2020年11月24日火曜日

24日 火曜日、先勝

+ CESA-2020:5083 Moderate CentOS 7 microcode_ctl Security Update
https://lwn.net/Articles/837743/

+ CESA-2020:5099 Critical CentOS 7 firefox Security Update
https://lwn.net/Articles/837876/

+ VMware Workstation 15.5.7
https://my.vmware.com/jp/web/vmware/downloads/info/slug/desktop_end_user_computing/vmware_workstation_player/15_0#product_downloads

+ VU#724367 VMware Workspace ONE Access and related components are vulnerable to command injection
https://www.kb.cert.org/vuls/id/724367
CVE-2020-4006

+Linux kernel 5.9.10, 5.4.79, 4.19.159, 4.14.208, 4.9.245, 4.4.245 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.10
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.79
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.159
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.208
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.245
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.245

+ VMSA-2020-0027 VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address command injection vulnerability
https://www.vmware.com/security/advisories/VMSA-2020-0027.html
CVE-2020-4006

+ VMSA-2020-0026 VMware ESXi, Workstation and Fusion updates address use-after-free and privilege escalation vulnerabilities (CVE-2020-4004, CVE-2020-4005)
https://www.vmware.com/security/advisories/VMSA-2020-0026.html
CVE-2020-4004
CVE-2020-4005

+ VMSA-2020-0025 VMware SD-WAN Orchestrator updates address multiple security vulnerabilities (CVE-2020-3984, CVE-2020-3985, CVE-2020-4000, CVE-2020-4001, CVE-2020-4002 ,CVE-2020-4003)
https://www.vmware.com/security/advisories/VMSA-2020-0025.html
CVE-2020-3984
CVE-2020-3985
CVE-2020-4000
CVE-2020-4001
CVE-2020-4002
CVE-2020-4003

+ Linux Kernelのfbconでバッファオーバー読み込みの脆弱性(CVE-2020-28974)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201124.html
CVE-2020-28974

+ Linux Kernelのfbconでのバッファオーバー読み込みの脆弱性(Moderate: CVE-2020-28915)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201118.html
CVE-2020-28915

+ Apache Tomcat AJP Ghostcat File Read/Inclusion (Metasploit)
https://cxsecurity.com/issue/WLB-2020110171

JVN#26835001 セイコーエプソン製の複数製品のインストーラにおける DLL 読み込みに関する脆弱性
http://jvn.jp/jp/JVN26835001/index.html

JVNVU#95980140 三菱電機製 MELSEC iQ-R シリーズにおけるリソース枯渇の脆弱性
http://jvn.jp/vu/JVNVU95980140/index.html

JVN#90729322 Hibernate ORM における SQL インジェクションの脆弱性
http://jvn.jp/jp/JVN90729322/index.html

著名人アカウントなど130件乗っ取り リモートワークの隙を突かれる
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/111600068/?ST=nxt_thmit_security

ドメイン登録事業者へのサイバー攻撃が仮想通貨交換所に影響、メールの盗聴被害
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600089/?ST=nxt_thmit_security

パスワード付きファイルの何が問題なのか、今こそ「PPAP」との決別を
https://xtech.nikkei.com/atcl/nxt/column/18/00676/112100065/?ST=nxt_thmit_security

ネット中傷被害者を早期に救え、新たな裁判手続きには期待と慎重論が交差
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04864/?ST=nxt_thmit_security

三菱電機のMicrosoft 365に不正アクセス、取引先情報8635件流出
https://xtech.nikkei.com/atcl/nxt/news/18/09168/?ST=nxt_thmit_security

「パスワード別送」は推奨していない、JIPDECが声明
https://xtech.nikkei.com/atcl/nxt/news/18/09164/?ST=nxt_thmit_security

イベント管理のPeatixに不正アクセス、最大677万件の顧客情報が流出
https://xtech.nikkei.com/atcl/nxt/news/18/09162/?ST=nxt_thmit_security

2020年11月20日金曜日

20日 金曜日、先負

+ Postgresql ODBC Driver 13.00 released
https://www.postgresql.org/ftp/odbc/versions/msi/

+ CESA-2020:5083 Moderate CentOS 7 microcode_ctl Security Update
https://lwn.net/Articles/837743/

+ CESA-2020:5003 Low CentOS 7 fence-agents Security Update
https://lwn.net/Articles/837739/

+ CESA-2020:5021 Moderate CentOS 7 qt Security Update
https://lwn.net/Articles/837746/

+ CESA-2020:5021 Moderate CentOS 7 qt5-qtbase Security Update
https://lwn.net/Articles/837747/

+ CESA-2020:5011 Moderate CentOS 7 bind Security Update
https://lwn.net/Articles/837737/

+ CESA-2020:5023 Moderate CentOS 7 kernel Security Update
https://lwn.net/Articles/837740/

+ CESA-2020:5020 Low CentOS 7 tomcat Security Update
https://lwn.net/Articles/837749/

+ CESA-2020:5004 Low CentOS 7 resource-agents Security Update
https://lwn.net/Articles/837748/

+ CESA-2020:5040 Moderate CentOS 7 libvirt Security Update
https://lwn.net/Articles/837742/

+ CESA-2020:5009 Moderate CentOS 7 python Security Update
https://lwn.net/Articles/837744/

+ CESA-2020:5002 Moderate CentOS 7 curl Security Update
https://lwn.net/Articles/837738/

+ CESA-2020:5012 Moderate CentOS 7 librepo Security Update
https://lwn.net/Articles/837741/

+ CESA-2020:5010 Moderate CentOS 7 python3 Security Update
https://lwn.net/Articles/837745/

JVNVU#95980140 三菱電機製 MELSEC iQ-R シリーズにおけるリソース枯渇の脆弱性
http://jvn.jp/vu/JVNVU95980140/index.html

JVN#90729322 Hibernate ORM における SQL インジェクションの脆弱性
http://jvn.jp/jp/JVN90729322/index.html

国内DX投資は2030年度に3兆円超 けん引役は交通・運輸業界
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/111000075/?ST=nxt_thmit_security

著名人アカウントなど130件乗っ取り、知られざるツイッターハックの全容
https://xtech.nikkei.com/atcl/nxt/column/18/01157/111700023/?ST=nxt_thmit_security

freeeがパスワード付きファイルのメール受信廃止を宣言
https://xtech.nikkei.com/atcl/nxt/news/18/09154/?ST=nxt_thmit_security

マイナンバーカードのパスワード初期化、2021年秋にコンビニで可能に
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04856/?ST=nxt_thmit_security

2020年11月19日木曜日

19日 木曜日、友引

+ RHSA-2020:5146 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:5146
CVE-2020-26950

+ Mozilla Thunderbird 78.5.0 released
https://www.thunderbird.net/en-US/thunderbird/78.5.0/releasenotes/

+ Linux kernel 5.9.9, 5.4.78, 4.19.158, 4.14.207, 4.9.244, 4.4.244 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.9
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.78
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.158
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.207
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.244
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.244

+ Apache Tomcat 9.0.40, 8.5.60 released
http://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.40_(markt)
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.60_(markt)

+ JVNVU#96249940 トレンドマイクロ株式会社製ウイルスバスター クラウドにおける任意のファイルが削除可能な脆弱性
http://jvn.jp/vu/JVNVU96249940/index.html
CVE-2020-25775

+ Linux Kernelのfbconでのバッファオーバー読み込みの脆弱性(Moderate: CVE-2020-28915)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201118.html
CVE-2020-28915

An update on our Gitforge
https://blog.centos.org/2020/11/an-update-on-our-gitforge/

JVNVU#94180712 複数の Sensormatic Electronics 製品に不適切な認可処理の脆弱性
http://jvn.jp/vu/JVNVU94180712/index.html

JVNVU#91732260 Paradox 製 IP150 に複数の脆弱性
http://jvn.jp/vu/JVNVU91732260/index.html

JVNVU#96484028 Real Time Automation 製 499ES EtherNet/IP Adaptor Source Code にスタックベースのバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU96484028/index.html

JVNVU#99979220 Schneider Electric 製 Interactive Graphical SCADA System (IGSS) に複数の脆弱性
http://jvn.jp/vu/JVNVU99979220/index.html

JVN#94245475 Movable Type Premium におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN94245475/index.html

東建コーポレーションで不正アクセス被害、個人情報65万件が流出か
https://xtech.nikkei.com/atcl/nxt/news/18/09143/?ST=nxt_thmit_security

2020年11月18日水曜日

18日 水曜日、先勝

+ About the security content of iTunes 12.11 for Windows
https://support.apple.com/ja-jp/HT211933
CVE-2020-10002
CVE-2020-27912
CVE-2020-27917
CVE-2020-27911
CVE-2020-27918
CVE-2020-27895

+ Google Chrome 87.0.4280.66 released
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_17.html

+ Mozilla Firefox 83.0 released
https://www.mozilla.org/en-US/firefox/83.0/releasenotes/

+ Mozilla Foundation Security Advisory 2020-50 Security Vulnerabilities fixed in Firefox 83
https://www.mozilla.org/en-US/security/advisories/mfsa2020-50/
CVE-2020-26951
CVE-2020-26952
CVE-2020-16012
CVE-2020-26953
CVE-2020-26954
CVE-2020-26955
CVE-2020-26956
CVE-2020-26957
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-15999
CVE-2020-26961
CVE-2020-26962
CVE-2020-26963
CVE-2020-26964
CVE-2020-26965
CVE-2020-26966
CVE-2020-26967
CVE-2020-26968
CVE-2020-26969

+ Mozilla Foundation Security Advisory 2020-52 Security Vulnerabilities fixed in Thunderbird 78.5
https://www.mozilla.org/en-US/security/advisories/mfsa2020-52/
CVE-2020-26951
CVE-2020-16012
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-15999
CVE-2020-26961
CVE-2020-26965
CVE-2020-26966
CVE-2020-26968

+ UPDATE: Oracle Critical Patch Update Advisory - October 2020
https://www.oracle.com/security-alerts/cpuoct2020.html

+ 2020 年 11 月のセキュリティ更新プログラム
https://msrc.microsoft.com/update-guide/releaseNote/2020-Nov

+ GnuPG 2.2.24 released
https://lists.gnupg.org/pipermail/gnupg-announce/2020q4/000449.html

+ Apache Struts 2.5.20 Double OGNL evaluation
https://cxsecurity.com/issue/WLB-2020110136
CVE-2019-0230
CVE-2020-0230

Announcing RHEL for the Edge
https://access.redhat.com/announcements/5580401

iPhoneに「ウイルス感染」の警告を表示、だましの手口を知らず慌てると窮地に
https://xtech.nikkei.com/atcl/nxt/column/18/00676/111400064/?ST=nxt_thmit_security

バイデン政権発足で「ファーウェイ排除」はどうなる、日本も蚊帳の外ではない
https://xtech.nikkei.com/atcl/nxt/column/18/01474/111700003/?ST=nxt_thmit_security

JVNVU#99880454 KonaWiki3 における複数の脆弱性
http://jvn.jp/vu/JVNVU99880454/index.html

2020年11月17日火曜日

17日 火曜日、赤口

+ Mozilla Firefox 82.0.3 released
https://www.mozilla.org/en-US/firefox/82.0.3/releasenotes/

+ PostgreSQLの脆弱性情報(CVE-2020-25694, CVE-2020-25695, CVE-2020-25696)と新バージョン(9.5.24, 9.6.20, 10.15, 11.10, 12.5, 13.1)
https://security.sios.com/vulnerability/postgresql-security-vulnerability-20201116.html
CVE-2020-25694
CVE-2020-25695
CVE-2020-25696

+ Intel製CPUの脆弱性("Platypus": INTEL-SA-00389)
https://security.sios.com/vulnerability/misc-security-vulnerability-20201116.html
CVE-2020-8694
CVE-2020-8695

UPDATE: JVNVU#94736763 Treck 製 IP スタックに複数の脆弱性
http://jvn.jp/vu/JVNVU94736763/index.html

カプコンから最大35万件の個人情報流出の可能性、サイバー犯罪集団から身代金要求も
https://xtech.nikkei.com/atcl/nxt/news/18/09133/?ST=nxt_thmit_security

ITを核とした「技術覇権」競う米中、バイデン政権下で日本の重要性が増す理由
https://xtech.nikkei.com/atcl/nxt/column/18/01474/111400002/?ST=nxt_thmit_security

2020年11月16日月曜日

16日 月曜日、大安

+ Safari 14.0.1 のセキュリティコンテンツについて
https://support.apple.com/ja-jp/HT211934
CVE-2020-9945
CVE-2020-27918

+ UPDATE: JVNVU#99462952 複数の Apple 製品における脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU99462952/index.html

JVNVU#98911990 BD 製 Alaris 8015 PC Unit および Alaris Systems Manager に不適切な認証の脆弱性
http://jvn.jp/vu/JVNVU98911990/index.html

JVN#44764844 MELSEC iQ-R シリーズシーケンサ CPU ユニットにおけるリソース枯渇の脆弱性
http://jvn.jp/jp/JVN44764844/index.html

JVNVU#97690270 Replay Protected Memory Block (RPMB) プロトコルにリプレイ攻撃対策が不十分な問題
http://jvn.jp/vu/JVNVU97690270/index.html

メルカリの配送サービスでセブンイレブンから発送できない障害、復旧時期は未定
https://xtech.nikkei.com/atcl/nxt/news/18/09128/?ST=nxt_thmit_security

カプコンがランサムウエア被害か、脅迫文や攻撃に使われたとするマルウエアが見つかる
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600088/?ST=nxt_thmit_security

バイデン政権はどう動く、「ねじれ議会」でもGAFA規制が進む可能性
https://xtech.nikkei.com/atcl/nxt/column/18/01474/111300001/?ST=nxt_thmit_security

カプコンから給与明細やパスポートなどのデータ流出か、ランサムウエア被害で
https://xtech.nikkei.com/atcl/nxt/news/18/09120/?ST=nxt_thmit_security

2020年11月13日金曜日

13日 金曜日、赤口

+ RHSA-2020:5099 Critical: firefox security update
https://access.redhat.com/errata/RHSA-2020:5099
CVE-2020-26950

+ RHSA-2020:5100 Critical: firefox security update
https://access.redhat.com/errata/RHSA-2020:5100
CVE-2020-26950

+ About the security content of Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave
https://support.apple.com/ja-jp/HT211946
CVE-2020-27930
CVE-2020-27932
CVE-2020-27950

+ PostgreSQL 13.1, 12.5, 11.10, 10.15, 9.6.20, & 9.5.24 Released!
https://www.postgresql.org/docs/13/release-13-1.html
https://www.postgresql.org/docs/12/release-12-5.html
https://www.postgresql.org/docs/11/release-11-10.html
https://www.postgresql.org/docs/10/release-10-15.html
https://www.postgresql.org/docs/9.6/release-9-6-20.html
https://www.postgresql.org/docs/9.5/release-9-5-24.html

+ Log4j 2.14.0 Released
http://logging.apache.org/log4j/2.x/changes-report.html#a2.14.0

JVN#44764844 MELSEC iQ-R シリーズシーケンサ CPU ユニットにおけるリソース枯渇の脆弱性
http://jvn.jp/jp/JVN44764844/index.html

ルーターとファイアウオールの利用実態、首位に立ったのはあのベンダー
https://xtech.nikkei.com/atcl/nxt/column/18/01464/110500003/?ST=nxt_thmit_security

パソコン大手が力を注ぐ独自セキュリティーソフト、対抗馬はあの会社
https://xtech.nikkei.com/atcl/nxt/column/18/01470/111100003/?ST=nxt_thmit_security

2020年11月12日木曜日

12日 木曜日、大安

+ RHSA-2020:5084 Moderate: microcode_ctl security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:5084
CVE-2020-8696
CVE-2020-8698

+ RHSA-2020:5083 Moderate: microcode_ctl security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:5083
CVE-2020-8695
CVE-2020-8696
CVE-2020-8698

+ RHSA-2020:5056 Moderate: podman security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5056
CVE-2020-14040
CVE-2020-14370

+ RHSA-2020:5055 Moderate: buildah security update
https://access.redhat.com/errata/RHSA-2020:5055
CVE-2020-14040

+ RHSA-2020:5085 Moderate: microcode_ctl security, bug fix and enhancement update
https://access.redhat.com/errata/RHSA-2020:5085
CVE-2020-8695
CVE-2020-8696
CVE-2020-8698

+ Google Chrome 86.0.4240.198 released
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html

+ Mozilla Thunderbird 78.4.3 relea
sed
https://www.thunderbird.net/en-US/thunderbird/78.4.3/releasenotes/

+ Linux kernel 5.9.8, 5.4.77, 4.19.157, 4.14.206, 4.9.243, 4.4.243 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.8
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.77
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.157
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.206
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.243
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.243

+ JVNVU#98002571 Intel 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU98002571/index.html
CVE-2019-11121
CVE-2020-0590
CVE-2020-0587
CVE-2020-0591
CVE-2020-0593
CVE-2020-0588
CVE-2020-0592
CVE-2020-0559
CVE-2020-8676
CVE-2020-8693
CVE-2020-8692
CVE-2020-8690
CVE-2020-8691
CVE-2020-8737
CVE-2020-12312
CVE-2020-8764
CVE-2020-8738
CVE-2020-8740
CVE-2020-8739
CVE-2020-8752
CVE-2020-12297
CVE-2020-12304
CVE-2020-8745
CVE-2020-8744
CVE-2020-8705
CVE-2020-8750
CVE-2020-12303
CVE-2020-12354
CVE-2020-8757
CVE-2020-8756
CVE-2020-8760
CVE-2020-12355
CVE-2020-8755
CVE-2020-8749
CVE-2020-12313
CVE-2020-12318
CVE-2020-12321
CVE-2020-12306
CVE-2020-12307
CVE-2020-12315
CVE-2020-12331
CVE-2020-12336
CVE-2020-12337
CVE-2020-24525
CVE-2020-12323
CVE-2020-12330
CVE-2020-12334
CVE-2020-12335
CVE-2020-12333
CVE-2020-12332
CVE-2020-12325
CVE-2020-12324
CVE-2020-12329
CVE-2020-12338
CVE-2020-12350
CVE-2020-12347
CVE-2020-12345
CVE-2020-12346
CVE-2020-0572
CVE-2020-24456
CVE-2020-0592
CVE-2020-0584
CVE-2020-8677
CVE-2020-8693
CVE-2020-8692
CVE-2020-8690
CVE-2020-8691
CVE-2020-8747
CVE-2020-8746
CVE-2020-8766
CVE-2020-8767
CVE-2020-12314
CVE-2020-12317
CVE-2020-12319
CVE-2020-12322
CVE-2020-12353
CVE-2020-24460
CVE-2020-0575
CVE-2020-12309
CVE-2020-12310
CVE-2020-12311
CVE-2020-8698
CVE-2020-8696
CVE-2020-8737
CVE-2020-8694
CVE-2020-8695
CVE-2020-8753
CVE-2020-8751
CVE-2020-8754
CVE-2020-8761
CVE-2020-8747
CVE-2020-12356
CVE-2020-12308
CVE-2020-12316
CVE-2020-12320
CVE-2020-12328
CVE-2020-12327
CVE-2020-12326
CVE-2020-0573
CVE-2020-8669
CVE-2020-12349
CVE-2020-24454
CVE-2017-13080

+ Microsoft Windows Local Spooler Bypass
https://cxsecurity.com/issue/WLB-2020110086
CVE-2020-1337

全PCが乗っ取られる脆弱性 パッチの適用進まず
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/110500453/?ST=nxt_thmit_security

企業内PCのセキュリティー、内蔵チップによるファームウエア防御が必須な理由
https://xtech.nikkei.com/atcl/nxt/column/18/01470/111000002/?ST=nxt_thmit_security

無線LANアクセスポイントとコントローラーの人気調査、あの2社が強かった
https://xtech.nikkei.com/atcl/nxt/column/18/01464/110500002/?ST=nxt_thmit_security

JVNVU#92857198 Schneider Electric 製 PLC Simulator for EcoStruxure Control Expert に複数の脆弱性
http://jvn.jp/vu/JVNVU92857198/index.html

JVNVU#97890337 複数の OSIsoft 製品に脆弱性
http://jvn.jp/vu/JVNVU97890337/index.html

JVNVU#98046719 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU98046719/index.html

2020年11月11日水曜日

11日 水曜日、仏滅

+ Apache OpenOffice 4.1.8 released
https://cwiki.apache.org/confluence/display/OOOUSERS/AOO+4.1.8+Release+Notes

+ RHSA-2020:5056 Moderate: podman security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5056
CVE-2020-14040
CVE-2020-14370

+ RHSA-2020:5055 Moderate: buildah security update
https://access.redhat.com/errata/RHSA-2020:5055
CVE-2020-14040

+ RHSA-2020:5054 Moderate: skopeo security update
https://access.redhat.com/errata/RHSA-2020:5054
CVE-2020-14040

+ RHSA-2020:5050 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2020:5050
CVE-2020-14385

+ RHSA-2020:5040 Moderate: libvirt security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5040
CVE-2020-25637

+ RHSA-2020:5023 Moderate: kernel security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5023
CVE-2019-20811
CVE-2020-14331

+ RHSA-2020:5021 Moderate: qt and qt5-qtbase security update
https://access.redhat.com/errata/RHSA-2020:5021
CVE-2020-17507

+ RHSA-2020:5020 Low: tomcat security update
https://access.redhat.com/errata/RHSA-2020:5020
CVE-2020-1935

+ RHSA-2020:5012 Moderate: librepo security update
https://access.redhat.com/errata/RHSA-2020:5012
CVE-2020-14352

+ RHSA-2020:5011 Moderate: bind security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5011
CVE-2020-8622
CVE-2020-8623
CVE-2020-8624

+ RHSA-2020:5010 Moderate: python3 security update
https://access.redhat.com/errata/RHSA-2020:5010
CVE-2019-20907
CVE-2020-14422

+ RHSA-2020:5009 Moderate: python security update
https://access.redhat.com/errata/RHSA-2020:5009
CVE-2019-20907

+ RHSA-2020:5003 Low: fence-agents security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5003
CVE-2020-11078

+ RHSA-2020:5002 Moderate: curl security update
https://access.redhat.com/errata/RHSA-2020:5002
CVE-2020-8177

+ Security update available for Adobe Reader Mobile | APSB20-71
https://helpx.adobe.com/security/products/reader-mobile/apsb20-71.html
CVE-2020-24441

+ Security updates available for Adobe Connect | APSB20-69
https://helpx.adobe.com/security/products/connect/apsb20-69.html
CVE-2020-24442
CVE-2020-24443

+ Mozilla Thunderbird 78.4.2 released
https://www.thunderbird.net/en-US/thunderbird/78.4.2/releasenotes/

+ Linux kernel 5.9.7, 5.4.76, 4.19.156, 4.14.205, 4.9.242, 4.4.242 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.7
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.76
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.156
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.205
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.242
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.242

+ OpenLDAP 2.4.56 released
https://www.openldap.org/software/release/changes.html

VU#231329 Replay Protected Memory Block (RPMB) protocol does not adequately defend against replay attacks
https://www.kb.cert.org/vuls/id/231329

米大統領選狙ったランサムウエア ボットネットを潰したMSの「秘策」
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/103000042/?ST=nxt_thmit_security

グーグルとMS、盟主はどちらか 盛り上がる「ゼロトラスト」同盟
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100111/103000037/?ST=nxt_thmit_security

大手パソコンメーカーのセキュリティー競争が激化、製品選びの新基準とは
https://xtech.nikkei.com/atcl/nxt/column/18/01470/111000001/?ST=nxt_thmit_security

恒例のネット機器利用実態調査、スイッチ部門でまさかの首位交代
https://xtech.nikkei.com/atcl/nxt/column/18/01464/110500001/?ST=nxt_thmit_security

2020年11月10日火曜日

10日 火曜日、先負

+ RHSA-2020:4974 Important: chromium-browser security update
https://access.redhat.com/errata/RHSA-2020:4974
CVE-2020-16004
CVE-2020-16005
CVE-2020-16006
CVE-2020-16008
CVE-2020-16009

+ Google Chrome 86.0.4240.193 released
https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_9.html

+ Mozilla Foundation Security Advisory 2020-49 Security Vulnerabilities fixed in Firefox 82.0.3, Firefox ESR 78.4.1, and Thunderbird 78.4.2
https://www.mozilla.org/en-US/security/advisories/mfsa2020-49/
CVE-2020-26950

+ Zabbix 5.2.1 released
https://www.zabbix.com/rn/rn5.2.1

+ CESA-2020:4056 Important CentOS 6 qemu-kvm Security Update
https://lwn.net/Articles/836620/

+ CESA-2020:4946 Important CentOS 6 libX11 Security Update
https://lwn.net/Articles/836619/

+ CESA-2020:4953 Important CentOS 6 xorg-x11-server Security Update
https://lwn.net/Articles/836622/

+ CESA-2020:4330 Important CentOS 6 firefox Security Update
https://lwn.net/Articles/836616/

+ CESA-2020:4182 Important CentOS 6 kernel Security Update
https://lwn.net/Articles/836618/

+ CESA-2020:4348 Moderate CentOS 6 java-1.8.0-openjdk Security Update
https://lwn.net/Articles/836617/

+ CESA-2020:4183 Moderate CentOS 6 bind Security Update
https://lwn.net/Articles/836615/

オラクル製品に緊急対応が必要な脆弱性、管理コンソールを公開したJPサーバーを確認
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600087/?ST=nxt_thmit_security

ゆうちょ銀が不正出金の点検結果を公表、mijicaで14項目のセキュリティー不備
https://xtech.nikkei.com/atcl/nxt/news/18/09092/?ST=nxt_thmit_security

2020年11月9日月曜日

9日 月曜日、友引

+ Mozilla Thunderbird 78.4.1 released
https://www.thunderbird.net/en-US/thunderbird/78.4.1/releasenotes/

+ Postfix stable release 3.5.8 and legacy releases 3.4.18, 3.3.15, 3.2.20
http://www.postfix.org/announcements/postfix-3.5.8.html
http://mirror.postfix.jp/postfix-release/official/postfix-3.5.8.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-3.4.18.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-3.3.15.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-3.2.20.HISTORY

+ JVNVU#99462952 複数の Apple 製品における脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU99462952/index.html

+ JVNVU#92053563 XOOPS 用モジュール XooNIps における複数の脆弱性
http://jvn.jp/vu/JVNVU92053563/index.html

JVNVU#95897894 WECON 製 PLC Editor に複数の脆弱性
http://jvn.jp/vu/JVNVU95897894/index.html

JVNVU#99562395 三菱電機製 GOT1000 シリーズ GT14 モデルにおける複数の脆弱性
http://jvn.jp/vu/JVNVU99562395/index.html

2020年11月6日金曜日

6日 金曜日、大安

+ RHSA-2020:4947 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:4947
CVE-2020-15683
CVE-2020-15969

+ RHSA-2020:4952 Important: freetype security update
https://access.redhat.com/errata/RHSA-2020:4952
CVE-2020-15999

+ RHSA-2020:4913 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:4913
CVE-2020-15683
CVE-2020-15969

+ About the security content of watchOS 7.1
https://support.apple.com/ja-jp/HT211928
CVE-2020-27910
CVE-2020-27916
CVE-2020-10017
CVE-2020-27909
CVE-2020-10003
CVE-2020-27930
CVE-2020-27927
CVE-2020-10002
CVE-2020-27912
CVE-2020-27905
CVE-2020-27950
CVE-2020-9974
CVE-2020-10016
CVE-2020-27932
CVE-2020-27917
CVE-2020-27911
CVE-2020-10010
CVE-2020-27918

+ About the security content of watchOS 6.2.9
https://support.apple.com/ja-jp/HT211944
CVE-2020-27930
CVE-2020-27950
CVE-2020-27932

+ About the security content of watchOS 5.3.9
https://support.apple.com/ja-jp/HT211945
CVE-2020-27930
CVE-2020-27950
CVE-2020-27932

+ About the security content of macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update
https://support.apple.com/ja-jp/HT211947
CVE-2020-27930
CVE-2020-27932
CVE-2020-27950

+ About the security content of tvOS 14.2
https://support.apple.com/ja-jp/HT211930
CVE-2020-27910
CVE-2020-27916
CVE-2020-10017
CVE-2020-27909
CVE-2020-10003
CVE-2020-27927
CVE-2020-10002
CVE-2020-27912
CVE-2020-27905
CVE-2020-9974
CVE-2020-10016
CVE-2020-27917
CVE-2020-27911
CVE-2020-10010
CVE-2020-27918

+ About the security content of iOS 14.2 and iPadOS 14.2
https://support.apple.com/ja-jp/HT211929
CVE-2020-27910
CVE-2020-27916
CVE-2020-27925
CVE-2020-10017
CVE-2020-27909
CVE-2020-10003
CVE-2020-27930
CVE-2020-27927
CVE-2020-10002
CVE-2020-27912
CVE-2020-27905
CVE-2020-27950
CVE-2020-9974
CVE-2020-10016
CVE-2020-27932
CVE-2020-27902
CVE-2020-27917
CVE-2020-27911
CVE-2020-27926
CVE-2020-10010
CVE-2020-10004
CVE-2020-13524
CVE-2020-10011
CVE-2020-27918

+ About the security content of iOS 12.4.9
https://support.apple.com/ja-jp/HT211940
CVE-2020-27929
CVE-2020-27930
CVE-2020-27950
CVE-2020-27932

+ Linux kernel 5.9.6, 5.4.75, 4.19.155, 4.14.204 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.6
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.75
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.155
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.204

+ Samba 4.12.10, 4.11.16 released
https://www.samba.org/samba/history/samba-4.12.10.html
https://www.samba.org/samba/history/samba-4.11.16.html

+ Linux Kernelのvt(virtual console)での脆弱性情報(Moderate: CVE-2020-25668)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201105.html
CVE-2020-25668

+ Trend Micro IMSVA CSRF / XML Injection / SSRF / File Disclosure
https://cxsecurity.com/issue/WLB-2020110030
CVE-2020-27019
CVE-2020-27694
CVE-2020-27016
CVE-2020-27017
CVE-2020-27018
CVE-2020-27693

UPDATE: JVNVU#99562395 三菱電機製 GOT1000 シリーズ GT14 モデルにおける複数の脆弱性
http://jvn.jp/vu/JVNVU99562395/index.html

JVN#57942454 サイボウズ Garoon における不適切な入力確認の脆弱性
http://jvn.jp/jp/JVN57942454/index.html

JVNVU#90224831 複数の三菱電機製 FA 製品における複数の脆弱性
http://jvn.jp/vu/JVNVU90224831/index.html

UPDATE: JVNVU#97662844 三菱電機製 MELSEC iQ-R シリーズの Ethernet ポートにおけるリソース枯渇の脆弱性
http://jvn.jp/vu/JVNVU97662844/index.html

JVN#00414047 スマートフォンアプリ「Studyplus(スタディプラス)」に外部サービスの API キーがハードコードされている問題
http://jvn.jp/jp/JVN00414047/index.html

2020年11月5日木曜日

5日 木曜日、仏滅

+ RHSA-2020:4910 Important: xorg-x11-server security update
https://access.redhat.com/errata/RHSA-2020:4910
CVE-2020-14345
CVE-2020-14346
CVE-2020-14361
CVE-2020-14362

+ RHSA-2020:4909 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:4909
CVE-2020-15683
CVE-2020-15969

+ RHSA-2020:4908 Important: libX11 security update
https://access.redhat.com/errata/RHSA-2020:4908
CVE-2020-14363

+ RHSA-2020:4907 Important: freetype security update
https://access.redhat.com/errata/RHSA-2020:4907
CVE-2020-15999

+ RHSA-2020:4913 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:4913
CVE-2020-15683
CVE-2020-15969

+ RHSA-2020:4685 Important: kernel security update
https://access.redhat.com/errata/RHSA-2020:4685
CVE-2020-24490
CVE-2020-25661
CVE-2020-25662

+ RHSA-2020:4827 Moderate: oniguruma security update
https://access.redhat.com/errata/RHSA-2020:4827
CVE-2019-13225

+ RHSA-2020:4820 Moderate: file-roller security update
https://access.redhat.com/errata/RHSA-2020:4820
CVE-2019-16680
CVE-2020-11736

+ RHSA-2020:4807 Moderate: prometheus-jmx-exporter security update
https://access.redhat.com/errata/RHSA-2020:4807
CVE-2017-18640

+ RHSA-2020:4806 Important: dpdk security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4806
CVE-2020-10722
CVE-2020-10723
CVE-2020-10725
CVE-2020-10726

+ RHSA-2020:4805 Moderate: edk2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4805
CVE-2019-14559

+ RHSA-2020:4799 Moderate: freeradius:3.0 security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4799
CVE-2019-17185

+ RHSA-2020:4766 Moderate: libexif security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4766
CVE-2019-9278
CVE-2020-0093
CVE-2020-0181
CVE-2020-0182
CVE-2020-0198
CVE-2020-12767
CVE-2020-13113
CVE-2020-13114

+ RHSA-2020:4763 Moderate: dovecot security update
https://access.redhat.com/errata/RHSA-2020:4763
CVE-2020-10958
CVE-2020-10967

+ RHSA-2020:4760 Moderate: tcpdump security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4760
CVE-2018-10103
CVE-2018-10105
CVE-2018-14461
CVE-2018-14462
CVE-2018-14463
CVE-2018-14464
CVE-2018-14465
CVE-2018-14466
CVE-2018-14467
CVE-2018-14468
CVE-2018-14469
CVE-2018-14470
CVE-2018-14879
CVE-2018-14880
CVE-2018-14881
CVE-2018-14882
CVE-2018-16227
CVE-2018-16228
CVE-2018-16229
CVE-2018-16230
CVE-2018-16300
CVE-2018-16451
CVE-2018-16452
CVE-2019-15166

+ RHSA-2020:4756 Moderate: varnish:6 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4756
CVE-2019-15892
CVE-2019-20637
CVE-2020-11653

+ RHSA-2020:4751 Moderate: httpd:2.4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4751
CVE-2018-17189
CVE-2019-0196
CVE-2019-0197
CVE-2019-10081
CVE-2019-10082
CVE-2019-10092
CVE-2019-10097
CVE-2019-10098
CVE-2020-1927
CVE-2020-1934

+ RHSA-2020:4743 Moderate: squid:4 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4743
CVE-2019-12520
CVE-2019-12521
CVE-2019-12523
CVE-2019-12524
CVE-2019-12526
CVE-2019-12528
CVE-2019-12529
CVE-2019-12854
CVE-2019-18676
CVE-2019-18677
CVE-2019-18678
CVE-2019-18679
CVE-2019-18860
CVE-2020-8449
CVE-2020-8450
CVE-2020-14058
CVE-2020-15049
CVE-2020-24606

+ RHSA-2020:4847 Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4847
CVE-2015-9251
CVE-2016-10735
CVE-2018-14040
CVE-2018-14042
CVE-2019-8331
CVE-2019-10146
CVE-2019-10179
CVE-2019-10221
CVE-2019-11358
CVE-2020-1721
CVE-2020-11022
CVE-2020-11023
CVE-2020-15720

+ RHSA-2020:4712 Moderate: subversion:1.10 security update
https://access.redhat.com/errata/RHSA-2020:4712
CVE-2018-11782

+ RHSA-2020:4709 Moderate: librsvg2 security update
https://access.redhat.com/errata/RHSA-2020:4709
CVE-2019-20446

+ CVE-2019-20446 Moderate: targetcli security and enhancement update
https://access.redhat.com/errata/RHSA-2020:4697
CVE-2020-13867

+ RHSA-2020:4694 Moderate: container-tools:rhel8 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4694
CVE-2020-10749
CVE-2020-10756
CVE-2020-14040

+ RHSA-2020:4690 Moderate: qt5-qtbase and qt5-qtwebsockets security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4690
CVE-2015-9541
CVE-2018-21035
CVE-2020-0569
CVE-2020-0570
CVE-2020-13962

+ RHSA-2020:4689 Moderate: openwsman security update
https://access.redhat.com/errata/RHSA-2020:4689
CVE-2019-3833

+ RHSA-2020:4687 Moderate: oddjob security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4687
CVE-2020-10737

+ RHSA-2020:4682 Moderate: grafana security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4682
CVE-2018-18624
CVE-2019-19499
CVE-2020-11110
CVE-2020-12052
CVE-2020-12245
CVE-2020-12458
CVE-2020-12459
CVE-2020-13430

+ RHSA-2020:4676 Moderate: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4676
CVE-2019-15890
CVE-2019-20485
CVE-2020-1983
CVE-2020-10703
CVE-2020-14301
CVE-2020-14339

+ RHSA-2020:4670 Moderate: idm:DL1 and idm:client security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4670
CVE-2015-9251
CVE-2016-10735
CVE-2018-14040
CVE-2018-14042
CVE-2018-20676
CVE-2018-20677
CVE-2019-8331
CVE-2019-11358
CVE-2020-1722
CVE-2020-11022

+ RHSA-2020:4667 Moderate: mailman:2.1 security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4667
CVE-2020-12137

+ RHSA-2020:4659 Moderate: gd security update
https://access.redhat.com/errata/RHSA-2020:4659
CVE-2018-14553
CVE-2019-6977
CVE-2019-6978

+ RHSA-2020:4655 Moderate: cyrus-imapd security update
https://access.redhat.com/errata/RHSA-2020:4655
CVE-2019-18928
CVE-2019-19783

+ RHSA-2020:4654 Moderate: python27:2.7 security update
https://access.redhat.com/errata/RHSA-2020:4654
CVE-2019-20907
CVE-2019-20916

+ RHSA-2020:4650 Moderate: cloud-init security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4650
CVE-2020-8631
CVE-2020-8632

+ RHSA-2020:4649 Low: evolution security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4649
CVE-2020-14928

+ RHSA-2020:4647 Moderate: freerdp and vinagre security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4647
CVE-2020-11018
CVE-2020-11019
CVE-2020-11038
CVE-2020-11039
CVE-2020-11040
CVE-2020-11041
CVE-2020-11042
CVE-2020-11043
CVE-2020-11044
CVE-2020-11045
CVE-2020-11046
CVE-2020-11047
CVE-2020-11048
CVE-2020-11049
CVE-2020-11058
CVE-2020-11085
CVE-2020-11086
CVE-2020-11087
CVE-2020-11088
CVE-2020-11089
CVE-2020-11522
CVE-2020-11525
CVE-2020-11526
CVE-2020-13396
CVE-2020-13397

+ RHSA-2020:4643 Low: poppler security update
https://access.redhat.com/errata/RHSA-2020:4643
CVE-2019-14494

+ RHSA-2020:4641 Moderate: python38:3.8 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4641
CVE-2019-20477
CVE-2019-20907
CVE-2020-1747
CVE-2020-8492
CVE-2020-14422

+ RHSA-2020:4638 Low: sysstat security update
https://access.redhat.com/errata/RHSA-2020:4638
CVE-2019-16167

+ RHSA-2020:4634 Moderate: libtiff security update
https://access.redhat.com/errata/RHSA-2020:4634
CVE-2019-17546

+ RHSA-2020:4629 Moderate: libvpx security update
https://access.redhat.com/errata/RHSA-2020:4629
CVE-2019-2126
CVE-2019-9232
CVE-2019-9371
CVE-2019-9433

+ RHSA-2020:4628 Low: libreoffice security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4628
CVE-2020-12802
CVE-2020-12803

+ RHSA-2020:4627 Moderate: SDL security update
https://access.redhat.com/errata/RHSA-2020:4627
CVE-2019-7572
CVE-2019-7573
CVE-2019-7574
CVE-2019-7575
CVE-2019-7576
CVE-2019-7577
CVE-2019-7578
CVE-2019-7635
CVE-2019-7636
CVE-2019-7637
CVE-2019-7638

+ RHSA-2020:4625 Moderate: spamassassin security update
https://access.redhat.com/errata/RHSA-2020:4625
CVE-2018-11805
CVE-2019-12420
CVE-2020-1930
CVE-2020-1931

+ RHSA-2020:4619 Moderate: frr security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4619
CVE-2020-12831

+ RHSA-2020:4599 Moderate: curl security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4599
CVE-2020-8177

+ RHSA-2020:4568 Moderate: libldb security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4568
CVE-2020-10730

+ RHSA-2020:4553 Low: systemd security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4553
CVE-2019-20386

+ RHSA-2020:4547 Low: libpcap security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4547
CVE-2019-15165

+ RHSA-2020:4545 Moderate: libssh security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4545
CVE-2019-14889
CVE-2020-1730

+ RHSA-2020:4542 Moderate: cryptsetup security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4542
CVE-2020-14382

+ RHSA-2020:4539 Moderate: pcre2 security and enhancement update
https://access.redhat.com/errata/RHSA-2020:4539
CVE-2019-20454

+ RHSA-2020:4514 Low: openssl security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4514
CVE-2019-1551

+ RHSA-2020:4508 Moderate: libsolv security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4508
CVE-2019-20387

+ RHSA-2020:4500 Moderate: bind security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4500
CVE-2020-8619
CVE-2020-8622
CVE-2020-8623
CVE-2020-8624

+ RHSA-2020:4497 Moderate: cyrus-sasl security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4497
CVE-2019-19906

+ RHSA-2020:4490 Moderate: gnupg2 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4490
CVE-2019-13050

+ RHSA-2020:4484 Moderate: expat security update
https://access.redhat.com/errata/RHSA-2020:4484
CVE-2018-20843
CVE-2019-15903

+ RHSA-2020:4483 Moderate: opensc security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4483
CVE-2019-15945
CVE-2019-15946
CVE-2019-19479
CVE-2019-19481
CVE-2019-20792

+ RHSA-2020:4482 Moderate: libgcrypt security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4482
CVE-2019-13627

+ RHSA-2020:4481 Moderate: bluez security update
https://access.redhat.com/errata/RHSA-2020:4481
CVE-2020-0556

+ RHSA-2020:4479 Moderate: libxml2 security update
https://access.redhat.com/errata/RHSA-2020:4479
CVE-2019-19956
CVE-2019-20388
CVE-2020-7595

+ RHSA-2020:4469 Low: cups security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4469
CVE-2020-3898

+ RHSA-2020:4465 Low: binutils security update
https://access.redhat.com/errata/RHSA-2020:4465
CVE-2019-17450

+ RHSA-2020:4464 Moderate: libxslt security update
https://access.redhat.com/errata/RHSA-2020:4464
CVE-2019-11068
CVE-2019-18197

+ RHSA-2020:4453 Moderate: vim security update
https://access.redhat.com/errata/RHSA-2020:4453
CVE-2019-20807

+ RHSA-2020:4451 Moderate: GNOME security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4451
CVE-2019-8625
CVE-2019-8710
CVE-2019-8720
CVE-2019-8743
CVE-2019-8764
CVE-2019-8766
CVE-2019-8769
CVE-2019-8771
CVE-2019-8782
CVE-2019-8783
CVE-2019-8808
CVE-2019-8811
CVE-2019-8812
CVE-2019-8813
CVE-2019-8814
CVE-2019-8815
CVE-2019-8816
CVE-2019-8819
CVE-2019-8820
CVE-2019-8823
CVE-2019-8835
CVE-2019-8844
CVE-2019-8846
CVE-2020-3862
CVE-2020-3864
CVE-2020-3865
CVE-2020-3867
CVE-2020-3868
CVE-2020-3885
CVE-2020-3894
CVE-2020-3895
CVE-2020-3897
CVE-2020-3899
CVE-2020-3900
CVE-2020-3901
CVE-2020-3902
CVE-2020-9802
CVE-2020-9803
CVE-2020-9805
CVE-2020-9806
CVE-2020-9807
CVE-2020-9843
CVE-2020-9850
CVE-2020-9862
CVE-2020-9893
CVE-2020-9894
CVE-2020-9895
CVE-2020-9915
CVE-2020-9925
CVE-2020-10018
CVE-2020-11793
CVE-2020-14391
CVE-2020-15503

+ RHSA-2020:4445 Moderate: librabbitmq security update
https://access.redhat.com/errata/RHSA-2020:4445
CVE-2019-18609

+ RHSA-2020:4444 Moderate: glibc security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4444
CVE-2020-1751
CVE-2020-1752
CVE-2020-10029

+ RHSA-2020:4443 Moderate: libarchive security update
https://access.redhat.com/errata/RHSA-2020:4443
CVE-2019-19221

+ RHSA-2020:4442 Moderate: sqlite security update
https://access.redhat.com/errata/RHSA-2020:4442
CVE-2019-5018
CVE-2019-16168
CVE-2019-20218
CVE-2020-6405
CVE-2020-9327
CVE-2020-13630
CVE-2020-13631
CVE-2020-13632

+ RHSA-2020:4436 Low: gnome-software and fwupd security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4436
CVE-2020-10759

+ RHSA-2020:4433 Moderate: python3 security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4433
CVE-2019-16935
CVE-2019-20907
CVE-2020-8492
CVE-2020-14422

+ RHSA-2020:4432 Moderate: python-pip security update
https://access.redhat.com/errata/RHSA-2020:4432
CVE-2019-20916

+ RHSA-2020:4431 Moderate: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4431
CVE-2019-9455
CVE-2019-9458
CVE-2019-12614
CVE-2019-15917
CVE-2019-15925
CVE-2019-16231
CVE-2019-16233
CVE-2019-18808
CVE-2019-18809
CVE-2019-19046
CVE-2019-19056
CVE-2019-19062
CVE-2019-19063
CVE-2019-19068
CVE-2019-19072
CVE-2019-19319
CVE-2019-19332
CVE-2019-19447
CVE-2019-19524
CVE-2019-19533
CVE-2019-19537
CVE-2019-19543
CVE-2019-19767
CVE-2019-19770
CVE-2019-20054
CVE-2019-20636
CVE-2020-0305
CVE-2020-8647
CVE-2020-8648
CVE-2020-8649
CVE-2020-10732
CVE-2020-10751
CVE-2020-10773
CVE-2020-10774
CVE-2020-10942
CVE-2020-11565
CVE-2020-11668
CVE-2020-12465
CVE-2020-12655
CVE-2020-12659
CVE-2020-12770
CVE-2020-12826
CVE-2020-14381
CVE-2020-25641

+ Red Hat Enterprise Linux 8.3 released
https://access.redhat.com/announcements/5532381

+ Mozilla Foundation Security Advisory 2020-48 OAuth session fixation vulnerability in Mozilla VPN
https://www.mozilla.org/en-US/security/advisories/mfsa2020-48/
CVE-2020-15679

+ Linux kernel 5.9.4 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.4

CentOS Community Newsletter, November 2020 (#2011)
https://blog.centos.org/2020/11/centos-community-newsletter-november-2020-2011/

JVNVU#99899290 WAGO 製の 750-88x および 750-352 シリーズにリソース枯渇の脆弱性
http://jvn.jp/vu/JVNVU99899290/index.html

JVNVU#99139582 NEXCOM 製 NIO 50 に複数の脆弱性
http://jvn.jp/vu/JVNVU99139582/index.html

JVNVU#95679259 ARC Informatique 製 PcVue に複数の脆弱性
http://jvn.jp/vu/JVNVU95679259/index.html

JVN#57942454 サイボウズ Garoon における不適切な入力確認の脆弱性
http://jvn.jp/jp/JVN57942454/index.html

2020年11月4日水曜日

4日 水曜日、先負

+ Samba 4.13.2 Available for Download
https://www.samba.org/samba/history/samba-4.13.2.html

マルウエアのサンドボックス回避術
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/102100012/?ST=nxt_thmit_security

iPhone画面がアイコンで埋め尽くされる、実は危ない「構成プロファイル」
https://xtech.nikkei.com/atcl/nxt/column/18/00676/102900062/?ST=nxt_thmit_security

仮想通貨を狙う攻撃者がクラウドストレージを装ったフィッシングを発信する理由
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600086/?ST=nxt_thmit_security

2020年11月2日月曜日

2日 月曜日、先勝

+ Linux kernel 5.9.3, 5.8.18, 5.4.74, 4.19.154 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.3
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.18
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.74
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.154

+ UPDATE: Oracle Critical Patch Update Advisory - October 2020
https://www.oracle.com/security-alerts/cpuoct2020.html

+ hitachi-sec-2020-134 Multiple Vulnerabilities in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-134/index.html
+ hitachi-sec-2020-134 Hitachi Command Suite製品, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center製品における複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-134/index.html
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14798
CVE-2020-14803

+ hitachi-sec-2020-133 Multiple Vulnerabilities in Cosminexus
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-133/index.html
+ hitachi-sec-2020-133 Cosminexusにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-133/index.html
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14798
CVE-2020-14803

+ hitachi-sec-2020-132 Vulnerability in JP1/Data Highway
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-132/index.html
+ hitachi-sec-2020-132 JP1/Data Highwayにおける脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-132/index.html
CVE-2019-10092

WANの通信を最適化するSD-WANの正体
[第2回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091700094/102100002/?ST=nxt_thmit_security

UPDATE: JVNVU#94736763 Treck 製 IP スタックに複数の脆弱性
http://jvn.jp/vu/JVNVU94736763/index.html

JVNVU#96558207 三菱電機製 MELSEC iQ-R、Q および L シリーズにおけるリソース枯渇の脆弱性
http://jvn.jp/vu/JVNVU96558207/index.html

JVNVU#92513419 三菱電機製 MELSEC iQ-R シリーズにおける複数の脆弱性
http://jvn.jp/vu/JVNVU92513419/index.html

2020年10月30日金曜日

30日 金曜日、仏滅

+ RHSA-2020:4351 Important: chromium-browser security update
https://access.redhat.com/errata/RHSA-2020:4351
CVE-2020-15999
CVE-2020-16000
CVE-2020-16001
CVE-2020-16002
CVE-2020-16003

+ RHSA-2020:4348 Moderate: java-1.8.0-openjdk security update
https://access.redhat.com/errata/RHSA-2020:4348
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14803

+ RHSA-2020:4330 Important: firefox security update
https://access.redhat.com/errata/RHSA-2020:4330
CVE-2020-15683
CVE-2020-15969

+ Prenotification Security Advisory for Adobe Acrobat and Reader | APSB20-67
https://helpx.adobe.com/security/products/acrobat/apsb20-67.html

+ Wireshark 3.4.0, 3.2.8 released
https://www.wireshark.org/docs/relnotes/wireshark-3.4.0.html
https://www.wireshark.org/docs/relnotes/wireshark-3.2.8.html

+ Linux kernel 5.9.2, 5.8.17, 5.4.73, 4.19.153, 4.14.203, 4.9.241, 4.4.241 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.2
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.17
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.73
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.153
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.203
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.241
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.241

+ Samba 4.13.1, 4.12.9 and 4.11.15 Security Releases Available
https://www.samba.org/samba/history/samba-4.13.1.html
https://www.samba.org/samba/history/samba-4.12.9.html
https://www.samba.org/samba/history/samba-4.11.15.html

+ PHP 7.4.12, 7.3.24 released
https://www.php.net/ChangeLog-7.php#7.4.12
https://www.php.net/ChangeLog-7.php#7.3.24

+ Sambaの複数の脆弱性情報(Medium: CVE-2020-14318, CVE-2020-14323, CVE-2020-14383 ) と修正バージョン(4.13.1, 4.12.9, 4.11.15)
https://security.sios.com/vulnerability/samba-security-vulnerability-20201030.html
CVE-2020-14318
CVE-2020-14323
CVE-2020-14383

Using connection delegation with mitogen for Ansible
https://arrfab.net/posts/2020/Oct/28/using-connection-delegation-with-mitogen-for-ansible/

JVNVU#96558207 三菱電機製 MELSEC iQ-R、Q および L シリーズにおけるリソース枯渇の脆弱性
http://jvn.jp/vu/JVNVU96558207/index.html

JVNVU#92513419 三菱電機製 MELSEC iQ-R シリーズにおける複数の脆弱性
http://jvn.jp/vu/JVNVU92513419/index.html

JVNVU#95194137 JUUKO (SHUN HU Technology) 製産業用無線コントローラに複数の脆弱性
http://jvn.jp/vu/JVNVU95194137/index.html

ネットワーク構成を理解 VPNを基礎から押さえる
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/102000097/102100002/?ST=nxt_thmit_security

役割と設置場所を知る ネットワークの分割も重要
Part1 ネットワーク機器
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/102000097/102000001/?ST=nxt_thmit_security

SaaSの利用を可視化するCASB、ゼロトラスト「仲介人」の役割とは
https://xtech.nikkei.com/atcl/nxt/column/18/01449/102800008/?ST=nxt_thmit_security

日立がクラウド型認証基盤、一度生体情報を登録すればどこでも使える
https://xtech.nikkei.com/atcl/nxt/news/18/09046/?ST=nxt_thmit_security

法人組織の4割超に被害 サイバー攻撃に有効な対策は
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/102200443/?ST=nxt_thmit_security

東証のシステム障害は他人事ではない、デジタル時代の2つのリスクに備えよ
https://xtech.nikkei.com/atcl/nxt/column/18/00849/00035/?ST=nxt_thmit_security

端末やアプリの挙動を遠隔制御、ゼロトラストでMDM/MAMが欠かせぬ理由
https://xtech.nikkei.com/atcl/nxt/column/18/01449/102700006/?ST=nxt_thmit_security

大学関係者がサイバー事故体験ゲームに挑戦、短時間で対応を決める難しさ
https://xtech.nikkei.com/atcl/nxt/column/18/00138/102800659/?ST=nxt_thmit_security

「研究所レベルの攻撃」に耐える消去ソフト、ADECが認証
https://xtech.nikkei.com/atcl/nxt/news/18/09037/?ST=nxt_thmit_security

2020年10月28日水曜日

28日 水曜日、友引

+ Mozilla Firefox 82.0.1 released
https://www.mozilla.org/en-US/firefox/82.0.1/releasenotes/

+ UPDATE: Oracle Critical Patch Update Advisory - October 2020
https://www.oracle.com/security-alerts/cpuoct2020.html

+ FreeBSD 12.2-RELEASE released
https://www.freebsd.org/releases/12.2R/announce.html

+ UPDATE: JVNVU#97307781 Apache Tomcat における HTTP/2 リクエスト処理の不備に起因する情報漏えいの脆弱性
http://jvn.jp/vu/JVNVU97307781/index.html

+ UPDATE: JVNVU#92546061 複数の Apple 製品における脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU92546061/index.html

CPE Weekly: 2020-10-25
https://blog.centos.org/2020/10/cpe-weekly-2020-10-25/

UPDATE: JVNVU#94780329 複数の B. Braun Melsungen 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU94780329/index.html

UPDATE: JVNVU#98112907 B. Braun Melsungen 製 OnlineSuite に複数の脆弱性
http://jvn.jp/vu/JVNVU98112907/index.html

UPDATE: JVNVU#96983217 Rockwell Automation 製 1794-AENT Flex I/O Series B に複数の脆弱性
http://jvn.jp/vu/JVNVU96983217/index.html

UPDATE: JVNVU#93430422 Hitachi ABB Power Grids 製 XMC20 Multiservice-Multiplexer に不適切な認証の脆弱性
http://jvn.jp/vu/JVNVU93430422/index.html

UPDATE: JVNVU#97695305 Advantech 製 WebAccess/SCADA にファイル名やパス名の外部制御の脆弱性
http://jvn.jp/vu/JVNVU97695305/index.html

UPDATE: JVNVU#93185015 Advantech 製 R-SeeNet に SQL インジェクションの脆弱性
http://jvn.jp/vu/JVNVU93185015/index.html

UPDATE: JVNVU#95462510 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU95462510/index.html

VPNのパスワードを狙う「ビッシング」
ワンタイムパスワードでも防げない
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800013/102000034/?ST=nxt_thmit_security

Emotetマルウエアが活動を再開
国内の検出件数が1カ月で5000件超に 攻撃メールの送信元を偽装する
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/102000121/?ST=nxt_thmit_security

2週間で在宅勤務の環境構築 「ゼロトラスト」の思想取り入れる
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600004/102100062/?ST=nxt_thmit_security

大手アダルトサイトの広告にワナ 標的は引退間近のIEとFlash
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/101900041/?ST=nxt_thmit_security

SDN(Software Defined Networking)
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/100800144/?ST=nxt_thmit_security

ゼロトラストの「ターミナル駅」、認証基盤のIAMが重要度を増す理由
https://xtech.nikkei.com/atcl/nxt/column/18/01449/102600005/?ST=nxt_thmit_security

2020年10月27日火曜日

27日 火曜日、先勝

+ RHSA-2020:4350 Moderate: java-1.8.0-openjdk security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4350
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14803

+ RHSA-2020:4347 Moderate: java-1.8.0-openjdk security update
https://access.redhat.com/errata/RHSA-2020:4347
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14803

+ RHSA-2020:4331 Important: kpatch-patch security update
https://access.redhat.com/errata/RHSA-2020:4331
CVE-2020-14385
CVE-2020-14386

+ About the security content of Apple Music 3.4.0 for Android
https://support.apple.com/ja-jp/HT211898
CVE-2020-9982

+ Zabbix 5.0.5, 4.0.26 released
https://www.zabbix.com/rn/rn5.0.5
https://www.zabbix.com/rn/rn4.0.26

+ hitachi-sec-2020-131 Multiple Vulnerabilities in Hitachi Ops Center Analyzer viewpoint
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-131/index.html
+ hitachi-sec-2020-131 Hitachi Ops Center Analyzer viewpointにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-131/index.html
CVE-2020-11110
CVE-2020-12245
CVE-2020-12458
CVE-2020-13379
CVE-2020-13430

+ hitachi-sec-2020-130 Multiple Vulnerabilities in Hitachi Ops Center Common Services
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-130/index.html
+ hitachi-sec-2020-130 Hitachi Ops Center Common Servicesにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-130/index.html
CVE-2019-20330
CVE-2020-7676
CVE-2020-8840
CVE-2020-11022
CVE-2020-11023
CVE-2020-11619
CVE-2020-13444
CVE-2020-13445
CVE-2020-13934
CVE-2020-13935

+ hitachi-sec-2020-129 Authentication Bypass Vulnerability in Hitachi Ops Center Administrator
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-129/index.html
+ hitachi-sec-2020-129 Hitachi Ops Center Administratorにおける認証バイパスの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-129/index.html

+ hitachi-sec-2020-128 Multiple Vulnerabilities in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Common Services
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-128/index.html
+ hitachi-sec-2020-128 Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center AnalyzerおよびHitachi Ops Center Common Servicesにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-128/index.html

+ hitachi-sec-2020-127 Information Disclosure Vulnerability in Hitachi Command Suite
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-127/index.html
+ hitachi-sec-2020-127 Hitachi Command Suite製品における情報露出の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-127/index.html

+ OpenLDAP 2.4.55 released
https://www.openldap.org/software/release/changes.html

VU#760767 Macrium Reflect is vulnerable to privilege escalation due to OPENSSLDIR location
https://www.kb.cert.org/vuls/id/760767

米政府機関がサイバー攻撃の被害に
国土安全保障省が詳細なリポート公表 攻撃手法のトレンドが明らかに
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/102000120/?ST=nxt_thmit_security

相次ぐ国内情報通信系企業への脅迫型DDoS攻撃、その目的とは
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600085/?ST=nxt_thmit_security

脱VPNの切り札、アイデンティティー認識型プロキシー(IAP)の仕組み
https://xtech.nikkei.com/atcl/nxt/column/18/01449/102600004/?ST=nxt_thmit_security

全PCが乗っ取られる脆弱性に即対応を、2カ月たってもパッチ適用が進まない緊急事態
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04766/?ST=nxt_thmit_security

教育現場を襲うランサムウエア
新年度を狙ったサイバー攻撃が相次ぐ 授業の開始時期を遅らせる学校も
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/101900119/?ST=nxt_thmit_security

パソコン選びに新機軸 セキュリティーで競う
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600014/102100074/?ST=nxt_thmit_security

いつでもどこでもデータを保護、情報漏洩防止(DLP)に3つの方式
https://xtech.nikkei.com/atcl/nxt/column/18/01449/102200003/?ST=nxt_thmit_security

押印廃止だけじゃない、都城市の実験に見る行政デジタル化を阻む壁
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04761/?ST=nxt_thmit_security

UPDATE: JVNVU#96827040 MELSEC iQ-R シリーズの Ethernet ポートにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU96827040/index.html

JVNVU#94780329 複数の B. Braun Melsungen 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU94780329/index.html

JVNVU#98112907 B. Braun Melsungen 製 OnlineSuite に複数の脆弱性
http://jvn.jp/vu/JVNVU98112907/index.html

JVNVU#90267651 Chocolatey Boxstarter に DLL 読み込みに関する脆弱性
http://jvn.jp/vu/JVNVU90267651/index.html

2020年10月23日金曜日

23日 金曜日、先負

+ RHSA-2020:4307 Moderate: java-11-openjdk security update
https://access.redhat.com/errata/RHSA-2020:4307
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14803

+ RHSA-2020:4305 Moderate: java-11-openjdk security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4305
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14792
CVE-2020-14796
CVE-2020-14797
CVE-2020-14803

+ Mozilla Thunderbird 78.4.0 released
https://www.thunderbird.net/en-US/thunderbird/78.4.0/releasenotes/

+ UPDATE: Oracle Critical Patch Update Advisory - October 2020
https://www.oracle.com/security-alerts/cpuoct2020.html

VU#208577 Chocolatey Boxstarter vulnerable to privilege escalation due to weak ACLs
https://www.kb.cert.org/vuls/id/208577

OpenSSL 3.0 Alpha7 Release
https://www.openssl.org/blog/blog/2020/10/20/OpenSSL3.0Alpha7/

UPDATE: JVNVU#94736763 Treck 製 IP スタックに複数の脆弱性
http://jvn.jp/vu/JVNVU94736763/index.html

プロキシーサーバーって何だろう?
[第44回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800010/101900033/?ST=nxt_thmit_security

脆弱性を2回に分けて修正 他製品との互換性を考慮
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/101900020/?ST=nxt_thmit_security

ゆうちょ銀行で相次ぐ口座の金銭被害、組織の縦割り体質が真因か
https://xtech.nikkei.com/atcl/nxt/column/18/01157/102100021/?ST=nxt_thmit_security

生体認証決済「Amazon One」への期待と懸念
https://xtech.nikkei.com/atcl/nxt/column/18/01113/102100013/?ST=nxt_thmit_security

ビッグデータ分析でサイバー攻撃を検出、「SIEM」のハードルが下がった理由
https://xtech.nikkei.com/atcl/nxt/column/18/01449/102100002/?ST=nxt_thmit_security

2020年10月22日木曜日

22日 木曜日、友引

+ Mozilla Foundation Security Advisory 2020-47 Security Vulnerabilities fixed in Thunderbird 78.4
https://www.mozilla.org/en-US/security/advisories/mfsa2020-47/
CVE-2020-15969
CVE-2020-15683

+ ISC BIND 9.17.6, 9.16.8, 9.11.24 released
https://downloads.isc.org/isc/bind9/9.17.6/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.16.8/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.11.24/RELEASE-NOTES-bind-9.11.24.html

+ Linux / Unix su Privilege Escalation
https://cxsecurity.com/issue/WLB-2020100135

+ Apache Struts 2 Remote Code Execution
https://cxsecurity.com/issue/WLB-2020100134
CVE-2013-2251

UPDATE: JVNVU#97347936 WECON 製 LeviStudioU に複数の脆弱性
http://jvn.jp/vu/JVNVU97347936/index.html

JVNVU#96983217 Rockwell Automation 製 1794-AENT Flex I/O Series B に複数の脆弱性
http://jvn.jp/vu/JVNVU96983217/index.html

JVNVU#93430422 Hitachi ABB Power Grids 製 XMC20 Multiservice-Multiplexer に不適切な認証の脆弱性
http://jvn.jp/vu/JVNVU93430422/index.html

JVN#31425618 WordPress 用プラグイン Simple Download Monitor における複数の脆弱性
http://jvn.jp/jp/JVN31425618/index.html

ゼロトラストの「門番」、セキュアWebゲートウエイ(SWG)とは
https://xtech.nikkei.com/atcl/nxt/column/18/01449/102000001/?ST=nxt_thmit_security

ドコモ口座事件、不正出金に必要な情報はどこで窃取されたか
https://xtech.nikkei.com/atcl/nxt/column/18/00138/101900652/?ST=nxt_thmit_security

Emotet検出数が前月比8倍の過去最大規模に、フィルタリングを巧妙に回避
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04747/?ST=nxt_thmit_security

2020年10月21日水曜日

21日 水曜日、先勝

+ RHSA-2020:4276 Important: kernel security update
https://access.redhat.com/errata/RHSA-2020:4276
CVE-2020-12351
CVE-2020-12352

+ Google Chrome 86.0.4240.111 released
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html

+ Mozilla Firefox 82.0 released
https://www.mozilla.org/en-US/firefox/82.0/releasenotes/

+ Mozilla Foundation Security Advisory 2020-45 Security Vulnerabilities fixed in Firefox 82
https://www.mozilla.org/en-US/security/advisories/mfsa2020-45/
CVE-2020-15969
CVE-2020-15254
CVE-2020-15680
CVE-2020-15681
CVE-2020-15682
CVE-2020-15683
CVE-2020-15684

+ Security update available for Adobe Creative Cloud Desktop Application | APSB20-68
https://helpx.adobe.com/security/products/creative-cloud/apsb20-68.html
CVE-2020-24422

+ Security Update Available for Adobe InDesign | APSB20-66
https://helpx.adobe.com/security/products/indesign/apsb20-66.html
CVE-2020-24421

+ Security Updates Available for Adobe Media Encoder | APSB20-65
https://helpx.adobe.com/security/products/media-encoder/apsb20-65.html
CVE-2020-24423

+ Security Updates Available for Adobe Premiere Pro | APSB20-64
https://helpx.adobe.com/security/products/premiere_pro/apsb20-64.html
CVE-2020-24424

+ Security updates available for Adobe Photoshop | APSB20-63
https://helpx.adobe.com/security/products/photoshop/apsb20-63.html
CVE-2020-24420

+ Security Updates Available for Adobe After Effects | APSB20-62
https://helpx.adobe.com/security/products/after_effects/apsb20-62.html
CVE-2020-24418
CVE-2020-24419

+ Security updates available for Adobe Animate | APSB20-61
https://helpx.adobe.com/security/products/animate/apsb20-61.html
CVE-2020-9747
CVE-2020-9748
CVE-2020-9749
CVE-2020-9750

+ Security?updates available?for?Marketo | APSB20-60?
https://helpx.adobe.com/security/products/marketo/apsb20-60.html
CVE-2020-24416

+ Security?update available?for Adobe Dreamweaver?| APSB20-55
https://helpx.adobe.com/security/products/dreamweaver/apsb20-55.html
CVE-2020-24425

+ Security Updates Available for Adobe Illustrator | APSB20-53
https://helpx.adobe.com/security/products/illustrator/apsb20-53.html
CVE-2020-24409
CVE-2020-24410
CVE-2020-24411
CVE-2020-24412
CVE-2020-24413
CVE-2020-24414
CVE-2020-24415

+ Oracle Critical Patch Update Advisory - October 2020
https://www.oracle.com/security-alerts/cpuoct2020.html

+ MySQLの脆弱性(Oracle Critical Patch Update Advisory - Oct 2020)
https://security.sios.com/vulnerability/mysql-security-vulnerability-20201021.html

+ Oracle Javaの脆弱性(Oracle Critical Patch Update Advisory - Oct 2020)
https://security.sios.com/vulnerability/java-security-vulnerability-20201021.html

JVNVU#99467898 OneThird CMS におけるローカルファイルインクルージョンの脆弱性
http://jvn.jp/vu/JVNVU99467898/index.html

年間の平均被害額は1億4800万円、サイバー攻撃に有効な対策2つとは
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04742/?ST=nxt_thmit_security

大統領選挙狙うランサムウエアを阻止せよ、ボットネットを潰したMSの「秘策」
https://xtech.nikkei.com/atcl/nxt/column/18/00676/101700061/?ST=nxt_thmit_security

防災メールのなりすまし対策をしている自治体はわずか14%、JIPDECなどが調査
https://xtech.nikkei.com/atcl/nxt/news/18/08988/?ST=nxt_thmit_security

IntelがNANDをSK hynixに売却、相変化メモリーのOptaneは維持
https://xtech.nikkei.com/atcl/nxt/news/18/08985/?ST=nxt_thmit_security

2020年10月20日火曜日

20日 火曜日、赤口

+ RHSA-2020:4272 Moderate: nodejs:12 security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4272
CVE-2020-8116
CVE-2020-8201
CVE-2020-8252
CVE-2020-15095

+ Mozilla Firefox 81.0.2 released
https://www.mozilla.org/en-US/firefox/81.0.2/releasenotes/

+ WinSCP 5.17.8 released
https://ja.osdn.net/projects/sfnet_winscp/downloads/WinSCP/5.17.8/WinSCP-5.17.8-ReadMe.txt/

+ Mozilla Thunderbird 78.3.3 released
https://www.thunderbird.net/en-US/thunderbird/78.3.3/releasenotes/

+ Linux kernel 5.9.1, 5.8.16, 5.4.72, 4.19.152, 4.14.202, 4.9.240, 4.4.240 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.1
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.16
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.72
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.152
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.202
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.240
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.240

+ VMSA-2020-0022 VMware Horizon Client update addresses a denial-of-service vulnerability (CVE-2020-3991)
https://www.vmware.com/security/advisories/VMSA-2020-0022.html
CVE-2020-3991

+ MySQL 8.0.22, 5.7.32, 5.6.50 released
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-22.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-32.html
https://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-50.html

+ Linux Kernelのbpfでの脆弱性情報(Moderate: CVE-2020-27194)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201020.html
CVE-2020-27194

CPE Q3 Achievements 2020
https://blog.centos.org/2020/10/cpe-q3-achievements-2020/

JVNVU#97695305 Advantech 製 WebAccess/SCADA にファイル名やパス名の外部制御の脆弱性
http://jvn.jp/vu/JVNVU97695305/index.html

JVNVU#93185015 Advantech 製 R-SeeNet に SQL インジェクションの脆弱性
http://jvn.jp/vu/JVNVU93185015/index.html

あなたはカモリストに載っていないか、不審な国際電話は詐欺の可能性
https://xtech.nikkei.com/atcl/nxt/column/18/00138/101300649/?ST=nxt_thmit_security

攻撃者の要求に応じなかったランサムウエア感染の建設会社、その被害の全容
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600084/?ST=nxt_thmit_security

2020年10月16日金曜日

16日 金曜日、先勝

+ phpMyAdmin 4.9.7 and 5.0.4 are released
https://www.phpmyadmin.net/news/2020/10/15/phpmyadmin-497-and-504-are-released/

+ Oracle Critical Patch Update Pre-Release Announcement - October 2020
https://www.oracle.com/security-alerts/cpuoct2020.html

+ Security Updates Available for Magento | APSB20-59
https://helpx.adobe.com/security/products/magento/apsb20-59.html
CVE-2020-24408
CVE-2020-24402
CVE-2020-24401
CVE-2020-24404
CVE-2020-24405
CVE-2020-24406
CVE-2020-24407
CVE-2020-24403
CVE-2020-24400

+ PostgreSQL JDBC Driver 42.2.18 Released
https://jdbc.postgresql.org/documentation/changelog.html#version_42.2.18

+ 2020 年 10 月のセキュリティ更新プログラム (月例)
https://msrc-blog.microsoft.com/2020/10/13/202010-security-updates/

「IT資格」を取得する意義を問う、技術者345人の本音
https://xtech.nikkei.com/atcl/nxt/column/18/01436/101400006/?ST=nxt_thmit_security

グーグルとMSが盟主の座をかけて激突、「ゼロトラスト同盟」が盛り上がる理由
https://xtech.nikkei.com/atcl/nxt/column/18/00692/101500041/?ST=nxt_thmit_security

クラウド政府共通基盤が稼働、AWSが日本政府に食い込めた真相
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04732/?ST=nxt_thmit_security

未確定の「2回目」給付金かたる偽サイト出現、総務省など注意喚起
https://xtech.nikkei.com/atcl/nxt/news/18/08959/?ST=nxt_thmit_security

2020年10月15日木曜日

15日 木曜日、赤口

+ RHSA-2020:4251 Critical: flash-plugin security update
https://access.redhat.com/errata/RHSA-2020:4251
CVE-2020-9746

+ RHSA-2020:4235 Critical: chromium-browser security update
https://access.redhat.com/errata/RHSA-2020:4235
CVE-2020-6557
CVE-2020-15967
CVE-2020-15968
CVE-2020-15969
CVE-2020-15970
CVE-2020-15971
CVE-2020-15972
CVE-2020-15973
CVE-2020-15974
CVE-2020-15975
CVE-2020-15976
CVE-2020-15977
CVE-2020-15978
CVE-2020-15979
CVE-2020-15980
CVE-2020-15981
CVE-2020-15982
CVE-2020-15983
CVE-2020-15984
CVE-2020-15985
CVE-2020-15986
CVE-2020-15987
CVE-2020-15988
CVE-2020-15989
CVE-2020-15990
CVE-2020-15991
CVE-2020-15992

+ curl 7.73.0 released
https://curl.haxx.se/changes.html#7_73_0

+ Linux kernel 5.9, 5.8.15, 5.4.71, 4.19.151, 4.14.201, 4.9.239, 4.4.239 released
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/?h=v5.9
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.15
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.71
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.151
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.201
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.239
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.239

+ JVNVU#97307781 Apache Tomcat における HTTP/2 リクエスト処理の不備に起因する情報漏えいの脆弱性
http://jvn.jp/vu/JVNVU97307781/index.html
CVE-2020-13943

+ Linux KernelのGENEVEトンネルでの脆弱性情報(Moderate: CVE-2020-25645)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201015.html
CVE-2020-25645

+ Linux Kernelのoverlayfsに関しての脆弱性情報(Moderate: CVE-2020-16120)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201014.html
CVE-2020-16120

JVNVU#95462510 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU95462510/index.html

JVNVU#92374129 Moxa 製 NPort IAW5000A-I/O シリーズに複数の脆弱性
http://jvn.jp/vu/JVNVU92374129/index.html

JVNVU#93774209 LCDS 製 LAquis SCADA に境界外読み取りの脆弱性
http://jvn.jp/vu/JVNVU93774209/index.html

JVNVU#91648232 Flexera InstallShield によって生成されたインストーラに DLL 読み込みに関する脆弱性
http://jvn.jp/vu/JVNVU91648232/index.html

JVNVU#98382209 Fieldcomm Group 製 HARP-IP Developer kit および hipserver にバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU98382209/index.html

JVN#92404841 WordPress 用プラグイン Live Chat ? Live support におけるクロスサイトリクエストフォージェリの脆弱性
http://jvn.jp/jp/JVN92404841/index.html

JVNVU#90263580 Intel 製 BlueZ に複数の脆弱性
http://jvn.jp/vu/JVNVU90263580/index.html

JVNVU#94568336 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU94568336/index.html

ドコモ口座不正、地銀に波紋 ゆうちょ銀被害は5千万円に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/100800440/?ST=nxt_thmit_security

「うっかりミス」でWebサイトの閲覧障害や改ざん被害が発生、対策が必要
https://xtech.nikkei.com/atcl/nxt/column/18/01438/100800003/?ST=nxt_thmit_security

ドコモとゆうちょ銀での不正利用は大事件、セキュリティー無視のお粗末な理由
https://xtech.nikkei.com/atcl/nxt/column/18/00849/00034/?ST=nxt_thmit_security

「AWS資格」が老舗3ベンダーに食い込む、取得意欲は持ち直すのか
https://xtech.nikkei.com/atcl/nxt/column/18/01436/101300005/?ST=nxt_thmit_security

スマートビルへのサイバー攻撃、竹中工務店やNECなどが防御システムの“予行演習”
https://xtech.nikkei.com/atcl/nxt/column/18/00154/01045/?ST=nxt_thmit_security

2020年10月14日水曜日

14日 水曜日、大安

+ Security updates available for Adobe Flash Player | APSB20-58
https://helpx.adobe.com/security/products/flash-player/apsb20-58.html
CVE-2020-9746

CentOS Community Newsletter, October 2020 (#2010)
https://blog.centos.org/2020/10/centos-community-newsletter-october-2020-2010/

JVNVU#92288299 Acronis 製の複数のバックアップソフトウェアに DLL 読み込みに関する脆弱性
http://jvn.jp/vu/JVNVU92288299/index.html

学校で荒れ狂うランサムウエア 遠隔授業狙う攻撃者の卑しい魂胆
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/100500040/?ST=nxt_thmit_security

エモテット(Emotet)
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/092400143/?ST=nxt_thmit_security

繰り返される墨塗りミスからの情報流出、費用をかけずに防ぐ方法
https://xtech.nikkei.com/atcl/nxt/column/18/01438/100800002/?ST=nxt_thmit_security

落ち込む「IT資格の取得意欲」、47種で前回調査からマイナス
https://xtech.nikkei.com/atcl/nxt/column/18/01436/101200004/?ST=nxt_thmit_security

お手軽ながらも本格派、セキュリティー事故体験ゲームの実力
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04716/?ST=nxt_thmit_security

2020年10月13日火曜日

13日 火曜日、仏滅

+ Google Chrome 86.0.4240.80 released
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_12.html

+ Apache Tomcat 9.0.39, 8.5.59 released
http://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.39_(markt)
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.59_(markt)

+ OpenLDAP 2.4.54 released
https://www.openldap.org/software/release/changes.html

+ phpMyadminの脆弱性情報(PMASA-2020-5 : CVE-2020-26934, PMASA-2020-6 : CVE-2020-26935)
https://security.sios.com/vulnerability/phpmyadmin-security-vulnerability-20201013.html
CVE-2020-26934
CVE-2020-26935

+ Apache Tomcatの脆弱性情報(Moderate: CVE-2020-13943)
https://security.sios.com/vulnerability/tomcat-security-vulnerability-20201012.html
CVE-2020-13943

VU#114757 Acronis backup software contains multiple privilege escalation vulnerabilities
https://www.kb.cert.org/vuls/id/114757

個人情報流出事故の原因トップはメールの誤送信、どうやって防ぐか
https://xtech.nikkei.com/atcl/nxt/column/18/01438/100800001/?ST=nxt_thmit_security

Huluで不正ログイン被害、対策を導入しても断続的に発生
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600083/?ST=nxt_thmit_security

新型コロナ禍で「IT資格」保有率が低下、役立ち度に大きな順位変動あり
https://xtech.nikkei.com/atcl/nxt/column/18/01436/100900003/?ST=nxt_thmit_security

2020年10月12日月曜日

12日 月曜日、先負

+ phpMyAdmin 4.9.6 and 5.0.3 are released
https://www.phpmyadmin.net/news/2020/10/10/phpmyadmin-496-and-503-are-released/

+ PostgreSQL JDBC Driver 42.2.17 Released
https://jdbc.postgresql.org/documentation/changelog.html#version_42.2.17

JVNVU#96766957 Sensormatic Electronics 製 American Dynamics victor Web Client に不適切な認可処理の脆弱性
http://jvn.jp/vu/JVNVU96766957/index.html

JVNVU#96827040 MELSEC iQ-R シリーズの Ethernet ポートにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU96827040/index.html

新型コロナで深まる米中分断 菅政権のデジタル政策に影響か
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/100800034/?ST=nxt_thmit_security

SDN(Software Defined Networking)
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600009/100200072/?ST=nxt_thmit_security

2020年10月9日金曜日

9日 金曜日、赤口

ドコモ、ゆうちょ銀での不正利用 大事件である本当の理由
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600007/100100071/?ST=nxt_thmit_security

UPDATE: JVNVU#96827040 MELSEC iQ-R シリーズの Ethernet ポートにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU96827040/index.html

JVN#40400577 トヨタ自動車製 Global TechStream (GTS) におけるバッファオーバーフローの脆弱性
http://jvn.jp/jp/JVN40400577/index.html

2020年10月8日木曜日

8日 木曜日、大安

+ Mozilla Thunderbird 78.3.2 released
https://www.thunderbird.net/en-US/thunderbird/78.3.2/releasenotes/

+ RHSA-2020:4206 Important: chromium-browser security update
https://access.redhat.com/errata/RHSA-2020:4206
CVE-2020-15960
CVE-2020-15961
CVE-2020-15962
CVE-2020-15963
CVE-2020-15964
CVE-2020-15965
CVE-2020-15966

+ RHSA-2020:4187 Important: spice and spice-gtk security update
https://access.redhat.com/errata/RHSA-2020:4187
CVE-2020-14355

+ RHSA-2020:4186 Important: spice and spice-gtk security update
https://access.redhat.com/errata/RHSA-2020:4186
CVE-2020-14355

+ Linux kernel 5.8.14, 5.4.70, 4.19.150 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.14
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.70
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.150

ドコモ口座問題であらわになった「本人確認」の誤解
https://xtech.nikkei.com/atcl/nxt/column/18/00139/100200071/?ST=nxt_thmit_security

2020年10月7日水曜日

7日 水曜日、仏滅

+ RHSA-2020:4080 Important: firefox security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4080
CVE-2020-12422
CVE-2020-12424
CVE-2020-12425
CVE-2020-15648
CVE-2020-15653
CVE-2020-15654
CVE-2020-15656
CVE-2020-15658
CVE-2020-15673
CVE-2020-15676
CVE-2020-15677
CVE-2020-15678

+ Google Chrome 86.0.4240.75 released
https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop.html

+ Mozilla Firefox 81.0.1 released
https://www.mozilla.org/en-US/firefox/81.0.1/releasenotes/

+ About the security content of macOS 10.14.6 Supplemental Update
https://support.apple.com/ja-jp/HT211872

+ Linux kernel 5.8.13, 5.4.69, 4.19.149, 4.14.200, 4.9.238, 4.4.238 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.8.13
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.69
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.149
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.200
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.238
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.238

+ Samba 4.11.14 Available for Download
https://www.samba.org/samba/history/samba-4.11.14.html

+ PHP 7.4.11, 7.3.23, 7.2.34 released
https://www.php.net/ChangeLog-7.php#7.4.11
https://www.php.net/ChangeLog-7.php#7.3.23
https://www.php.net/ChangeLog-7.php#7.2.34

+ JVNVU#95014999 トレンドマイクロ株式会社製ウイルスバスター for Mac に権限昇格の脆弱性
http://jvn.jp/vu/JVNVU95014999/index.html
CVE-2020-25776

+ UPDATE: VNVU#95778184 Microsoft Windows Netlogon Remote Protocol (MS-NRPC) に権限昇格の脆弱性
http://jvn.jp/vu/JVNVU95778184/index.html

JVN#82892096 複数のエレコム製 LAN ルーターにおける OS コマンドインジェクションの脆弱性
http://jvn.jp/jp/JVN82892096/index.html

UPDATE: JVNVU#94736763 Treck 製 IP スタックに複数の脆弱性
http://jvn.jp/vu/JVNVU94736763/index.html

UPDATE: JVNVU#90224831 複数の三菱電機製 FA 製品における複数の脆弱性
http://jvn.jp/vu/JVNVU90224831/index.html

2020年10月1日木曜日

1日 木曜日、仏滅

+ RHSA-2020:4056 Important: qemu-kvm security update
https://access.redhat.com/errata/RHSA-2020:4056
CVE-2020-14364

+ RHSA-2020:4080 Important: firefox security and bug fix update
https://access.redhat.com/errata/RHSA-2020:4080
CVE-2020-12422
CVE-2020-12424
CVE-2020-12425
CVE-2020-15648
CVE-2020-15653
CVE-2020-15654
CVE-2020-15656
CVE-2020-15658
CVE-2020-15673
CVE-2020-15676
CVE-2020-15677
CVE-2020-15678

+ RHSA-2020:4059 Important: virt:rhel security update
https://access.redhat.com/errata/RHSA-2020:4059
CVE-2020-10756
CVE-2020-14364

+ RHSA-2020:4082 Important: squid security update
https://access.redhat.com/errata/RHSA-2020:4082
CVE-2019-12528
CVE-2020-8449
CVE-2020-8450
CVE-2020-15049
CVE-2020-15810
CVE-2020-15811
CVE-2020-24606

+ RHSA-2020:4031 Moderate: freerdp security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:4031
CVE-2020-11018
CVE-2020-11019
CVE-2020-11038
CVE-2020-11039
CVE-2020-11040
CVE-2020-11041
CVE-2020-11042
CVE-2020-11043
CVE-2020-11044
CVE-2020-11045
CVE-2020-11046
CVE-2020-11047
CVE-2020-11048
CVE-2020-11049
CVE-2020-11058
CVE-2020-11085
CVE-2020-11086
CVE-2020-11087
CVE-2020-11088
CVE-2020-11089
CVE-2020-11522
CVE-2020-11525
CVE-2020-11526
CVE-2020-13396
CVE-2020-13397

+ RHSA-2020:3981 Moderate: samba security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:3981
CVE-2019-14907

+ Red Hat Enterprise Linux 7.9 released
https://access.redhat.com/announcements/5440131

JVNVU#92528056 MB Connect line 製 mbCONNECT24 および mymbCONNECT24 に複数の脆弱性
http://jvn.jp/vu/JVNVU92528056/index.html

JVNVU#92593614 B&R Industrial Automation 製 SiteManager および GateManager に複数の脆弱性
http://jvn.jp/vu/JVNVU92593614/index.html

JVN#07426151 InfoCage SiteShell においてサービス実行ファイルが書き換え可能な脆弱性
http://jvn.jp/jp/JVN07426151/index.html

JVNVU#96842058 横河電機製 WideField3 にバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU96842058/index.html

JVNVU#92546061 複数の Apple 製品における脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU92546061/index.html

ゆうちょ銀行で大量の不正出金 2要素認証巡り決済側と齟齬
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/092400431/?ST=nxt_thmit_security

クラウドサービスを安全に利用するネットワーク構成
[第1回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091700094/091700001/?ST=nxt_thmit_security

「安心・安全」の誇りを汚したドコモ 不正利用問題で地銀から恨み節
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100110/092300036/?ST=nxt_thmit_security

VPNへの不正侵入狙うビッシング ワンタイムパスワードで防げない
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/092300039/?ST=nxt_thmit_security

「VPN渋滞」を一気に解消 1週間でテレワーク環境刷新
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600004/092300060/?ST=nxt_thmit_security

スマホもウイルスに感染するの?
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800014/091600035/?ST=nxt_thmit_security

町工場にこそセキュリティー、日立システムズ柴原新社長
https://xtech.nikkei.com/atcl/nxt/column/18/00134/092400235/?ST=nxt_thmit_security