2017年10月13日金曜日

13日 金曜日、先勝

+ FTP PWD response parser out of bounds read
https://curl.haxx.se/docs/adv_20171004.html
CVE-2017-1000254

+ MantisBT 2.7.0 released
http://www.mantisbt.org/blog/?p=536

+ CVE-2017-0250 | Microsoft JET データベース エンジンのリモートでコードが実行される脆弱性
https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/CVE-2017-0250

+ ADV170012 | TPM の脆弱性により、セキュリティ機能のバイパス
https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/ADV170012

+ ADV170014 | Optional Windows NTLM SSO authentication changes
https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/ADV170014

+ ADV170016 | Windows Server 2008 の多層防御
https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/ADV170016

+ ADV170017 | Office の多層防御機能の更新プログラム
https://portal.msrc.microsoft.com/ja-JP/security-guidance/advisory/ADV170017

+ RHSA-2017:2885 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2017:2885
CVE-2017-7793
CVE-2017-7810
CVE-2017-7814
CVE-2017-7818
CVE-2017-7819
CVE-2017-7823
CVE-2017-7824

+ RHSA-2017:2863 Moderate: kernel security and bug fix update
https://access.redhat.com/errata/RHSA-2017:2863
CVE-2017-7541

+ RHSA-2017:2860 Moderate: postgresql security update
https://access.redhat.com/errata/RHSA-2017:2860
CVE-2017-7546

+ RHSA-2017:2838 Critical: dnsmasq security update
https://access.redhat.com/errata/RHSA-2017:2838
CVE-2017-14491

+ RHSA-2017:2882 Moderate: httpd security update
https://access.redhat.com/errata/RHSA-2017:2882
CVE-2017-9798

+ RHSA-2017:2836 Critical: dnsmasq security update
https://access.redhat.com/errata/RHSA-2017:2836
CVE-2017-14491
CVE-2017-14492
CVE-2017-14493
CVE-2017-14494
CVE-2017-14495
CVE-2017-14496

+ Selenium Standard Server 3.6.0 released
http://docs.seleniumhq.org/download/

+ Selenium IE Driver Server 3.6.0 released
http://docs.seleniumhq.org/download/

+ Selenium Client & WebDriver 3.6.0 released
http://docs.seleniumhq.org/download/

+ About the security content of iOS 11.0.3
https://support.apple.com/ja-jp/HT208182

+ macOS High Sierra 10.13 追加アップデートのセキュリティコンテンツについて
https://support.apple.com/ja-jp/HT208165

+ watchOS 4.0.1 のセキュリティコンテンツについて
https://support.apple.com/ja-jp/HT208163

+ iOS 11.0.2 のセキュリティコンテンツについて
https://support.apple.com/ja-jp/HT208164

+ Mozilla Firefox 56.0.1 released
https://www.mozilla.org/en-US/firefox/56.0.1/releasenotes/

+ Security update available for RoboHelp | APSB17-25
https://helpx.adobe.com/security/products/robohelp/apsb17-25.html

+ Security updates available for Flash Player | APSB17-28
https://helpx.adobe.com/security/products/flash-player/apsb17-28.html

+ Security updates available for ColdFusion | APSB17-30
https://helpx.adobe.com/security/products/coldfusion/apsb17-30.html

+ CESA-2017:2885 Important CentOS 6 thunderbird Security Update
https://lwn.net/Alerts/736155/

+ CESA-2017:2885 Important CentOS 7 thunderbird Security Update
https://lwn.net/Alerts/736154/

+ CESA-2017:2882 Moderate CentOS 7 httpd Security Update
https://lwn.net/Alerts/736153/

+ CESA-2017:2860 Moderate CentOS 6 postgresql Security Update
https://lwn.net/Alerts/735842/

+ Mozilla Thunderbird 52.4.0 released
https://www.mozilla.org/en-US/thunderbird/52.4.0/releasenotes/

+ Wireshark 2.4.2, 2.2.10, 2.0.16 released
https://www.wireshark.org/docs/relnotes/wireshark-2.4.2.html
https://www.wireshark.org/docs/relnotes/wireshark-2.2.10.html
https://www.wireshark.org/docs/relnotes/wireshark-2.0.16.html

+ 2017 年 10 月のセキュリティ更新プログラム (月例)
https://blogs.technet.microsoft.com/jpsecurity/2017/10/11/201710-security-bulletin/

+ curl 7.56.0 release
https://curl.haxx.se/changes.html#7_56_0

+ Linux kernel 4.13.6, 4.9.56, 4.4.92, 3.18.75, 3.16.49, 3.2.94 released
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.6
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.56
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.92
https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.75
https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.49
https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.94

+ Oracle Critical Patch Update Pre-Release Announcement - October 2017
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html

+ Apache HTTP Server 2.4.28 Released
http://www.apache.org/dist/httpd/Announcement2.4.html

+ Apache Tomcat 8.0.47, 7.0.82 Released
http://tomcat.apache.org/tomcat-8.0-doc/changelog.html#Tomcat_8.0.47_(violetagg)
http://tomcat.apache.org/tomcat-7.0-doc/changelog.html#Tomcat_7.0.82_(violetagg)

+ GCC 5.5 released
https://gcc.gnu.org/gcc-5/

VU#590639 NXP Semiconductors MQX RTOS contains multiple vulnerabilities
https://www.kb.cert.org/vuls/id/590639

Announcing the Release of repmgr v4.0 Beta
https://www.postgresql.org/about/news/1793/

0 件のコメント:

コメントを投稿