2016年2月4日木曜日

4日 木曜日、先勝

+ Google Chrome 48.0.2564.103 released
http://googlechromereleases.blogspot.jp/2016/02/stable-channel-update.html

+ UPDATE: Cisco Jabber STARTTLS Downgrade Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20151224-jab

+ UPDATE: Cisco Adaptive Security Appliance Information Disclosure Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160115-asa

+ Cisco Unity Connection Web Framework Cross-Site Scripting Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-uc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1310

+ Cisco Jabber Guest Server HTTP Web-Based Management Interface Cross-Site Scripting Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-jgs
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1311

+ Cisco Unified Communications Manager SQL Injection Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-ucm
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1308

+ Cisco ASA-CX and Cisco Prime Security Manager Privilege Escalation Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-prsm
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1301

+ Cisco Application Policy Infrastructure Controller Access Control Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-apic
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1302

+ Cisco Nexus 9000 Series ACI Mode Switch ICMP Record Route Vulnerability
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160203-n9knci
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-6398

+ UPDATE: Multiple Vulnerabilities in OpenSSL (January 2016) Affecting Cisco Products
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160129-openssl

+ Samba 4.2.8 Available for Download
https://www.samba.org/samba/history/samba-4.2.8.html

+ A Tale of openssl_seal(), PHP,d Apache2handle
https://cxsecurity.com/issue/WLB-2016020027

VU#777024 Netgear Management System NMS300 contains arbitrary file upload and path traversal vulnerabilities
https://www.kb.cert.org/vuls/id/777024

記者の眼
マルウエアと正面から向き合うのはもうやめよう
http://itpro.nikkeibp.co.jp/atcl/watcher/14/334361/020300476/?ST=security

チェックしておきたい脆弱性情報<2016.02.04>
http://itpro.nikkeibp.co.jp/atcl/column/14/268561/020200097/?ST=security

LRMがクラウド上の個人情報管理規格「ISO27018」認証取得支援サービス開始
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/020200431/?ST=security

サイバー法改正案が閣議決定、「情報処理安全確保支援士」新設へ
http://itpro.nikkeibp.co.jp/atcl/news/16/020300358/?ST=security

欧州と米国、セーフハーバー協定に代わるデータ移転の枠組みで合意
http://itpro.nikkeibp.co.jp/atcl/news/16/020300349/?ST=security

JVNVU#99349751 フィッシャープライス Smart Toy 向けウェブサービスにおいて認証なしで API を呼び出せる脆弱性
http://jvn.jp/vu/JVNVU99349751/index.html

JVNVU#99850969 OpenELEC と RasPlex に root の SSH パスワードがハードコードされている問題
http://jvn.jp/vu/JVNVU99850969/index.html

0 件のコメント:

コメントを投稿