2014年3月14日金曜日

14日 金曜日、先負

+ RHSA-2014:0292 Important: 389-ds-base security update
http://rhn.redhat.com/errata/RHSA-2014-0292.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0132

+ RHSA-2014:0293 Important: udisks security update
http://rhn.redhat.com/errata/RHSA-2014-0293.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0004

+ APSB14-10 Security update available for Adobe Shockwave Player
http://helpx.adobe.com/security/products/shockwave/apsb14-10.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0505

+ UPDATE: Cisco Prime Infrastructure Command Execution Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140226-pi
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0679

+ HPSBMU02975 rev.1 - HP Smart Update Manager for Linux, Elevation of Privileges
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04000397-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6208

+ HPSBMU02967 rev.1 - HP Unified Functional Testing Running on Windows, Remote Execution of Arbitrary Code
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04122007-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6210

+ RHSA-2014:0285 Important: kernel security, bug fix, and enhancement update
http://rhn.redhat.com/errata/RHSA-2014-0285.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2929
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4483
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4554
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6381
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6383
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6885
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7263

+ Sudo 1.8.10p1 released
http://www.sudo.ws/sudo/stable.html#1.8.10p1

+ Cisco Cloud Portal Discloses Cryptographic Material That Lets Remote Users Decrypt Data
http://www.securitytracker.com/id/1029915
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0694

+ Google Chrome Bugs Let Remote Users Execute Arbitrary Code and Conduct Cross-Site Scripting Attacks
http://www.securitytracker.com/id/1029914
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1700
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1701
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1702
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1703
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1704

+ Squid Flaw in SSL-Bump Lets Remote Users Deny Service
http://www.securitytracker.com/id/1029908
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0128

+ Wireshark NFS/M3UA/RLC Dissector Bugs Let Remote Users Deny Service and MPEG Buffer Overflow Lets Remote Users Execute Arbitrary Code
http://www.securitytracker.com/id/1029907
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2281
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2282
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2283
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2299

+ MacOSX Safari Firefox Kaspersky RegExp Remote/Local Denial of Service
http://cxsecurity.com/issue/WLB-2014030108
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4051
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-4052
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-3336

+ Firefox 27.0.1 and Safari 7.0.2 (9537.74.9) Remote Denial of Service
http://cxsecurity.com/issue/WLB-2014030107

+ Kaspersky 14.0.0.4651 Remote Denial of Service PoC
http://cxsecurity.com/issue/WLB-2014030106

+ SA57372 McAfee Email Gateway / McAfee Email and Web Security Appliance Multiple SQL Injection Vulnerabilities
http://secunia.com/advisories/57372/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7092

学校でのIT利用には「子供たちのプライバシー保護」が重要
米国のNPO法人代表が訴える
http://itpro.nikkeibp.co.jp/article/NEWS/20140313/543394/?ST=security

標的型攻撃サイトをDNSでアクセス制御する機能を提供開始
http://itpro.nikkeibp.co.jp/article/NEWS/20140313/543403/?ST=security

NSA、Facebookを装う手口などで盗聴活動を拡大---米サイトの報道
http://itpro.nikkeibp.co.jp/article/NEWS/20140313/543282/?ST=security

VU#807134 WatchGuard Fireware XTM devices contain a cross-site scripting vulnerability
http://www.kb.cert.org/vuls/id/807134

0 件のコメント:

コメントを投稿