2012年7月5日木曜日

5日 水曜日、友引

+ Linux kernel 3.2.22 released
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.22
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2669

+ libTIFF TIFF Image CVE-2012-2088 Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/54270
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2088

+ Linux Kernel 'fs/eventpoll.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/54283

コンピュータウイルス・不正アクセスの届出状況[6月分および上半期]について
http://www.ipa.go.jp/security/txt/2012/07outline.html

[対策2]これが標的型攻撃メール、「だまし」のテクニックを駆使
http://itpro.nikkeibp.co.jp/article/COLUMN/20120617/403226/?ST=security

JVNDB-2012-002977 Expat の XML パーサ (xmlparse.c) におけるサービス運用妨害 (CPU 資源の消費) の脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002977.html

JVNDB-2011-005054 X.Org xserver の os/utils.c における任意のファイルのアクセス権を 444 に変更される脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-005054.html

JVNDB-2011-005053 X.Org xserver の os/utils.c における情報漏えいの脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-005053.html

JVNDB-2012-002976 bcfg2 の Trigger プラグインにおける任意のコマンドを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002976.html

JVNDB-2012-002975 389 Directory Server におけるパスワードを読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002975.html

JVNDB-2012-002974 389 Directory Server におけるパスワードを読まれる脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002974.html

JVNDB-2012-002973 Linux Kernel におけるサービス運用妨害 (システムクラッシュ) の脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002973.html

JVNDB-2012-002972 Linux Kernel の fs/ext4/super.c におけるファイルシステムグループデータの不整合を誘発される脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002972.html

JVNDB-2012-002971 Automatic Bug Reporting Tool (ABRT) の C handler プラグインにおける重要な情報を取得される脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002971.html

JVNDB-2012-002970 389 Directory Server の servers/plugins/acl/acllas.c におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002970.html

JVNDB-2012-002969 Linux Kernel の KVM の実装におけるサービス運用妨害 (ゲスト OS クラッシュ) の脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002969.html

JVNDB-2012-002968 Linux Kernel における制限を回避される脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002968.html

JVNDB-2012-002967 Linux Kernel の fs/jbd2/transaction.c におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002967.html

JVNDB-2012-002966 BusyBox の DHCP クライアント (udhcpc) における任意のコマンドを実行される脆弱性
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-002966.html

JVNDB-2011-005052 gdk-pixbuf の gdk-pixbuf/io-gif.c におけるサービス運用妨害 (メモリ消費) の脆弱性
http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-005052.html

Freeside SelfService CGI|API 2.3.3 - Multiple Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00035.html

Classified Ads Script PHP v1.1 - SQL Injection Vulnerabilities
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00034.html

GuestBook Scripts PHP v1.5 - Multiple Web Vulnerabilites
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00033.html

Event Script PHP v1.1 CMS - Multiple Web Vulnerabilites
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00032.html

.Net Framework Tilde Character DoS - Sorry, exploit-db link corrected
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00031.html

.Net Framework Tilde Character DoS
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00030.html

IIS Short File/Folder Name Disclosure by using tilde ~ character
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00029.html

Blind SQL Injection in Webmatic
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00025.html

[SECURITY] [DSA 2507-1] openjdk-6 security update
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00028.html

Wordpress (editormonkey) Arbitrary File Upload Vulnerability
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00027.html

[CVE-2012-0911] Tiki Wiki CMS Groupware <= 8.3 "unserialize()" PHP Code Execution
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00019.html

[ MDVSA-2012:101 ] libtiff
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00018.html

Just4meeting 3.0 - Lisbon/Portugal - 6 to 8 - July
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00026.html

Vulnerable Microsoft VC++ 2005 runtime libraries in "Microsoft Live Meeting 2007 Client" installed i
http://www.derkeiler.com/Mailing-Lists/securityfocus/bugtraq/2012-07/msg00024.html

RSA Access Manager Session Replay Flaw Lets Remote Users Access the System
http://www.securitytracker.com/id/1027220

Webify Link Directory / SQL Injection
http://cxsecurity.com/issue/WLB-2012070030

Microsoft IIS 6, 7.5 FTP Server Remote Denial Of Service
http://cxsecurity.com/issue/WLB-2012070029

Alienvault OSSIM Open Source SIEM 3.1 Multiple security vulnerabilities
http://cxsecurity.com/issue/WLB-2012070028

Microsoft Live Meeting 2007 Client Libraries
http://cxsecurity.com/issue/WLB-2012070027

phpMyBackupPro 2.2 Local File Inclusion
http://cxsecurity.com/issue/WLB-2012070026

CLscript Classified Script 3.0 SQL Injection
http://cxsecurity.com/issue/WLB-2012070025

gp Easy CMS Minishop 1.5 Cross Site Scripting
http://cxsecurity.com/issue/WLB-2012070024

Cyberoam DPI Device Shared SSL CA
http://cxsecurity.com/issue/WLB-2012070023

phpMyVisites SQL Injection
http://cxsecurity.com/issue/WLB-2012070022

TYPO3 swfupload Cross-Site Scripting Vulnerability
http://secunia.com/advisories/49780/

SPIP "connect" PHP Injection Vulnerability
http://secunia.com/advisories/49764/

WebSphere Application Server Feature Pack for Web Services Security Bypass Vulnerability
http://secunia.com/advisories/49793/

Linux Kernel epoll Denial of Service Vulnerability
http://secunia.com/advisories/49737/

SUSE update for krb5
http://secunia.com/advisories/49766/

SUSE update for python-crypto
http://secunia.com/advisories/49768/

SUSE update for kvm
http://secunia.com/advisories/49769/

SUSE update for tiff
http://secunia.com/advisories/49770/

SUSE update for java-1_6_0-openjdk
http://secunia.com/advisories/49772/

SUSE update for php5
http://secunia.com/advisories/49773/

Ubuntu update for nova
http://secunia.com/advisories/49802/

Linux Kernel UDF File System Denial of Service Vulnerabilities
http://secunia.com/advisories/49742/

SUSE update for opera
http://secunia.com/advisories/49803/

OpenStack Compute (Nova) Host File Injection and File Corruption Vulnerabilities
http://secunia.com/advisories/49763/

gpEasy CMS Minishop Plugin Multiple Script Insertion Vulnerabilities
http://secunia.com/advisories/49771/

WordPress Email Newsletter Plugin Unspecified Vulnerability
http://secunia.com/advisories/49758/

Oracle Java SE CVE-2012-1723 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53960

Oracle Java SE CVE-2012-1717 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53952

Oracle Java SE CVE-2012-1724 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53958

Oracle Java SE CVE-2012-1719 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53950

Oracle Java SE CVE-2012-1725 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53954

Oracle Java SE CVE-2012-1711 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53949

Oracle Java SE CVE-2012-1718 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53951

Oracle Java SE CVE-2012-1713 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53946

IBM WebSphere Application Server JAX-WS Unspecified Vulnerability
http://www.securityfocus.com/bid/50310

SWFUpload 'movieName' Parameter Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/54245

LibTIFF 'tiff2pdf' Utility Remote Integer Overflow Vulnerability
http://www.securityfocus.com/bid/54076

libTIFF TIFF Image CVE-2012-2088 Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/54270

OpenStack Nova CVE-2012-3361 Memory Corruption Vulnerability
http://www.securityfocus.com/bid/54278

OpenStack Nova CVE-2012-3360 Remote Code Injection Vulnerability
http://www.securityfocus.com/bid/54277

IBM Rational ClearQuest 'cqole.dll' ActiveX Control Heap Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/53170

Multiple AntiVirus Products CVE-2012-1458 CHM File Scan Evasion Vulnerability
http://www.securityfocus.com/bid/52611

Multiple AntiVirus Products CVE-2012-1459 TAR File Scan Evasion Vulnerability
http://www.securityfocus.com/bid/52623

Multiple AntiVirus Products CVE-2012-1457 TAR File Scan Evasion Vulnerability
http://www.securityfocus.com/bid/52610

Oracle Java SE CVE-2012-1716 Remote Java Runtime Environment Vulnerability
http://www.securityfocus.com/bid/53947

Boost 'ordered_malloc()' Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/54233

RSA Access Manager Server Session Replay Security Bypass Vulnerability
http://www.securityfocus.com/bid/54301

GuestBook Script PHP Multiple SQL Injection and Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/54300

Classified Ads Script PHP 'admin.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/54299

Tiki Wiki CMS Groupware 'unserialize()' Multiple PHP Code Execution Vulnerabilities
http://www.securityfocus.com/bid/54298

Event Script PHP 'eventscript.php' Multiple SQL Injection Vulnerabilities
http://www.securityfocus.com/bid/54296

Freeside Multiple Input Validation Vulnerabilities
http://www.securityfocus.com/bid/54295

SPIP 'connect' Parameter PHP Code Injection Vulnerability
http://www.securityfocus.com/bid/54292

Cyberoam DPI Security Bypass Vulnerability
http://www.securityfocus.com/bid/54291

Forum Oxalis 'id' Parameter SQL Injection Vulnerability
http://www.securityfocus.com/bid/54288

Webmatic 'Referer:' Field SQL Injection Vulnerability
http://www.securityfocus.com/bid/54287

WordPress Email Newsletter Unspecified Security Vulnerability
http://www.securityfocus.com/bid/54284

Linux Kernel 'fs/eventpoll.c' Local Denial of Service Vulnerability
http://www.securityfocus.com/bid/54283

1 件のコメント: