2017年12月1日金曜日

1日 金曜日、大安

+ RHSA-2017:3368 Moderate: qemu-kvm security update
https://access.redhat.com/errata/RHSA-2017:3368
CVE-2017-14167
CVE-2017-15289

+ RHSA-2017:3315 Important: kernel security and bug fix update
https://access.redhat.com/errata/RHSA-2017:3315
CVE-2017-1000380

+ Selenium Standard Server 3.8.0 released
http://docs.seleniumhq.org/download/

+ Selenium Client & WebDriver 3.8.0 released
http://docs.seleniumhq.org/download/

+ Selenium IE Driver Server 3.7.0 released
https://raw.githubusercontent.com/SeleniumHQ/selenium/master/cpp/iedriverserver/CHANGELOG

+ Mozilla Firefox 57.0.1 released
https://www.mozilla.org/en-US/firefox/57.0.1/releasenotes/

+ Wireshark 2.4.3, 2.2.11 released
https://www.wireshark.org/docs/relnotes/wireshark-2.4.3.html
https://www.wireshark.org/docs/relnotes/wireshark-2.2.11.html

+ UPDATE: Multiple Vulnerabilities in Cisco WebEx Recording Format and Advanced Recording Format Players
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex-players

+ UPDATE: Multiple Vulnerabilities in Cisco Data Center Network Manager Software
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-dcnm

+ UPDATE: Cisco WebEx Network Recording Player Buffer Overflow Vulnerability
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171129-webex

+ Linux kernel 4.14.3, 4.9.66, 4.4.103, 3.18.85 released
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.3
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.66
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.103
https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.85

+ hitachi-sec-2017-132 Cross-site Scripting Vulnerability in JP1/Operations Analytics
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2017-132/index.html

+ hitachi-sec-2017-132 JP1/Operations Analyticsにおけるクロスサイトスクリプティングの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2017-132/index.html

+ PHP 7.2.0 Released
http://php.net/ChangeLog-7.php#7.2.0

+ JVNVU#113765 Apple macOS High Sierra に無効化されているアカウントに対する認証回避の問題
http://jvn.jp/vu/JVNVU113765/
CVE-2017-13872

+ Microsoft Windows 10 Creators Update 1703 WARBIRD NtQuerySystemInformation Kernel Local Privilege Escalation
https://cxsecurity.com/issue/WLB-2017110160

+ Mac OS X 10.13.1 Root Privilege Escalation
https://cxsecurity.com/issue/WLB-2017110159

AWSファンクション毎の同時実行数の上限設定
https://aws.amazon.com/jp/blogs/news/set-concurrency-limits-on-individual-aws-lambda-functions/

インターネット再生計画
ネットに入れない11億人、ブロックチェーン個人認証が救う!?
http://itpro.nikkeibp.co.jp/atcl/column/17/111000513/111000003/?ST=security&itp_list_theme

JVN#78501037 Movable Type 用プラグイン A-Member および A-Reserve における SQL インジェクションの脆弱性
http://jvn.jp/jp/JVN78501037/

JVN#98295787 ワイヤレスモバイルストレージ「デジ蔵 ShAirDisk」PTW-WMS1 における複数の脆弱性
http://jvn.jp/jp/JVN98295787/

0 件のコメント:

コメントを投稿