2014年11月7日金曜日

7日 金曜日、大安

+ RHSA-2014:1824 Important: php security update
https://rhn.redhat.com/errata/RHSA-2014-1824.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3669
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3670
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8626

+ Mozilla Firefox 33.0.3 released
https://www.mozilla.org/en-US/firefox/33.0.3/releasenotes/

+ UPDATE: GNU Bash Environment Variable Command Injection Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140926-bash

+ DoS/PoC: VMware Workstations 10.0.0.40273 vmx86.sys Arbitrary Kernel Read
http://www.exploit-db.com/exploits/35182

+ VMWare vmx86.sys Arbitrary Kernel Read
http://cxsecurity.com/issue/WLB-2014110023

+ SA62132 LibreOffice Impress Remote Use-After-Free Vulnerability
http://secunia.com/advisories/62132/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-3693

+ PHP 'date_from_ISO8601()' Function Buffer Overflow Vulnerability
http://www.securityfocus.com/bid/70928

+ Linux Kernel 'net/mac80211/tx.c' Information Disclosure Vulnerability
http://www.securityfocus.com/bid/70965

+ Trend Micro InterScan Web Security Virtual Appliance Multiple Information Disclosure Vulnerabilities
http://www.securityfocus.com/bid/70964
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8510

UPDATE: JVNVU#97219505 GNU Bash に OS コマンドインジェクションの脆弱性
http://jvn.jp/vu/JVNVU97219505/

デンソーウェーブとレピカが提携、QRコードでブランド品の真贋判定
http://itpro.nikkeibp.co.jp/atcl/news/14/110601787/?ST=security

REMOTE: Citrix NetScaler SOAP Handler Remote Code Execution
http://www.exploit-db.com/exploits/35180

REMOTE: X7 Chat 2.0.5 lib/message.php preg_replace() PHP Code Execution
http://www.exploit-db.com/exploits/35183

LOCAL: i-FTP 2.20 - Buffer Overflow SEH Exploit
http://www.exploit-db.com/exploits/35177

DoS/PoC: MINIX 3.3.0 Local Denial of Service PoC
http://www.exploit-db.com/exploits/35173

DoS/PoC: i.Hex 0.98 - Local Crash PoC
http://www.exploit-db.com/exploits/35178

DoS/PoC: i.Mage 1.11 - Local Crash PoC
http://www.exploit-db.com/exploits/35179

0 件のコメント:

コメントを投稿