2017年9月6日水曜日

6日 水曜日、仏滅

+ PostgreSQL ODBC Driver 09.06.0500 released
https://www.postgresql.org/ftp/odbc/versions/msi/

+ RHSA-2017:2569 Moderate: 389-ds-base security and bug fix update
https://access.redhat.com/errata/RHSA-2017:2569
CVE-2017-7551

+ Google Chrome 61.0.3163.79 released
https://chromereleases.googleblog.com/2017/09/stable-channel-update-for-desktop.html
CVE-2017-5111
CVE-2017-5112
CVE-2017-5113
CVE-2017-5114
CVE-2017-5115
CVE-2017-5116
CVE-2017-5117
CVE-2017-5118
CVE-2017-5119
CVE-2017-5120

+ A regular expression Denial of Service when using URLValidator (similar to S2-044 & S2-047)
http://struts.apache.org/docs/s2-050.html
CVE-2017-9804

+ A remote attacker may create a DoS attack by sending crafted xml request when using the Struts REST plugin
http://struts.apache.org/docs/s2-051.html
CVE-2017-9793

+ Possible Remote Code Execution attack when using the Struts REST plugin with XStream handler to handle XML payloads
http://struts.apache.org/docs/s2-052.html
CVE-2017-9805

+ Apache Struts REST Plugin XStream Deserialization Flaw Lets Remote Users Execute Arbitrary Code on the Target System
http://www.securitytracker.com/id/1039263
CVE-2017-9805

+ Apache Struts REST Plugin XStream Library Lets Remote Users Deny Service
http://www.securitytracker.com/id/1039262
CVE-2017-9793

+ Apache Struts Regex Processing Flaw in URLValidator Lets Remote Users Consume Excessive CPU Resources on the Target System
http://www.securitytracker.com/id/1039261
CVE-2017-9804

+ Linux kernel 4.13 released
https://git.kernel.org/torvalds/h/v4.13

総務省、重要インフラ向けIoT機器に対する脆弱性調査を実施へ
http://itpro.nikkeibp.co.jp/atcl/news/17/090502179/?ST=security&itp_list_theme

On internet privacy, be very afraid
http://www.linuxsecurity.com/content/view/175764/169/

Linux Security Week: September 5th, 2017
http://www.linuxsecurity.com/content/view/175763/187/

Microsoft Releases Long-Awaited Security Tool, Sets Linux Preview
http://www.linuxsecurity.com/content/view/175762/169/

MongoDB ransacking starts again: Hackers ransom 26,000 unsecured instances
http://www.linuxsecurity.com/content/view/175761/169/

0 件のコメント:

コメントを投稿