2016年2月12日金曜日

12日 金曜日、大安

+ Mozilla Firefox 44.0.2 released
https://www.mozilla.org/en-US/firefox/44.0.2/releasenotes/

+ MFSA 2016-14 Vulnerabilities in Graphite 2
https://www.mozilla.org/en-US/security/advisories/mfsa2016-14/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1523

+ MFSA 2016-13 Same-origin-policy violation using Service Workers with plugins
https://www.mozilla.org/en-US/security/advisories/mfsa2016-13/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1949

+ CESA-2016:0152 Moderate CentOS 6 sos Security Update
http://lwn.net/Alerts/675023/

+ UPDATE: Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160129-openssl

+ Cisco Advanced Malware Protection and Email Security Appliance Proxy Engine Security Bypass Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160211-esaamp
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1315

+ Cisco Spark Representational State Transfer Interface Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-sp3
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1324

+ Cisco Spark Representational State Transfer Interface Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-sp2
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1323

+ Cisco Spark Representational State Transfer Interface Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-sp2
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1323

+ Cisco ASA Software IKEv1 and IKEv2 Buffer Overflow Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160210-asa-ike
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1287

+ UPDATE: Multiple Vulnerabilities in OpenSSL (December 2015) Affecting Cisco Products
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151204-openssl

+ CTX206001 Citrix NetScaler Application Delivery Controller and NetScaler Gateway Multiple Security Updates
http://support.citrix.com/article/CTX206001
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2071
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2072

+ HS16-005 Multiple Vulnerabilities in JP1/Automatic Operation
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS16-005/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3269
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5255

+ HS16-005 JP1/Automatic Operationにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS16-005/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3269
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5255

+ Apache Tomcat 8.0.32 Released
http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.32_(markt)

+ 2016-02-11 Security Update Release
http://www.postgresql.org/about/news/1644/

+ PostgreSQL 9.5.1, 9.4.6, 9.3.11, 9.2.15, 9.1.20 released
http://www.postgresql.org/docs/9.5/static/release-9-5-1.html
http://www.postgresql.org/docs/9.4/static/release-9-4-6.html
http://www.postgresql.org/docs/9.3/static/release-9-3-11.html
http://www.postgresql.org/docs/9.2/static/release-9-2-15.html
http://www.postgresql.org/docs/9.1/static/release-9-1-20.html

VU#327976 Cisco Adaptive Security Appliance (ASA) IKEv1 and IKEv2 contains a buffer overflow vulnerability
https://www.kb.cert.org/vuls/id/327976

UPDATE: JVN#48135658 複数のルータ製品におけるクリックジャッキングの脆弱性
http://jvn.jp/jp/JVN48135658/

1分で理解するプロの知恵[ネットワーク設計&運用編]
ユーザーの手が届くスイッチはループ対策オンがマスト
http://itpro.nikkeibp.co.jp/atcl/column/16/020400029/020400004/?ST=security

News & Trend
年金機構事件が残した“宿題”、改正サイバー法は政府機関を守れるのか?
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/020900440/?ST=security

林 伸夫のLong and Winding Mac
マイナンバーカード取得の光と闇
http://itpro.nikkeibp.co.jp/atcl/column/15/051100119/020900018/?ST=security

日本オラクル、「セキュリティ・リスク・アセスメント」をユーザーに無償提供
http://itpro.nikkeibp.co.jp/atcl/news/16/021000421/?ST=security

米政府、17年度予算から190億ドルをサイバーセキュリティ対策へ
http://itpro.nikkeibp.co.jp/atcl/news/16/021000420/?ST=security

0 件のコメント:

コメントを投稿