2020年7月13日月曜日

13日 月曜日、先負

+ Mozilla Foundation Security Advisory 2020-28 Security Vulnerabilities fixed in Firefox 78.0.2
https://www.mozilla.org/en-US/security/advisories/mfsa2020-28/

+ Moziila Firefox 78.0.2 released
https://www.mozilla.org/en-US/firefox/78.0.2/releasenotes/

+ CESA-2020:2827 Important CentOS 7 firefox Security Update
https://lwn.net/Articles/825702/

+ CESA-2020:2824 Important CentOS 6 firefox Security Update
https://lwn.net/Articles/825701/

+ Linux kernel 5.7.8, 5.4.51, 4.19.132, 4.14.188, 4.9.230, 4.4.230 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.7.8
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.51
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.132
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.188
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.230
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.230

+ Oracle Critical Patch Update Pre-Release Announcement - July 2020
https://www.oracle.com/security-alerts/cpujul2020.html

+ hitachi-sec-2020-120 Server Side Request Forgery Vulnerability in Hitachi Ops Center Analyzer viewpoint
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-120/index.html

+ hitachi-sec-2020-119 Cross-site Scripting Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-119/index.html

+ hitachi-sec-2020-120 Hitachi Ops Center Analyzer viewpointにおけるServer Side Request Forgeryの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-120/index.html

+ hitachi-sec-2020-119 Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center Analyzerにおけるクロスサイトスクリプティングの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-119/index.html

+ Apache Tomcat 7.0.105 Released
http://tomcat.apache.org/tomcat-7.0-doc/changelog.html#Tomcat_7.0.105_(violetagg)

+ PHP 7.4.8, 7.3.20, 7.2.32 released
https://www.php.net/ChangeLog-7.php#7.4.8
https://www.php.net/ChangeLog-7.php#7.3.20
https://www.php.net/ChangeLog-7.php#7.2.32

JVNVU#97113078 Phoenix Contact 製 Automation Worx Software Suite に複数の脆弱性
http://jvn.jp/vu/JVNVU97113078/index.html

JVNVU#96476381 Rockwell Automation 製 Logix Designer Studio 5000 に XML 外部エンティティ参照の不適切な制限の脆弱性
http://jvn.jp/vu/JVNVU96476381/index.html

JVNVU#91454414 Rockwell Automation 製 FactoryTalk Linx Software に複数の脆弱性
http://jvn.jp/vu/JVNVU91454414/index.html

JVNVU#90376702 F5 Networks 製 BIG-IP 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU90376702/index.html

UPDATE: JVNVU#94736763 Treck 製 IP スタックに複数の脆弱性
http://jvn.jp/vu/JVNVU94736763/index.html

UPDATE: JVNVU#96632139 NETGEAR 製の複数製品にバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU96632139/index.html

JVN#55657988 SHIRASAGI におけるオープンリダイレクトの脆弱性
http://jvn.jp/jp/JVN55657988/index.html

GMOや帝国データも名乗り、社印の電子版「eシール」始動へ
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04303/?ST=nxt_thmit_security

0 件のコメント:

コメントを投稿