2014年3月26日水曜日

26日 水曜日、先負

+ RHSA-2014:0328 Important: kernel security and bug fix update
http://rhn.redhat.com/errata/RHSA-2014-0328.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1860
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0055
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0069
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101

+ RHSA-2014:0330 Moderate: samba and samba3x security update
http://rhn.redhat.com/errata/RHSA-2014-0330.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496

+ CESA-2014:0330 Moderate CentOS 5 samba3x Update
http://lwn.net/Alerts/591872/

+ CESA-2014:0322 Moderate CentOS 5 net-snmp Update
http://lwn.net/Alerts/591870/

+ CESA-2014:0321 Moderate CentOS 6 net-snmp Update
http://lwn.net/Alerts/591871/

+ CVE-2013-0900 Race Conditions vulnerability in ICU
https://blogs.oracle.com/sunsecurity/entry/cve_2013_0900_race_conditions
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0900

+ CVE-2013-5745 Input Validation vulnerability in Vino
https://blogs.oracle.com/sunsecurity/entry/cve_2013_5745_input_validation
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-5745

+ CVE-2008-0386 Improper Input Validation vulnerability in Xdg-utils
https://blogs.oracle.com/sunsecurity/entry/cve_2008_0386_improper_input
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0386

+ CVE-2014-0591 Buffer Errors vulnerability in Bind
https://blogs.oracle.com/sunsecurity/entry/cve_2014_0591_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0591

+ CVE-2013-6462 Buffer Errors vulnerability in X.Org
https://blogs.oracle.com/sunsecurity/entry/cve_2013_6462_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6462

+ CVE-2013-2561 Link Following vulnerability in OpenFabrics ibutils
https://blogs.oracle.com/sunsecurity/entry/cve_2013_2561_link_following
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2561

+ Multiple vulnerabilities in Wireshark
https://blogs.oracle.com/sunsecurity/entry/multiple_vulnerabilities_in_wireshark9
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7112
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7114

+ CVE-2014-0397 Buffer Errors vulnerability in libXtsol
https://blogs.oracle.com/sunsecurity/entry/cve_2014_0397_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0397

+ CVE-2013-4408 Buffer Errors vulnerability in Samba
https://blogs.oracle.com/sunsecurity/entry/cve_2013_4408_buffer_errors
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408

+ CVE-2012-6150 Input Validation vulnerability in Samba
https://blogs.oracle.com/sunsecurity/entry/cve_2012_6150_input_validation
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150

+ CVE-2006-4810 Buffer overflow vulnerability in Texinfo
https://blogs.oracle.com/sunsecurity/entry/cve_2006_4810_buffer_overflow
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4810

+ Microsoft Security Advisory (2953095) Vulnerability in Microsoft Word Could Allow Remote Code Execution
http://technet.microsoft.com/en-us/security/advisory/2953095
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1761

+ マイクロソフト セキュリティ アドバイザリ (2953095) Microsoft Word の脆弱性により、リモートでコードが実行される
http://technet.microsoft.com/ja-jp/security/advisory/2953095
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1761

+ OpenSSL 1.0.0l cache side-channel attack
http://cxsecurity.com/issue/WLB-2014030197
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0076

+ Linux kernel 3.13.6 DCCP arbitrary code execution
http://cxsecurity.com/issue/WLB-2014030194
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2523

+ Windows Media Player 11.0.5721.5230 Memory Corruption PoC
http://cxsecurity.com/issue/WLB-2014030192

+ SA57564 PHP Fileinfo libmagic AWK File Processing Denial of Service Vulnerability
http://secunia.com/advisories/57564/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7345

+ SA53612 Linux Kernel xen-netback NAPI Packet Handling Denial of Service Vulnerability
http://secunia.com/advisories/53612/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2580

+ SA57577 Microsoft Word RTF Memory Corruption Vulnerability
http://secunia.com/advisories/57577/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1761

+ PHP Fileinfo Component Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/66406
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7345

Deep Discovery Inspector 3.5 Patch 1 (Build 1442) 公開のお知らせ
http://app.trendmicro.co.jp/support/news.asp?id=2093

“スマホ版仮想デスクトップ”で強固なセキュリティを、トレンドマイクロ
http://itpro.nikkeibp.co.jp/article/NEWS/20140325/545826/?ST=security

Wordに危険な脆弱性が発覚、悪用した標的型攻撃も
http://itpro.nikkeibp.co.jp/article/NEWS/20140325/545727/?ST=security

日本ベリサイン、「シマンテック・ウェブサイトセキュリティ」に社名変更
http://itpro.nikkeibp.co.jp/article/NEWS/20140325/545687/?ST=security

NSAのHuaweiサーバー侵入について中国が米国に説明を要求---海外メディアの報道
http://itpro.nikkeibp.co.jp/article/NEWS/20140325/545643/?ST=security

VU#213046 Virtual Access GW6110A router privilege escalation vulnerability
http://www.kb.cert.org/vuls/id/213046

REMOTE: FreePBX config.php Remote Code Execution
http://www.exploit-db.com/exploits/32512

DoS/PoC: Haihaisoft HUPlayer 1.0.4.8 (.m3u, .pls, .asx) - Buffer Overflow (SEH)
http://www.exploit-db.com/exploits/32513

DoS/PoC: Haihaisoft Universal Player 1.5.8 (.m3u, .pls, .asx) - Buffer Overflow (SEH)
http://www.exploit-db.com/exploits/32514

0 件のコメント:

コメントを投稿