2014年3月7日金曜日

7日 金曜日、友引

+ CESA-2014:0255 Moderate CentOS 6 subversion Update
http://lwn.net/Alerts/589698/

+ CESA-2014:0255 Moderate CentOS 5 subversion Update
http://lwn.net/Alerts/589699/

+ phpMyAdmin 4.1.9 is released
http://sourceforge.net/p/phpmyadmin/news/2014/03/phpmyadmin-419-is-released/

+ Microsoft Security Bulletin Advance Notification for March 2014
http://technet.microsoft.com/en-us/security/bulletin/ms14-mar

+ Apache Struts 2.3.16.1 GA released
http://struts.apache.org/announce.html#a20140302
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0050
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0094

+ PHP 5.5.10 released
http://www.php.net/archive/2014.php#id2014-03-06-1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1943
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7327

+ Sudo 1.7.10p8 released
http://www.sudo.ws/sudo/maintenance.html#1.7.10p8
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0106

+ Linux Kernel SCTP Null Pointer Dereference Lets Remote Users Deny Service
http://www.securitytracker.com/id/1029872
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0101

+ SA57158 PHP Fileinfo libmagic Multiple Denial of Service Vulnerabilities
http://secunia.com/advisories/57158/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1943
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270

+ Microsoft March 2014 Notification Multiple Vulnerabilities
http://www.securityfocus.com/bid/66016

+ PHP Fileinfo Component Out of Bounds Memory Corruption Vulnerability
http://www.securityfocus.com/bid/66002
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2270

+ Apache Struts ClassLoader Manipulation CVE-2014-0094 Security Bypass Vulnerability
http://www.securityfocus.com/bid/65999
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0094

Advisory: 'License exceeded' warning after upgrading to SafeGuard Enterprise 6.1
http://www.sophos.com/en-us/support/knowledgebase/120710.aspx

サンディスク、読み取り最大260MB/秒・書き込み最大240MB/秒のUSB 3.0対応フラッシュメモリー
http://itpro.nikkeibp.co.jp/article/NEWS/20140307/541823/?ST=security

「セクシー画像」にコマンドを隠す、新たなウイルスが出現
http://itpro.nikkeibp.co.jp/article/NEWS/20140306/541765/?ST=security

FreedomPop、通信を暗号化する盗聴防止スマホ「Privacy Phone」を発表
http://itpro.nikkeibp.co.jp/article/NEWS/20140306/541566/?ST=security

JVNVU#95919136 Synology DiskStation Manager にアクセス制御不備の脆弱性
http://jvn.jp/vu/JVNVU95919136/

JVNVU#93289336 Serena Dimensions CM web client に複数の脆弱性
http://jvn.jp/vu/JVNVU93289336/

VU#687278 Aker Secure Mail Gateway reflected XSS vulnerability
http://www.kb.cert.org/vuls/id/687278

VU#341526 Huawei E355 contains a direct request vulnerability
http://www.kb.cert.org/vuls/id/341526

0 件のコメント:

コメントを投稿