2017年2月20日月曜日

20日 月曜日、赤口

+ Ubuntu 16.04.2 LTS released
http://cdimage.ubuntu.com/ubuntu/releases/16.04.2/release/

+ UPDATE: Cisco ASA Clientless SSL VPN CIFS Heap Overflow Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170208-asa

+ UPDATE: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170130-openssl

+ UPDATE: Cisco Unified Communications Manager Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170215-cucm3

+ Linux kernel 4.10, 4.9.11, 4.4.50 released
https://www.kernel.org/
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.11
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.50

+ SA75408 Hitachi Multiple Cosminexus / uCosminexus Products Information Disclosure Vulnerability
https://secuniaresearch.flexerasoftware.com/advisories/75408/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0887

+ SA75378 Trend Micro InterScan Web Security Virtual Appliance Multiple Vulnerabilities
https://secuniaresearch.flexerasoftware.com/advisories/75378/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9269
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9314
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9315
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9316

+ SA75406 Hitachi Multiple Cosminexus / uCosminexus Products Security Bypass Vulnerability
https://secuniaresearch.flexerasoftware.com/advisories/75406/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6816

+ SA75403 Hitachi HiRDB Control Manager Denial of Service Vulnerability
https://secuniaresearch.flexerasoftware.com/advisories/75403/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3092

+ SA75355 Microsoft Windows EMF EMR_SETDIBITSTODEVICE Record Processing Information Disclosure Vulnerability
https://secuniaresearch.flexerasoftware.com/advisories/75355/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-0038

+ hitachi-sec-2017-108 Vulnerability in Cosminexus HTTP Server and Hitachi Web Server
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2017-108/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0887

+ hitachi-sec-2017-107 Vulnerability in Cosminexus
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2017-107/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6816

+ hitachi-sec-2017-106 Vulnerability in Cosminexus
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2017-106/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0762

+ hitachi-sec-2017-105 DoS Vulnerability in HiRDB Control Manager - Server
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2017-105/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3092

+ hitachi-sec-2017-104 Cross-site Scripting Vulnerability in uCosminexus Portal Framework, Groupmax Collaboration, Hitachi Navigation Platform and JP1/Navigation Platform
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2017-104/index.html

+ hitachi-sec-2017-108 Cosminexus HTTP Server, Hitachi Web Serverにおける脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2017-108/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0887

+ hitachi-sec-2017-107 Cosminexusにおける脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2017-107/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6816

+ hitachi-sec-2017-106 Cosminexusにおける脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2017-106/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0762

+ hitachi-sec-2017-105 HiRDB Control Manager - ServerにおけるDoS脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2017-105/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3092

+ hitachi-sec-2017-104 uCosminexus Portal Framework, Groupmax Collaboration, Hitachi Navigation PlatformおよびJP1/Navigation Platformにおけるクロスサイトスクリプティングの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2017-104/index.html

+ JVNDB-2017-000024 7-ZIP32.DLL で作成された自己解凍書庫における任意の DLL 読み込みに関する脆弱性
http://jvndb.jvn.jp/ja/contents/2017/JVNDB-2017-000024.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2107

+ JVNVU#90017300 OpenSSL にサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU90017300/index.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-3733

+ Microsoft SQL Server Clr Stored Procedure Payload Execution
https://cxsecurity.com/issue/WLB-2017020181

+ QEMU Host Filesystem Arbitrary Access
https://cxsecurity.com/issue/WLB-2017020179
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9602

+ Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Remote Root
https://cxsecurity.com/issue/WLB-2017020170

+ Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Privilege Escalation
https://cxsecurity.com/issue/WLB-2017020169
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9315

+ Trendmicro InterScan 6.5-SP2_Build_Linux_1548 Arbitrary File Write
https://cxsecurity.com/issue/WLB-2017020168

セキュリティ国家試験、解けますか?
NTPリフレクション攻撃の特徴とは?
http://itpro.nikkeibp.co.jp/atcl/column/17/021700034/021700001/?ST=security&itp_list_theme

マイナンバー1992名分を誤送付、静岡県湖西市が表計算ソフトの操作ミスで
http://itpro.nikkeibp.co.jp/atcl/news/17/021700529/?ST=security&itp_list_theme

UPDATE: JVN#87662835 脆弱性体験学習ツール AppGoat における DNS リバインディングの脆弱性
http://jvn.jp/jp/JVN87662835/

0 件のコメント:

コメントを投稿