2021年2月8日月曜日

8日 月曜日、友引

+ RHSA-2021:0411 Important: flatpak security update
https://access.redhat.com/errata/RHSA-2021:0411
CVE-2021-21261

+ RHSA-2021:0395 Important: RHV-H security, bug fix, enhancement update (redhat-virtualization-host) 4.3.13
https://access.redhat.com/errata/RHSA-2021:0395
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2021-3156

+ Mozilla Firefox 85.0.1 released
https://www.mozilla.org/en-US/firefox/85.0.1/releasenotes/

+ Mozilla Foundation Security Advisory 2021-06 Security Vulnerabilities fixed in Firefox 85.0.1 and Firefox ESR 78.7.1
https://www.mozilla.org/en-US/security/advisories/mfsa2021-06/

+ Prenotification Security Advisory for Adobe Acrobat and Reader | APSB21-09
https://helpx.adobe.com/security/products/acrobat/apsb21-09.html

+ Mozilla Thunderbird 78.7.1 released
https://www.thunderbird.net/en-US/thunderbird/78.7.1/releasenotes/

+ Linux kernel 5.10.14, 5.4.96, 4.19.174, 4.14.220, 4.9.256, 4.4.256 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.14
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.96
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.174
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.220
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.256
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.256

+ hitachi-sec-2021-105 Improper access control vulnerability in JP1/IT Desktop Management 2 - Manager and JP1/NETM/Asset Information Manager
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2021-105/index.html

+ hitachi-sec-2021-104 Cross-site Scripting Vulnerability in Hitachi Application Server Help
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2021-104/index.html

+ hitachi-sec-2021-103 Vulnerability in Hitachi Command Suite, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2021-103/index.html
CVE-2020-14803

+ hitachi-sec-2021-105 JP1/IT Desktop Management 2 - Manager, JP1/NETM/Asset Information Managerにおけるアクセス制御不備による脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2021-105/index.html

+ hitachi-sec-2021-104 Hitachi Application Server ヘルプにおけるクロスサイトスクリプティングの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2021-104/index.html

+ hitachi-sec-2021-103 Hitachi Command Suite製品, Hitachi Automation Director, Hitachi Configuration Manager, Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center製品における脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2021-103/index.html
CVE-2020-14803

+ JVNVU#96493147 sudo にヒープベースのバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU96493147/index.html
CVE-2021-3156

+ Linux Kernelの脆弱性(Important: CVE-2021-20226)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20210207.html
CVE-2021-20226

+ Linux Kernelの脆弱性(Important: CVE-2021-26708)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20210206.html
CVE-2021-26708

JVNVU#93791310 複数の Luxion 製品に脆弱性
http://jvn.jp/vu/JVNVU93791310/index.html

JVNVU#94972291 Horner Automation 製 Cscape に境界外読み取りの脆弱性
http://jvn.jp/vu/JVNVU94972291/index.html

JVN#50470170 WordPress 用プラグイン Name Directory におけるクロスサイトリクエストフォージェリの脆弱性
http://jvn.jp/jp/JVN50470170/index.html

2021年2月5日金曜日

5日 金曜日、大安

+ RHSA-2021:0348 Moderate: glibc security and bug fix update
https://access.redhat.com/errata/RHSA-2021:0348
CVE-2019-25013
CVE-2020-10029
CVE-2020-29573

+ RHSA-2021:0347 Moderate: qemu-kvm security and bug fix update
https://access.redhat.com/errata/RHSA-2021:0347
CVE-2020-13765
CVE-2020-16092

+ RHSA-2021:0343 Moderate: perl security update
https://access.redhat.com/errata/RHSA-2021:0343
CVE-2020-10543
CVE-2020-10878
CVE-2020-12723

+ RHSA-2021:0339 Important: linux-firmware security update
https://access.redhat.com/errata/RHSA-2021:0339
CVE-2020-12321

+ RHSA-2021:0336 Moderate: kernel security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2021:0336
CVE-2020-15436
CVE-2020-35513

+ Google Chrome 88.0.4324.150 released
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop_4.html

+ CESA-2021:0343 Moderate CentOS 7 perl Security Update
https://lwn.net/Articles/845070/

+ CESA-2021:0348 Moderate CentOS 7 glibc Security Update
https://lwn.net/Articles/845068/

+ CESA-2021:0339 Important CentOS 7 linux-firmware Security Update
https://lwn.net/Articles/845069/

+ CESA-2021:0347 Moderate CentOS 7 qemu-kvm Security Update
https://lwn.net/Articles/845071/

+ VU#794544 Heap-Based Buffer Overflow in Sudo
https://www.kb.cert.org/vuls/id/794544
CVE-2021-3156

+ curl 7.75.0 released
https://curl.se/changes.html#7_75_0

+ PHP 8.0.2, 7.4.15, 7.3.27 released
https://www.php.net/ChangeLog-8.php#8.0.2
https://www.php.net/ChangeLog-7.php#7.4.15
https://www.php.net/ChangeLog-7.php#7.3.27

JVN#42252698 パナソニック Video Insight VMS において任意のコードが実行可能な脆弱性
http://jvn.jp/jp/JVN42252698/index.html

ソフトバンク元社員の営業秘密持ち出しは他人事ではない、IT9社の対策は?
https://xtech.nikkei.com/atcl/nxt/column/18/00989/020200045/?ST=nxt_thmit_security

GitHubへのソースコード流出問題が残した教訓、対策は多重下請け構造の管理にあり
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05154/?ST=nxt_thmit_security

2021年2月4日木曜日

4日 木曜日、仏滅

+ Linux kernel 5.10.13, 5.4.95, 4.19.173, 4.14.219, 4.9.255, 4.4.255 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.13
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.95
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.173
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.219
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.255
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.255

+ Apache Tomcat 10.0.2, 9.0.43 released
http://tomcat.apache.org/tomcat-10.0-doc/changelog.html#Tomcat_10.0.2_(markt)
http://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.43_(markt)

+ ClamAV 0.103.1 released
https://blog.clamav.net/2021/02/clamav-01031-patch-release.html

JVNVU#98209799 トレンドマイクロ株式会社製スマートホームスキャナー (Windows 版) に DLL 読み込みに関する脆弱性
http://jvn.jp/vu/JVNVU98209799/index.html

JVNVU#93359735 Rockwell Automation 製 MicroLogix 1400 にバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU93359735/index.html

JVNVU#92618342 Siemens 製 HMI 製品に重要な機能に対する認証の欠如の脆弱性
http://jvn.jp/vu/JVNVU92618342/index.html

日立が脱「PPAP」 暗号化ファイルの添付禁止へ
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/012800489/?ST=nxt_thmit_security

PayPayやd払いも使える「給与デジタル払い」解禁へ、課題とシステムへの影響は?
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05149/?ST=nxt_thmit_security

2021年2月3日水曜日

3日 水曜日、先負

+ About the security content of Safari 14.0.3
https://support.apple.com/ja-jp/HT212152
CVE-2021-1788
CVE-2021-1789
CVE-2021-1799

+ Google Chrome 88.0.4324.146 released
https://chromereleases.googleblog.com/2021/02/stable-channel-update-for-desktop.html

+ dockerパッケージの脆弱性情報(CVE-2021-2184, CVE-2021-2185)
https://security.sios.com/vulnerability/docker-security-vulnerability-20210203.html
CVE-2021-2184
CVE-2021-2185

「ボーナス支給」クリックで炎上 標的型メール訓練は役立つのか
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/012200048/?ST=nxt_thmit_security

「コンフィデンシャル」に注目 ゼロトラスト最後の抜け穴ふさぐ
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100111/012200042/?ST=nxt_thmit_security

セーフモードを悪用するランサムウエア
[第15回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/012200015/?ST=nxt_thmit_security

なぜ認証を巡るセキュリティー事故がなくならないのか、再発防ぐ決め手を探る
https://xtech.nikkei.com/atcl/nxt/column/18/01544/020100003/?ST=nxt_thmit_security

拡大する「セールスフォース設定不備問題」、3分でまるわかり
https://xtech.nikkei.com/atcl/nxt/column/18/00157/020200078/?ST=nxt_thmit_security

GitHub上のソースコード流出問題の被害は5社に、NECとコアも確認
https://xtech.nikkei.com/atcl/nxt/news/18/09574/?ST=nxt_thmit_security

JVNVU#91588948 Adobe ColdFusion にインストールディレクトリの ACL 設定不備による権限昇格の脆弱性
http://jvn.jp/vu/JVNVU91588948/index.html

JVN#38248512 Aterm WF800HP、Aterm WG2600HP および Aterm WG2600HP2 における複数の脆弱性
http://jvn.jp/jp/JVN38248512/index.html

2021年2月2日火曜日

2日 火曜日、友引

+ RHSA-2021:0304 Important: flatpak security update
https://access.redhat.com/errata/RHSA-2021:0304
CVE-2021-21261

+ RHSA-2021:0320 Moderate: Red Hat Single Sign-On 7.4.5 security update on RHEL 8
https://access.redhat.com/errata/RHSA-2021:0320
CVE-2020-10770

+ RHSA-2021:0319 Moderate: Red Hat Single Sign-On 7.4.5 security update on RHEL 7
https://access.redhat.com/errata/RHSA-2021:0319
CVE-2020-10770

+ RHSA-2021:0318 Moderate: Red Hat Single Sign-On 7.4.5 security update on RHEL 6
https://access.redhat.com/errata/RHSA-2021:0318
CVE-2020-10770

+ About the security content of macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave
https://support.apple.com/ja-jp/HT212147
CVE-2021-1761
CVE-2021-1797
CVE-2020-27945
CVE-2021-1760
CVE-2021-1747
CVE-2021-1776
CVE-2021-1759
CVE-2021-1772
CVE-2021-1792
CVE-2021-1761
CVE-2021-1787
CVE-2021-1786
CVE-2020-27937
CVE-2021-1802
CVE-2021-1791
CVE-2021-1790
CVE-2021-1775
CVE-2020-29608
CVE-2021-1758
CVE-2021-1783
CVE-2021-1741
CVE-2021-1743
CVE-2021-1773
CVE-2021-1778
CVE-2021-1736
CVE-2021-1785
CVE-2021-1766
CVE-2021-1818
CVE-2021-1742
CVE-2021-1746
CVE-2021-1754
CVE-2021-1774
CVE-2021-1777
CVE-2021-1793
CVE-2021-1737
CVE-2021-1738
CVE-2021-1744
CVE-2021-1779
CVE-2021-1757
CVE-2020-27904
CVE-2021-1764
CVE-2021-1782
CVE-2021-1750
CVE-2020-29633
CVE-2021-1771
CVE-2021-1762
CVE-2020-29614
CVE-2021-1763
CVE-2021-1767
CVE-2021-1745
CVE-2021-1753
CVE-2021-1768
CVE-2021-1751
CVE-2020-25709
CVE-2020-27938
CVE-2019-20838
CVE-2020-14155
CVE-2020-15358
CVE-2021-1769
CVE-2021-1788
CVE-2021-1765
CVE-2021-1801
CVE-2021-1789
CVE-2021-1871
CVE-2021-1870
CVE-2021-1799

+ VU#125331 Adobe ColdFusion is vulnerable to privilege escalation due to weak ACLs
https://www.kb.cert.org/vuls/id/125331
CVE-2020-10145

+ glibc 2.33 released
https://sourceware.org/pipermail/libc-alpha/2021-February/122207.html

+ JVNVU#99814910 トレンドマイクロ株式会社製ウイルスバスター クラウドのインストーラにおける複数の脆弱性
http://jvn.jp/vu/JVNVU99814910/index.html

End of PHP 5 support
https://mantisbt.org/blog/archives/mantisbt/678

不正アクセスで約3万件漏洩の恐れ 秋学期の授業開始が1週間遅れる
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/012600073/?ST=nxt_thmit_security

誤れば大ごとになる「本人確認」、考え方と設定のポイントとは
https://xtech.nikkei.com/atcl/nxt/column/18/01544/012900002/?ST=nxt_thmit_security

VPN製品に見つかった脆弱性の恐怖再び、パッチ未提供の中で回避策はあるか
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010400099/?ST=nxt_thmit_security

セールスフォース製品「設定不備」による不具合続々、バンダイや日本政府観光局でも
https://xtech.nikkei.com/atcl/nxt/news/18/09570/?ST=nxt_thmit_security

止まらぬ新型コロナ感染者の個人情報流出、1週間で新たに5自治体から
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05130/?ST=nxt_thmit_security

聖マリアンナ医科大学、「Googleグループ」で業務連絡メールが公開状態
https://xtech.nikkei.com/atcl/nxt/news/18/09565/?ST=nxt_thmit_security

東京ガス、オンラインゲームへの不正アクセスで1万365件のメールアドレス流出
https://xtech.nikkei.com/atcl/nxt/news/18/09566/?ST=nxt_thmit_security

「脆弱性に起因するものではない」、セールスフォースが設定不備問題で改めて主張
https://xtech.nikkei.com/atcl/nxt/news/18/09564/?ST=nxt_thmit_security

2021年2月1日月曜日

1日 月曜日、先勝

+ RHSA-2021:0290 Important: firefox security update
https://access.redhat.com/errata/RHSA-2021:0290
CVE-2020-26976
CVE-2021-23953
CVE-2021-23954
CVE-2021-23960
CVE-2021-23964

+ RHSA-2021:0298 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2021:0298
CVE-2020-15685
CVE-2020-26976
CVE-2021-23953
CVE-2021-23954
CVE-2021-23960
CVE-2021-23964

+ RHSA-2021:0288 Important: firefox security update
https://access.redhat.com/errata/RHSA-2021:0288
CVE-2020-26976
CVE-2021-23953
CVE-2021-23954
CVE-2021-23960
CVE-2021-23964

+ Wireshark 3.4.3, 3.2.11 released
https://www.wireshark.org/docs/relnotes/wireshark-3.4.3.html
https://www.wireshark.org/docs/relnotes/wireshark-3.2.11.html

+ FreeBSD-SA-21:02.xenoom Xen guests can triger backend Out Of Memory
https://www.freebsd.org/security/advisories/FreeBSD-SA-21:02.xenoom.asc
CVE-2020-29568

+ FreeBSD-SA-21:01.fsdisclosure Uninitialized kernel stack leaks in several file systems
https://www.freebsd.org/security/advisories/FreeBSD-SA-21:01.fsdisclosure.asc
CVE-2020-25578
CVE-2020-25579

+ Linux kernel 5.10.12, 5.4.94, 4.19.172, 4.14.218 4.9.254, 4.4.254 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.12
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.94
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.172
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.218
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.254
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.254

+ hitachi-sec-2021-102 Vulnerability in Cosminexus
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2021-102/index.html
CVE-2020-14803

+ hitachi-sec-2021-101 Vulnerability in JP1/VERITAS
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2021-101/index.html

+ hitachi-sec-2021-102 Cosminexusにおける脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2021-102/index.html
CVE-2020-14803

+ hitachi-sec-2021-101 JP1/VERITAS製品における脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2021-101/index.html

+ libgcryptの脆弱性情報(Critical: CVE-2021-3345)
https://security.sios.com/vulnerability/libgcrypt-security-vulnerability-20210201.html
CVE-2021-3345

+ Linux Kernelの脆弱性(Moderate: CVE-2021-3347)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20210201.html
CVE-2021-3347

+ qemuの脆弱性情報(Important: CVE-2020-35517)
https://security.sios.com/vulnerability/qemu-security-vulnerability-20210129.html
CVE-2020-35517

「ドコモ口座」問題の舞台裏、銀行と決済サービス事業者が自ら招いた不正出金
https://xtech.nikkei.com/atcl/nxt/column/18/01544/012800001/?ST=nxt_thmit_security

NISCが「セールスフォース製品の設定不備」に注意促す、楽天などで不正アクセス
https://xtech.nikkei.com/atcl/nxt/news/18/09560/?ST=nxt_thmit_security

SMBCに続きNTTデータも被害を確認、広がるGitHub上のコード流出問題
https://xtech.nikkei.com/atcl/nxt/news/18/09557/?ST=nxt_thmit_security

不正利用で停止中の「ドコモ口座」が銀行口座の登録再開へ、まずゆうちょ銀行から
https://xtech.nikkei.com/atcl/nxt/news/18/09556/?ST=nxt_thmit_security

SMBCのソースコード流出で話題騒然、3分でまるわかり「GitHub」
https://xtech.nikkei.com/atcl/nxt/column/18/00157/012900077/?ST=nxt_thmit_security

GitHub上に三井住友銀の一部コードが流出、「事実だがセキュリティーに影響せず」
https://xtech.nikkei.com/atcl/nxt/news/18/09551/?ST=nxt_thmit_security

JVNVU#92618342 Siemens 製 HMI 製品に重要な機能に対する認証の欠如の脆弱性
http://jvn.jp/vu/JVNVU92618342/index.html

JVNVU#98988953 複数の Rockwell Automation 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU98988953/index.html

2021年1月29日金曜日

29日 金曜日、仏滅

+ RHSA-2021:0298 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2021:0298
CVE-2020-15685
CVE-2020-26976
CVE-2021-23953
CVE-2021-23954
CVE-2021-23960
CVE-2021-23964

+ qemuの脆弱性情報(Important: CVE-2020-35517)
https://security.sios.com/vulnerability/qemu-security-vulnerability-20210129.html
CVE-2020-35517

What's new in Red Hat Enterprise Linux 8.3
https://access.redhat.com/announcements/5753171

慶応大学にサイバー攻撃、授業支援システムが狙われた理由
https://xtech.nikkei.com/atcl/nxt/column/18/01157/012700028/?ST=nxt_thmit_security

「sudo」コマンドに管理者権限奪取される脆弱性、利用者は至急更新を
https://xtech.nikkei.com/atcl/nxt/news/18/09543/?ST=nxt_thmit_security

2021年1月28日木曜日

28日 木曜日、先負

+ RHSA-2021:0290 Important: firefox security update
https://access.redhat.com/errata/RHSA-2021:0290
CVE-2020-26976
CVE-2021-23953
CVE-2021-23954
CVE-2021-23960
CVE-2021-23964

+ RHSA-2021:0288 Important: firefox security update
https://access.redhat.com/errata/RHSA-2021:0288
CVE-2020-26976
CVE-2021-23953
CVE-2021-23954
CVE-2021-23960
CVE-2021-23964

+ CESA-2021:0221 Important CentOS 7 sudo Security Update
https://lwn.net/Articles/844156/

+ Linux kernel 5.10.11, 5.4.93, 4.19.171 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.11
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.93
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.171

UPDATE: JVN#41853173 インフォサイエンス製の複数のログ管理ツールにおける OS コマンドインジェクションの脆弱性
http://jvn.jp/jp/JVN41853173/index.html

JVNVU#99473977 Eaton 製 easySoft に複数の脆弱性
http://jvn.jp/vu/JVNVU99473977/index.html

JVNVU#93293369 富士電機製の複数製品に任意コード実行の脆弱性
http://jvn.jp/vu/JVNVU93293369/index.html

DXで変わるセキュリティー環境 多層防御でデータと基盤を守る
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/041400166/012200011/?ST=nxt_thmit_security

部屋の「電球」で盗聴する新手口
光のわずかな振動を音声に変換
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800013/012100037/?ST=nxt_thmit_security

NEWS pickup&digest(2020/12/23~1/12)
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800011/012100039/?ST=nxt_thmit_security

IPAが情報セキュリティーの「10大脅威」を発表、あの攻撃が急浮上
https://xtech.nikkei.com/atcl/nxt/news/18/09536/?ST=nxt_thmit_security

脱ハンコで「マイナンバーカード実印化」目指すクラウドサイン、勝算はあるか
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05112/?ST=nxt_thmit_security

イオンでも不正アクセス、セールスフォース製品の設定不備で
https://xtech.nikkei.com/atcl/nxt/news/18/09526/?ST=nxt_thmit_security

2021年1月27日水曜日

27日 水曜日、友引

+ dnsmasqにおける「DNSpooq」脆弱性の公開について
https://jprs.jp/tech/security/2021-01-25-dnspooq.html
CVE-2020-25681
CVE-2020-25682
CVE-2020-25683
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2020-25687

+ RHSA-2021:0221 Important: sudo security update
https://access.redhat.com/errata/RHSA-2021:0221
CVE-2021-3156

+ RHSA-2021:0218 Important: sudo security update
https://access.redhat.com/errata/RHSA-2021:0218
CVE-2021-3156

+ About the security content of Xcode 12.4
https://support.apple.com/ja-jp/HT212153
CVE-2021-1800

+ About the security content of iCloud for Windows 12.0
https://support.apple.com/ja-jp/HT212145
CVE-2020-29611
CVE-2020-29618
CVE-2020-29617
CVE-2020-29619

+ About the security content of iOS 14.4 and iPadOS 14.4
https://support.apple.com/ja-jp/HT212146
CVE-2021-1782
CVE-2021-1871
CVE-2021-1870

+ About the security content of tvOS 14.4
https://support.apple.com/ja-jp/HT212149
CVE-2021-1782

+ About the security content of watchOS 7.3
https://support.apple.com/ja-jp/HT212148
CVE-2021-1782

+ Mozilla Firefox 85.0 released
https://www.mozilla.org/en-US/firefox/85.0/releasenotes/

+ Mozilla Foundation Security Advisory 2021-03 Security Vulnerabilities fixed in Firefox 85
https://www.mozilla.org/en-US/security/advisories/mfsa2021-03/
CVE-2021-23953
CVE-2021-23954
CVE-2021-23955
CVE-2021-23956
CVE-2021-23957
CVE-2021-23958
CVE-2021-23959
CVE-2021-23960
CVE-2021-23961
CVE-2021-23962
CVE-2021-23963
CVE-2021-23964
CVE-2021-23965

+ WinSCP 5.17.10 released
https://ja.osdn.net/projects/sfnet_winscp/downloads/WinSCP/5.17.10/WinSCP-5.17.10-ReadMe.txt/

+ Zabbix 5.2.4, 5.0.8 4.0.28 released
https://www.zabbix.com/rn/rn5.2.4
https://www.zabbix.com/rn/rn5.0.8
https://www.zabbix.com/rn/rn4.0.28

+ CESA-2021:0162 Important CentOS 7 xstream Security Update
https://lwn.net/Articles/844033/

+ CESA-2021:0153 Moderate CentOS 7 dnsmasq Security Update
https://lwn.net/Articles/844031/

+ CESA-2020:5350 Important CentOS 7 net-snmp Security Update
https://lwn.net/Articles/844032/

+ Mozilla Thunderbird 78.7.0 released
https://www.thunderbird.net/en-US/thunderbird/78.7.0/releasenotes/

+ Mozilla Foundation Security Advisory 2021-05 Security Vulnerabilities fixed in Thunderbird 78.7
https://www.mozilla.org/en-US/security/advisories/mfsa2021-05/
CVE-2021-23953
CVE-2021-23954
CVE-2020-15685
CVE-2020-26976
CVE-2021-23960
CVE-2021-23964

+ UPDATE: Oracle Critical Patch Update Advisory - January 2021
https://www.oracle.com/security-alerts/cpujan2021.html

+ Samba 4.13.4 Available for Download
https://www.samba.org/samba/history/samba-4.13.4.html

+ Sudo 1.9.5p2 released
https://www.sudo.ws/stable.html#1.9.5p2

+ sudoの脆弱性情報(Important: CVE-2021-3156)
https://security.sios.com/vulnerability/sudo-security-vulnerability-20210127.html
CVE-2021-3156

+ OpenLDAPの脆弱性情報(CVE-2020-36221, CVE-2020-36222, CVE-2020-36223, CVE-2020-36224, CVE-2020-36225, CVE-2020-36226, CVE-2020-36227, CVE-2020-36228, CVE-2020-36229, CVE-2020-36230)
https://security.sios.com/vulnerability/openldap-security-vulnerability-20210127.html
CVE-2020-36221
CVE-2020-36222
CVE-2020-36223
CVE-2020-36224
CVE-2020-36225
CVE-2020-36226
CVE-2020-36227
CVE-2020-36228
CVE-2020-36229
CVE-2020-36230

+ MySQLの脆弱性(Oracle Critical Patch Update Advisory - Jan 2021)
https://security.sios.com/vulnerability/mysql-security-vulnerability-20210125.html

+ Oracle Javaの脆弱性(Oracle Critical Patch Update Advisory - Jan 2021)
https://security.sios.com/vulnerability/java-security-vulnerability-20210125.html

大規模なサイバー攻撃演習をオンラインで開催
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/012000131/?ST=nxt_thmit_security

グーグルがゼロトラスト製品「BeyondCorp Enterprise」発表、Chromeでユーザー保護
https://xtech.nikkei.com/atcl/nxt/news/18/09522/?ST=nxt_thmit_security

多要素認証でも防げないクラウド攻撃出現、「最高謝罪責任者」を用意するベンダーも
https://xtech.nikkei.com/atcl/nxt/column/18/00676/011900070/?ST=nxt_thmit_security

埼玉県がコロナ陽性者191人の情報漏洩、ファイル管理と作業ミスが原因
https://xtech.nikkei.com/atcl/nxt/news/18/09518/?ST=nxt_thmit_security

「サプライチェーン攻撃」が全米揺るがす
正規の更新プログラムにマルウエア 米国土安全保障省が緊急指令
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/012000130/?ST=nxt_thmit_security

コロナ感染者の個人情報を「うっかり流出」、地方自治体で相次ぐ事故の理由
https://xtech.nikkei.com/atcl/nxt/column/18/00138/012200715/?ST=nxt_thmit_security

神奈川県コロナ協力金のLINE申請で他人の入力情報が表示される障害、その原因は
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010400098/?ST=nxt_thmit_security

境界線防御の破綻で大被害続出、トレンドマイクロが示すサイバー防御の「その先」とは
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05100/?ST=nxt_thmit_security

JVN#96783542 複数のロジテック製品における複数の脆弱性
http://jvn.jp/jp/JVN96783542/index.html

JVN#98115035 Android アプリ「ELECOM File Manager」におけるディレクトリトラバーサルの脆弱性
http://jvn.jp/jp/JVN98115035/index.html

JVN#47580234 複数のエレコム製品における複数の脆弱性
http://jvn.jp/jp/JVN47580234/index.html

2021年1月25日月曜日

25日 月曜日、赤口

+ Linux kernel 5.10.10, 5.4.92, 4.19.170, 4.14.217, 4.9.253, 4.4.253 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.10
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.92
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.170
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.217
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.253
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.253

+ UPDATE: JVNVU#90340376 Dnsmasq における複数の脆弱性 (DNSpooq)
http://jvn.jp/vu/JVNVU90340376/index.html

+ UPDATE: JVNVU#96491057 複数の組み込み TCP/IP スタックにメモリ管理の不備に起因する複数の脆弱性
http://jvn.jp/vu/JVNVU96491057/index.html

+ Oracle Javaの脆弱性(Oracle Critical Patch Update Advisory - Jan 2021)
https://security.sios.com/vulnerability/java-security-vulnerability-20210125.html
CVE-2020-14803

+ Oracle WebLogic Server 14.1.1.0 Remote Code Execution
https://cxsecurity.com/issue/WLB-2021010172

DMZって何だろう?
[第47回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800010/012000036/?ST=nxt_thmit_security

無関係のWebページが開く 原因はサイトに埋め込んだURL
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/012000023/?ST=nxt_thmit_security

ピコ太郎氏も驚いた「PPAP全面禁止」、3分でまるわかりPPAP
https://xtech.nikkei.com/atcl/nxt/column/18/00157/012200076/?ST=nxt_thmit_security

JVN#38248512 Aterm WF800HP、Aterm WG2600HP および Aterm WG2600HP2 における複数の脆弱性
http://jvn.jp/jp/JVN38248512/index.html

JVNVU#95339074 複数の Delta Electronics 製品に脆弱性
http://jvn.jp/vu/JVNVU95339074/index.html

JVNVU#90896392 Matrikon 製 OPC UA Tunneller における複数の脆弱性
http://jvn.jp/vu/JVNVU90896392/index.html

JVNVU#94008268 M&M Software 製 fdtCONTAINER に信頼性のないデータのデシリアライゼーションの脆弱性
http://jvn.jp/vu/JVNVU94008268/index.html

JVNVU#92444096 TP-Link 製 TL-WR841N V13 (JP) におけるOSコマンドインジェクションの脆弱性
http://jvn.jp/vu/JVNVU92444096/index.html

JVNVU#96738752 三菱電機製 MELFA FR シリーズおよび CR シリーズならびに ASSISTA のロボットコントローラにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU96738752/index.html

2021年1月22日金曜日

22日 金曜日、先負

+ ISC BIND 9.17.9, 9.16.11, 9.11.27 released
https://downloads.isc.org/isc/bind9/9.17.9/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.16.11/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.11.27/RELEASE-NOTES-bind-9.11.27.html

JVNVU#96738752 三菱電機製 MELFA FR シリーズおよび CR シリーズならびに ASSISTA のロボットコントローラにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU96738752/index.html

無料のツールからクラウドサービスまで、ネットワーク監視の始め方
https://xtech.nikkei.com/atcl/nxt/column/18/01525/010800004/?ST=nxt_thmit_security

ID管理も「非集中」へ、米マイクロソフトらが実装中のDIDに注目すべき理由
https://xtech.nikkei.com/atcl/nxt/column/18/01515/122300014/?ST=nxt_thmit_security

DeNA元従業員がカーシェア「Anyca」の顧客データを不正利用、カードローンを申し込み
https://xtech.nikkei.com/atcl/nxt/news/18/09494/?ST=nxt_thmit_security

2021年1月21日木曜日

21日 木曜日、友引

+ ISC BIND 9.17.9 released
https://ftp.isc.org/isc/bind9/9.17.9/CHANGES

楽天、PayPayに不正アクセス セールスフォース製品の設定に不備
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/011400483/?ST=nxt_thmit_security

2021年は自宅ネットが標的に ルーターやWebカメラに注意
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/011400488/?ST=nxt_thmit_security

ネットワーク監視に不可欠のプロトコル、知っておくべきSNMPとテレメトリー
https://xtech.nikkei.com/atcl/nxt/column/18/01525/010800003/?ST=nxt_thmit_security

日立がPPAP全面禁止へ、「秘文」の添付ファイル自動暗号化ツールも既に販売終了
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05086/?ST=nxt_thmit_security

JVNVU#90340376 Dnsmasq における複数の脆弱性 (DNSpooq)
http://jvn.jp/vu/JVNVU90340376/index.html

JVNVU#99865781 複数の Philips 製 Interventional Workstation に OS コマンドインジェクションの脆弱性
http://jvn.jp/vu/JVNVU99865781/index.html

JVNVU#96898747 Reolink 製 P2P Cameras シリーズにおける複数の脆弱性
http://jvn.jp/vu/JVNVU96898747/index.html

2021年1月20日水曜日

20日 水曜日、先勝

+ RHSA-2021:0153 Moderate: dnsmasq security update
https://access.redhat.com/errata/RHSA-2021:0153
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686

+ RHSA-2021:0150 Important: dnsmasq security update
https://access.redhat.com/errata/RHSA-2021:0150
CVE-2020-25681
CVE-2020-25682
CVE-2020-25683
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2020-25687

+ Google Chrome 88.0.4324.96 released
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html

+ VU#434904 Dnsmasq is vulnerable to memory corruption and cache poisoning
https://www.kb.cert.org/vuls/id/434904
CVE-2020-25681
CVE-2020-25682
CVE-2020-25683
CVE-2020-25684
CVE-2020-25685
CVE-2020-25686
CVE-2020-25687

+ Linux kernel 5.10.9, 5.4.91, 4.19.169 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.9
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.91
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.169

+ Oracle Critical Patch Update Advisory - January 2021
https://www.oracle.com/security-alerts/cpujan2021.html

急増する暴露型ランサムウエア 身代金支払いは無駄と言える訳
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/010800047/?ST=nxt_thmit_security

ユニクロが「UNIQLO Pay」でスマホ決済に参入、アプリのQRコード提示で決済完了
https://xtech.nikkei.com/atcl/nxt/news/18/09477/?ST=nxt_thmit_security

JVN#57544707 GROWI におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN57544707/index.html

2021年1月19日火曜日

19日 火曜日、赤口

+ RHSA-2021:0162 Important: xstream security update
https://access.redhat.com/errata/RHSA-2021:0162
CVE-2020-26217

+ CESA-2021:0053 Critical CentOS 7 firefox Security Update
https://lwn.net/Articles/842996/

+ CESA-2021:0087 Critical CentOS 7 thunderbird Security Update
https://lwn.net/Articles/842997/

+ Apache POI 5.0.0 released
https://www.apache.org/dyn/closer.lua/poi/release/RELEASE-NOTES.txt

+ Security Updates Available for Adobe Bridge | APSB21-07
https://helpx.adobe.com/security/products/bridge/apsb21-07.html
CVE-2021-21012
CVE-2021-21013

+ Security hotfix available for Adobe Captivate | APSB21-06
https://helpx.adobe.com/security/products/captivate/apsb21-06.html
CVE-2021-21011

+ Security Update Available for Adobe InCopy | APSB21-05
https://helpx.adobe.com/security/products/incopy/apsb21-05.html
CVE-2021-21010

+ Security updates available for Adobe Campaign Classic | APSB21-04
https://helpx.adobe.com/security/products/campaign/apsb21-04.html
CVE-2021-21009

+ Security updates available for Adobe Animate | APSB21-03
https://helpx.adobe.com/security/products/animate/apsb21-03.html
CVE-2021-21008

+ Security Updates Available for Adobe Illustrator | APSB21-02
https://helpx.adobe.com/security/products/illustrator/apsb21-02.html
CVE-2021-21007

+ Security updates available for Adobe Photoshop | APSB21-01
https://helpx.adobe.com/security/products/photoshop/apsb21-01.html
CVE-2021-21006

+ MySQL 8.0.23, 5.7.33, 5.6.51 released
https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-23.html
https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-33.html
https://dev.mysql.com/doc/relnotes/mysql/5.6/en/news-5-6-51.html

+ OpenLDAP 2.4.57 released
https://www.openldap.org/software/release/changes.html

UPDATE: JVNVU#91685542 Siemens 製品に対するアップデート(2021年1月)
http://jvn.jp/vu/JVNVU91685542/index.html

Windowsコマンドで手軽にネットワーク監視、pingとtracertを使いこなす
https://xtech.nikkei.com/atcl/nxt/column/18/01525/010800002/?ST=nxt_thmit_security

愛知県の芸術祭でメール乗っ取り被害、直後に発表されたメールソフトの脆弱性が関連か
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010400097/?ST=nxt_thmit_security

2021年1月18日月曜日

18日 月曜日、大安

+ Windows DNSの脆弱性情報が公開されました(CVE-2021-1637)
https://jprs.jp/tech/security/2021-01-15-windowsdns.html
CVE-2021-1637

+ Linux kernel 5.10.8, 5.4.90, 4.19.168, 4.14.216, 4.9.252, 4.4.252 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.8
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.90
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.168
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.216
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.252
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.252

+ hitachi-sec-2020-139 Cross-site Scripting Vulnerability in Hitachi Command Suite
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-139/index.html

+ hitachi-sec-2020-139 Hitachi Command Suite製品におけるクロスサイトスクリプティングの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-139/index.html

+ Postfix stable release 3.5.9 and legacy releases 3.4.19, postfix-3.3.16, 3.2.21
http://www.postfix.org/announcements/postfix-3.5.9.html
http://mirror.postfix.jp/postfix-release/official/postfix-3.5.9.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-3.4.19.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-3.3.16.HISTORY
http://mirror.postfix.jp/postfix-release/official/postfix-3.2.21.HISTORY

+ JVNVU#96136392 Apache Tomcat における Java API の実装不備に起因する情報漏えいの脆弱性
http://jvn.jp/vu/JVNVU96136392/index.html
CVE-2021-24122

匿名化した個人データの利活用 48%が企業の販促などに「利用OK」
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/010800079/?ST=nxt_thmit_security

注目のインフラ技術 21年は「ゼロトラスト」
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600014/011300080/?ST=nxt_thmit_security

コロナ禍で狙われる医療機関 サイバー攻撃への対策が急務
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/011400041/?ST=nxt_thmit_security

トラブルが発生してからでは遅すぎる、ネットワーク監視が必要なワケ
https://xtech.nikkei.com/atcl/nxt/column/18/01525/010800001/?ST=nxt_thmit_security

2021年1月15日金曜日

15日 金曜日、友引

+ Oracle Critical Patch Update Pre-Release Announcement - January 2021
https://www.oracle.com/security-alerts/cpujan2021.html

+ Samba 4.12.11 Available for Download
https://www.samba.org/samba/history/samba-4.12.11.html

JVNVU#99904867 ウイルスバスタービジネスセキュリティシリーズにおける複数の脆弱性
http://jvn.jp/vu/JVNVU99904867/index.html

JVNVU#92683420 Apex One およびウイルスバスター コーポレートエディションにおける複数の脆弱性
http://jvn.jp/vu/JVNVU92683420/index.html

JVN#35906450 acmailer における複数の脆弱性
http://jvn.jp/jp/JVN35906450/index.html

UPDATE: JVNVU#90224831 複数の三菱電機製 FA 製品における複数の脆弱性
http://jvn.jp/vu/JVNVU90224831/index.html

2021年1月14日木曜日

14日 木曜日、先勝

+ RHSA-2021:0087 Critical: thunderbird security update
https://access.redhat.com/errata/RHSA-2021:0087
CVE-2020-16044

+ RHSA-2021:0095 Important: dotnet3.1 security and bugfix update
https://access.redhat.com/errata/RHSA-2021:0095
CVE-2021-1723

+ RHSA-2021:0094 Important: dotnet5.0 security and bugfix update
https://access.redhat.com/errata/RHSA-2021:0094
CVE-2021-1723

+ RHSA-2021:0089 Critical: thunderbird security update
https://access.redhat.com/errata/RHSA-2021:0089
CVE-2020-16044

+ Security Updates Available for Adobe Bridge | APSB21-07
https://helpx.adobe.com/security/products/bridge/apsb21-07.html
CVE-2021-21012
CVE-2021-21013

+ Security hotfix available for Adobe Captivate | APSB21-06
https://helpx.adobe.com/security/products/captivate/apsb21-06.html
CVE-2021-21011

+ Security Update Available for Adobe InCopy | APSB21-05
https://helpx.adobe.com/security/products/incopy/apsb21-05.html
CVE-2021-21010

+ Security updates available for Adobe Campaign Classic | APSB21-04
https://helpx.adobe.com/security/products/campaign/apsb21-04.html
CVE-2021-21009

+ Security updates available for Adobe Animate | APSB21-03
https://helpx.adobe.com/security/products/animate/apsb21-03.html
CVE-2021-21008

+ Security Updates Available for Adobe Illustrator | APSB21-02
https://helpx.adobe.com/security/products/illustrator/apsb21-02.html
CVE-2021-21007

+ Security updates available for Adobe Photoshop | APSB21-01
https://helpx.adobe.com/security/products/photoshop/apsb21-01.html
CVE-2021-21006

+ 2021 年 1 月のセキュリティ更新プログラム (月例)
https://msrc-blog.microsoft.com/2021/01/12/202101-security-updates/

JVNVU#99322606 複数の SOOIL Developments 製品に脆弱性
http://jvn.jp/vu/JVNVU99322606/index.html

JVNVU#99870119 Schneider Electric 製 EcoStruxure Power Build - Rapsody に危険なタイプのファイルの無制限アップロードの脆弱性
http://jvn.jp/vu/JVNVU99870119/index.html

JVNVU#91685542 Siemens 製品に対するアップデート(2021年1月)
http://jvn.jp/vu/JVNVU91685542/index.html

UPDATE: JVNVU#97872642 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU97872642/index.html

DCオペレーターを在宅化したSCSK、現場作業をリモートでこなせる理由
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05041/?ST=nxt_thmit_security

2021年1月13日水曜日

13日 水曜日、赤口

+ Gpg4win 3.1.15 released
https://www.gpg4win.org/change-history.html

+ RHSA-2021:0083 Important: Red Hat Ceph Storage 4.2 security and bug fix update
https://access.redhat.com/errata/RHSA-2021:0083
CVE-2020-1971
CVE-2020-13379
CVE-2020-24659

+ RHSA-2021:0057 Important: libpq security update
https://access.redhat.com/errata/RHSA-2021:0057
CVE-2020-25694
CVE-2020-25696

+ Mozilla Thunderbird 78.6.1 released
https://www.thunderbird.net/en-US/thunderbird/78.6.1/releasenotes/

+ Linux kernel 5.10.7, 5.4.89, 4.19.167, 4.14.215, 4.9.251, 4.4.251 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.7
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.89
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.167
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.215
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.251
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.251

+ Sudo 1.9.5p1 released
https://www.sudo.ws/stable.html#1.9.5p1

+ JVN#69635538 SKYSEA Client View のインストーラにおける DLL 読み込みに関する脆弱性
http://jvn.jp/jp/JVN69635538/index.html
CVE-2021-20616

+ sudoの脆弱性情報(Moderate: CVE-2021-23239, CVE-2021-23240)
https://security.sios.com/vulnerability/sudo-security-vulnerability-20210113.html
CVE-2021-23239
CVE-2021-23240

CentOS Community Newsletter, January 2021 (#2101)
https://blog.centos.org/2021/01/centos-community-newsletter-january-2020-2101/?utm_source=rss&utm_medium=rss&utm_campaign=centos-community-newsletter-january-2020-2101

UPDATE: JVN#38752718 IPMI over LAN による RMCP 接続を行う日本電気製の複数製品に認証不備の脆弱性
http://jvn.jp/jp/JVN38752718/index.html

JVNVU#95231601 オムロン製 CX-One に複数の脆弱性
http://jvn.jp/vu/JVNVU95231601/index.html

クラウドストレージ(Cloud Storage)
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/121400152/?ST=nxt_thmit_security

「ボーナス欲しければクリック」、炎上招く標的型メール訓練は本当に役立つのか
https://xtech.nikkei.com/atcl/nxt/column/18/00676/010700069/?ST=nxt_thmit_security

2021年1月12日火曜日

12日 火曜日、先負

+ RHSA-2021:0052 Critical: firefox security update
https://access.redhat.com/errata/RHSA-2021:0052
CVE-2020-16044

+ Mozilla Foundation Security Advisory 2021-02 Security Vulnerabilities fixed in Thunderbird 78.6.1
https://www.mozilla.org/en-US/security/advisories/mfsa2021-02/
CVE-2020-16044

+ Linux kernel 5.10.6, 5.4.88, 4.19.166, 4.14.214, 4.9.250, 4.4.250 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.6
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.88
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.166
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.214
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.250
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.250

+ Sudo 1.9.5 released
https://www.sudo.ws/stable.html#1.9.5

+ Symbolic link attack in SELinux-enabled sudoedit
https://www.sudo.ws/alerts/sudoedit_selinux.html
CVE-2021-23240

JVNVU#94662375 Vital Signs Monitor VC150 における複数の脆弱性
http://jvn.jp/vu/JVNVU94662375/index.html

JVNVU#98810190 Hitachi ABB Power Grids 製 FOX615 Multiservice-Multiplexer に不適切な認証の脆弱性
http://jvn.jp/vu/JVNVU98810190/index.html

JVNVU#99473977 Eaton 製 EASYsoft に複数の脆弱性
http://jvn.jp/vu/JVNVU99473977/index.html

JVNVU#97478563 Delta Electronics CNCSoft-B における複数の脆弱性
http://jvn.jp/vu/JVNVU97478563/index.html

2021年1月8日金曜日

8日 金曜日、大安

+ PHP 8.0.1, 7.3.26, 7.4.14 released
https://www.php.net/ChangeLog-8.php#8.0.1
https://www.php.net/ChangeLog-7.php#7.3.26
https://www.php.net/ChangeLog-7.php#7.4.14

+ Linux Kernelの脆弱性(Moderate: CVE-2020-27835)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20210108.html
CVE-2020-27835

+ Dovecot 2.3.11.3 Denial Of Service
https://cxsecurity.com/issue/WLB-2021010058
CVE-2020-25275
CVE-2020-12100

+ Dovecot 2.3.11.3 Access Bypass
https://cxsecurity.com/issue/WLB-2021010056
CVE-2020-24386

UPDATE: JVN#38752718 IPMI over LAN による RMCP 接続を行う日本電気製の複数製品に認証不備の脆弱性
http://jvn.jp/jp/JVN38752718/index.html

JVNVU#90523924 GE 製 Reason RT43X Clocks シリーズに複数の脆弱性
http://jvn.jp/vu/JVNVU90523924/index.html

JVNVU#94511327 Red Lion 製 Crimson 3.1 における複数の脆弱性
http://jvn.jp/vu/JVNVU94511327/index.html

「コンフィデンシャルコンピューティング」に注目、ゼロトラストの最後の抜け穴ふさぐ
https://xtech.nikkei.com/atcl/nxt/column/18/00692/010700046/?ST=nxt_thmit_security

ネットワーク機器のパスワードがさらされる緊急事態、パッチでしか対処できない理由
https://xtech.nikkei.com/atcl/nxt/column/18/00598/010400096/?ST=nxt_thmit_security

コロナ禍の医療機関を狙う言語道断のサイバー攻撃が増加、対策が急務
https://xtech.nikkei.com/atcl/nxt/column/18/00989/010500043/?ST=nxt_thmit_security

福岡県がコロナ陽性者9500人の情報漏洩、メール誤送信とアクセス権修正ミス重なる
https://xtech.nikkei.com/atcl/nxt/news/18/09429/?ST=nxt_thmit_security

2021年1月7日木曜日

7日 木曜日、仏滅

+ Google Chrome 87.0.4280.141 released
https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop.html

+ Mozilla Foundation Security Advisory 2021-01 Security Vulnerabilities fixed in Firefox 84.0.2, Firefox for Android 84.1.3, and Firefox ESR 78.6.1
https://www.mozilla.org/en-US/security/advisories/mfsa2021-01/
CVE-2020-16044

+ FreeBSD-SA-20:33.openssl OpenSSL NULL pointer de-reference
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:33.openssl.asc
CVE-2020-1971

+ Linux kernel 5.10.5, 5.4.87, 4.19.165 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.5
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.87
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.165

JVNVU#91241691 複数の Schneider Electric 製品に脆弱性
http://jvn.jp/vu/JVNVU91241691/index.html

JVNVU#92365365 パナソニック製 FPWIN Pro に境界外読み取りの脆弱性
http://jvn.jp/vu/JVNVU92365365/index.html

JVNVU#90523924 GE 製 Reason RT43X Clocks シリーズに複数の脆弱性
http://jvn.jp/vu/JVNVU90523924/index.html

JVNVU#94511327 Red Lion 製 Crimson 3.1 における複数の脆弱性
http://jvn.jp/vu/JVNVU94511327/index.html

JVNVU#91044574 Delta Electronics 製 HMI ソフトウェアに複数の脆弱性
http://jvn.jp/vu/JVNVU91044574/index.html

自宅ネットが危ない、セキュリティーベンダーが2021年の脅威を予測
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05023/?ST=nxt_thmit_security

2021年1月6日水曜日

6日 水曜日、先負

+ RHSA-2021:0003 Important: kernel security and bug fix update
https://access.redhat.com/errata/RHSA-2021:0003
CVE-2020-25211

+ Linux kernel 5.10.4, 5.4.86, 4.19.164, 4.14.213, 4.9.249, 4.4.249 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.4
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.86
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.164
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.213
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.249
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.249

+ JVNVU#98351146 トレンドマイクロ製 InterScan Web Security シリーズの管理画面用サービスにおける複数の脆弱性
http://jvn.jp/vu/JVNVU98351146/index.html
CVE-2020-28578
CVE-2020-28579
CVE-2020-28580
CVE-2020-28581

+ Linux Kernelの脆弱性(Important: CVE-2020-36158)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20210106.html
CVE-2020-36158

+ dovecotの複数の脆弱性情報(CVE-2020-24386, CVE-2020-25275)
https://security.sios.com/vulnerability/dovecot-security-vulnerability-20210105.html
CVE-2020-24386
CVE-2020-25275

Web会議中の「悪口」が筒抜けに? キー入力を推測する驚きの研究
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/122200046/?ST=nxt_thmit_security

多要素認証
複数の要素を使ったユーザー認証方式
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/122200153/?ST=nxt_thmit_security

GAFAに頼らないID管理へ
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/122300207/122400014/?ST=nxt_thmit_security

UPDATE: JVNVU#96491057 複数の組み込み TCP/IP スタックにメモリ管理の不備に起因する複数の脆弱性
http://jvn.jp/vu/JVNVU96491057/index.html

JVN#38752718 IPMI over LAN による RMCP 接続を行う日本電気製の複数製品に認証不備の脆弱性
http://jvn.jp/jp/JVN38752718/index.html

JVN#38784555 UNIVERGE SV9500/SV8500 シリーズにおける複数の脆弱性
http://jvn.jp/jp/JVN38784555/index.html

JVNVU#94395061 SolarWinds Orion API に認証回避の脆弱性
http://jvn.jp/vu/JVNVU94395061/index.html

2020年12月25日金曜日

25日 金曜日、先負

UPDATE: JVNVU#93089606 Veritas 製 Veritas Backup Exec に権限昇格の脆弱性
http://jvn.jp/vu/JVNVU93089606/index.html

多要素認証
複数の要素を使ったユーザー認証方式
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091900032/121800028/?ST=nxt_thmit_security

VPNの脆弱性はなぜ放置された、パスワード流出が相次ぐわけ
岐阜県庁など
https://xtech.nikkei.com/atcl/nxt/column/18/01157/122400026/?ST=nxt_thmit_security

メルペイの不正被害額は225万円、対策強化し群馬銀行など3行と新規接続再開
https://xtech.nikkei.com/atcl/nxt/news/18/09402/?ST=nxt_thmit_security

2020年12月24日木曜日

24日 木曜日、友引

VU#429301 Veritas Backup Exec is vulnerable to privilege escalation due to OPENSSLDIR location
https://www.kb.cert.org/vuls/id/429301

VPN認証情報、またもネット公開 パッチ未適用の国内組織が被害に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/121400469/?ST=nxt_thmit_security

実は危ない「構成プロファイル」
iPhone画面がアイコンで埋め尽くされる フィッシングサイトへの誘導も
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/121800129/?ST=nxt_thmit_security

IT連が企業のセキュリティーを採点、説明責任が高評価の11社とは
https://xtech.nikkei.com/atcl/nxt/column/18/00001/05000/?ST=nxt_thmit_security

Webブラウザー「Smooz」がサービス終了、閲覧情報の外部送信疑惑で炎上
https://xtech.nikkei.com/atcl/nxt/news/18/09392/?ST=nxt_thmit_security

UPDATE: JVNVU#96491057 複数の組み込み TCP/IP スタックにメモリ管理の不備に起因する複数の脆弱性
http://jvn.jp/vu/JVNVU96491057/index.html

2020年12月23日水曜日

23日 水曜日、先勝

+ Mozilla Firefox 84.0.1 released
https://www.mozilla.org/en-US/firefox/84.0.1/releasenotes/

+ CESA-2020:5437 Important CentOS 7 kernel Security Update
https://lwn.net/Articles/841072/

+ CESA-2020:5618 Important CentOS 7 thunderbird Security Update
https://lwn.net/Articles/841073/

UPDATE: JVN#55917325 NEC Aterm SA3500G における複数の脆弱性
http://jvn.jp/jp/JVN55917325/index.html

JVNVU#94829658 Treck 社製 TCP/IP スタックに複数の脆弱性
http://jvn.jp/vu/JVNVU94829658/index.html

部屋の「電球」で盗聴が可能に スパイ映画顔負けのLamphone
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/120900045/?ST=nxt_thmit_security

2万超のサイトでパスワード流出 「解読済み」の平文で出回る
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/031800050/121800022/?ST=nxt_thmit_security

PPAP
https://xtech.nikkei.com/atcl/nxt/keyword/18/00002/112600151/?ST=nxt_thmit_security

NCA初の「オンライン」サイバー攻撃演習、静寂の中で得た収穫と課題
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04986/?ST=nxt_thmit_security

2020年12月22日火曜日

22日 火曜日、赤口

+ Zabbix 5.2.3, 5.0.7 released
https://www.zabbix.com/rn/rn5.2.3
https://www.zabbix.com/rn/rn5.0.7

+ Linux kernel 5.10.2, 5.9.16, 5.4.85 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.2
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.16
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.85

+ Apache PDFBox 2.0.22 released
https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12310760&version=12348605

+ GnuPG 2.2.26 released
https://lists.gnupg.org/pipermail/gnupg-announce/2020q4/000451.html

サーバーの95%が暗号化の被害に 未知マルウエアの感染に気づけず
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/121400070/?ST=nxt_thmit_security

詐欺メールが急増、攻撃者はWebサイトに設置されたあの機能を悪用
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600094/?ST=nxt_thmit_security

JVNVU#94829658 Treck 社製 TCP/IP スタックに複数の脆弱性
http://jvn.jp/vu/JVNVU94829658/index.html

Sony Playstation 4 ValidationMessage::buildBubbleTree() Use-After-Free
https://cxsecurity.com/issue/WLB-2020120150

2020年12月21日月曜日

21日 月曜日、大安

+ nginx 1.19.6 released
http://nginx.org/en/CHANGES

+ CESA-2020:5453 Moderate CentOS 7 pacemaker Security Update
https://lwn.net/Articles/840709/

+ CESA-2020:5566 Important CentOS 7 openssl Security Update
https://lwn.net/Articles/840708/

+ CESA-2020:5435 Moderate CentOS 7 python-rtslib Security Update
https://lwn.net/Articles/840710/

+ CESA-2020:5434 Moderate CentOS 7 targetcli Security Update
https://lwn.net/Articles/840712/

+ CESA-2020:5443 Moderate CentOS 7 gd Security Update
https://lwn.net/Articles/840707/

+ CESA-2020:5439 Moderate CentOS 7 samba Security Update
https://lwn.net/Articles/840711/

+ sudo 1.9.4p2 released
https://www.sudo.ws/stable.html#1.9.4p2

+ VMSA-2020-0029 VMware ESXi, Workstation, Fusion and Cloud Foundation updates address a denial of service vulnerability (CVE-2020-3999)
https://www.vmware.com/security/advisories/VMSA-2020-0029.html
CVE-2020-3999

+ hitachi-sec-2020-139 Cross-site Scripting Vulnerability in Hitachi Command Suite
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-139/index.html

+ hitachi-sec-2020-139 Hitachi Command Suite製品におけるクロスサイトスクリプティングの脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-139/index.html

+ Rocket.Chat Cross Site Scripting
https://cxsecurity.com/issue/WLB-2020120139

Balancing the needs around the CentOS platform
https://blog.centos.org/2020/12/balancing-the-needs-around-the-centos-platform/?utm_source=rss&utm_medium=rss&utm_campaign=balancing-the-needs-around-the-centos-platform

クラウドストレージ(Cloud Storage)
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600009/121400077/?ST=nxt_thmit_security

自治体管理ドメイン悪用が増加 アダルト転用も新たに発覚
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/121400039/?ST=nxt_thmit_security

米国土安全保障省が緊急指令、全米揺るがした「サプライチェーン攻撃」が日本上陸か
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04995/?ST=nxt_thmit_security

JVN#10100024 日本電気株式会社製ディスクアレイ管理ソフトウェアにサーバ証明書の検証不備の脆弱性
http://jvn.jp/jp/JVN10100024/index.html

JVNVU#97718282 Emerson 製 Rosemount X-STREAM に不適切な認証の脆弱性
http://jvn.jp/vu/JVNVU97718282/index.html

2020年12月18日金曜日

18日 金曜日、友引

+ RHSA-2020:5618 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:5618
CVE-2020-16042
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35113

+ RHSA-2020:5624 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:5624
CVE-2020-16042
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35113

+ RHSA-2020:5620 Important: postgresql:12 security update
https://access.redhat.com/errata/RHSA-2020:5620
CVE-2020-1720
CVE-2020-14349
CVE-2020-14350
CVE-2020-25694
CVE-2020-25695
CVE-2020-25696

+ RHSA-2020:5619 Important: postgresql:9.6 security update
https://access.redhat.com/errata/RHSA-2020:5619
CVE-2019-10130
CVE-2019-10208
CVE-2020-1720
CVE-2020-14350
CVE-2020-25694
CVE-2020-25695
CVE-2020-25696

+ RHSA-2020:5607 Important: fapolicyd bug fix update
https://access.redhat.com/errata/RHSA-2020:5607

+ Mozilla Firefox 84.0 released
https://www.mozilla.org/en-US/firefox/84.0/releasenotes/

+ Sudo 1.9.4p1 released
https://www.sudo.ws/stable.html#1.9.4p1

サーバーの95%が暗号化の被害に、未知マルウエアの感染に気づけず
https://xtech.nikkei.com/atcl/nxt/column/18/01157/121400025/?ST=nxt_thmit_security

通話内容で「振り込め詐欺」を見破る、NTTが月440円で提供するAIサービスの中身
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04982/?ST=nxt_thmit_security

UPDATE: JVNVU#96491057 複数の組み込み TCP/IP スタックにメモリ管理の不備に起因する複数の脆弱性
http://jvn.jp/vu/JVNVU96491057/index.html

UPDATE: JVNVU#93893801 複数の三菱電機製 FA エンジニアリングソフトウェア製品における不適切なファイルアクセス制御の脆弱性
http://jvn.jp/vu/JVNVU93893801/index.html

2020年12月17日木曜日

17日 木曜日、先勝

+ RHSA-2020:5586 Moderate: java-1.7.1-ibm security update
https://access.redhat.com/errata/RHSA-2020:5586
CVE-2020-14779
CVE-2020-14781
CVE-2020-14782
CVE-2020-14796
CVE-2020-14797

+ RHSA-2020:5561 Important: firefox security update
https://access.redhat.com/errata/RHSA-2020:5561
CVE-2020-16042
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35113

+ RHSA-2020:5443 Moderate: gd security update
https://access.redhat.com/errata/RHSA-2020:5443
CVE-2016-5766

+ RHSA-2020:5439 Moderate: samba security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5439
CVE-2020-1472
CVE-2020-14318
CVE-2020-14323

+ RHSA-2020:5437 Important: kernel security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5437
CVE-2019-18282
CVE-2020-10769
CVE-2020-14314
CVE-2020-14385
CVE-2020-24394
CVE-2020-25212
CVE-2020-25643

+ RHSA-2020:5435 Moderate: python-rtslib security update
https://access.redhat.com/errata/RHSA-2020:5435
CVE-2020-14019

+ RHSA-2020:5434 Moderate: targetcli security update
https://access.redhat.com/errata/RHSA-2020:5434
CVE-2020-13867

+ RHSA-2020:5567 Important: postgresql:10 security update
https://access.redhat.com/errata/RHSA-2020:5567
CVE-2020-25694
CVE-2020-25695
CVE-2020-25696

+ RHSA-2020:5562 Important: firefox security update
https://access.redhat.com/errata/RHSA-2020:5562
CVE-2020-16042
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35113

+ Announcing transition of Red Hat Enterprise Linux 6 to extended life phase
https://access.redhat.com/announcements/5620181

+ ISC BIND 9.17.8, 9.16.10, 9.11.26 relesed
https://downloads.isc.org/isc/bind9/9.17.8/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.16.10/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.11.26/RELEASE-NOTES-bind-9.11.26.html

+ Linux kernel 5.9.15, 5.4.84 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.15
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.84

+ UPDATE: JVNVU#95288122 複数の Apple 製品における脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU95288122/index.html

+ Microsoft Windows DrawIconEx Local Privilege Escalation
https://cxsecurity.com/issue/WLB-2020120117
CVE-2020-1054

UPDATE: JVNVU#99899290 WAGO 製の 750-88x および 750-352 シリーズにリソース枯渇の脆弱性
http://jvn.jp/vu/JVNVU99899290/index.html

敵のわなに飛び込み攻撃を遮断、bitFlyerが「積極的防御」で成果
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04977/?ST=nxt_thmit_security

2020年12月16日水曜日

16日 水曜日、赤口

+ RHSA-2020:5503 Moderate: mariadb-connector-c security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:5503
CVE-2020-2574
CVE-2020-2752
CVE-2020-2922
CVE-2020-13249

+ RHSA-2020:5500 Important: mariadb:10.3 security, bug fix, and enhancement update
https://access.redhat.com/errata/RHSA-2020:5500
CVE-2019-2938
CVE-2019-2974
CVE-2020-2574
CVE-2020-2752
CVE-2020-2760
CVE-2020-2780
CVE-2020-2812
CVE-2020-2814
CVE-2020-13249
CVE-2020-14765
CVE-2020-14776
CVE-2020-14789
CVE-2020-14812
CVE-2020-15180

+ RHSA-2020:5499 Moderate: nodejs:12 security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5499
CVE-2020-7774
CVE-2020-8277
CVE-2020-15366

+ RHSA-2020:5495 Moderate: nginx:1.16 security update
https://access.redhat.com/errata/RHSA-2020:5495
CVE-2019-20372

+ RHSA-2020:5483 Moderate: gnutls security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5483
CVE-2020-24659

+ RHSA-2020:5480 Important: net-snmp security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5480
CVE-2020-15862

+ RHSA-2020:5479 Important: linux-firmware security and enhancement update
https://access.redhat.com/errata/RHSA-2020:5479
CVE-2020-12321

+ RHSA-2020:5473 Moderate: kernel security and bug fix update
https://access.redhat.com/errata/RHSA-2020:5473
CVE-2020-16166

+ Mozilla Foundation Security Advisory 2020-54 Security Vulnerabilities fixed in Firefox 84
https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/
CVE-2020-16042
CVE-2020-26971
CVE-2020-26972
CVE-2020-26973
CVE-2020-26974
CVE-2020-26975
CVE-2020-26976
CVE-2020-26977
CVE-2020-26978
CVE-2020-26979
CVE-2020-35111
CVE-2020-35112
CVE-2020-35113
CVE-2020-35114

+ Mozilla Foundation Security Advisory 2020-56 Security Vulnerabilities fixed in Thunderbird 78.6
https://www.mozilla.org/en-US/security/advisories/mfsa2020-56/
CVE-2020-16042
CVE-2020-26971
CVE-2020-26973
CVE-2020-26974
CVE-2020-26978
CVE-2020-35111
CVE-2020-35112
CVE-2020-35113

+ Mozilla Thunderbird 78.6.0 released
https://www.thunderbird.net/en-US/thunderbird/78.6.0/releasenotes/

+ Samba 4.13.3 Available for Download
https://www.samba.org/samba/history/samba-4.13.3.html

+ VMSA-2020-0028 VMware Carbon Black Cloud macOS Sensor installer updates address file overwrite issue (CVE-2020-4008)
https://www.vmware.com/security/advisories/VMSA-2020-0028.html
CVE-2020-4008

+ JVNVU#95288122 複数の Apple 製品における脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU95288122/index.html

チャットでの悪口が筒抜けに、ビデオ会議の映像でキー入力を推測する手法に仰天
https://xtech.nikkei.com/atcl/nxt/column/18/00676/121100067/?ST=nxt_thmit_security

DXに伴いセキュリティー戦略見直した日本企業はわずか2割、NRIセキュア調査
https://xtech.nikkei.com/atcl/nxt/news/18/09329/?ST=nxt_thmit_security

JVN#94169589 GROWI における複数の脆弱性
http://jvn.jp/jp/JVN94169589/index.html

2020年12月15日火曜日

15日 火曜日、大安

+ RHSA-2020:5408 Important: xorg-x11-server security update
https://access.redhat.com/errata/RHSA-2020:5408
CVE-2020-14347
CVE-2020-14360
CVE-2020-25712

+ RHSA-2020:5402 Important: libexif security update
https://access.redhat.com/errata/RHSA-2020:5402
CVE-2020-0452

+ RHSA-2020:5400 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:5400
CVE-2020-26970

+ RHSA-2020:5401 Important: libpq security update
https://access.redhat.com/errata/RHSA-2020:5401
CVE-2020-25694
CVE-2020-25696

+ RHSA-2020:5398 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:5398
CVE-2020-26970

+ RHSA-2020:5393 Important: libexif security update
https://access.redhat.com/errata/RHSA-2020:5393
CVE-2020-0452

+ About the security content of iOS 14.3 and iPadOS 14.3
https://support.apple.com/ja-jp/HT212003
CVE-2020-29613
CVE-2020-27948
CVE-2020-27946
CVE-2020-27943
CVE-2020-27944
CVE-2020-29617
CVE-2020-29619
CVE-2020-29618
CVE-2020-29611
CVE-2020-27951
CVE-2020-15969

+ About the security content of macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave
https://support.apple.com/ja-jp/HT212011
CVE-2020-27914
CVE-2020-27915
CVE-2020-27903
CVE-2020-27941
CVE-2020-29621
CVE-2020-27910
CVE-2020-9943
CVE-2020-9944
CVE-2020-27916
CVE-2020-27906
CVE-2020-27948
CVE-2020-9960
CVE-2020-27908
CVE-2020-10017
CVE-2020-27922
CVE-2020-27946
CVE-2020-9962
CVE-2020-27952
CVE-2020-9956
CVE-2020-27931
CVE-2020-27943
CVE-2020-27944
CVE-2020-10002
CVE-2020-27947
CVE-2020-29612
CVE-2020-9978
CVE-2020-27919
CVE-2020-29616
CVE-2020-27924
CVE-2020-29618
CVE-2020-29611
CVE-2020-29617
CVE-2020-29619
CVE-2020-27912
CVE-2020-27923
CVE-2020-10015
CVE-2020-27897
CVE-2020-27907
CVE-2020-9974
CVE-2020-10016
CVE-2020-9967
CVE-2020-9975
CVE-2020-27921
CVE-2020-27949
CVE-2020-29620
CVE-2020-27911
CVE-2020-27920
CVE-2020-27926
CVE-2020-10014
CVE-2020-10010
CVE-2020-13524
CVE-2020-10004
CVE-2020-27901
CVE-2020-10007
CVE-2020-10012
CVE-2020-27896
CVE-2020-10009
CVE-2020-15969
CVE-2020-27898

+ About the security content of tvOS 14.3
https://support.apple.com/ja-jp/HT212005
CVE-2020-27948
CVE-2020-27946
CVE-2020-27943
CVE-2020-27944
CVE-2020-29617
CVE-2020-29619
CVE-2020-29618
CVE-2020-29611
CVE-2020-15969

+ About the security content of watchOS 7.2
https://support.apple.com/ja-jp/HT212009
CVE-2020-27948
CVE-2020-27946
CVE-2020-27943
CVE-2020-27944
CVE-2020-29617
CVE-2020-29619
CVE-2020-29618
CVE-2020-29611
CVE-2020-27951
CVE-2020-15969

+ About the security content of Safari 14.0.2
https://support.apple.com/ja-jp/HT212007
CVE-2020-15969

+ About the security content of iOS 12.5
https://support.apple.com/ja-jp/HT212004
CVE-2020-27951

+ About the security content of watchOS 6.3
https://support.apple.com/ja-jp/HT212006
CVE-2020-27951

+ Linux kernel 5.10.1 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.1

+ Linux Kernelの脆弱性(Moderate: CVE-2020-27825)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201215-1.html
CVE-2020-27825

+ Linux Kernelに複数の脆弱性(Moderate: CVE-2020-29660, CVE-2020-29661)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201215.html
CVE-2020-29660
CVE-2020-29661

概念の提唱者キンダーバグ氏に聞く、ゼロトラストを今すぐ始めるべき理由
https://xtech.nikkei.com/atcl/nxt/column/18/01449/121100011/?ST=nxt_thmit_security

オリックスのホテルで予約者情報を記録したサーバーが行方不明、資産の棚卸しで判明
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600093/?ST=nxt_thmit_security

2020年12月14日月曜日

14日 月曜日、先負

+ Windows DNSに関するセキュリティアドバイザリが公開されました
https://jprs.jp/tech/security/2020-12-11-windowsdnsresolver.html

+ Linux kernel 5.9.14, 5.4.83, 4.19.163, 4.14.212, 4.9.248, 4.4.248 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.14
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.83
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.163
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.212
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.248
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.248

+ Kubernetesのsecretが漏洩するという複数の脆弱性情報(Moderate: CVE-2020-8563, CVE-2020-8564,CVE-2020-8565,CVE-2020-8566)
https://security.sios.com/vulnerability/kubernetes-security-vulnerability-20201213.html
CVE-2020-8563
CVE-2020-8564
CVE-2020-8565
CVE-2020-8566

+ OpenLDAPの脆弱性情報(Moderate: CVE-2020-25692)
https://security.sios.com/vulnerability/openldap-security-vulnerability-20201213.html
CVE-2020-25692

+ Linux Kernelに権限昇格の脆弱性(Moderate: CVE-2020-29534)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201214.html
CVE-2020-29534

+ Linux Kernelに権限昇格の脆弱性(Moderate: CVE-2020-14351)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201213.html
CVE-2020-14351

How RHEL is Made
https://blog.centos.org/2020/12/how-rhel-is-made/?utm_source=rss&utm_medium=rss&utm_campaign=how-rhel-is-made

Minutes for CentOS Board of Directors for 2020-11-11
https://blog.centos.org/2020/12/minutes-for-centos-board-of-directors-for-2020-11-11/?utm_source=rss&utm_medium=rss&utm_campaign=minutes-for-centos-board-of-directors-for-2020-11-11

Minutes for CentOS Board of Directors for 2020-09-09
https://blog.centos.org/2020/12/minutes-for-centos-board-of-directors-for-2020-09-09/?utm_source=rss&utm_medium=rss&utm_campaign=minutes-for-centos-board-of-directors-for-2020-09-09

CentOS Stream is Continuous Delivery
https://blog.centos.org/2020/12/centos-stream-is-continuous-delivery/?utm_source=rss&utm_medium=rss&utm_campaign=centos-stream-is-continuous-delivery

SASE、SDP、SD-WAN、ゼロトラストで企業ネットワークはこう変わる
https://xtech.nikkei.com/atcl/nxt/column/18/01449/120900010/?ST=nxt_thmit_security

三菱パワーが不正アクセス被害を公表、日立システムズの運用監視サービス経由か
https://xtech.nikkei.com/atcl/nxt/news/18/09317/?ST=nxt_thmit_security

UPDATE: JVNVU#96491057 複数の組み込み TCP/IP スタックにメモリ管理の不備に起因する複数の脆弱性
http://jvn.jp/vu/JVNVU96491057/index.html

JVNVU#96535665 Medtronic 製 MyCareLink (MCL) Smart Model 25000 Patient Reader に複数の脆弱性
http://jvn.jp/vu/JVNVU96535665/index.html

JVNVU#98190554 Host Engineering 製 ECOM100 Module に不適切な入力検証の脆弱性
http://jvn.jp/vu/JVNVU98190554/index.html

2020年12月11日金曜日

11日 金曜日、赤口

+ CESA-2020:5235 Important CentOS 7 thunderbird Security Update
https://lwn.net/Articles/839624/

+ CESA-2020:5239 Important CentOS 7 firefox Security Update
https://lwn.net/Articles/839623/

+ Wireshark 3.4.1, 3.2.9 released
https://www.wireshark.org/docs/relnotes/wireshark-3.4.1.html
https://www.wireshark.org/docs/relnotes/wireshark-3.2.9.html

+ hitachi-sec-2020-138 Improper certificate validation vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-138/index.html

+ hitachi-sec-2020-137 Cleartext Transmission of Sensitive Information Vulnerability in Hitachi Infrastructure Analytics Advisor and Hitachi Ops Center Analyzer
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-137/index.html

+ hitachi-sec-2020-136 Multiple Vulnerabilities in Hitachi Ops Center Common Services
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-136/index.html
CVE-2020-1714
CVE-2020-10693
CVE-2020-10740
CVE-2020-10758

+ hitachi-sec-2020-138 Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center AnalyzerにおけるSSLサーバ証明書の検証不備
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-138/index.html

+ hitachi-sec-2020-137 Hitachi Infrastructure Analytics AdvisorおよびHitachi Ops Center Analyzerにおける平文通信の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-137/index.html

+ hitachi-sec-2020-136 Hitachi Ops Center Common Servicesにおける複数の脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-136/index.html
CVE-2020-1714
CVE-2020-10693
CVE-2020-10740
CVE-2020-10758

+ JVN#43969166 Apache Struts 2 において任意のコードが実行可能な脆弱性 (S2-061)
http://jvn.jp/jp/JVN43969166/index.html
CVE-2020-17530

JVN#55917325 NEC Aterm SA3500G における複数の脆弱性
http://jvn.jp/jp/JVN55917325/index.html

JVNVU#95638588 三菱電機製 MELSEC iQ-F シリーズにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU95638588/index.html

自治体管理ドメイン悪用が相次ぎ発覚、「使い捨て感覚」脱せずアダルト転用も
https://xtech.nikkei.com/atcl/nxt/column/18/00989/120900041/?ST=nxt_thmit_security

出前館ウェブサイトとアプリに不具合、お昼前には復旧
https://xtech.nikkei.com/atcl/nxt/news/18/09301/?ST=nxt_thmit_security

2020年12月10日木曜日

10日 木曜日、大安

+ Inferior OCSP verification
https://curl.se/docs/CVE-2020-8286.html
CVE-2020-8286

+ curl 7.74.0 released
https://curl.se/changes.html#7_74_0

+ FreeBSD-SA-20:33.openssl OpenSSL NULL pointer de-reference
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:33.openssl.asc
CVE-2020-1971

+ Apache Tomcat 9.0.41, 8.5.61 released
http://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.41_(markt)
http://tomcat.apache.org/tomcat-8.5-doc/changelog.html#Tomcat_8.5.61_(markt)

+ JVNVU#91053554 OpenSSL における NULL ポインタ参照の脆弱性
http://jvn.jp/vu/JVNVU91053554/index.html
CVE-2020-1971

+ curlの複数の脆弱性情報(Low: CVE-2020-8284, Medium: CVE-2020-8285, CVE-2020-8286 )
https://security.sios.com/vulnerability/curl-security-vulnerability-20201210.html
CVE-2020-8284
CVE-2020-8285
CVE-2020-8286

JVNVU#91936841 Schneider Electric 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU91936841/index.html

JVNVU#99742251 GE Healthcare 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU99742251/index.html

JVNVU#94568336 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU94568336/index.html

JVNVU#96514651 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU96514651/index.html

JVNVU#97872642 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU97872642/index.html

JVNVU#97501786 Siemens 製品に複数の脆弱性
http://jvn.jp/vu/JVNVU97501786/index.html

JVNVU#96491057 複数の組み込み TCP/IP スタックにメモリ管理の不備に起因する複数の脆弱性
http://jvn.jp/vu/JVNVU96491057/index.html

JVNVU#99277775 三菱電機製 GOT およびテンションコントローラにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU99277775/index.html

「PPAPお断り」の企業が続々 パスワード別送と決別なるか
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/120200468/?ST=nxt_thmit_security

米FireEye、サイバー攻撃でセキュリティー診断ツールが盗まれたと公表
https://xtech.nikkei.com/atcl/nxt/news/18/09287/?ST=nxt_thmit_security

2020年12月9日水曜日

9日 水曜日、仏滅

+ RHSA-2020:5350 Important: net-snmp security update
https://access.redhat.com/errata/RHSA-2020:5350
CVE-2020-15862

+ Prenotification Security Advisory for Adobe Acrobat and Reader | APSB20-75
https://helpx.adobe.com/security/products/acrobat/apsb20-75.html

+ Security Updates Available for Adobe Lightroom | APSB20-74
https://helpx.adobe.com/security/products/lightroom/apsb20-74.html
CVE-2020-24447

+ Security updates available for Adobe Experience Manager | APSB20-72
https://helpx.adobe.com/security/products/experience-manager/apsb20-72.html
CVE-2020-24444
CVE-2020-24445

+ Security Updates Available for Adobe Prelude | APSB20-70
https://helpx.adobe.com/security/products/prelude/apsb20-70.html
CVE-2020-24440

+ VU#815128 Embedded TCP/IP stacks have memory corruption vulnerabilities
https://www.kb.cert.org/vuls/id/815128
CVE-2020-13984
CVE-2020-13985
CVE-2020-13986
CVE-2020-13987
CVE-2020-13988
CVE-2020-17437
CVE-2020-17438
CVE-2020-17439
CVE-2020-17440
CVE-2020-17441
CVE-2020-17442
CVE-2020-17443
CVE-2020-17444
CVE-2020-17445
CVE-2020-17467
CVE-2020-17468
CVE-2020-17469
CVE-2020-17470
CVE-2020-24334
CVE-2020-24336
CVE-2020-24337
CVE-2020-24338
CVE-2020-24339
CVE-2020-24340
CVE-2020-24340
CVE-2020-24341
CVE-2020-24383
CVE-2020-25107
CVE-2020-25108
CVE-2020-25109
CVE-2020-25110
CVE-2020-25111
CVE-2020-25112

+ Linux kernel 5.9.13, 5.4.82, 4.19.162, 4.14.211 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.13
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.82
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.162
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.211

+ OpenSSL 1.1.1i released
https://www.openssl.org/

+ OpenSSL Security Advisory [08 December 2020]
https://www.openssl.org/news/secadv/20201208.txt
CVE-2020-1971

+ UPDATE: Oracle Critical Patch Update Advisory - October 2020
https://www.oracle.com/security-alerts/cpuoct2020.html

+ 2020 年 12 月のセキュリティ更新プログラム
https://msrc.microsoft.com/update-guide/releaseNote/2020-Dec

+ Apache Struts 2.5.26 released
https://struts.apache.org/announce.html#a20201206

+ S2-061 Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution - similar to S2-059
https://cwiki.apache.org/confluence/display/WW/S2-061
CVE-2020-17530

+ OpenSSLの脆弱性情報(High: CVE-2020-1971)
https://security.sios.com/vulnerability/openssl-security-vulnerability-20201209.html
CVE-2020-1971

+ Struts 2のリモートコード実行の脆弱性情報(Important: CVE-2020-17530)
https://security.sios.com/vulnerability/struts-security-vulnerability-20201208.html
CVE-2020-17530

+ マルチテナントクラスタに影響するKubernetesのMan-In-the-Middle 脆弱性情報(Moderate: CVE-2020-8554)
https://security.sios.com/vulnerability/kubernetes-security-vulnerability-20201208.html
CVE-2020-8554

+ Apache 2 HTTP2 Module Concurrent Pool Usage
https://cxsecurity.com/issue/WLB-2020120049
CVE-2020-11993

Unboundの脆弱性情報が公開されました(CVE-2020-28935)
https://jprs.jp/tech/security/2020-12-08-unbound.html

CentOS Project shifts focus to CentOS Stream
https://blog.centos.org/2020/12/future-is-centos-stream/?utm_source=rss&utm_medium=rss&utm_campaign=future-is-centos-stream

iPhoneのカレンダー機能を悪用 不審な通知に慌てると窮地に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/112700044/?ST=nxt_thmit_security

どちらを実施すべき?似て非なる脆弱性診断とペネトレーションテスト
https://xtech.nikkei.com/atcl/nxt/column/18/01493/120400002/?ST=nxt_thmit_security

2020年12月8日火曜日

8日 火曜日、先負

JVN#59779918 Apache Cordova Plugin camera における情報漏えいの脆弱性
http://jvn.jp/jp/JVN59779918/index.html

JVNVU#97704455 トレンドマイクロ株式会社製 ServerProtect for Linux にヒープベースのバッファオーバーフローの脆弱性
http://jvn.jp/vu/JVNVU97704455/index.html

福井県の企業支援サイトが“消失” ベンダーがクラウド更新手続き怠る
ふくい産業支援センター
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600011/120200069/?ST=nxt_thmit_security

サイバー攻撃で学ぶ「セキュアコーディング演習」、東大発ベンチャーが5万円から提供
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04931/?ST=nxt_thmit_security

カプコンに続く「オーダーメード型ランサムウエア」で被害、ログを削除され調査難航
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600092/?ST=nxt_thmit_security

ベンチャー企業が脆弱性を見つけるのに大枚をはたいたわけ
https://xtech.nikkei.com/atcl/nxt/column/18/01493/120400001/?ST=nxt_thmit_security

PayPay、設定不備で加盟店情報2000万件が不正閲覧された可能性
https://xtech.nikkei.com/atcl/nxt/news/18/09272/?ST=nxt_thmit_security

日立システムズの「ITマネジメントサービス」が不正アクセス被害に、利用企業にも影響か
https://xtech.nikkei.com/atcl/nxt/news/18/09269/?ST=nxt_thmit_security

2020年12月7日月曜日

7日 月曜日、友引

+ VMSA-2020-0027.2 VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address command injection vulnerability
https://www.vmware.com/security/advisories/VMSA-2020-0027.html
CVE-2020-4006

+ hitachi-sec-2020-135 Vulnerability in JP1
http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/hitachi-sec-2020-135/index.html
CVE-2020-1968

+ hitachi-sec-2020-135 JP1製品における脆弱性
http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/hitachi-sec-2020-135/index.html
CVE-2020-1968

+ UPDATE: JVNVU#97472624 複数の VMware 製品に OS コマンドインジェクションの脆弱性
http://jvn.jp/vu/JVNVU97472624/index.html

+ JVNVU#94251682 Apache Tomcat における HTTP/2 リクエスト処理の不備に起因する情報漏えいの脆弱性
http://jvn.jp/vu/JVNVU94251682/index.html
CVE-2020-17527

+ Zabbix 5.0.0 Stored XSS via URL Widget Iframe
https://cxsecurity.com/issue/WLB-2020120027
CVE-2020-15803

JVNVU#91733265 National Instruments 製 CompactRIO に重要なリソースに対する不適切なパーミッションの割り当ての脆弱性
http://jvn.jp/vu/JVNVU91733265/index.html

JVNVU#97347936 WECON 製 LeviStudioU に複数の脆弱性
http://jvn.jp/vu/JVNVU97347936/index.html

PPAP
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600009/112600076/?ST=nxt_thmit_security

個人情報「誤送付」が増加傾向 システム設計ミスや不正アクセス急増
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600010/112600076/?ST=nxt_thmit_security

暗号化と暴露でカプコンに11億円要求 「二重脅迫型」ランサムウエアの脅威
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/092400133/120100038/?ST=nxt_thmit_security

2020年12月4日金曜日

4日 金曜日、大安

+ Samba 4.11.17 Available for Download
https://www.samba.org/samba/history/samba-4.11.17.html

+ JVNVU#92370378 Apple iCloud for Windows における脆弱性に対するアップデート
http://jvn.jp/vu/JVNVU92370378/index.html

+ Apache Tomcatの脆弱性情報(Moderate: CVE-2020-17527)
https://security.sios.com/vulnerability/tomcat-security-vulnerability-20201204.html
CVE-2020-17527

「隠しデスクトップ」の恐怖
[第13回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/111900013/?ST=nxt_thmit_security

福井県の企業支援サイトが消失、バックアップが残っていた意外な場所
ふくい産業支援センター
https://xtech.nikkei.com/atcl/nxt/column/18/01157/120200024/?ST=nxt_thmit_security

NEWS pickup&digest(2020/10/14~11/12)
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800011/111900037/?ST=nxt_thmit_security

UPDATE: JVN#24457594 EC-CUBE における複数の脆弱性
http://jvn.jp/jp/JVN24457594/index.html

JVNVU#99277775 三菱電機製 GOT およびテンションコントローラにおけるサービス運用妨害 (DoS) の脆弱性
http://jvn.jp/vu/JVNVU99277775/index.html

JVN#42199826 desknet's NEO におけるクロスサイトスクリプティングの脆弱性
http://jvn.jp/jp/JVN42199826/index.html

2020年12月3日木曜日

3日 木曜日、仏滅

+ About the security content of iCloud for Windows 11.5
https://support.apple.com/ja-jp/HT211935
CVE-2020-10002
CVE-2020-9961
CVE-2020-27912
CVE-2020-9876
CVE-2020-27917
CVE-2020-27911
CVE-2020-9981
CVE-2020-13434
CVE-2020-13435
CVE-2020-13630
CVE-2020-9849
CVE-2020-13631
CVE-2020-9951
CVE-2020-27918
CVE-2020-9983
CVE-2020-27918
CVE-2020-9947
CVE-2020-9951

+ Google Chrome 87.0.4280.88 released
https://chromereleases.googleblog.com/2020/12/stable-channel-update-for-desktop.html

+ Mozilla Foundation Security Advisory 2020-53 Security Vulnerabilities fixed in Thunderbird 78.5.1
https://www.mozilla.org/en-US/security/advisories/mfsa2020-53/
CVE-2020-26970

+ Mozilla Thunderbird 78.5.1 released
https://www.thunderbird.net/en-US/thunderbird/78.5.1/releasenotes/

+ Linux kernel 5.9.12, 5.4.81, 4.19.161, 4.14.210, 4.9.247, 4.4.247 released
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.9.12
https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.81
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.161
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.210
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.247
https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.247

+ Linux Kernelの脆弱性(Moderate: CVE-2020-25704)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201203-1.html
CVE-2020-25704

+ Linux Kernelの脆弱性(Moderate: CVE-2020-25656)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201203.html
CVE-2020-25656

Announcing transition of Red Hat Enterprise Linux 6 to extended life phase
https://access.redhat.com/announcements/5620181

クラウド時代に即したビデオ会議システム活用術
[第3回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091700094/111900003/?ST=nxt_thmit_security

VPN認証情報がネット上に公開され国内で被害、パッチ未適用の機器は世界に5万台
https://xtech.nikkei.com/atcl/nxt/column/18/00001/04918/?ST=nxt_thmit_security

JVNVU#95940991 Schneider Electric 製 EcoStruxure Operator Terminal Expert に不適切な権限管理の脆弱性
http://jvn.jp/vu/JVNVU95940991/index.html

JVNVU#97997181 横河電機製 CAMS for HIS に複数の脆弱性
http://jvn.jp/vu/JVNVU97997181/index.html

2020年12月2日水曜日

2日 水曜日、先負

+ FreeBSD-SA-20:32.rtsold Multiple vulnerabilities in rtsold
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:32.rtsold.asc
CVE-2020-25577

+ FreeBSD-SA-20:31.icmp6 ICMPv6 use-after-free in error message handling
https://www.freebsd.org/security/advisories/FreeBSD-SA-20:31.icmp6.asc
CVE-2020-7469

+ Linux Kernelに複数の脆弱性(Moderate: CVE-2020-15436, CVE-2020-15437)
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201202.html
CVE-2020-15436
CVE-2020-15437

CPE Weekly: November 22 2020
https://blog.centos.org/2020/12/cpe-weekly-november-22-2020/?utm_source=rss&utm_medium=rss&utm_campaign=cpe-weekly-november-22-2020

クラウドのネットワークってどうなっているの?
part2 内部構造
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111800099/111900002/?ST=nxt_thmit_security

ドコモ口座不正送金のシナリオ
個人情報の入手方法を専門家が推測 暗証番号はブルートフォースで突破か
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/111900126/?ST=nxt_thmit_security

部屋の「電球」を観測すると盗聴が可能に、スパイ映画顔負けのLamphone
https://xtech.nikkei.com/atcl/nxt/column/18/00676/112500066/?ST=nxt_thmit_security

2020年12月1日火曜日

1日 火曜日、友引

+ RHSA-2020:5257 Important: firefox security update
https://access.redhat.com/errata/RHSA-2020:5257
CVE-2020-16012
CVE-2020-26951
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-26961
CVE-2020-26965
CVE-2020-26968

+ RHSA-2020:523 Important: firefox security update
https://access.redhat.com/errata/RHSA-2020:5239
CVE-2020-16012
CVE-2020-26951
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-26961
CVE-2020-26965
CVE-2020-26968

+ RHSA-2020:5235 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:5235
CVE-2020-16012
CVE-2020-26951
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-26961
CVE-2020-26965
CVE-2020-26968

+ RHSA-2020:5237 Important: firefox security update
https://access.redhat.com/errata/RHSA-2020:5237
CVE-2020-16012
CVE-2020-26951
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-26961
CVE-2020-26965
CVE-2020-26968

+ RHSA-2020:5236 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2020:5236
CVE-2020-16012
CVE-2020-26951
CVE-2020-26953
CVE-2020-26956
CVE-2020-26958
CVE-2020-26959
CVE-2020-26960
CVE-2020-26961
CVE-2020-26965
CVE-2020-26968

+ Zabbix 5.2.2, 5.0.6, 4.0.27 released
https://www.zabbix.com/rn/rn5.2.2
https://www.zabbix.com/rn/rn5.0.6
https://www.zabbix.com/rn/rn4.0.27

+ Sudo 1.9.4 released
https://www.sudo.ws/stable.html#1.9.4

+ Linux Kernelの複数の脆弱性(CVE-2020-29368,CVE-2020-29369, CVE-2020-29370, CVE-2020-29371, CVE-2020-29372, CVE-2020-29373, CVE-2020-29374 )
https://security.sios.com/vulnerability/kernel-security-vulnerability-20201201.html
CVE-2020-29368
CVE-2020-29369
CVE-2020-29370
CVE-2020-29371
CVE-2020-29372
CVE-2020-29373
CVE-2020-29374

国内法人1000社超にセキュリティー調査
8割がセキュリティーインシデントを経験 平均被害額は1億4800万円
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/111800125/?ST=nxt_thmit_security

200以上の国内サービスからパスワードが流出か、暗号化していても犯人は「解読済み」
https://xtech.nikkei.com/atcl/nxt/column/18/00598/082600091/?ST=nxt_thmit_security

みずほ銀行の法人向けサービスでシステム障害、月末で困惑の声相次ぐ
https://xtech.nikkei.com/atcl/nxt/news/18/09230/?ST=nxt_thmit_security