2020年3月23日月曜日

23日 月曜日、赤口

+ phpMyAdmin 4.9.5 and 5.0.2 are released
https://www.phpmyadmin.net/news/2020/3/21/phpmyadmin-495-and-502-are-released/

+ Linux kernel 5.5.11, 5.4.27, 4.19.112, 4.14.174, 4.9.217, 4.4.217 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.11
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.27
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.112
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.174
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.217
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.217

+ UPDATE: VMSA-2020-0005.1 VMware Workstation, Fusion, VMware Remote Console and Horizon Client updates address privilege escalation and denial-of-service vulnerabilities (CVE-2020-3950, CVE-2020-3951)
https://www.vmware.com/security/advisories/VMSA-2020-0005.html

+ UPDATE: VMSA-2020-0004.1 VMware Horizon Client, VMRC, VMware Workstation and Fusion updates address use-after-free and privilege escalation vulnerabilities (CVE-2019-5543, CVE-2020-3947, CVE-2020-3948)
https://www.vmware.com/security/advisories/VMSA-2020-0004.html

+ RHSA-2020:0898 Important: python-imaging security update
https://access.redhat.com/errata/RHSA-2020:0898
CVE-2020-5312

+ RHSA-2020:0896 Important: icu security update
https://access.redhat.com/errata/RHSA-2020:0896
CVE-2020-10531

+ RHSA-2020:0892 Important: zsh security update
https://access.redhat.com/errata/RHSA-2020:0892
CVE-2019-20044

+ RHSA-2020:0905 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:0905
CVE-2019-20503
CVE-2020-6805
CVE-2020-6806
CVE-2020-6807
CVE-2020-6811
CVE-2020-6812
CVE-2020-6814

+ RHSA-2020:0897 Important: icu security update
https://access.redhat.com/errata/RHSA-2020:0897
CVE-2020-10531

+ RHSA-2020:0889 Important: slirp4netns security update
https://access.redhat.com/errata/RHSA-2020:0889
CVE-2019-14378
CVE-2019-15890
CVE-2020-7039
CVE-2020-8608

+ RHSA-2020:0903 Important: zsh security update
https://access.redhat.com/errata/RHSA-2020:0903
CVE-2019-20044

+ RHSA-2020:0902 Important: icu security update
https://access.redhat.com/errata/RHSA-2020:0902
CVE-2020-10531

+ Apache Tomcat 7.0.103 Released
http://tomcat.apache.org/tomcat-7.0-doc/changelog.html#Tomcat_7.0.103_(violetagg)

+ FreeBSD-SA-20:09.ntp Multiple denial of service in ntpd
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:09.ntp.asc

+ FreeBSD-SA-20:08.jail Kernel memory disclosure with nested jails
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:08.jail.asc
CVE-2020-7453

+ FreeBSD-SA-20:07.epair Incorrect user-controlled pointer use in epair
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:07.epair.asc
CVE-2020-7452

+ FreeBSD-SA-20:06.if_ixl_ioctl Insufficient ixl(4) ioctl(2) privilege checking
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:06.if_ixl_ioctl.asc
CVE-2019-15877

+ FreeBSD-SA-20:05.if_oce_ioctl Insufficient oce(4) ioctl(2) privilege checking
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:05.if_oce_ioctl.asc
CVE-2019-15876

+ FreeBSD-SA-20:04.tcp TCP IPv6 SYN cache kernel information disclosure
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:04.tcp.asc
CVE-2020-7451

+ PHP 7.4.4, 7.3.16, 7.2.29 released
https://www.php.net/ChangeLog-7.php#7.4.4
https://www.php.net/ChangeLog-7.php#7.3.16
https://www.php.net/ChangeLog-7.php#7.2.29

+ phpMyadminの脆弱性情報(Moderate: CVE-2020-10802, CVE-2020-10803, CVE-2020-10804 )
https://security.sios.com/vulnerability/phpmyadmin-security-vulnerability-20200322.html
CVE-2020-10802
CVE-2020-10803
CVE-2020-10804

VU#425163 Machine learning classifiers trained via gradient descent are vulnerable to arbitrary misclassification attack
https://www.kb.cert.org/vuls/id/425163/

SODが顧客情報流出の経緯を公表、購入や視聴の履歴が閲覧可能な状態だった
https://xtech.nikkei.com/atcl/nxt/news/18/07370/?ST=nxt_thmit_security

香川県ゲーム条例は通信の秘密を侵害しない?サイトブロッキング問題との違いは
https://xtech.nikkei.com/atcl/nxt/column/18/00001/03788/?ST=nxt_thmit_security

SODが顧客情報を流出、原因と人数は「調査中」
https://xtech.nikkei.com/atcl/nxt/news/18/07360/?ST=nxt_thmit_security

0 件のコメント:

コメントを投稿