2017年2月17日金曜日

17日 金曜日、先負

+ UPDATE: Cisco Secure Access Control System XML External Entity Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-acs1

+ OpenSSL Security Advisory [16 Feb 2017]
https://www.openssl.org/news/secadv/20170216.txt
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3733

+ OpenSSL 1.1.0e is now available
https://www.openssl.org/

+ SA75302 Linux Kernel RDMA "mem_check_range()" Integer Overflow Vulnerability
https://secuniaresearch.flexerasoftware.com/advisories/75302/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8636

+ PHP 7.0.16 Released
http://www.php.net/ChangeLog-7.php#7.0.16

+ JVNVU#99002156 Apple GarageBand の脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU99002156/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2374

+ Trend Micro InterScan Web Security Virtual Appliance Bugs Let Remote Users Conduct Cross-Site Scripting Attacks and Let Remote Authenticated Users Execute Arbitrary Commands and Gain Elevated Privileges
http://www.securitytracker.com/id/1037849
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9269
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9314
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9315
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9316

+ OpenSSL Flaw in Encrypt-Then-Mac Extension Negotiation Lets Remote Authenticated Users Cause the Target Service to Crash
http://www.securitytracker.com/id/1037846
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3733

+ Microsoft GDI32.DLL EMR_SETDIBITSTODEVICE Boundary Error Lets Local Users View Portions of System Memory on the Target System
http://www.securitytracker.com/id/1037845
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0038

JVNVU#93522863 複数の Hughes Satellite Modem に複数の脆弱性
http://jvn.jp/vu/JVNVU93522863/

セマネ試験直前猛特訓
内部不正防止に役立つのは、人事評価や処罰の制度、従業員の良好なコミュニケーション
http://itpro.nikkeibp.co.jp/atcl/column/17/020800024/020800005/?ST=security&itp_list_theme

0 件のコメント:

コメントを投稿