2014年8月26日火曜日

26日 火曜日、先負

+ RHSA-2014:1091 Important: mod_wsgi security update
https://access.redhat.com/errata/RHSA-2014:1091
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0240

+ CESA-2014:1091 Important CentOS 7 mod_wsgi Security Update
http://lwn.net/Alerts/609472/

+ HPSBMU03079 rev.1 - HP Service Manager, Multiple Vulnerabilities
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04388127-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6222
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2632
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2633
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-2634

+ UPDATE: HPSBMU03076 rev.2 - HP Systems Insight Manager (SIM) on Linux and Windows running OpenSSL, Multiple Vulnerabilities
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04379485-2%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ Zimbra Collaboration Suite Open Source Edition 8.5.0 GA Release
http://files.zimbra.com/website/docs/8.5/ZCS_850_OS_ReleaseNotes_UpgradeInst.pdf

+ SA60746 phpMyAdmin Multiple Script Insertion Vulnerabilities
http://secunia.com/advisories/60746/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5273
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5274

+ MySQL token (Keystone) retain access via an expired token
http://cxsecurity.com/issue/WLB-2014080110
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5251

+ Apache Traffic Server releases for security incident
http://cxsecurity.com/issue/WLB-2014080107
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3525

+ phpMyAdmin CVE-2014-5274 Cross Site Scripting Vulnerability
http://www.securityfocus.com/bid/69269
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5274

+ phpMyAdmin Multiple Cross Site Scripting Vulnerabilities
http://www.securityfocus.com/bid/69268
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5273

JVNDB-2014-000101 WordPress 用プラグイン MailPoet Newsletters におけるクロスサイトリクエストフォージェリの脆弱性
http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000101.html

新人D太と先輩M子のITビジネス日誌
金銭奪取を目的とする「リスト型攻撃」が急増、利用者をどう守る?
http://itpro.nikkeibp.co.jp/atcl/column/14/493082/082100003/?ST=security

記者の眼
2015年は官民挙げての“セキュリティブーム”が来る?
http://itpro.nikkeibp.co.jp/atcl/watcher/14/334361/082200035/?ST=security

プレステ関連サービスにDDoS攻撃、約20時間アクセス不安定に
http://itpro.nikkeibp.co.jp/atcl/news/14/082500549/?ST=security

POS端末を狙うマルウエア「Backoff」の感染拡大を米当局が警告
http://itpro.nikkeibp.co.jp/atcl/news/14/082500537/?ST=security

0 件のコメント:

コメントを投稿