2014年9月4日木曜日

4日 木曜日、赤口

+ RHSA-2014:1144 Critical: firefox security update
https://rhn.redhat.com/errata/RHSA-2014-1144.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1562
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1567

+ RHSA-2014:1148 Important: squid security update
https://rhn.redhat.com/errata/RHSA-2014-1148.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4115
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3609

+ RHSA-2014:1143 Moderate: kernel security and bug fix update
https://rhn.redhat.com/errata/RHSA-2014-1143.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3917

+ RHSA-2014:1145 Important: thunderbird security update
https://rhn.redhat.com/errata/RHSA-2014-1145.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1562
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1567

+ RHSA-2014:1144 Critical: firefox security update
https://rhn.redhat.com/errata/RHSA-2014-1144.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1562
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1567

+ RHSA-2014:1146 Important: httpcomponents-client security update
https://access.redhat.com/errata/RHSA-2014:1146
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3577

+ RHSA-2014:1147 Important: squid security update
https://access.redhat.com/errata/RHSA-2014:1147
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3609

+ HPSBGN03099 rev.1 - HP IceWall SSO Dfw, SSO Agent and MCRP running OpenSSL, Remote Disclosure of Information
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04424322-1%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3508

+ UPDATE: HPSBMU03083 rev.2 - HP BladeSystem c-Class Virtual Connect Firmware running OpenSSL, Remote Unauthorized Access or Disclosure of Information
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04392919-2%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ UPDATE: HPSBST03004 rev.3 - HP IBRIX X9320 Storage running OpenSSL, Remote Disclosure of Information
https://h20565.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04264595-3%257CdocLocale%253Dja_JP%257CcalledBy%253D&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

+ VU#582497 Multiple Android applications fail to properly validate SSL certificates
http://www.kb.cert.org/vuls/id/582497

+ Android Browser Same Origin Policy Bypass
http://cxsecurity.com/issue/WLB-2014090009
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6041

+ Facebook Messenger / App MIME Sniffing Cross Site Scripting
http://cxsecurity.com/issue/WLB-2014090005

+ SA60788 Net-SNMP snmptrapd Multiple Denial of Service Vulnerabilities
http://secunia.com/advisories/60788/

+ Linux Kernel CVE-2014-5045 Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/68862
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5045

世界のセキュリティ・ラボから
国家レベルの標的型攻撃、製薬業界に照準
http://itpro.nikkeibp.co.jp/atcl/column/14/264220/090100009/?ST=security

危なすぎる数字だけのパスワード、JALとANAがユーザー認証を強化
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/090100042/?ST=security

トレンドマイクロ、ウイルスバスター最新版で脆弱性チェック機能を搭載
パスワード管理ツール「パスワードマネージャー 無料版」を同梱
http://itpro.nikkeibp.co.jp/atcl/news/14/090300710/?ST=security

「内部に攻撃者がいる前提で対策を」、トーマツが提言
http://itpro.nikkeibp.co.jp/atcl/news/14/090300704/?ST=security

A10、DDoS対策ハードウエアをNAT装置や負荷分散装置に順次搭載
http://itpro.nikkeibp.co.jp/atcl/news/14/090300694/?ST=security

Apple、アカウントハッキングは確認するもiCloudシステムの侵害は否定
http://itpro.nikkeibp.co.jp/atcl/news/14/090300684/?ST=security

0 件のコメント:

コメントを投稿