2014年9月1日月曜日

1日 月曜日、先負

+ RHSA-2014:1110 Important: glibc security update
https://rhn.redhat.com/errata/RHSA-2014-1110.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0475
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119

+ RHSA-2014:1110 Important: glibc security update
https://access.redhat.com/errata/RHSA-2014:1110
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0475
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119

+ phpMyAdmin 4.2.8 is released
http://sourceforge.net/p/phpmyadmin/news/2014/08/phpmyadmin-428-is-released/

+ Glibc Heap Overflow in __gconv_translit_find() Lets Local Users Gain Elevated Privileges
http://www.securitytracker.com/id/1030786
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119

+ glibc Off-by-One NUL Byte gconv_translit_find Exploit
http://cxsecurity.com/issue/WLB-2014080131
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5119

+ Internet Explorer MS14-029 Memory Corruption PoC
http://cxsecurity.com/issue/WLB-2014080141
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1815

+ iPhone Call From LockScreen ByPass By Siri On iOS 7.1.2 (0day) *youtube
http://cxsecurity.com/issue/WLB-2014080144

+ GNU glibc 'iconv()' Denial of Service Vulnerability
http://www.securityfocus.com/bid/69472

DbWrench Database Design 3.2 Released
http://www.postgresql.org/about/news/1541/

JVNDB-2014-000102 Android 版アプリ Kindle における SSL サーバ証明書の検証不備の脆弱性
http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000102.html

やり取り型攻撃の全貌
担当者の警戒を緩め侵入を狙う、情報共有で見えた攻撃の全貌
http://itpro.nikkeibp.co.jp/atcl/column/14/082700049/082700001/?ST=security

「サイバー闇市場」は数千億円規模、サイバー攻撃のSaaSも用意
http://itpro.nikkeibp.co.jp/atcl/news/14/082900628/?ST=security

REMOTE: F5 Big-IP - Unauthenticated rsync Access
http://www.exploit-db.com/exploits/34465

REMOTE: NRPE 2.15 - Remote Code Execution Vulnerability
http://www.exploit-db.com/exploits/34461

DoS/PoC: HTML Help Workshop 1.4 - (SEH) Buffer Overflow
http://www.exploit-db.com/exploits/34463

0 件のコメント:

コメントを投稿