Configuration and Cause Denial of Service Conditions
http://www.securitytracker.com/id/1026747

LimeSurvey Script Insertion and SQL Injection Vulnerabilities
http://secunia.com/advisories/48184/

ImgPals Photo Host "u" SQL Injection Vulnerability
http://secunia.com/advisories/48182/

Hitachi JP1/Cm2/Network Node Manager Multiple Unspecified Vulnerabilities
http://secunia.com/advisories/48201/

Sysax Multi Server Two Buffer Overflow Vulnerabilities
http://secunia.com/advisories/48188/

Kongreg8 Script Insertion and SQL Injection Vulnerabilities
http://secunia.com/advisories/48195/

Ubuntu update for kernel
http://secunia.com/advisories/47681/

Ubuntu update for kernel
http://secunia.com/advisories/48189/

Anchor CMS "real_name" Script Insertion Vulnerability
http://secunia.com/advisories/48191/

Webfolio CMS Cross-Site Request Forgery Vulnerability
http://secunia.com/advisories/48190/

Debian update for openjdk-6
http://secunia.com/advisories/48181/

IBM Personal Communications WS File Processing Buffer Overflow Vulnerability
http://secunia.com/advisories/48185/

SUSE update for libpng
http://secunia.com/advisories/48205/

SUSE update for libpng12
http://secunia.com/advisories/48206/

SUSE update for csound
http://secunia.com/advisories/48207/

Ubuntu update for postgresql
http://secunia.com/advisories/48198/

REMOTE: Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability
http://www.exploit-db.com/exploits/18543

REMOTE: Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability
http://www.exploit-db.com/exploits/18542

REMOTE: ASUS Net4Switch ipswcom.dll ActiveX Stack Buffer Overflow
http://www.exploit-db.com/exploits/18538

REMOTE: IBM Personal Communications I-Series Access WorkStation 5.9 Profile
http://www.exploit-db.com/exploits/18539

DoS/PoC: Netmechanica NetDecision HTTP Server Denial Of Service Vulnerability
http://www.exploit-db.com/exploits/18541

Stunnel Unspecified Memory Corruption Vulnerability
http://www.securityfocus.com/bid/49254

Samba 'AndX' Request CVE-2012-0870 Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/52103

Oracle Java SE CVE-2011-3547 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50243

Oracle Java SE CVE-2011-3560 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50236

Oracle Java SE CVE-2011-3556 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50231

Oracle Java SE CVE-2011-3552 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50248

Oracle Java SE CVE-2011-3548 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50211

Oracle Java SE CVE-2011-3549 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50223

Oracle Java SE CVE-2011-3557 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50234

Oracle Java SE CVE-2011-3545 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/50220

SSL/TLS Protocol Initialization Vector Implementation Information Disclosure Vulnerability
http://www.securityfocus.com/bid/49778

PostgreSQL Multiple Security Vulnerabilities
http://www.securityfocus.com/bid/52188

IBM Personal Communications '.ws' File 'pcspref.dll' Remote Stak Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/52200

ASUS Net4Switch 'ipswcom.dll' ActiveX Remote Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/52110

libpng 'png_decompress_chunk()' Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/52049

Linux Kernel 'net/ipv4/igmp.c' Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/51343

Linux Kernel PTE Pages OOM Score Denial of Service Vulnerability
http://www.securityfocus.com/bid/48477

Linux Kernel '/mm/oom_kill.c' Integer Overflow Vulnerability
http://www.securityfocus.com/bid/50459

Linux Kernel 'icmp_send()' NULL Pointer Dereference Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/47872

Linux Kernel 'net/bridge/br_multicast.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/46433

Linux Kernel 'apparmor_setprocattr()' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/50172

Traidnt Topics Viewer 'main.php' Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/52224

Multiple NetEase Applications Multiple Unspecified Vulnerabilities
http://www.securityfocus.com/bid/52223

Youdao Dictionary For Android Unspecified Security Vulnerability
http://www.securityfocus.com/bid/52222

Dotclear Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/52221

Cisco Wireless LAN Controller CVE-2012-0370 'WebAuth' Denial of Service Vulnerability
http://www.securityfocus.com/bid/52220

Cisco Wireless LAN Controller CVE-2012-0369 IPv6 Packets Handling Denial of Service Vulnerability
http://www.securityfocus.com/bid/52219

Webfolio CMS Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/52218

Cisco Unity Connection TCP Segment Denial of Service Vulnerability
http://www.securityfocus.com/bid/52217

Cisco Wireless LAN Controller CVE-2012-0369 IPv6 Packets Handling Denial of Service Vulnerability
http://www.securityfocus.com/bid/52219

Webfolio CMS Cross Site Request Forgery Vulnerability
http://www.securityfocus.com/bid/52218

Cisco Unity Connection TCP Segment Denial of Service Vulnerability
http://www.securityfocus.com/bid/52217

Cisco Unity Connection CVE-2012-0366 Remote Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/52216

Cisco Wireless LAN Controller CVE-2012-0371 Unauthorized Access Security Bypass Vulnerability
http://www.securityfocus.com/bid/52215

Cisco TelePresence Video Communication Server Session Denial of Service Vulnerabilities
http://www.securityfocus.com/bid/52214

Cisco Unified Communications Manager SCCP (CVE-2011-4487) SQL Injection Vulnerability
http://www.securityfocus.com/bid/52213

Cisco Wireless LAN Controller CVE-2012-0368 HTTP Request Denial of Service Vulnerability
http://www.securityfocus.com/bid/52212

Cisco Unified Communications Manager SCCP (CVE-2011-4486) Denial of Service Vulnerability
http://www.securityfocus.com/bid/52211

Cisco Cius Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/52210

Yealink VOIP Phone Multiple HTML Injection Vulnerabilities
http://www.securityfocus.com/bid/52209

NetDecision HTTP Server Long HTTP Request Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/52208

Anchor CMS 'real_name' Parameter HTML Injection Vulnerability
http://www.securityfocus.com/bid/52207

GNOME NetworkManager Local Arbitrary File Access Vulnerability
http://www.securityfocus.com/bid/52206

Hitachi JP1/Cm2/Network Node Manager i Multiple Unspecified Remote Code Execution Vulnerabilities
http://www.securityfocus.com/bid/52205

Linux Kernel TOMOYO LSM CVE-2011-2518 Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/52202

0 件のコメント:

コメントを投稿