2017年3月24日金曜日

24日 金曜日、仏滅

+ RHSA-2017:0837 Important: icoutils security update
https://rhn.redhat.com/errata/RHSA-2017-0837.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5208
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5332
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5333
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6009
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6010
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6011

+ RHSA-2017:0838 Moderate: openjpeg security update
https://rhn.redhat.com/errata/RHSA-2017-0838.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5139
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5158
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5159
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7163
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9573
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9675

+ UPDATE: Apache Struts2 Jakarta Multipart Parser File Upload Code Execution Vulnerability Affecting Cisco Products
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170310-struts2

+ UPDATE: Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: January and February 2017
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170130-openssl

+ Samba 4.6.1, 4.5.7 and 4.4.12 Security Releases Available for Download
https://www.samba.org/samba/history/samba-4.6.1.html
https://www.samba.org/samba/history/samba-4.5.7.html
https://www.samba.org/samba/history/samba-4.4.11.html

+ Apple iTunes Multiple Vulnerabilities
https://secuniaresearch.flexerasoftware.com/advisories/75929/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6702
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-7443
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1283
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3717
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0718
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4472
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-5300
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6153

+ Apache Struts < 1.3.10 / < 2.3.16.2 ClassLoader Manipulation Remote Code Execution
https://cxsecurity.com/issue/WLB-2017030205
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0094

+ Samba Symlink Race Condition Lets Remote Authenticated Users View Non-Exported Files on the Target System
http://www.securitytracker.com/id/1038117
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2619

+ VMware AirWatch Input Validation Flaw in Shared Filenames Lets Remote Authenticated Users Conduct Cross-Site Scripting Attacks
http://www.securitytracker.com/id/1038116

JVNDB-2017-000050 WordPress 用プラグイン YOP Poll におけるクロスサイトスクリプティングの脆弱性
http://jvndb.jvn.jp/ja/contents/2017/JVNDB-2017-000050.html

追跡!犯罪テクノロジーの実態
「報われないから報告しない」、若者ハッカーの本音
http://itpro.nikkeibp.co.jp/atcl/column/17/031500082/031700003/?ST=security&itp_list_theme

岡山県のStruts2稼動サイト、不正アクセスでDoS攻撃の踏み台に
http://itpro.nikkeibp.co.jp/atcl/news/17/032300910/?ST=security&itp_list_theme

ニュース解説
CIAの機密文書で発覚、シスコ製品300種類にパッチ提供未定の危険な脆弱性
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/032300899/?ST=security&itp_list_theme

Is Linux Mint a secure distribution?
http://www.linuxsecurity.com/content/view/171101/169/

Mozilla beats rivals, patches Firefox's Pwn2Own bug
http://www.linuxsecurity.com/content/view/171100/169/

0 件のコメント:

コメントを投稿