2014年9月24日水曜日

24日 水曜日、先負

+ RHSA-2014:1281 Moderate: kernel security and bug fix update
https://access.redhat.com/errata/RHSA-2014:1281
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917

+ Selenium IDE 2.7.0 released
https://code.google.com/p/selenium/wiki/SeIDEReleaseNotes

+ Selenium Server 2.43.1 released
http://code.google.com/p/selenium/wiki/Grid2

+ Selenium Internet Explorer Driver Server 2.43.0 released
http://selenium.googlecode.com/git/cpp/iedriverserver/CHANGELOG

+ Selenium Client & WebDriver 2.43.1 released
http://selenium.googlecode.com/git/java/CHANGELOG

+ CESA-2014:1281 Moderate CentOS 7 kernel Security Update
http://lwn.net/Alerts/612873/

+ Lightning Calendar 3.3.1 released
https://www.mozilla.org/en-US/projects/calendar/

+ BIND 9.10.1, 9.9.6, 9.8.8 released
https://kb.isc.org/article/AA-01209/81/BIND-9.10.1-Release-Notes.html
https://kb.isc.org/article/AA-01210/81/BIND-9.9.6-Release-Notes.html
https://kb.isc.org/article/AA-01211/81/BIND-9.8.8-Release-Notes.html

+ HPSBPI03107 rev.1 - Certain HP LaserJet Printers, MFPs and Certain HP OfficeJet Enterprise Printers using OpenSSL, Remote Unauthorized Access
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04451722-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224

+ HPSBST03103 rev.1 - HP Storage EVA Command View Suite running OpenSSL, Remote Unauthorized Access, Disclosure of Information
https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04425253-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224

+ MySQL 5.6.21, 5.5.40 released
http://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-21.html
http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-40.html

+ Sudo 1.8.11 released
http://www.sudo.ws/sudo/stable.html#1.8.11

+ nginx SSL Session Cache Reuse May Let Remote Users Hijack Sessions Across Virtual Hosts
http://www.securitytracker.com/id/1030882
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3616

+ SA61385 Linux Kernel "SMB2_tcon()" NULL Pointer Dereference Denial of Service Vulnerability
http://secunia.com/advisories/61385/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7145

+ SA60109 Linux Kernel User Namespaces Mount Flags Handling Security Bypass Vulnerabilities
http://secunia.com/advisories/60109/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5206
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5207

JVNDB-2014-000111 Android 版アプリ「ゆこゆこ」における SSL サーバ証明書の検証不備の脆弱性
http://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-000111.html

JVNVU#96848844 FortiGate および FortiWiFi アプライアンスに複数の脆弱性
http://jvn.jp/vu/JVNVU96848844/

【「ソーシャル新人類」の不夜城?10代は何を考えているのか】
デマを簡単に信じる中高生、狭い空間での情報拡散をSNSが増幅
http://itpro.nikkeibp.co.jp/atcl/column/14/537662/091900009/?ST=security

【世界のセキュリティ・ラボから】
HTTPSは100%安全の証? 油断は禁物
http://itpro.nikkeibp.co.jp/atcl/column/14/264220/091800011/?ST=security

【Apple IDの「困った!」にお答えします】
【第2回】Apple IDで困ったときにはここをチェック!
http://itpro.nikkeibp.co.jp/atcl/column/14/091800071/091800002/?ST=security

スマホ版LINEのPINコード設定が義務化、不正ログインの被害拡大防止
http://itpro.nikkeibp.co.jp/atcl/news/14/092201017/?ST=security

独自解像度縮小技術で再生時に高精細化、画質と長時間を両立するネットワークカメラ
http://itpro.nikkeibp.co.jp/atcl/news/14/092201014/?ST=security

DoS/PoC: Fast Image Resizer 098 - Local Crash Poc
http://www.exploit-db.com/exploits/34720

DoS/PoC: Seafile-server <= 3.1.5 - Remote DoS
http://www.exploit-db.com/exploits/34729

0 件のコメント:

コメントを投稿