2014年11月28日金曜日

28日 金曜日、仏滅

+ HPSBGN03202 rev.1 - HP CMS: Configuration Manager running OpenSSL, Remote Disclosure of Information
https://h20566.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04507568&docLocale=ja_JP
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3566

+ HPSBUX03166 SSRT101489 rev.1 - HP-UX running PAM libpam_updbe, Remote Authentication Bypass
https://h20566.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04511778&docLocale=ja_JP
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7879

+ ActivePerl 5.20.1.2000 released
http://www.activestate.com/activeperl/downloads

+ SA60229 Yamaha WLX302 Router OpenSSL "tls_decrypt_ticket()" Denial of Service Vulnerability
http://secunia.com/advisories/60229/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3567

+ SA62542 ClamAV "cli_scanpe()" Buffer Overflow Vulnerability
http://secunia.com/advisories/62542/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9050

+ SA60239 Linux Kernel #SS Trap Handling Denial of Service Vulnerability
http://secunia.com/advisories/60239/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9090

+ SA60043 Kaspersky Security Center OpenSSL Security Issue and Two Vulnerabilities
http://secunia.com/advisories/60043/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0160
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0224

+ MantisBT Captcha System Security Weakness
http://www.securityfocus.com/bid/71321

+ Linux Kernel 'lesspipe' Multiple Local Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/71248

【社長に説明できるセキュリティ】
セキュリティ対策に見えないセキュリティ対策とは
http://itpro.nikkeibp.co.jp/atcl/column/14/511845/111100004/?ST=security

チェックしておきたい脆弱性情報<2014.11.28>
http://itpro.nikkeibp.co.jp/atcl/column/14/268561/112600029/?ST=security

トレンドマイクロ、標的型攻撃の原因を過去に遡って探る新機能
http://itpro.nikkeibp.co.jp/atcl/news/14/112702048/?ST=security

EU、米国版Google検索にも「忘れられる権利」の適用を迫る指針策定
http://itpro.nikkeibp.co.jp/atcl/news/14/112702043/?ST=security

UPDATE: JVNVU#98283300 SSLv3 プロトコルに暗号化データを解読される脆弱性(POODLE 攻撃)
http://jvn.jp/vu/JVNVU98283300/

0 件のコメント:

コメントを投稿