2014年3月4日火曜日

4日 火曜日、大安










+ RHSA-2014:0246 Important: gnutls security update
http://rhn.redhat.com/errata/RHSA-2014-0246.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0092

+ Google Chrome 33.0.1750.146 released
http://googlechromereleases.blogspot.jp/2014/03/stable-channel-update.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6663
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6664
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6665
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6666
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6667
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6668

+ UPDATE: マイクロソフト セキュリティ アドバイザリ (2862152) DirectAccess および IPSec の脆弱性により、セキュリティ機能のバイパスが起こる
http://technet.microsoft.com/ja-jp/security/advisory/2862152

+ RHSA-2014:0247 Important: gnutls security update
http://rhn.redhat.com/errata/RHSA-2014-0247.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-5138
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0092

+ SA57216 Linux Kernel "complete_emulated_mmio()" Memory Corruption Vulnerability
http://secunia.com/advisories/57216/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0049

+ Linux Kernel kvm mmio_fragments out-of-the-bounds access
http://cxsecurity.com/issue/WLB-2014030021
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0049

+ MantisBT Admin SQL Injection Arbitrary File Read
http://cxsecurity.com/issue/WLB-2014030019
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2238

+ OpenVPN (DSM) 4.3-3810 has a hardcoded root password of synopass
http://cxsecurity.com/issue/WLB-2014030016
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2264

+ MantisBT 1.2.16 SQL Injection
http://cxsecurity.com/issue/WLB-2014030014
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2238

+ Linux Kernel 'complete_emulated_mmio()' Function Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/65909
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0049

Bitcoin取引所は今後も狙われる、セキュリティ企業が指摘
http://itpro.nikkeibp.co.jp/article/NEWS/20140303/540691/?ST=security

mixiに不正ログイン、1万件以上のIDで身に覚えのない投稿
http://itpro.nikkeibp.co.jp/article/NEWS/20140303/540651/?ST=security

JVNVU#93097036 Blue Coat ProxySG に脆弱性
http://jvn.jp/vu/JVNVU93097036/

JVNVU#97434093 CMS Made Simple にクロスサイトスクリプティングの脆弱性
http://jvn.jp/vu/JVNVU97434093/

VU#525132 Foscam IP camera authentication bypass vulnerability
http://www.kb.cert.org/vuls/id/525132

LOCAL: ALLPlayer 5.8.1 - (.m3u file) Buffer Overflow (SEH)
http://www.exploit-db.com/exploits/32041

0 件のコメント:

コメントを投稿