2014年7月24日木曜日

24日 木曜日、先負

+ RHSA-2014:0920 Important: httpd security update
https://rhn.redhat.com/errata/RHSA-2014-0920.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0118
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0226
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0231

+ RHSA-2014:0926 Moderate: kernel security and bug fix update
https://rhn.redhat.com/errata/RHSA-2014-0926.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2678
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4021

+ RHSA-2014:0924 Important: kernel security update
https://rhn.redhat.com/errata/RHSA-2014-0924.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4943

+ RHSA-2014:0919 Critical: firefox security update
https://access.redhat.com/errata/RHSA-2014:0919
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1547
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1555
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1556
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1557

+ CESA-2014:0919 Critical CentOS 6 firefox Update
http://lwn.net/Alerts/606261/

+ CESA-2014:0919 Critical CentOS 5 firefox Update
http://lwn.net/Alerts/606260/

+ CESA-2014:0919 Critical CentOS 7 firefox and xulrunner Security Update
http://lwn.net/Alerts/606262/

+ CESA-2014:0914 Moderate CentOS 7 libvirt Security Update
http://lwn.net/Alerts/606263/

+ CESA-2014:0916 Critical CentOS 5 nss Update
http://lwn.net/Alerts/606265/

+ CESA-2014:0916 Critical CentOS 7 nss and nspr Security Update
http://lwn.net/Alerts/606266/

+ CESA-2014:0917 Critical CentOS 6 nspr Update
http://lwn.net/Alerts/606267/

+ CESA-2014:0917 Critical CentOS 6 nss-util Update
http://lwn.net/Alerts/606268/

+ CESA-2014:0917 Critical CentOS 6 nss Update
http://lwn.net/Alerts/606269/

+ CESA-2014:0916 Critical CentOS 5 nspr Update
http://lwn.net/Alerts/606264/

+ CESA-2014:0918 Important CentOS 5 thunderbird Update
http://lwn.net/Alerts/606270/

+ CESA-2014:0918 Important CentOS 6 thunderbird Update
http://lwn.net/Alerts/606271/

+ UPDATE: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140605-openssl

+ HPSBMU03073 rev.1 - HP Network Virtualization, Remote Execution of Code, Disclosure of Information
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04374202-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2625
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2626

+ HPSBMU03076 rev.1 - HP Systems Insight Manager (SIM) on Linux and Windows running OpenSSL, Multiple Vulnerabilities
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04379485-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5298
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0076
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0195
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0198
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3470

+ HPSBMU03074 rev.1 - HP Insight Control server migration on Linux and Windows running OpenSSL, Remote Denial of Service (DoS), Code Execution, Unauthorized Access, Disclosure of Information
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04378799-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5298
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0076
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0195
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0198
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3470

+ Apache 2.4.x mod_proxy Denial Of Service
http://cxsecurity.com/issue/WLB-2014070127

+ Linux Kernel ptrace/sysret Local Privilege Escalation
http://cxsecurity.com/issue/WLB-2014070126
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4699

+ Apache HTTP Server http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0118 Remote Denial of Service Vulnerability
http://www.securityfocus.com/bid/68745
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0118

チェックしておきたい脆弱性情報<2014.07.24>
http://itpro.nikkeibp.co.jp/atcl/column/14/268561/071800007/?ST=security

KCCS、サーバーセキュリティを含んだAWSの構築/運用サービス
http://itpro.nikkeibp.co.jp/atcl/news/14/072300186/?ST=security

企業のセキュリティ人材育成を支援、日本IBMがCSIRT研修サービスを提供開始
http://itpro.nikkeibp.co.jp/atcl/news/14/072300179/?ST=security

NTTコムのサービス、個人情報最大378人分がWeb閲覧可能だったことが判明
http://itpro.nikkeibp.co.jp/atcl/news/14/072300177/?ST=security

VU#162308 Resin Pro improperly performs Unicode transformations
http://www.kb.cert.org/vuls/id/162308

0 件のコメント:

コメントを投稿