2016年7月6日水曜日

6日 水曜日、友引









+ nginx 1.11.2 released
http://nginx.org/en/CHANGES

+ VU#690343 Acer Portal app for Android does not properly validate SSL certificates
https://www.kb.cert.org/vuls/id/690343
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5648

+ SA71282 Linux Kernel "hiddev_ioctl_usage()" Buffer Overflow Vulnerability
https://secunia.com/advisories/71282/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5829

+ SA71381 Linux Kernel "ec_device_ioctl_xcmd()" Buffer Overflow Vulnerability
https://secunia.com/advisories/71381/

+ SA71284 Linux Kernel PowerPC Transactions Denial of Service Vulnerability
https://secunia.com/advisories/71284/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5828

+ UPDATE: JVN#07710476 Apache Struts において任意のコードを実行可能な脆弱性
http://jvn.jp/jp/JVN07710476/index.html

+ Apache HTTPD HTTP/2 Certificate Validation Flaw Lets Remote Users Bypass Client Certificate Authentication on the Target System
http://www.securitytracker.com/id/1036225
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4979

+ Apple Safari for Mac OS X SVG local XXE PoC
https://cxsecurity.com/issue/WLB-2016070019

セレブ画像流出事件、容疑者がハッキングの罪を認める
http://itpro.nikkeibp.co.jp/atcl/news/16/070501976/?ST=security

0 件のコメント:

コメントを投稿