2016年4月1日金曜日

1日 金曜日、先勝

+ RHSA-2016:0561 Low: Red Hat Enterprise Linux 5 One-Year Retirement Notice
https://rhn.redhat.com/errata/RHSA-2016-0561.html

+ RHSA-2016:0534 Moderate: mariadb security and bug fix update
https://rhn.redhat.com/errata/RHSA-2016-0534.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4792
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4802
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4815
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4816
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4819
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4826
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4830
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4836
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4858
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4861
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4870
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4879
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4913
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0505
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0546
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0596
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0597
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0598
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0600
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0606
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0608
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0609
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0616
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2047

+ RHSA-2016:0532 Moderate: krb5 security update
https://rhn.redhat.com/errata/RHSA-2016-0532.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8629
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8630
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8631

+ About the security content of iBooks Author 2.4.1
https://support.apple.com/ja-jp/HT206224
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1789

+ UPDATE: Cisco Unified Communications Domain Manager Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160328-ucdm

+ Citrix XenServer Security Update for CVE-2016-0800
http://support.citrix.com/article/CTX208403
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0800

+ HS16-011 Multiple Vulnerabilities in Cosminexus XML Processor
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS16-011/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4803
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0466

+ HS16-011 Cosminexus XML Processorにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS16-011/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4803
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0466

+ PHP 7.0.5, 5.6.20, 5.5.34 Released
http://www.php.net/ChangeLog-7.php#7.0.5
http://www.php.net/ChangeLog-5.php#5.6.20
http://www.php.net/ChangeLog-5.php#5.5.34

+ 2016-03-31 Security Update Release
http://www.postgresql.org/about/news/1656/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2193
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3065

+ PostgreSQL 9.5.2, 9.4.7, 9.3.12, 9.2.16 and 9.1.21 Released!
http://www.postgresql.org/docs/9.5/static/release-9-5-2.html
http://www.postgresql.org/docs/9.4/static/release-9-4-7.html
http://www.postgresql.org/docs/9.3/static/release-9-3-12.html
http://www.postgresql.org/docs/9.2/static/release-9-2-16.html
http://www.postgresql.org/docs/9.1/static/release-9-1-21.html

+ LibTIFF Buffer Overflow in gif2tiff Lets Remote Users Deny Service
http://www.securitytracker.com/id/1035442
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3186

+ Linux Kernel ims_pcu_parse_cdc_data() Device Driver Flaw Lets Local Users Cause Denial of Service Conditions on the Target System
http://www.securitytracker.com/id/1035441

記者の眼
分かりにくいよセキュリティ用語、ばらまき型で標的型って何?
http://itpro.nikkeibp.co.jp/atcl/watcher/14/334361/032500517/?ST=security

サイバー犯罪にどう立ち向かうか~JC3イベントレポート
「サイバー犯罪者は楽に成功している、被害公表を褒めて被害共有で手口封じる」、パネル討議
http://itpro.nikkeibp.co.jp/atcl/column/16/032400067/032500006/?ST=security

米当局のデバイスロック解除命令、AppleだけでなくGoogleも受けていた
http://itpro.nikkeibp.co.jp/atcl/news/16/033100939/?ST=security

JVNVU#91828421 Eaglesoft (Patterson Dental) でパスワードがハードコードされている問題
http://jvn.jp/vu/JVNVU91828421/

0 件のコメント:

コメントを投稿