2014年5月14日水曜日

14日 水曜日、先勝

+ 2014 年 5 月のマイクロソフト セキュリティ情報の概要
https://technet.microsoft.com/ja-jp/library/security/ms14-may

+ MS14-021 - Critical Security Update for Internet Explorer (2965111)
https://technet.microsoft.com/library/security/ms14-021
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1776

+ MS14-022 - Critical Vulnerabilities in Microsoft SharePoint Server Could Allow Remote Code Execution (2952166)
https://technet.microsoft.com/library/security/ms14-022
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0251
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1754
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1813

+ MS14-023 - Important Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2961037)
https://technet.microsoft.com/library/security/ms14-023
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1756
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1808

+ MS14-024 - Important Vulnerability in a Microsoft Common Control Could Allow Security Feature Bypass (2961033)
https://technet.microsoft.com/library/security/ms14-024
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1809

+ MS14-025 - Important Vulnerability in Group Policy Preferences Could Allow Elevation of Privilege (2962486)
https://technet.microsoft.com/library/security/ms14-025
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1812

+ MS14-026 - Important Vulnerability in .NET Framework Could Allow Elevation of Privilege (2958732)
https://technet.microsoft.com/library/security/ms14-026
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1806

+ MS14-027 - Important Vulnerability in Windows Shell Handler Could Allow Elevation of Privilege (2962488)
https://technet.microsoft.com/library/security/ms14-027
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1807

+ MS14-028 - Important Vulnerabilities in iSCSI Could Allow Denial of Service (2962485)
https://technet.microsoft.com/library/security/ms14-028
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0255
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0256

+ MS14-029 - Critical Security Update for Internet Explorer (2962482)
https://technet.microsoft.com/library/security/ms14-029
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0310
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1815

+ Google Chrome 34.0.1847.137 released
http://googlechromereleases.blogspot.jp/2014/05/stable-channel-update.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1741
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1742

+ APSB14-14 Security updates available for Adobe Flash Player
http://helpx.adobe.com/security/products/flash-player/apsb14-14.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0510
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0516
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0517
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0518
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0519
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0520

+ APSB14-11 Security hotfix available for Adobe Illustrator (CS6)
http://helpx.adobe.com/security/products/illustrator/apsb14-11.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0513

+ phpMyAdmin 4.2.1 released
http://sourceforge.net/p/phpmyadmin/news/2014/05/phpmyadmin-421-is-released/

+ UPDATE: HPSBMU03022 rev.2 - HP Systems Insight Manager (SIM) Bundled Software running OpenSSL, Remote Disclosure of Information
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04263236-2%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ UPDATE: HPSBMU02998 rev.4 - HP System Management Homepage (SMH) running OpenSSL on Linux and Windows, Remote Disclosure of Information, Denial of Service (DoS)
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04239372-4%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ UPDATE: HPSBMU02964 rev.2 - HP Service Manager, Cross-Site Scripting (XSS), Remote Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access, Disclosure of Information and Authentication Issues
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04117626-2%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ Linux kernel 3.14.4, 3.10.40, 3.4.90 released
https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.4
https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.40
https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.90

+ FreeBSD-SA-14:10.openssl OpenSSL NULL pointer deference vulnerability
http://www.freebsd.org/security/advisories/FreeBSD-SA-14:10.openssl.asc

+ SA58481 IBM Tivoli Netcool/Reporter OpenSSL Weakness and Two Vulnerabilities
http://secunia.com/advisories/58481/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0076
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160

+ SA58312 Google Chrome Multiple Vulnerabilities
http://secunia.com/advisories/58312/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0510
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0516
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0517
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0518
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0519
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0520
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1740
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1741
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1742

+ SA58456 GNU Emacs Multiple Insecure Temporary File Security Issues
http://secunia.com/advisories/58456/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3421
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3422
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3424

+ SA58291 Symantec Workspace Streaming Unauthenticated XMLRPC Access Security Issue
http://secunia.com/advisories/58291/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1649

+ Yokogawa CENTUM CS3000 'BKCLogSvr.exe' Heap Based Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/66130
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0781

+ Dovecot Denial of Service Vulnerability
http://www.securityfocus.com/bid/67306
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3430

+ Google Chrome CVE-2014-1741 Integer Overflow Vulnerability
http://www.securityfocus.com/bid/67376
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1741

+ Google Chrome CVE-2014-1742 Use After Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/67375
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1742

+ Google Chrome CVE-2014-1741 Use After Free Remote Code Execution Vulnerability
http://www.securityfocus.com/bid/67374
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1740

pg_catcheck released
http://www.postgresql.org/about/news/1521/

エレコム、家族の居場所を確認できる見守りアプリ
http://itpro.nikkeibp.co.jp/article/NEWS/20140513/556466/?ST=security

三井住友銀行の不正送金は「MITB攻撃」、ワンタイムパスワード利用者も被害に
http://itpro.nikkeibp.co.jp/article/NEWS/20140513/556399/?ST=security

低価格ロードバランサーに中位モデル、WAFを標準提供
http://itpro.nikkeibp.co.jp/article/NEWS/20140513/556382/?ST=security

セガのWebサイトに不正アクセス、Webページ改ざんや情報流出は確認されず
http://itpro.nikkeibp.co.jp/article/NEWS/20140513/556294/?ST=security

0 件のコメント:

コメントを投稿