2016年2月25日木曜日

25日 木曜日、赤口

+ nginx 1.9.12 released
http://nginx.org/

+ squid 3.5.15 released
http://www.squid-cache.org/Versions/v3/3.5/squid-3.5.15-RELEASENOTES.html

+ UPDATE: Vulnerability in GNU glibc Affecting Cisco Products: February 2016
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160218-glibc

+ Cisco FirePOWER Management Center Unauthenticated Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160224-fmc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1342

+ Cisco ACE 4710 Application Control Engine Command Injection Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160224-ace
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1297

+ Cisco Nexus 2000 Series Fabric Extender Software Default Credential Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160223-nx2000
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1341

+ Samba 4.3.5 Available for Download
https://www.samba.org/samba/history/samba-4.3.5.html

+ UPDATE: JVNVU#97236594 glibc にバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU97236594/

+ JVNVU#94679988 Apache Tomcat の複数の脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU94679988/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5174
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5345
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5346
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5351
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0706
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0714
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0763

+ Squid HTTP Response Processing Bugs Let Remote Users Deny Service to Proxy Client Users
http://www.securitytracker.com/id/1035101

+ Linux Kernel Double-Free Memory Error in usb-midi Driver Lets Physically Local Users Crash the System or Execute Arbitrary Code
http://www.securitytracker.com/id/1035072
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2384

+ Apache Tomcat Bugs Let Remote Users Bypass Security Restrictions, Hijack Sessions, and Obtain Potentially Sensitive Information
http://www.securitytracker.com/id/1035069
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5346
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5351
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0706
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0714
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0763

+ Apache Tomcat 9.0.0.M1 Security Manager Persistence Bypass
https://cxsecurity.com/issue/WLB-2016020190
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0714

+ Apache Tomcat 8.0.26 Limited Directory Traversal
https://cxsecurity.com/issue/WLB-2016020188
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5174

+ Apache Tomcat 9.0.0.M1 Security Manager StatusManagerServlet Bypass
https://cxsecurity.com/issue/WLB-2016020189
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0706

+ Apache Tomcat 9.0.0.M2 CSRF Token Leak
https://cxsecurity.com/issue/WLB-2016020187
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5351

VU#981271 Multiple wireless keyboard/mouse devices use an unsafe proprietary wireless protocol
https://www.kb.cert.org/vuls/id/981271

瀧口範子のシリコンバレー通信
Apple対FBIの「ロック解除論争」、真っ二つに割れる米国世論
http://itpro.nikkeibp.co.jp/atcl/column/15/060200138/022400038/?ST=security

ハミングヘッズ、ホワイトリスト型サイバー攻撃対策ソフトのパッケージ版を発売
http://itpro.nikkeibp.co.jp/atcl/news/16/022400566/?ST=security

iPhoneロック解除問題、「ビル・ゲイツ氏は米政府を支持」と英紙報道
http://itpro.nikkeibp.co.jp/atcl/news/16/022400552/?ST=security

私用LINEの業務利用はこれで止める
[2]技術者を魅了する「Slack」とは?
http://itpro.nikkeibp.co.jp/atcl/column/16/021800038/021800003/?ST=security

BIGLOBEが中小向け標的型攻撃対策、クラウドでサンドボックス提供
http://itpro.nikkeibp.co.jp/atcl/news/16/022300548/?ST=security

NEC、Webサイト閲覧でのマルウエア感染を防ぐ装置を出荷
http://itpro.nikkeibp.co.jp/atcl/news/16/022300541/?ST=security

Apple、政府に命令取り下げと委員会設置を提案 iPhoneロック解除問題で
http://itpro.nikkeibp.co.jp/atcl/news/16/022300536/?ST=security

JVNVU#91895172 FlexNet Publisher の lmgrd にバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU91895172/

0 件のコメント:

コメントを投稿