2014年11月19日水曜日

19日 水曜日、大安

+ MS14-068 - 緊急 Kerberos の脆弱性により特権が昇格される (3011780)
https://technet.microsoft.com/ja-jp/library/security/ms14-068
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6324

+ RHSA-2014:1870 Important: libXfont security update
https://rhn.redhat.com/errata/RHSA-2014-1870.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0209
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0210
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0211

+ RHSA-2014:1873 Moderate: libvirt security and bug fix update
https://rhn.redhat.com/errata/RHSA-2014-1873.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3633
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3657
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7823

+ RHSA-2014:1870 Important: libXfont security update
https://access.redhat.com/errata/RHSA-2014:1870
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0209
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0210
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0211

+ About the security content of Apple TV 7.0.2
https://support.apple.com/en-us/HT6592
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4452
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4462
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4455
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4461

+ About the security content of OS X Yosemite v10.10.1
https://support.apple.com/en-us/HT6591
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4460
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4453
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4458
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4459

+ About the security content of iOS 8.1.1
https://support.apple.com/en-us/HT6590
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4460
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4455
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4461
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4463
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4457
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4453
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4452
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4462

+ CESA-2014:1870 Important CentOS 6 libXfont Security Update
http://lwn.net/Alerts/621563/

+ CESA-2014:1861 Important CentOS 7 mariadb Security Update
http://lwn.net/Alerts/621564/

+ CESA-2014:1859 Important CentOS 5 mysql55-mysql Security Update
http://lwn.net/Alerts/621565/

+ UPDATE: GNU Bash Environment Variable Command Injection Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash

+ UPDATE: HPSBUX03139 SSRT101608 rev.3 - HP-UX running System Management Homepage (SMH), Remote Cross-Site Request Forgery
https://h20565.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04476799&docLocale=ja_JP

+ Tcpdump Multiple Flaws Let Remote Users Deny Service
http://www.securitytracker.com/id/1031235
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8767
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8768
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8769

+ Apple iOS Lets Local Users Bypass Access Controls and Remote Applications Launch Arbitrary Binaries
http://www.securitytracker.com/id/1031232
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4451
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4457
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4463

+ Apple TV Bugs Let Remote Users Execute Arbitrary Code and Local Users Gain Elevated Privileges
http://www.securitytracker.com/id/1031231
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4452
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4455
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4461
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4462

+ Apple OS X Bugs Let Remote Users Execute Arbitrary Code and Obtain Potentially Sensitive Information
http://www.securitytracker.com/id/1031230
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4453
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4458
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4459
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4460

+ VU#213119 Microsoft Windows Kerberos Key Distribution Center (KDC) fails to properly validate Privilege Attribute Certificate (PAC) signature
http://www.kb.cert.org/vuls/id/213119
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6324

+ REMOTE: Samsung Galaxy KNOX Android Browser RCE
http://www.exploit-db.com/exploits/35282

+ REMOTE: MantisBT XmlImportExport Plugin PHP Code Injection Vulnerability
http://www.exploit-db.com/exploits/35283

+ REMOTE: Internet Explorer 8 - Fixed Col Span ID Full ASLR, DEP & EMET 5.1 Bypass (MS12-037)
http://www.exploit-db.com/exploits/35273

+ Internet Explorer 8 Fixed Col Span ID full ASLR, DEP and EMET 5.1 bypass
http://cxsecurity.com/issue/WLB-2014110125
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-1876

+ Samsung Galaxy KNOX Android Browser Remote Code Execution
http://cxsecurity.com/issue/WLB-2014110124

+ MantisBT XmlImportExport Plugin PHP Code Injection
http://cxsecurity.com/issue/WLB-2014110118
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7146

+ Linux Kernel User Namespace Local Security Bypass Vulnerability
http://www.securityfocus.com/bid/71154

+ tcpdump CVE-2014-8769 Out-of-bounds Memory Access Vulnerability
http://www.securityfocus.com/bid/71153
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8769

+ Microsoft Windows Phone Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/71152

+ tcpdump 'olsr_print()' Function Denial of Service Vulnerability
http://www.securityfocus.com/bid/71150
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8767

「パスポート顔写真の加工は誤認招く」、出国・帰国審査“顔パス”実験で
http://itpro.nikkeibp.co.jp/atcl/news/14/111801954/?ST=security

標的型攻撃を検知してSDNで自動制御、NECが来春販売
http://itpro.nikkeibp.co.jp/atcl/news/14/111801951/?ST=security

0 件のコメント:

コメントを投稿