2016年3月14日月曜日

14日 月曜日、先勝

+ CESA-2016:0430 Important CentOS 7 xerces-c Security Update
http://lwn.net/Alerts/679735/

+ CESA-2016:0428 Moderate CentOS 6 libssh2 Security Update
http://lwn.net/Alerts/679733/

+ CESA-2016:0428 Moderate CentOS 7 libssh2 Security Update
http://lwn.net/Alerts/679734/

+ Cisco Gigabit Switch Router 12000 Series Routers Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160311-gsr
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1361

+ Linux kernel 2.6.32.71 released
https://cdn.kernel.org/pub/linux/kernel/v2.6/longterm/v2.6.32/ChangeLog-2.6.32.71

+ S2-030 Possible XSS vulnerability in I18NInterceptor
http://struts.apache.org/docs/s2-030.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2162

+ S2-029 Double OGNL evaluation when using raw user input in tag's attributes.
http://struts.apache.org/docs/s2-029.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0785

+ S2-028 Use of a JRE with broken URLDecoder implementation may lead to XSS vulnerability in Struts 2 based web applications.
http://struts.apache.org/docs/s2-028.html

VU#713312 DTE Energy Insight app vulnerable to information exposure
https://www.kb.cert.org/vuls/id/713312

JVNVU#94745180 Quagga にバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU94745180/

チェックしておきたい脆弱性情報<2016.03.14>
http://itpro.nikkeibp.co.jp/atcl/column/14/268561/030300102/?ST=security

[CD 2016]「組織を立て直さないと標的型攻撃の餌食になる」、中央大学法科大学院の野村教授
http://itpro.nikkeibp.co.jp/atcl/news/16/031100762/?ST=security

江崎グリコで不正アクセス、漏洩件数は?
http://itpro.nikkeibp.co.jp/atcl/column/14/556302/030900071/?ST=security

0 件のコメント:

コメントを投稿