2016年3月16日水曜日

16日 水曜日、先負

+ RHSA-2016:0450 Important: kernel security update
https://rhn.redhat.com/errata/RHSA-2016-0450.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-2596
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2151

+ RHSA-2016:0448 Moderate: samba security update
https://rhn.redhat.com/errata/RHSA-2016-0448.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7560

+ RHSA-2016:0449 Moderate: samba4 security update
https://rhn.redhat.com/errata/RHSA-2016-0449.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7560

+ Red Hat Enterprise Linux 6.8 Beta
https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6-Beta/html/6.8_Release_Notes/index.html

+ Opera 36 released
http://www.opera.com/docs/changelogs/unified/3600/

+ Mozilla Thunderbird 38.7.0 released
https://www.mozilla.org/en-US/thunderbird/38.7.0/releasenotes/

+ UPDATE: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: March 2016
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl

+ UPDATE: Oracle Solaris Third Party Bulletin - January 2016
http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html

+ VMSA-2016-0003 VMware vRealize Automation and vRealize Business Advanced and Enterprise address Cross-Site Scripting (XSS) issues.
http://www.vmware.com/security/advisories/VMSA-2016-0003.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-2344
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2075

+ JVNTA#99929369 国内のウェブサイトに SQL インジェクションの脆弱性
http://jvn.jp/ta/JVNTA99929369/

+ Windows Kernel ATMFD.DLL OTF Font Processing Stack Corruption (MS16-026)
https://cxsecurity.com/issue/WLB-2016030081
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0120

+ Windows Kernel ATMFD.DLL OTF Font Processing Pool-Based Buffer Overflow (MS16-026)
https://cxsecurity.com/issue/WLB-2016030080
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0121

+ Internet Explorer Read AV in MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout [MS16-023]
https://cxsecurity.com/issue/WLB-2016030079
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0108

+ RHEL 7.1 Kernel - iowarrior driver Crash PoC
https://cxsecurity.com/issue/WLB-2016030078
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2188

+ RHEL 7.1 Kernel - snd-usb-audio Crash PoC
https://cxsecurity.com/issue/WLB-2016030077
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2184

UPDATE: JVNVU#91475438 Internet Key Exchange (IKEv1, IKEv2) が DoS 攻撃の踏み台として使用される問題
http://jvn.jp/vu/JVNVU91475438/

記者の眼
エストニアの国民IDカード制度がFinTechと融合してとんでもないことになっていた
http://itpro.nikkeibp.co.jp/atcl/watcher/14/334361/031400507/?ST=security

「どんなサイトも丸裸に」、SimilarWebの手法はありなのか
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/031300475/?ST=security

0 件のコメント:

コメントを投稿