2014年4月10日木曜日

10日 木曜日、先勝

+ RHSA-2014:0383 Moderate: samba4 security update
http://rhn.redhat.com/errata/RHSA-2014-0383.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4496
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6442

+ Google Chrome 34.0.1847.116 released
http://googlechromereleases.blogspot.jp/2014/04/stable-channel-update.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1716
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1717
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1718
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1719
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1720
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1721
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1722
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1723
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1724
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1725
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1726
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1727
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1729

+ Multiple Vulnerabilities in Cisco ASA Software
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-asa
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2126
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2127
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2128
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2129

+ OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed

+ Linux kernel 3.2.57 released
https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.57

+ FreeBSD NFS Server Deadlock Bug Lets Remote Authenticated Users Deny Service
http://www.securitytracker.com/id/1030041
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1453

+ SA57758 Juniper SSL VPN (IVEOS) OpenSSL TLS Heartbeat Information Disclosure Vulnerability
http://secunia.com/advisories/57758/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160

+ SA57806 McAfee Asset Manager Arbitrary File Download and SQL Injection Two Vulnerabilities
http://secunia.com/advisories/57806/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2587
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2588

+ Microsoft Word RTF Object Confusion Exploit (MS14-017)
http://cxsecurity.com/issue/WLB-2014040051
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1761

+ OpenSSL TLS Heartbeat User Session Extraction
http://cxsecurity.com/issue/WLB-2014040046
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160

+ Linux Kernel 'cma_req_handler()' Function Denial of Service Vulnerability
http://www.securityfocus.com/bid/66716

+ FreeBSD CVE-2014-1453 Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/66726
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1453

InterScan Web Security Suite 5.6 Linux版 Service Pack 1 build 1074 再公開のお知らせ
http://app.trendmicro.co.jp/support/news.asp?id=2106

XPとOffice 2003の「最後のパッチ」が公開、危険な脆弱性を修正
http://itpro.nikkeibp.co.jp/article/NEWS/20140409/549458/?ST=security

JVNVU#94612196 J2K-Codec に複数の脆弱性
http://jvn.jp/vu/JVNVU94612196/

UPDATE: JVNVU#94401838 OpenSSL の heartbeat 拡張に情報漏えいの脆弱性
http://jvn.jp/vu/JVNVU94401838/index.html

0 件のコメント:

コメントを投稿