2014年8月13日水曜日

13日 水曜日、赤口

+ 2014 年 8 月のマイクロソフト セキュリティ情報の概要
https://technet.microsoft.com/ja-jp/library/security/ms14-aug

+ MS14-043 - 緊急 Windows Media Center の脆弱性により、リモートでコードが実行される (2978742)
https://technet.microsoft.com/library/security/ms14-043
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4060

+ MS14-044 - 重要 SQL Server の脆弱性により、特権が昇格される (2984340)
https://technet.microsoft.com/library/security/MS14-044
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1820
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4061

+ MS14-045 - 重要 カーネルモード ドライバーの脆弱性により、特権が昇格される (2984615)
https://technet.microsoft.com/library/security/MS14-045
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0318
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1819
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4064

+ MS14-046 - 重要 .NET Framework の脆弱性により、セキュリティ機能のバイパスが起こる (2984625)
https://technet.microsoft.com/library/security/MS14-046
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4062

+ MS14-047 - 重要 LRPC の脆弱性により、セキュリティ機能のバイパスが起こる (2978668)
https://technet.microsoft.com/library/security/MS14-047
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0316

+ MS14-048 - 重要 OneNote の脆弱性により、リモートでコードが実行される (2977201)
https://technet.microsoft.com/library/security/MS14-048
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2815

+ MS14-049 - 重要 Windows Installer サービスの脆弱性により、特権が昇格される (2962490)
https://technet.microsoft.com/library/security/MS14-049
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1814

+ MS14-050 - 重要 Microsoft SharePoint Server の脆弱性により、特権が昇格される (2977202)
https://technet.microsoft.com/library/security/MS14-050
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2816

+ MS14-051 - 緊急 Internet Explorer 用の累積的なセキュリティ更新プログラム (2976627)
https://technet.microsoft.com/library/security/MS14-051
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2817
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2819
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2774
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2784
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2796
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2808
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2810
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2811
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2818
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2820
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2821
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2822
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2823
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2824
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2825
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2826
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2827
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4050
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4051
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4052
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4055
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4056
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4057
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4058
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4063
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4067

+ UPDATE: マイクロソフト セキュリティ アドバイザリ (2755801) Internet Explorer 上の Adobe Flash Player の脆弱性に対応する更新プログラム
https://technet.microsoft.com/ja-jp/library/security/2755801

+ TortoiseSVN 1.8.8 released
http://tortoisesvn.net/downloads.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3522
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3528
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3504

+ APSB14-19 Security Updates available for Adobe Reader and Acrobat
http://helpx.adobe.com/security/products/reader/apsb14-19.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0546

+ APSB14-18 Security updates available for Adobe Flash Player
http://helpx.adobe.com/security/products/flash-player/apsb14-18.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0538
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0540
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0541
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0542
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0543
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0544
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0545

+ ISC DHCP 4.2.7 released
https://kb.isc.org/article/AA-01193/82/DHCP-4.2.7-Release-Notes.html

+ HPSBHF03084 rev.1 HP PCs with UEFI Firmware, Execution of Arbitrary Code
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04393276-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4859
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4860

+ HPSBMU03086 rev.1 - HP Operations Agent running Glance, Local Elevation of Privilege
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04394554-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2630

+ HPSBMU03062 rev.1 - HP Insight Control server deployment on Linux and Windows running OpenSSL, Multiple Vulnerabilities
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04355095-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-5298
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0076
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0195
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0198
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0221
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3470

+ HPSBMU03089 rev.1 - HP Executive Scorecard, Running OpenSSL, Disclosure of Information
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04398968-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224

+ HPSBUX03087 SSRT101413 rev.1 - HP-UX CIFS Server (Samba), Remote Denial of Service (DoS), Execution of Arbitrary Code, Unauthorized Access
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04396638-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6150
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4124
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4408

+ SA60100 Apache Subversion Common Names and Subject Alternate Names Spoofing Two Security Issues
http://secunia.com/advisories/60100/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3522

pgBadger 6.0 is out!
http://www.postgresql.org/about/news/1535/

JVNDB-2014-000097 Dominion KX2-101 におけるサービス運用妨害 (DoS) の脆弱性
http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000097.html

JSSECが企業のスマホ利用実態調査、社員の54.7%が個人端末に業務情報を保存
http://itpro.nikkeibp.co.jp/atcl/news/14/081200452/?ST=security

商業施設内で無断撮影した人物映像を研究活用、京大が謝罪
http://itpro.nikkeibp.co.jp/atcl/news/14/081200451/?ST=security

「防災コンテスト」Webサイトが改ざん被害、フィッシング詐欺が目的か
http://itpro.nikkeibp.co.jp/atcl/news/14/081200442/?ST=security

JVNVU#93614707 OpenSSL クライアントにナルポインタ参照の脆弱性
http://jvn.jp/vu/JVNVU93614707/

JVN#07957080 Dominion KX2-101 におけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/jp/JVN07957080/

Yokogawa BKBCopyD.exe Client Exploit
http://cxsecurity.com/issue/WLB-2014080052

0 件のコメント:

コメントを投稿