2017年6月22日木曜日

22日 木曜日、友引










+ RHSA-2017:1561 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2017:1561

+ CESA-2017:1484 Important CentOS 7 kernel Security Update
https://lwn.net/Alerts/726096/

+ Cisco Virtualized Packet Core-Distributed Instance Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-vpc
CVE-2017-6678

+ Cisco WebEx Network Recording Player Multiple Buffer Overflow Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-wnrp
CVE-2017-6669

+ Cisco Prime Infrastructure and Evolved Programmable Network Manager XML Injection Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piepnm1
CVE-2017-6662

+ Cisco Wide Area Application Services TCP Fragment Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-waas
CVE-2017-6721

+ Cisco Unified Contact Center Express Clear Text Authentication Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ucce
CVE-2017-6722

+ Cisco Prime Infrastructure Web Framework Code Cross-Site Scripting Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piwf1
CVE-2017-6725

+ Cisco Prime Infrastructure Web Framework Code Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piwf
CVE-2017-6724

+ Cisco Prime Infrastructure and Evolved Programmable Network Manager DOM Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piepnm4
CVE-2017-6700

+ Cisco Prime Infrastructure and Evolved Programmable Network Manager Reflected Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piepnm3
CVE-2017-6699

+ Cisco Prime Infrastructure and Evolved Programmable Network Manager SQL Injection Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-piepnm2
CVE-2017-6698

+ Cisco Prime Collaboration Provisioning Tool Log File Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-pcp4
CVE-2017-6706

+ Cisco Prime Collaboration Provisioning Tool Information Disclosure Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-pcp3
CVE-2017-6705

+ Cisco Prime Collaboration Provisioning Tool Arbitrary File Download Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-pcp2
CVE-2017-6704

+ Cisco Prime Collaboration Provisioning Tool Session Hijacking Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-pcp1
CVE-2017-6703

+ Cisco Identity Services Engine Reflected Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ise1
CVE-2017-6605

+ Cisco Identity Services Engine Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ise
CVE-2017-6701

+ Cisco IOS XR Software Privilege Escalation Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ios1
CVE-2017-6718

+ Cisco IOS XR Software Local Command Injection Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-ios
CVE-2017-6719

+ Cisco Firepower Management Center Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-fpmc
CVE-2017-6717

+ Cisco Firepower Management Center Stored Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-fmc2
CVE-2017-6716

+ Cisco Firepower Management Center Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-fmc1
CVE-2017-6715

+ Cisco SocialMiner Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-csm
CVE-2017-6702

+ Cisco StarOS for ASR 5000 Series Routers IPsec VPN Tunnel Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170621-asr
CVE-2017-3865

+ SA77539 McAfee Security for Microsoft Exchange PostgreSQL Multiple Vulnerabilities
https://secuniaresearch.flexerasoftware.com/advisories/77539/
VE-2016-0703
CVE-2016-0704
CVE-2016-5423
CVE-2016-5424

+ UPDATE: JVNVU#94071181 ISC BIND に複数の脆弱性
http://jvn.jp/vu/JVNVU94071181/index.html

+ OpenVPN Multiple Vulnerabilities post-audit bug bonanza
https://cxsecurity.com/issue/WLB-2017060152
CVE-2017-7520
CVE-2017-7521
CVE-2017-7522
CVE-2017-7508

+ Microsoft Windows Kernel DeviceApi Stack Memory Disclosure
https://cxsecurity.com/issue/WLB-2017060151
CVE-2017-8474

PL/Java 1.5.1-BETA1 announced; security note.
https://www.postgresql.org/about/news/1758/

IoT時代の最新SELinux入門
動かしてわかるSELinuxセキュリティの基本
http://itpro.nikkeibp.co.jp/atcl/column/17/041900153/052500003/?ST=security&itp_list_theme

今日も誰かが狙われる
繰り返される悲劇、「1億円あげます」メールの罠
http://itpro.nikkeibp.co.jp/atcl/column/17/050800181/061900005/?ST=security&itp_list_theme

ニュース解説
次に来るネットワーク技術、Interopの受賞製品を分析
http://itpro.nikkeibp.co.jp/atcl/column/14/346926/061601020/?ST=security&itp_list_theme

セキュリティ診断のイロハ
セキュリティ診断、稼働中のサービスを探す前にやること
http://itpro.nikkeibp.co.jp/atcl/column/17/061600244/061900003/?ST=security&itp_list_theme

日本IBM、セキュリティ被害の初動対応を支援する「X-Force IRIS」サービス
http://itpro.nikkeibp.co.jp/atcl/news/17/062101726/?ST=security&itp_list_theme

マックの障害が復旧、マルウエアの正体は「解析中」
http://itpro.nikkeibp.co.jp/atcl/news/17/062101720/?ST=security&itp_list_theme

SBSホールディングスのシステム障害、ランサムウエアに感染するも現在は復旧
http://itpro.nikkeibp.co.jp/atcl/news/17/062101719/?ST=security&itp_list_theme

ホンダの狭山工場、WannaCry感染で1000台生産できず
http://itpro.nikkeibp.co.jp/atcl/news/17/062101717/?ST=security&itp_list_theme

ホンダが工場など複数拠点でWannaCry感染、一部の生産に影響
http://itpro.nikkeibp.co.jp/atcl/news/17/062101713/?ST=security&itp_list_theme

Honeypots and the Internet of Things
http://www.linuxsecurity.com/content/view/171870/169/

Ztorg malware hid in Google Play to send premium-rate SMS texts, delete incoming SMS messages
http://www.linuxsecurity.com/content/view/171869/169/

0 件のコメント:

コメントを投稿