2017年7月20日木曜日

20日 木曜日、先勝

+ Zabbix 3.2.7, 3.0.10, 2.2.19 released
https://www.zabbix.com/rn3.2.7
https://www.zabbix.com/rn3.0.10
https://www.zabbix.com/rn2.2.19

+ Wireshark 2.4.0, 2.2.8, 2.0.14 released
https://www.wireshark.org/docs/relnotes/wireshark-2.4.0.html
https://www.wireshark.org/docs/relnotes/wireshark-2.2.8.html
https://www.wireshark.org/docs/relnotes/wireshark-2.0.14.html

+ Cisco WebEx Browser Extension Remote Code Execution Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170717-webex
CVE-2017-6753

+ Cisco Web Security Appliance Command Injection and Privilege Escalation Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa1
CVE-2017-6746

+ Cisco Web Security Appliance Administrative Interface Access Control Bypass Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa5
CVE-2017-6751

+ Cisco Web Security Appliance Static Credentials Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa4
CVE-2017-6750

+ Cisco Web Security Appliance Stored Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa3
CVE-2017-6749

+ Cisco Web Security Appliance Authenticated Command Injection and Privilege Escalation Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-wsa2
CVE-2017-6748

+ Cisco Prime Collaboration Provisioning Tool Web Portal Cross-Site Scripting Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-pcpt
CVE-2017-6755

+ Cisco ASR 5000 Series Aggregation Services Routers Access Control List Security Bypass Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-asr1
CVE-2017-6672

+ Cisco ASR 5000 Series Aggregation Services Routers GGSN Gateway Redirect Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170719-asr
CVE-2017-6612

JVNDB-2017-000176 ソニー製ポータブルワイヤレスサーバー WG-C10 におけるアクセス制限不備の脆弱性
http://jvndb.jvn.jp/ja/contents/2017/JVNDB-2017-000176.html

JVNDB-2017-000175 ソニー製ポータブルワイヤレスサーバー WG-C10 における複数の脆弱性
http://jvndb.jvn.jp/ja/contents/2017/JVNDB-2017-000175.html

UPDATE: JVNVU#98841854 Dahua 製ネットワークカメラに複数の脆弱性
http://jvn.jp/vu/JVNVU98841854/

IoT時代の最新SELinux入門
コンテナ乗っ取りの脅威、SELinuxでどこまで守れる?
http://itpro.nikkeibp.co.jp/atcl/column/17/041900153/071800007/?ST=security&itp_list_theme

記者の眼
ランサムウエアで“復権”するワーム、金儲けのツールに
http://itpro.nikkeibp.co.jp/atcl/watcher/14/334361/071200881/?ST=security&itp_list_theme

シスコがネット自動化戦略「直感ネットワーク」を国内展開、8月から順次提供
http://itpro.nikkeibp.co.jp/atcl/news/17/071901932/?ST=security&itp_list_theme

Zero-Day Exploit Surfaces that May Affect Millions of IoT Users
http://www.linuxsecurity.com/content/view/172240/169/

Let's harden Internet crypto so quantum computers can't crack it
http://www.linuxsecurity.com/content/view/172238/169/

0 件のコメント:

コメントを投稿