2017年9月8日金曜日

8日 金曜日、赤口

+ Android to x86 7.1-rc1 released
http://www.android-x86.org/releases/releasenote-7-1-rc1

+ Multiple Vulnerabilities in Apache Struts 2 Affecting Cisco Products: September 2017
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170907-struts2
CVE-2017-9793
CVE-2017-9804
CVE-2017-9805

+ Cisco IOS and Cisco IOS XE Software UDP Packet Processing Denial of Service Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170906-ios-udp
CVE-2017-6627

+ Linux kernel 4.12.11, 4.9.48, 4.4.87, 3.18.70 released
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.12.11
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.48
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.87
https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.70

+ Sudo 1.8.21p2 released
https://www.sudo.ws/stable.html#1.8.21p2

+ S2-053 A possible Remote Code Execution attack when using an unintentional expression in Freemarker tag instead of string literals
http://struts.apache.org/docs/s2-053.html
CVE-2017-12611

+ Apache Struts 2.3.34 released
http://struts.apache.org/announce.html#a20170907

+ UPDATE: JVNVU#92761484 Apache Struts2 に任意のコードが実行可能な脆弱性 (S2-052)
http://jvn.jp/vu/JVNVU92761484/index.html

+ Google Chrome Multiple Flaws Let Remote Bypass Security Restrictions and Execute Arbitrary Code
http://www.securitytracker.com/id/1039291
CVE-2017-5111
CVE-2017-5112
CVE-2017-5113
CVE-2017-5114
CVE-2017-5115
CVE-2017-5116
CVE-2017-5117
CVE-2017-5118
CVE-2017-5119
CVE-2017-5120

+ Apache Struts 2.5 Remote Code Execution
https://cxsecurity.com/issue/WLB-2017090047
CVE-2017-9805

ウイルスバスターの最新版はXGenの技術と機械学習機能を搭載
http://itpro.nikkeibp.co.jp/atcl/news/17/090702203/?ST=security&itp_list_theme

0 件のコメント:

コメントを投稿