2015年4月8日水曜日

8日 水曜日、先負

+ RHSA-2015:0783 Important: kernel security and bug fix update
https://rhn.redhat.com/errata/RHSA-2015-0783.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8159
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8867

+ nginx 1.7.12, 1.6.3 released
http://nginx.org/en/CHANGES
http://nginx.org/en/CHANGES-1.6

+ phpMyAdmin 4.4.1 released
https://sourceforge.net/projects/phpmyadmin/files/phpMyAdmin/4.4.1/phpMyAdmin-4.4.1-notes.html/view

+ HPSBGN03306 rev.1 - HP IceWall SSO MCRP, SSO Dfw, and SSO Agent running OpenSSL, Remote Denial of Service (DoS)
https://h20566.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04626468&docLocale=ja_JP
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0209
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0286
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0287
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0288
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0289

+ UPDATE: HPSBHF03151 rev.2 - HP Integrated Lights-Out 2 and 4 (iLO 2, iLO 4), Chassis Management (iLO CM), Remote Denial of Service, Remote Execution of Code, Elevation of Privilege
https://h20566.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04486432&docLocale=ja_JP

+ UPDATE: HPSBHF03275 rev.2 - HP Integrated Lights-Out 2, 3, and 4 (iLO 2, iLO 3, iLO 4), Remote Disclosure of Information
https://h20566.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04582218&docLocale=ja_JP

+ UPDATE: HPSBMU03296 rev.2 - HP BladeSystem c-Class Onboard Administrator running OpenSSL, Remote Denial of Service (DoS)
https://h20566.www2.hp.com/hpsc/doc/public/display?calledBy=&docId=emr_na-c04599440&docLocale=ja_JP

+ FreeBSD-SA-15:07.ntp Multiple vulnerabilities of ntp
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:07.ntp.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9297
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1798
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1799

+ FreeBSD-SA-15:08.bsdinstall Insecure default GELI keyfile permissions
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:08.bsdinstall.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1415

+ FreeBSD-SA-15:09.ipv6 Denial of Service with IPv6 Router Advertisements
https://www.freebsd.org/security/advisories/FreeBSD-SA-15:09.ipv6.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2923

+ NTP 4.2.8p2 released
http://archive.ntp.org/ntp4/ChangeLog-stable

+ Ntpd MAC Checking Failure Lets Remote Users Bypass Authentication
http://www.securitytracker.com/id/1032032
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1798

+ Ntpd Symmetric Mode Packet Processing Flaw Lets Remote Users Deny Service
http://www.securitytracker.com/id/1032031
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1799

+ Mozilla Firefox HTTP/2 Alt-Svc Header Processing Bug Lets Remote Users Bypass Certificate Verification
http://www.securitytracker.com/id/1032030
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0799

+ Mozilla Firefox Reader Mode Flaw Lets Remote Users Access Privileged URLs
http://www.securitytracker.com/id/1032029
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0798

+ VU#374268 NTP Project ntpd reference implementation contains multiple vulnerabilities
http://www.kb.cert.org/vuls/id/374268
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1798
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1799

JVNDB-2015-000047 bBlog におけるクロスサイトリクエストフォージェリの脆弱性
http://jvndb.jvn.jp/ja/contents/2015/JVNDB-2015-000047.html

要件定義・基本設計で役立つ、安全なWebアプリ&インフラ構築術
第5回 意外と知らない?HTTPSを使いこなすテクニック
http://itpro.nikkeibp.co.jp/atcl/column/15/021900028/040600007/?ST=security

企業が悩むセキュリティ対策の実態
第3回 「パスワードは8桁以上」が4割超、「BYODを認めない」は半数
http://itpro.nikkeibp.co.jp/atcl/column/15/033000053/033000003/?ST=security

NEC、サポート終了間近の2003搭載サーバーを無償でリストアップ
http://itpro.nikkeibp.co.jp/atcl/news/15/040701215/?ST=security

マルウエア対策、全自動で確実に 米国の気鋭製品が日本上陸
http://itpro.nikkeibp.co.jp/atcl/news/15/040701211/?ST=security

JVN#71903938 bBlog におけるクロスサイトリクエストフォージェリの脆弱性
http://jvn.jp/jp/JVN71903938/

0 件のコメント:

コメントを投稿