2017年2月16日木曜日

16日 木曜日、友引

+ RHSA-2017:0276 Moderate: bind security update
https://rhn.redhat.com/errata/RHSA-2017-0276.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3135

+ CESA-2017:0276 Moderate CentOS 7 bind Security Update
https://lwn.net/Alerts/714570/

+ Cisco UCS Director Privilege Escalation Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-ucs
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3801

+ Cisco Unified Communications Manager Web Interface Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-ucm
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3833

+ Cisco Prime Collaboration Assurance Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp3
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3845

+ Cisco Prime Collaboration Assurance Directory Listing Unauthorized Access Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp2
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3844

+ Cisco Prime Collaboration Assurance Arbitrary File Download Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-pcp1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3843

+ Cisco Identity Services Engine SQL Injection Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-ise
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3835

+ Cisco Intrusion Prevention System Device Manager Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-idm
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3842

+ Cisco Firepower Management Center Web Framework Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-fpmc
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3847

+ Cisco Unified Communications Manager Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-cucm3
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3836

+ Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-cucm2
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3829

+ Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-cucm1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3828

+ Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-cucm
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3821

+ Cisco Meeting Server HTTP Packet Processing Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-cms1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3837

+ Cisco Meeting Server API Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-cms
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3830

+ Cisco AsyncOS Software for Cisco ESA and Cisco WSA Filtering Bypass Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-asyncos
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3827

+ Cisco Secure Access Control System Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs3
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3841

+ Cisco Secure Access Control System Open Redirect Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs2
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3840

+ Cisco Secure Access Control System XML External Entity Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs1
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3839

+ Cisco Secure Access Control System Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3838

+ Linux kernel 4.9.10, 4.4.49 released
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.10
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.49

+ Microsoft Edge - TypedArray.sort Use-After-Free
https://cxsecurity.com/issue/WLB-2017020157

VU#614751 Hughes satellite modems contain multiple vulnerabilities
https://www.kb.cert.org/vuls/id/614751

JVNDB-2017-000026 Apache Brooklyn におけるクロスサイトリクエストフォージェリの脆弱性
http://jvndb.jvn.jp/ja/contents/2017/JVNDB-2017-000026.html

JVNDB-2017-000025 Apache Brooklyn におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2017/JVNDB-2017-000025.html

セマネ試験直前猛特訓
内部不正対策には証拠保全や従業員教育、コンプライアンスが不可欠
http://itpro.nikkeibp.co.jp/atcl/column/17/020800024/020800004/?ST=security&itp_list_theme

マイナンバー、トラブル続出の深層
マイナンバーのシステム問題、多発の根本原因はガバナンスの欠如だ
http://itpro.nikkeibp.co.jp/atcl/column/17/021000029/021000004/?ST=security&itp_list_theme

ブロックチェーンでデータ保護、ランサムウエア対策強化の「Acronis True Image」新版
http://itpro.nikkeibp.co.jp/atcl/news/17/021500504/?ST=security&itp_list_theme

予想よりも多かった4175人、情報処理安全確保支援士の初回申請者数
http://itpro.nikkeibp.co.jp/atcl/news/17/021500493/?ST=security&itp_list_theme

「今月は遅れます」、マイクロソフトが2017年2月のパッチ公開を延期
http://itpro.nikkeibp.co.jp/atcl/news/17/021500486/?ST=security&itp_list_theme

0 件のコメント:

コメントを投稿