2017年8月15日火曜日

15日 火曜日、大安

+ Selenium Client & WebDriver 3.5.0 released
http://docs.seleniumhq.org/download/

+ Selenium IE Driver Server 3.5 released
http://docs.seleniumhq.org/download/

+ Selenium Standard Server 3.5.0 released
http://docs.seleniumhq.org/download/

+ TortoiseSVN 1.9.7 released
https://tortoisesvn.net/downloads.html

+ Google Chorme 60.0.3112.101 released
https://chromereleases.googleblog.com/2017/08/stable-channel-update-for-desktop_14.html

+ Mozilla Firefox 55.0.1 released
https://www.mozilla.org/en-US/firefox/55.0.1/releasenotes/

+ UPDATE: Cisco WebEx Browser Extension Remote Code Execution Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170717-webex

+ FreeBSD-SA-17:06.openssh OpenSSH Denial of Service vulnerability
https://www.freebsd.org/security/advisories/FreeBSD-SA-17:06.openssh.asc
CVE-2016-6515

+ Linux kernel 4.12.7, 4.9.43, 4.4.82, 3.18.65 released
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.7
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.43
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.82
https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.65

+ UPDATE: Oracle Critical Patch Update Advisory - July 2017
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html

+ 2017-08-10 Security Update Release
https://www.postgresql.org/about/news/1772/
CVE-2017-7546
CVE-2017-7547
CVE-2017-7548

+ PostgreSQL 9.6.4, 9.5.8, 9.4.13, 9.3.18, 9.2.22 released
https://www.postgresql.org/docs/9.6/static/release-9-6-4.html
https://www.postgresql.org/docs/9.5/static/release-9-5-8.html
https://www.postgresql.org/docs/9.4/static/release-9-4-13.html
https://www.postgresql.org/docs/9.3/static/release-9-3-18.html
https://www.postgresql.org/docs/9.2/static/release-9-2-22.html

+ GCC 7.2 released
https://gcc.gnu.org/gcc-7/changes.html

+ Sysstat 11.6.0, 11.4.6, 11.2.12 released
http://sebastien.godard.pagesperso-orange.fr/

+ PostgreSQL Bugs Let Remote Users Bypass Authentication in Certain Cases and Let Remote Authenticated Users Obtain Passwords and Deny Service
http://www.securitytracker.com/id/1039142
CVE-2017-7546
CVE-2017-7547
CVE-2017-7548

+ Linux Kernel packet_set_ring() Race Condition Lets Local Users Obtain Root Privileges
http://www.securitytracker.com/id/1039132
CVE-2017-1000111

+ Apache Subversion 'svn+ssh://' URL Processing Flaw Lets Remote Users Execute Arbitrary Commands on the Target System
http://www.securitytracker.com/id/1039127
CVE-2017-9800

+ cURL 'file://' URL Processing Bug Lets Local Users View Portions of System Memory on the Target System
http://www.securitytracker.com/id/1039119
CVE-2017-1000099

+ cURL TFTP URL Processing Bug Lets Remote Users Obtain Potentially Sensitive Information on the Target System
http://www.securitytracker.com/id/1039118
CVE-2017-1000100

+ cURL URL Globbing Flaw Lets Local Users View Portions of System Memory on the Target System
http://www.securitytracker.com/id/1039117
CVE-2017-1000101

+ Linux Kernel CVE-2017-1000111 Local Privilege Escalation Vulnerability
http://www.securityfocus.com/bid/100267
CVE-2017-1000111

+ Linux Kernel CVE-2017-1000112 Local Memory Corruption Vulnerability
http://www.securityfocus.com/bid/100262
CVE-2017-1000112

MSRC の 2017 年 “トップ 100 人” セキュリティ研究者一覧
https://blogs.technet.microsoft.com/jpsecurity/2017/08/10/the-msrc-2017-list-of-top-100-security-researchers/

PostgreSQL 10 Beta 3 Released!
https://www.postgresql.org/about/news/1771/

UPDATE: JVN#81659403 Qua station接続ツール (Windows版) のインストーラにおける DLL 読み込みに関する脆弱性
http://jvn.jp/jp/JVN81659403/index.html

Linux Security Week: August 14th, 2017
http://www.linuxsecurity.com/content/view/175481/187/

Schoolboy bags $10,000 reward from Google with easy HTTP Host bypass
http://www.linuxsecurity.com/content/view/175480/169/

Those Free Stingray-Detector Apps? Yeah, Spies Could Outsmart Them
http://www.linuxsecurity.com/content/view/175479/169/

Linux Advisory Watch: August 11th, 2017
http://www.linuxsecurity.com/content/view/175472/187/

Git, SVN and Mercurial Open-Source Version Control Systems Update for Critical Security Vulnerabilit
http://www.linuxsecurity.com/content/view/175471/169/

The DDoS Threat: Ukraine's Postal Service Hit by Two-Day Attack
http://www.linuxsecurity.com/content/view/175470/169/

Hackers are now using the exploit behind WannaCry to snoop on hotel Wi-Fi
http://www.linuxsecurity.com/content/view/175469/169/

World's first hack using DNA? Malware in genetic code could wreck police CSI work
http://www.linuxsecurity.com/content/view/175463/169/

So you're thinking about becoming an illegal hacker ? what's your business plan?
http://www.linuxsecurity.com/content/view/175461/169/

Mingw-w64: How to compile Windows exploits on Kali Linux
http://www.linuxsecurity.com/content/view/175460/161/

0 件のコメント:

コメントを投稿