2016年1月15日金曜日

15日 金曜日、大安

+ RHSA-2016:0043 Moderate: openssh security update
https://rhn.redhat.com/errata/RHSA-2016-0043.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0777
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0778

+ UPDATE: Cisco IOS XR Software OSPF Link State Advertisement PCE Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160104-iosxr

+ UPDATE: Cisco IOS and IOS XE Software IPv6 First Hop Security Denial of Service Vulnerabilities
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-fhs

+ UPDATE: Cisco IOS Software Virtual Routing and Forwarding ICMP Queue Wedge Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150325-wedge

+ UPDATE: Cisco IOS Software and IOS XE Software TCP Packet Memory Leak Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150325-tcpleak

+ UPDATE: Cisco IOS Software and IOS XE Software mDNS Gateway Denial of Service Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150325-mdns

+ UPDATE: Multiple Vulnerabilities in Cisco IOS Software Common Industrial Protocol
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150325-cip

+ UPDATE: Cisco IOS Software and IOS XE Software Internet Key Exchange Version 2 Denial of Service Vulnerabilities
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150325-ikev2

+ UPDATE: Multiple Vulnerabilities in Cisco IOS Software and IOS XE Software Autonomic Networking Infrastructure
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150325-ani

+ UPDATE: Cisco IOS and IOS XE Software SSH Version 2 RSA-Based User Authentication Bypass Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150923-sshpk

+ UPDATE: Oracle Solaris Third Party Bulletin - October 2015
http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html

+ Oracle Critical Patch Update Pre-Release Announcement - January 2016
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html

+ FreeBSD-SA-16:06.bsnmpd Insecure default snmpd.config permissions
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:06.bsnmpd.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5677

+ FreeBSD-SA-16:05.tcp TCP MD5 signature denial of service
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:05.tcp.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1882

+ FreeBSD-SA-16:04.linux Linux compatibility layer setgroups(2) system call vulnerability
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:04.linux.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1881

+ FreeBSD-SA-16:03.linux Linux compatibility layer incorrect futex handling
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:03.linux.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1880

+ FreeBSD-SA-16:02.ntp ntp panic threshold bypass vulnerability
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:02.ntp.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5300

+ FreeBSD-SA-16:01.sctp SCTP ICMPv6 error message vulnerability
https://www.freebsd.org/security/advisories/FreeBSD-SA-16:01.sctp.asc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1879

+ OpenSSH 7.1p2 released
http://www.openssh.com/

+ OpenSSH Flaws Let Remote Authenticated Users Obtain Potentially Sensitive Information From Client Memory
http://www.securitytracker.com/id/1034671
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0777
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0778

PipelineDB Enterprise Now Available
http://www.postgresql.org/about/news/1641/

UPDATE: JVNVU#98704210 ISC Kea DHCP サーバにサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU98704210/

チェックしておきたい脆弱性情報<2016.01.15>
http://itpro.nikkeibp.co.jp/atcl/column/14/268561/011100095/?ST=security

統計&調査
[データは語る]2015年4Qのインシデントは前年同期比45%減―JPCERT/CC
http://itpro.nikkeibp.co.jp/atcl/news/14/110601779/011400467/?ST=security

0 件のコメント:

コメントを投稿