2025年9月19日金曜日

19日 金曜日、仏滅

+ RHSA-2025:16156 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2025:16156
CVE-2025-10527
CVE-2025-10528
CVE-2025-10529
CVE-2025-10532
CVE-2025-10533
CVE-2025-10536
CVE-2025-10537

+ RHSA-2025:16046 Moderate: mysql:8.4 security update
https://access.redhat.com/errata/RHSA-2025:16046
CVE-2025-21574
CVE-2025-21575
CVE-2025-21577
CVE-2025-21579
CVE-2025-21580
CVE-2025-21581
CVE-2025-21584
CVE-2025-21585
CVE-2025-21588
CVE-2025-30681
CVE-2025-30682
CVE-2025-30683
CVE-2025-30684
CVE-2025-30685
CVE-2025-30687
CVE-2025-30688
CVE-2025-30689
CVE-2025-30693
CVE-2025-30695
CVE-2025-30696
CVE-2025-30699
CVE-2025-30703
CVE-2025-30704
CVE-2025-30705
CVE-2025-30715
CVE-2025-30721
CVE-2025-30722
CVE-2025-50077
CVE-2025-50078
CVE-2025-50079
CVE-2025-50080
CVE-2025-50081
CVE-2025-50082
CVE-2025-50083
CVE-2025-50084
CVE-2025-50085
CVE-2025-50086
CVE-2025-50087
CVE-2025-50088
CVE-2025-50091
CVE-2025-50092
CVE-2025-50093
CVE-2025-50094
CVE-2025-50096
CVE-2025-50097
CVE-2025-50098
CVE-2025-50099
CVE-2025-50100
CVE-2025-50101
CVE-2025-50102
CVE-2025-50104

+ watchOS 26.0.1 released
https://support.apple.com/en-us/100100

不快なネット広告を遮断せよ!
第14回
端末に履歴を残さないブラウザーの「プライベートモード」、共用パソコンで重宝
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800014/?ST=nxt_thmit_security

JVNVU#96277701 OpenAM(OpenAMコンソーシアム版)にサービス運用妨害(DoS)につながる脆弱性
https://jvn.jp/vu/JVNVU96277701/index.html

JVNVU#93403671 オムロンソーシアルソリューションズ製無停電電源装置(UPS)管理アプリケーションにおけるWindowsサービスの実行ファイルパスが引用符で囲まれていない脆弱性
https://jvn.jp/vu/JVNVU93403671/index.html

JVNVU#97846038 三菱電機製MELSEC-QシリーズCPUユニットにおけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU97846038/index.html

JVNVU#90283680 三菱電機製エコガイドTABにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90283680/index.html

JVNVU#95103362 三菱電機製FAエンジニアリングソフトウェア製品における複数の脆弱性
https://jvn.jp/vu/JVNVU95103362/index.html

JVN#95938761 UNIVERGE IX/IX-R/IX-Vシリーズルータにおけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN95938761/index.html

JVNVU#90043828 複数のブラザー製品における複数の脆弱性
https://jvn.jp/vu/JVNVU90043828/index.html

2025年9月18日木曜日

18日 木曜日、先負

+ RHSA-2025:15921 Important: kpatch-patch-4_18_0-553_16_1, kpatch-patch-4_18_0-553_30_1, kpatch-patch-4_18_0-553_40_1, kpatch-patch-4_18_0-553_53_1, and kpatch-patch-4_18_0-553_72_1 security update
https://access.redhat.com/errata/RHSA-2025:15921
CVE-2025-38052
CVE-2025-38352

+ RHSA-2025:15904 Important: container-tools:rhel8 security update
https://access.redhat.com/errata/RHSA-2025:15904
CVE-2025-9566

+ RHSA-2025:16046 Moderate: mysql:8.4 security update
https://access.redhat.com/errata/RHSA-2025:16046
CVE-2024-13176
CVE-2025-5399
CVE-2025-21574
CVE-2025-21575
CVE-2025-21577
CVE-2025-21579
CVE-2025-21580
CVE-2025-21581
CVE-2025-21584
CVE-2025-21585
CVE-2025-21588
CVE-2025-30681
CVE-2025-30682
CVE-2025-30683
CVE-2025-30684
CVE-2025-30685
CVE-2025-30687
CVE-2025-30688
CVE-2025-30689
CVE-2025-30693
CVE-2025-30695
CVE-2025-30696
CVE-2025-30699
CVE-2025-30703
CVE-2025-30704
CVE-2025-30705
CVE-2025-30715
CVE-2025-30721
CVE-2025-30722
CVE-2025-50077
CVE-2025-50078
CVE-2025-50079
CVE-2025-50080
CVE-2025-50081
CVE-2025-50082
CVE-2025-50083
CVE-2025-50084
CVE-2025-50085
CVE-2025-50086
CVE-2025-50087
CVE-2025-50088
CVE-2025-50091
CVE-2025-50092
CVE-2025-50093
CVE-2025-50094
CVE-2025-50096
CVE-2025-50097
CVE-2025-50098
CVE-2025-50099
CVE-2025-50100
CVE-2025-50101
CVE-2025-50102
CVE-2025-50104

+ RHSA-2025:15887 Moderate: opentelemetry-collector security update
https://access.redhat.com/errata/RHSA-2025:15887
CVE-2025-4673

+ RHSA-2025:15874 Moderate: python-cryptography security update
https://access.redhat.com/errata/RHSA-2025:15874
CVE-2023-49083

+ Google Chrome 140.0.7339.185/.186 released
https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop_17.html

+ Mozilla Firefox 143.0 released
https://www.firefox.com/en-US/firefox/143.0/releasenotes/

+ Mozilla Foundation Security Advisory 2025-73 Security Vulnerabilities fixed in Firefox 143
https://www.mozilla.org/en-US/security/advisories/mfsa2025-73/
CVE-2025-10527
CVE-2025-10528
CVE-2025-10529
CVE-2025-10530
CVE-2025-10531
CVE-2025-10532
CVE-2025-10533
CVE-2025-10534
CVE-2025-10535
CVE-2025-10536
CVE-2025-10537

+ Mozilla Foundation Security Advisory 2025-77 Security Vulnerabilities fixed in Thunderbird 143
https://www.mozilla.org/en-US/security/advisories/mfsa2025-77/
CVE-2025-10527
CVE-2025-10528
CVE-2025-10529
CVE-2025-10530
CVE-2025-10531
CVE-2025-10532
CVE-2025-10533
CVE-2025-10534
CVE-2025-10536
CVE-2025-10537

+ Mozilla Thunderbird 143.0, 140.3 released
https://www.thunderbird.net/en-US/thunderbird/143.0/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/140.3.0esr/releasenotes/

+ Linux Kernelの脆弱性(CVE-2025-39736~CVE-2025-39804, CVE-2025-40300)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20250916/
CVE-2025-39736
CVE-2025-39737
CVE-2025-39738
CVE-2025-39739
CVE-2025-39740
CVE-2025-39741
CVE-2025-39742
CVE-2025-39743
CVE-2025-39744
CVE-2025-39745
CVE-2025-39746
CVE-2025-39747
CVE-2025-39748
CVE-2025-39749
CVE-2025-39750
CVE-2025-39751
CVE-2025-39752
CVE-2025-39753
CVE-2025-39754
CVE-2025-39755
CVE-2025-39756
CVE-2025-39757
CVE-2025-39758
CVE-2025-39759
CVE-2025-39760
CVE-2025-39761
CVE-2025-39762
CVE-2025-39763
CVE-2025-39764
CVE-2025-39765
CVE-2025-39766
CVE-2025-39767
CVE-2025-39768
CVE-2025-39769
CVE-2025-39770
CVE-2025-39771
CVE-2025-39772
CVE-2025-39773
CVE-2025-39774
CVE-2025-39775
CVE-2025-39776
CVE-2025-39777
CVE-2025-39778
CVE-2025-39779
CVE-2025-39780
CVE-2025-39781
CVE-2025-39782
CVE-2025-39783
CVE-2025-39784
CVE-2025-39785
CVE-2025-39786
CVE-2025-39787
CVE-2025-39788
CVE-2025-39789
CVE-2025-39790
CVE-2025-39791
CVE-2025-39792
CVE-2025-39793
CVE-2025-39794
CVE-2025-39795
CVE-2025-39796
CVE-2025-39797
CVE-2025-39798
CVE-2025-39799
CVE-2025-39800
CVE-2025-39801
CVE-2025-39802
CVE-2025-39803
CVE-2025-39804
CVE-2025-40300

JVNVU#93294882 ブラザーおよびそのOEMベンダーが提供する複数の製品における管理者パスワードの初期設定について
https://jvn.jp/vu/JVNVU93294882/index.html

JVNVU#93913883 Daikin Europe N.V.製Security Gatewayに脆弱なパスワードリカバリの問題
https://jvn.jp/vu/JVNVU93913883/index.html

JVNVU#91790481 複数のSchneider Electric製品におけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/vu/JVNVU91790481/index.html

JVNVU#93117073 Hitachi Energy製RTU500シリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU93117073/index.html

JVNVU#98116919 Delta Electronics製DIALinkにおけるパストラバーサルの脆弱性
https://jvn.jp/vu/JVNVU98116919/index.html

JVNVU#96277701 OpenAM(OpenAMコンソーシアム版)にサービス運用妨害(DoS)につながる脆弱性
https://jvn.jp/vu/JVNVU96277701/index.html

JVN#84697061 Century HW RAID Managerにおける引用符で囲まれていないファイルパスの脆弱性
https://jvn.jp/jp/JVN84697061/index.html

JVNVU#97490987 アイ・オー・データ製無線LANルーターにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97490987/index.html

UPDATE: JVNVU#96418823 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU96418823/index.html

UPDATE: JVNVU#99030761 Siemens製品に対するアップデート(2022年6月)
https://jvn.jp/vu/JVNVU99030761/index.html

UPDATE: JVNVU#98748974 Siemens製品に対するアップデート(2022年2月)
https://jvn.jp/vu/JVNVU98748974/index.html

JVNVU#90253343 Xerox FreeFlow Coreにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90253343/index.html

ニュース&リポート
社労夢ユーザー90人が集団訴訟 エムケイシステムに3億円超請求
訴状で「クラウドサービスにあるまじき危険な設定」と指摘
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/090501314/?ST=nxt_thmit_security

ニュース&リポート
指静脈認証でチェックインが可能に 日立のサービスを東武系ホテルが導入
事前登録必須などの課題も
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/090801320/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第13回
Braveブラウザーの広告遮断機能をすり抜ける広告、設定変更で対処する
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800013/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第12回
広告を遮断する「Brave」ブラウザーのインストール&運用マニュアル、独自AIも便利
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800012/?ST=nxt_thmit_security

間接プロンプトインジェクションに気をつけろ
第1回
LLMのガードレールは万能か、「論文PDF内の秘密プロンプト」で検証
https://xtech.nikkei.com/atcl/nxt/column/18/03336/091600001/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
AIが10分で脆弱性突くプログラムを生成、セキュリティー対策の見直し不可避に
https://xtech.nikkei.com/atcl/nxt/column/18/00676/090800205/?ST=nxt_thmit_security

NTTドコモ、iPhoneのマイナンバーカードを用いて本人確認 dアカウントやd払いで
https://xtech.nikkei.com/atcl/nxt/news/24/02820/?ST=nxt_thmit_security

2025年9月16日火曜日

16日 火曜日、先勝

+ RHSA-2025:15798 Important: kpatch-patch-5_14_0-570_17_1 and kpatch-patch-5_14_0-570_39_1 security update
https://access.redhat.com/errata/RHSA-2025:15798
CVE-2025-38052
CVE-2025-38352

+ About the security content of iOS 26 and iPadOS 26
https://support.apple.com/en-us/125108
CVE-2025-43344
CVE-2025-43317
CVE-2025-43346
CVE-2025-43354
CVE-2025-43303
CVE-2025-43357
CVE-2025-43349
CVE-2025-43372
CVE-2025-43302
CVE-2025-31255
CVE-2025-43359
CVE-2025-43362
CVE-2025-43355
CVE-2025-43203
CVE-2025-31254
CVE-2025-43329
CVE-2025-43358
CVE-2025-30468
CVE-2025-43190
CVE-2025-6965
CVE-2025-43347
CVE-2025-24133
CVE-2025-43356
CVE-2025-43272
CVE-2025-43343
CVE-2025-43342

+ About the security content of iOS 18.7 and iPadOS 18.7
https://support.apple.com/en-us/125109

+ About the security content of iOS 16.7.12 and iPadOS 16.7.12
https://support.apple.com/en-us/125141

+ About the security content of iOS 15.8.5 and iPadOS 15.8.5
https://support.apple.com/en-us/125142

+ About the security content of macOS Tahoe 26
https://support.apple.com/en-us/125110

+ About the security content of macOS Sequoia 15.7
https://support.apple.com/en-us/125111

+ About the security content of macOS Sonoma 14.8
https://support.apple.com/en-us/125112

+ About the security content of tvOS 26
https://support.apple.com/en-us/125114

+ About the security content of watchOS 26
https://support.apple.com/en-us/125116

+ About the security content of visionOS 26
https://support.apple.com/en-us/125115

+ About the security content of Safari 26
https://support.apple.com/en-us/125113

+ About the security content of Xcode 26
https://support.apple.com/en-us/125117

+ Apache Tomcat 10.1.46 Released
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.46_(schultz)

Current:VU#949137 Langchaingo supports jinja2 and gonja for syntax parsing, allowing for arbitrary file read
https://www.kb.cert.org/vuls/id/949137

不快なネット広告を遮断せよ!
第11回
広告を遮断する最強ブラウザー「Brave」、ダウンロードサイトの偽ボタンも消える
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800011/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
primeNumber出稿の広告のリンク先が個人情報入りのフォルダー、最大3人がアクセス
https://xtech.nikkei.com/atcl/nxt/column/18/00598/041800332/?ST=nxt_thmit_security

JVN#89109713 スマートフォンアプリ「WTW-EAGLE」におけるサーバ証明書の検証不備の脆弱性
https://jvn.jp/jp/JVN89109713/index.html

JVNVU#90637001 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU90637001/index.html

JVNVU#95775509 Siemens製品に対するアップデート(2025年9月)
https://jvn.jp/vu/JVNVU95775509/index.html

JVNVU#99451862 複数のSchneider Electric製品における複数の脆弱性 
https://jvn.jp/vu/JVNVU99451862/index.html

2025年9月12日金曜日

12日 金曜日、先負

+ RHSA-2025:15661 Important: kernel security update
https://access.redhat.com/errata/RHSA-2025:15661
CVE-2025-22097
CVE-2025-38332
CVE-2025-38352
CVE-2025-38449

ハック、パンプ・アンド・ダンプ(Hack, Pump And Dump)
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600009/090800203/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
PCとスマホでフィッシングの実験 被害に遭いやすいのはどちらか
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/090500167/?ST=nxt_thmit_security

5日間で丸分かり、OSPFとBGPの基礎
第5回
実は2種類あるBGP、「eBGP」と「iBGP」を使い分ける理由を学ぶ
https://xtech.nikkei.com/atcl/nxt/column/18/03319/090200005/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第10回
DNSを活用した広告ブロッカー 設定はIPアドレスの登録のみ、スマホも使える
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800010/?ST=nxt_thmit_security

2025年9月11日木曜日

11日 木曜日、友引

+ predictable WebSocket mask
https://curl.se/docs/CVE-2025-10148.html
CVE-2025-10148

+ Out of bounds read for cookie path
https://curl.se/docs/CVE-2025-9086.html
CVE-2025-9086

+ RHSA-2025:15643 Important: Satellite 6.15.5.4 Async Update
https://access.redhat.com/errata/RHSA-2025:15643
CVE-2024-13009

+ RHSA-2025:15608 Important: python3.12-cryptography security update
https://access.redhat.com/errata/RHSA-2025:15608
CVE-2024-26130

+ ISC BIND 9.20.13 released
https://downloads.isc.org/isc/bind9/9.20.13/doc/arm/html/notes.html

+ 2025 年 9 月のセキュリティ更新プログラム (月例)
https://msrc.microsoft.com/blog/2025/09/202509-security-update/

+ Linux Kernelの脆弱性(CVE-2025-38731~CVE-2025-39735)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20250911/
CVE-2025-38731
CVE-2025-38732
CVE-2025-38733
CVE-2025-38734
CVE-2025-38735
CVE-2025-38736
CVE-2025-38737
CVE-2025-39673
CVE-2025-39674
CVE-2025-39675
CVE-2025-39676
CVE-2025-39677
CVE-2025-39678
CVE-2025-39679
CVE-2025-39680
CVE-2025-39681
CVE-2025-39682
CVE-2025-39683
CVE-2025-39684
CVE-2025-39685
CVE-2025-39686
CVE-2025-39687
CVE-2025-39688
CVE-2025-39689
CVE-2025-39690
CVE-2025-39691
CVE-2025-39692
CVE-2025-39693
CVE-2025-39694
CVE-2025-39695
CVE-2025-39696
CVE-2025-39697
CVE-2025-39698
CVE-2025-39699
CVE-2025-39700
CVE-2025-39701
CVE-2025-39702
CVE-2025-39703
CVE-2025-39704
CVE-2025-39705
CVE-2025-39706
CVE-2025-39707
CVE-2025-39708
CVE-2025-39709
CVE-2025-39710
CVE-2025-39711
CVE-2025-39712
CVE-2025-39713
CVE-2025-39714
CVE-2025-39715
CVE-2025-39716
CVE-2025-39717
CVE-2025-39718
CVE-2025-39719
CVE-2025-39720
CVE-2025-39721
CVE-2025-39722
CVE-2025-39723
CVE-2025-39724
CVE-2025-39725
CVE-2025-39726
CVE-2025-39727
CVE-2025-39728
CVE-2025-39729
CVE-2025-39730
CVE-2025-39731
CVE-2025-39732
CVE-2025-39733
CVE-2025-39734
CVE-2025-39735

VU#974249 Elevated Privileges and Arbitrary Code Execution issues in Sunshine for Windows v2025.122.141614
https://www.kb.cert.org/vuls/id/974249

VU#763183 Amp'ed RF BT-AP 111 Bluetooth access point lacks an authentication mechanism
https://www.kb.cert.org/vuls/id/763183

VU#461364 Hiawatha open-source web server has multiple vulnerabilities
https://www.kb.cert.org/vuls/id/461364

UPDATE: JVNVU#92973034 複数のSchneider Electric製品における境界外書き込みの脆弱性
https://jvn.jp/vu/JVNVU92973034/index.html

UPDATE: JVNVU#98646422 EG4 Electronics製EG4インバーターにおける複数の脆弱性
https://jvn.jp/vu/JVNVU98646422/index.html

UPDATE: JVNVU#96783966 複数のRockwell Automation製品における複数の脆弱性
https://jvn.jp/vu/JVNVU96783966/index.html

JVNVU#95775509 Siemens製品に対するアップデート(2025年9月)
https://jvn.jp/vu/JVNVU95775509/index.html

JVNVU#91167869 複数のRockwell Automation製品における複数の脆弱性
https://jvn.jp/vu/JVNVU91167869/index.html

JVNVU#96617894 複数のABB製品における複数の脆弱性
https://jvn.jp/vu/JVNVU96617894/index.html

5日間で丸分かり、OSPFとBGPの基礎
第4回
クラウドでよく使うBGPの基礎を解説、経路の選び方はOSPFよりも少し複雑
https://xtech.nikkei.com/atcl/nxt/column/18/03319/090200004/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第9回
Windowsが表示する「おすすめ」は広告、邪魔なら非表示にしよう
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800009/?ST=nxt_thmit_security

三菱電機がセキュリティー対策の米ノゾミを買収、工場向けデータ事業を強化へ
https://xtech.nikkei.com/atcl/nxt/news/24/02814/?ST=nxt_thmit_security

証券口座乗っ取り、8月の不正アクセス件数は4カ月ぶりに増加
https://xtech.nikkei.com/atcl/nxt/news/24/02812/?ST=nxt_thmit_security

5日間で丸分かり、OSPFとBGPの基礎
第3回
OSPFルーターが増えると経路計算が大変、解決する妙技「エリア分割」を知る
https://xtech.nikkei.com/atcl/nxt/column/18/03319/090200003/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第8回
ブラウザーの標準機能で悪質な広告を除去、「トラッカー」もブロックできる
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800008/?ST=nxt_thmit_security

ニュース解説
委託先がサイバー攻撃被害、金融ISACの攻撃演習シナリオで対処方法を検証
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11066/?ST=nxt_thmit_security

2025年9月9日火曜日

9日 火曜日、赤口

+ Apache Tomcat 10.1.45 released
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.45_(schultz)

+ FreeBSD-SA-25:07.libarchive Integer overflow in libarchive leading to double free
https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc
CVE-2025-5914

5日間で丸分かり、OSPFとBGPの基礎
第2回
OSPFが「最短経路」をどう導くのかをマスター、経由地の数よりも帯域が重要に
https://xtech.nikkei.com/atcl/nxt/column/18/03319/090200002/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第7回
法規制はなくてもネット収益を揺るがす広告ブロッカー、広告を残すしくみも用意
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800007/?ST=nxt_thmit_security

記者の眼
「誰が」に着目の米国コネクテッドカー規制、半導体や工作機械の貿易に見た共通点
https://xtech.nikkei.com/atcl/nxt/column/18/00138/090201842/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
保険見直し本舗がランサムウエア被害の原因公表、再発防止に24時間の監視体制を構築
https://xtech.nikkei.com/atcl/nxt/column/18/00598/041800331/?ST=nxt_thmit_security

JVN#75307484 RICOH Streamline NXにおける操作履歴の改ざんにつながる脆弱性
https://jvn.jp/jp/JVN75307484/index.html

JVN#47404248 スマートフォンアプリ「グノシー」における送信データへの機微な情報の挿入の脆弱性
https://jvn.jp/jp/JVN47404248/index.html

2025年9月8日月曜日

8日 月曜日、大安

+ Apache Tomcat 11.0.11, 9.0.109 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.11_(markt)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.109_(remm)

5日間で丸分かり、OSPFとBGPの基礎
第1回
まずは「ルーティング」の基本から、ルーターが経路を選ぶ仕組みをゼロから解説
https://xtech.nikkei.com/atcl/nxt/column/18/03319/090200001/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第6回
ネット広告を止めるブロッカー、サーバーのリストを開発者やボランティアが日々更新
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800006/?ST=nxt_thmit_security

JVN#98737186 RATOC RAID監視マネージャー(Windows用)における引用符で囲まれていないファイルパスの脆弱性
https://jvn.jp/jp/JVN98737186/index.html

JVN#41633999 Obsidian GitHub Copilot Pluginにおける重要情報の平文保存の脆弱性
https://jvn.jp/jp/JVN41633999/index.html

JVN#35290164 Androidアプリ「Yahoo!ショッピング」におけるアクセス制限不備の脆弱性
https://jvn.jp/jp/JVN35290164/index.html

JVN#48739895 Pythonライブラリ「TkEasyGUI」における複数の脆弱性
https://jvn.jp/jp/JVN48739895/index.html

JVNVU#90284485 Honeywell製OneWireless WDMにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90284485/index.html

JVNVU#92236694 Delta Electronics製COMMGRにおける暗号論的強度が不十分なPRNGの使用の脆弱性
https://jvn.jp/vu/JVNVU92236694/index.html

2025年9月5日金曜日

5日 金曜日、友引

+ RHSA-2025:15371 Moderate: Satellite 6 Client Bug Fix Update
https://access.redhat.com/errata/RHSA-2025:15371
CVE-2024-49761

UPDATE: JVNVU#95548104 三菱電機製GENESIS64およびMC Works64におけるインストール時の不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/vu/JVNVU95548104/index.html

日経 xTECH SPECIAL
【PR】生成AIやクラウドでリスク急増…STOP内部不正
解説「AI時代のログ管理」の勘所
https://xtech.nikkei.com/atcl/nxt/special/18/00001/082000075/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第5回
「プラットフォーム」で変わったネット広告、配信の仕組みをおさらい
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800005/?ST=nxt_thmit_security

2025年9月4日木曜日

4日 木曜日、先勝

+ RHSA-2025:15124 Moderate: Satellite 6.16.5.3 Async Update
https://access.redhat.com/errata/RHSA-2025:15124
CVE-2024-49761

+ RHSA-2025:15123 Moderate: httpd:2.4 security update
https://access.redhat.com/errata/RHSA-2025:15123
VE-2024-47252
CVE-2025-23048
CVE-2025-49630
CVE-2025-49812

+ RHSA-2025:15115 Important: postgresql:12 security update
https://access.redhat.com/errata/RHSA-2025:15115
CVE-2025-8714
CVE-2025-8715

+ RHSA-2025:15124 Moderate: Satellite 6.16.5.3 Async Update
https://access.redhat.com/errata/RHSA-2025:15124
CVE-2024-49761

+ RHSA-2025:15099 Important: pam security update
https://access.redhat.com/errata/RHSA-2025:15099
CVE-2025-6020
CVE-2025-8941

+ Mozilla Thunderbird 140.2.1 released
https://www.thunderbird.net/en-US/thunderbird/140.2.1esr/releasenotes/

+ UPDATE: JVNVU#92928084 複数のHTTP/2サーバー実装におけるストリームリセット処理の不備(CVE-2025-8671)
https://jvn.jp/vu/JVNVU92928084/index.html

不快なネット広告を遮断せよ!
第4回
うっとうしいネット広告、「不快さ」を取り締まる法律はあるのか
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800004/?ST=nxt_thmit_security

JVNVU#92183348 Delta Electronics製EIP BuilderにおけるXML外部エンティティ参照(XXE)の不適切な制限の脆弱性
https://jvn.jp/vu/JVNVU92183348/index.html

JVNVU#91978467 富士電機製FRENIC-Loader 4における信頼できないデータのデシリアライゼーションの脆弱性
https://jvn.jp/vu/JVNVU91978467/index.html

JVN#65839588 Web Caster V130におけるクロスサイトリクエストフォージェリの脆弱性
https://jvn.jp/jp/JVN65839588/index.html

2025年9月3日水曜日

3日 水曜日、赤口

+ RHSA-2025:14983 Moderate: mod_http2 security update
https://access.redhat.com/errata/RHSA-2025:14983
CVE-2025-49630

+ Google Chrome 140.0.7339.80/81 released
https://chromereleases.googleblog.com/2025/09/stable-channel-update-for-desktop.html

+ UPDATE: JVNVU#92928084 複数のHTTP/2サーバー実装におけるストリームリセット処理の不備(CVE-2025-8671)
https://jvn.jp/vu/JVNVU92928084/index.html

JVN#47404248 スマートフォンアプリ「グノシー」における送信データへの機微な情報の挿入の脆弱性
https://jvn.jp/jp/JVN47404248/index.html

実験を通じて理解する、HTTP/3の真実
第3回
HTTP/3の性能を実地で検証、驚くべき結果がそこに
https://xtech.nikkei.com/atcl/nxt/column/18/03312/082600003/?ST=nxt_thmit_security

勝村幸博の「今日も誰かが狙われる」
フィッシング被害に遭いやすいのはパソコンかスマホか、250人超を対象に実験
https://xtech.nikkei.com/atcl/nxt/column/18/00676/082800204/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第3回
偽広告のクリック先で待ち受ける「わな」 サポート詐欺にマルウエア、架空投資話
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800003/?ST=nxt_thmit_security

2025年9月2日火曜日

2日 火曜日、大安

+ Wireshark 4.4.9, 4.2.13 released
https://www.wireshark.org/docs/relnotes/wireshark-4.4.9.html
https://www.wireshark.org/docs/relnotes/wireshark-4.2.13.html

マルウエア徹底解剖
インフォスティーラーの手口を理解する
[第69回]
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/111900071/081800070/?ST=nxt_thmit_security

実験を通じて理解する、HTTP/3の真実
第2回
HTTPはいかに進化してきたか、仕様の変遷を技術面から解説
https://xtech.nikkei.com/atcl/nxt/column/18/03312/082600002/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第2回
ネットの行動を追跡する「トラッキング」、支えるサードパーティCookieは制限対象に
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800002/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
国交省の港湾物流システム「CONPAS」から偽のメール送信か、受信者に送金求める
https://xtech.nikkei.com/atcl/nxt/column/18/00598/041800330/?ST=nxt_thmit_security

絵で見て分かるネットワーク必修キーワード
多要素認証
性格が異なる複数の要素を使った認証方式
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/091900172/081800024/?ST=nxt_thmit_security

フォーカス
不正売買5700億円 口座乗っ取り対策の実態
ネット証券15社を緊急調査
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020600014/082700210/?ST=nxt_thmit_security

実験を通じて理解する、HTTP/3の真実
第1回
HTTP/3の普及率は3割で頭打ち、実は主要ソフトが非対応
https://xtech.nikkei.com/atcl/nxt/column/18/03312/082600001/?ST=nxt_thmit_security

不快なネット広告を遮断せよ!
第1回
Webもメールも埋め尽くすネット広告、正規サイトでも「本物」が分かりにくい
https://xtech.nikkei.com/atcl/nxt/column/18/03299/081800001/?ST=nxt_thmit_security

JVN#22016482 セイコーソリューションズ製SkyBridge BASIC MB-A130におけるOSコマンドインジェクションの脆弱性
https://jvn.jp/jp/JVN22016482/index.html

udisksの脆弱性(High: CVE-2025-8067)
https://security.sios.jp/vulnerability/udisks-security-vulnerability-20250829/

2025年8月29日金曜日

29日 金曜日、先勝

+ RHSA-2025:14900 Moderate: python39:3.9 security update
https://access.redhat.com/errata/RHSA-2025:14900
CVE-2025-8194
CVE-2025-47273

+ RHSA-2025:14899 Important: postgresql:16 security update
https://access.redhat.com/errata/RHSA-2025:14899
CVE-2025-8714
CVE-2025-8715

+ RHSA-2025:14841 Moderate: python3.11 security update
https://access.redhat.com/errata/RHSA-2025:14841
CVE-2025-8194

+ RHSA-2025:14878 Important: postgresql security update
https://access.redhat.com/errata/RHSA-2025:14878
CVE-2025-8714
CVE-2025-8715

+ RHSA-2025:14862 Important: postgresql:15 security update
https://access.redhat.com/errata/RHSA-2025:14862
CVE-2025-8714
CVE-2025-8715

+ RHSA-2025:14827 Important: postgresql:16 security update
https://access.redhat.com/errata/RHSA-2025:14827
CVE-2025-8714
CVE-2025-8715

+ PHP 8.4.12, 8.3.25 released
https://www.php.net/ChangeLog-8.php#8.4.12
https://www.php.net/ChangeLog-8.php#8.3.25

JVNVU#90041458 三菱電機製MELSEC iQ-F CPUユニットにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90041458/index.html

月刊ランサムリポート
被害件数の減少傾向は2カ月で打ち止め 医療サービスを重点的に狙う「Qilin」の攻撃が増加
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041600214/081800006/?ST=nxt_thmit_security

日経コンピュータ 勝村幸博の「今日も誰かが狙われる」
スマホアプリの画面を「透明」に 危険な操作に誘導する新手口
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/052100113/082700166/?ST=nxt_thmit_security

月刊ランサムリポート
第9回
25年7月のランサム被害を分析、新たなグループ「D4RK 4RMY」に要注意
https://xtech.nikkei.com/atcl/nxt/column/18/03053/082200009/?ST=nxt_thmit_security

2025年8月28日木曜日

28日 木曜日、赤口

+ RHSA-2025:14750 Moderate: fence-agents security update
https://access.redhat.com/errata/RHSA-2025:14750
CVE-2024-47081

+ RHSA-2025:14743 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2025:14743
CVE-2025-9179
CVE-2025-9180
CVE-2025-9181
CVE-2025-9182
CVE-2025-9185

+ RHSA-2025:14573 Important: aide security update
https://access.redhat.com/errata/RHSA-2025:14573
CVE-2025-54389

+ RHSA-2025:14553 Moderate: python-cryptography security update
https://access.redhat.com/errata/RHSA-2025:14553
CVE-2023-49083

+ RHSA-2025:14640 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2025:14640
CVE-2025-9179
CVE-2025-9180
CVE-2025-9181
CVE-2025-9182
CVE-2025-9185

+ Mozilla Firefox 142.0.1 released
https://www.firefox.com/en-US/firefox/142.0.1/releasenotes/

+ Linux Kernelの脆弱性(CVE-2025-38616?CVE-2025-38675)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20250826/
CVE-2025-38616
CVE-2025-38617
CVE-2025-38618
CVE-2025-38619
CVE-2025-38620
CVE-2025-38621
CVE-2025-38622
CVE-2025-38623
CVE-2025-38624
CVE-2025-38625
CVE-2025-38626
CVE-2025-38627
CVE-2025-38628
CVE-2025-38629
CVE-2025-38630
CVE-2025-38631
CVE-2025-38632
CVE-2025-38633
CVE-2025-38634
CVE-2025-38635
CVE-2025-38636
CVE-2025-38637
CVE-2025-38638
CVE-2025-38639
CVE-2025-38640
CVE-2025-38641
CVE-2025-38642
CVE-2025-38643
CVE-2025-38644
CVE-2025-38645
CVE-2025-38646
CVE-2025-38647
CVE-2025-38648
CVE-2025-38649
CVE-2025-38650
CVE-2025-38651
CVE-2025-38652
CVE-2025-38653
CVE-2025-38654
CVE-2025-38655
CVE-2025-38656
CVE-2025-38657
CVE-2025-38658
CVE-2025-38659
CVE-2025-38660
CVE-2025-38661
CVE-2025-38662
CVE-2025-38663
CVE-2025-38664
CVE-2025-38665
CVE-2025-38666
CVE-2025-38667
CVE-2025-38668
CVE-2025-38669
CVE-2025-38670
CVE-2025-38671
CVE-2025-38672
CVE-2025-38673
CVE-2025-38674
CVE-2025-38675

決算調査で判明、サイバー被害52社のリアル
10社がサイバー保険で損失軽減 保険金が億円単位のケースも
[第3回]
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/063000493/082500003/?ST=nxt_thmit_security

NEWS close-up
フィッシングメール訓練は効果があるか
米国で2万人対象の大規模調査 失敗率や学習効果に驚きの結果
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/081800298/?ST=nxt_thmit_security

日経NETWORK 特別リポート
ネット証券口座乗っ取り対策の実態調査
不正売買6200億円
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800013/081800094/?ST=nxt_thmit_security

NEWS close-up
狙われる地銀の法人ネット口座
不正送金の被害額は120倍に 主犯はボイスフィッシング
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/081800297/?ST=nxt_thmit_security

JVN#55678602 複数のi-フィルター製品における不適切なファイルアクセス権設定の脆弱性
https://jvn.jp/jp/JVN55678602/index.html

JVN#99577552 SS1における複数の脆弱性
https://jvn.jp/jp/JVN99577552/index.html

JVNVU#94006179 複数のSchneider Electric製品における不適切な入力検証の脆弱性
https://jvn.jp/vu/JVNVU94006179/index.html

JVN#69684540 ScanSnap Managerのインストーラにおける権限昇格につながる脆弱性
https://jvn.jp/jp/JVN69684540/index.html

JVNVU#96395440 Danfoss製AK-SM 8xxAシリーズにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96395440/index.html

JVNVU#92928084 複数のHTTP/2サーバー実装におけるストリームリセット処理の不備(CVE-2025-8671)
https://jvn.jp/vu/JVNVU92928084/index.html

2025年8月26日火曜日

26日 火曜日、仏滅

+ Zabbix 7.4.2, 7.0.18 released
https://www.zabbix.com/rn/rn7.4.2
https://www.zabbix.com/rn/rn7.0.18

NEWS close-up
証券口座乗っ取り対策に新指針
ワンタイムパスワードは原則禁止へ 送信ドメイン認証の導入も求める
https://xtech.nikkei.com/atcl/nxt/mag/nnw/18/041800012/081800296/?ST=nxt_thmit_security

北郷達郎のテクノロジー温故知新
いい意味で変化がないCLIプログラミング、刻々と変わるGUIプログラミング
https://xtech.nikkei.com/atcl/nxt/column/18/02598/081900024/?ST=nxt_thmit_security

piyokangoの週刊システムトラブル
バレーボールリーグの共用システム、開始1カ月で15件の不具合 検証不足が根本原因
https://xtech.nikkei.com/atcl/nxt/column/18/00598/041800329/?ST=nxt_thmit_security

2025年8月25日月曜日

25日 月曜日、先負

吉川孝志のマルウエア徹底解剖
第19回
存在感高まる「インフォスティーラー」、はびこる背景から関連技術まで徹底解説
https://xtech.nikkei.com/atcl/nxt/column/18/02805/081900020/?ST=nxt_thmit_security

ニュース解説
社労夢の3億円訴訟、訴状で指摘する「クラウドサービスにあるまじき危険な設定」
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11029/?ST=nxt_thmit_security

社労夢ユーザー90人がエムケイシステムに集団訴訟 3億円超請求、ランサム被害で
https://xtech.nikkei.com/atcl/nxt/news/24/02770/?ST=nxt_thmit_security

JVNVU#90316328 三菱電機製MELSEC iQ-F CPUユニットのWebサーバ機能におけるレングスパラメーターの不適切な処理
https://jvn.jp/vu/JVNVU90316328/index.html

JVN#75211379 Western Digital Kitfoxにおける引用符で囲まれていないファイルパスの脆弱性
https://jvn.jp/jp/JVN75211379/index.html

JVNVU#94286093 富士フイルムヘルスケアアメリカ製Synapse MobilityにおけるWebパラメタの外部制御による権限昇格の脆弱性
https://jvn.jp/vu/JVNVU94286093/index.html

2025年8月22日金曜日

22日 金曜日、仏滅

+ Linux Kernelの脆弱性(CVE-2025-38498?CVE-2025-38615)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20250820/
CVE-2025-38498
CVE-2025-38499
CVE-2025-38500
CVE-2025-38501
CVE-2025-38502
CVE-2025-38503
CVE-2025-38504
CVE-2025-38505
CVE-2025-38506
CVE-2025-38507
CVE-2025-38508
CVE-2025-38509
CVE-2025-38510
CVE-2025-38511
CVE-2025-38512
CVE-2025-38513
CVE-2025-38514
CVE-2025-38515
CVE-2025-38516
CVE-2025-38517
CVE-2025-38518
CVE-2025-38519
CVE-2025-38520
CVE-2025-38521
CVE-2025-38522
CVE-2025-38523
CVE-2025-38524
CVE-2025-38525
CVE-2025-38526
CVE-2025-38527
CVE-2025-38528
CVE-2025-38529
CVE-2025-38530
CVE-2025-38531
CVE-2025-38532
CVE-2025-38533
CVE-2025-38534
CVE-2025-38535
CVE-2025-38536
CVE-2025-38537
CVE-2025-38538
CVE-2025-38539
CVE-2025-38540
CVE-2025-38541
CVE-2025-38542
CVE-2025-38543
CVE-2025-38544
CVE-2025-38545
CVE-2025-38546
CVE-2025-38547
CVE-2025-38548
CVE-2025-38549
CVE-2025-38550
CVE-2025-38551
CVE-2025-38552
CVE-2025-38553
CVE-2025-38554
CVE-2025-38555
CVE-2025-38556
CVE-2025-38557
CVE-2025-38558
CVE-2025-38559
CVE-2025-38560
CVE-2025-38561
CVE-2025-38562
CVE-2025-38563
CVE-2025-38564
CVE-2025-38565
CVE-2025-38566
CVE-2025-38567
CVE-2025-38568
CVE-2025-38569
CVE-2025-38570
CVE-2025-38571
CVE-2025-38572
CVE-2025-38573
CVE-2025-38574
CVE-2025-38575
CVE-2025-38576
CVE-2025-38577
CVE-2025-38578
CVE-2025-38579
CVE-2025-38580
CVE-2025-38581
CVE-2025-38582
CVE-2025-38583
CVE-2025-38584
CVE-2025-38585
CVE-2025-38586
CVE-2025-38587
CVE-2025-38588
CVE-2025-38589
CVE-2025-38590
CVE-2025-38591
CVE-2025-38592
CVE-2025-38593
CVE-2025-38594
CVE-2025-38595
CVE-2025-38596
CVE-2025-38597
CVE-2025-38598
CVE-2025-38599
CVE-2025-38600
CVE-2025-38601
CVE-2025-38602
CVE-2025-38603
CVE-2025-38604
CVE-2025-38605
CVE-2025-38606
CVE-2025-38607
CVE-2025-38608
CVE-2025-38609
CVE-2025-38610
CVE-2025-38611
CVE-2025-38612
CVE-2025-38613
CVE-2025-38614
CVE-2025-38615

基礎から分かるローカルブレークアウト
第3回
ローカルブレークアウトは3ステップで導入しよう、セキュリティー対策も忘れずに
https://xtech.nikkei.com/atcl/nxt/column/18/03293/080800003/?ST=nxt_thmit_security

Black Hat USA 2025現地リポート
第4回
セキュリティー研究の大御所がBlack Hatの基調講演、「転機は2003年」と30年を総括
https://xtech.nikkei.com/atcl/nxt/column/18/03295/081800005/?ST=nxt_thmit_security

ニュース解説
東武と日立、指静脈認証でホテルチェックイン&決済 省人化・高精度の一方で課題も
https://xtech.nikkei.com/atcl/nxt/column/18/00001/11010/?ST=nxt_thmit_security

UPDATE: JVNVU#98989635 Delta Electronics製DIAViewにおける‘.../...//‘に関するパストラバーサルの脆弱性
https://jvn.jp/vu/JVNVU98989635/index.html

JVNVU#90316328 三菱電機製MELSEC iQ-F CPUユニットのWebサーバ機能におけるレングスパラメーターの不適切な処理
https://jvn.jp/vu/JVNVU90316328/index.html

JVNVU#96471539 三菱電機製空調管理システムにおける認証回避の脆弱性
https://jvn.jp/vu/JVNVU96471539/index.html

JVN#72111431 Group-Officeにおける複数の脆弱性
https://jvn.jp/jp/JVN72111431/index.html

2025年8月21日木曜日

21日 木曜日、先負

+ RHSA-2025:14177 Important: tomcat security update
https://access.redhat.com/errata/RHSA-2025:14177
CVE-2025-48976
CVE-2025-48988
CVE-2025-48989
CVE-2025-49125
CVE-2025-52434
CVE-2025-52520
CVE-2025-53506

+ RHSA-2025:14135 Important: libarchive security update
https://access.redhat.com/errata/RHSA-2025:14135
CVE-2025-5914

+ RHSA-2025:14126 Important: pki-deps:10.6 security update
https://access.redhat.com/errata/RHSA-2025:14126
CVE-2025-52999

+ RHSA-2025:14181 Important: tomcat security update
https://access.redhat.com/errata/RHSA-2025:14181
CVE-2025-48976
CVE-2025-48988
CVE-2025-48989
CVE-2025-49125
CVE-2025-52434
CVE-2025-52520
CVE-2025-53506

+ RHSA-2025:14130 Important: libarchive security update
https://access.redhat.com/errata/RHSA-2025:14130
CVE-2025-5914

+ About the security content of iOS 18.6.2 and iPadOS 18.6.2
https://support.apple.com/en-us/124925
CVE-2025-43300

+ About the security content of iPadOS 17.7.10
https://support.apple.com/en-us/124926
CVE-2025-43300

+ About the security content of macOS Sequoia 15.6.1
https://support.apple.com/en-us/124927
CVE-2025-43300

+ About the security content of macOS Sonoma 14.7.8
https://support.apple.com/en-us/124928
CVE-2025-43300

+ About the security content of macOS Ventura 13.7.8
https://support.apple.com/en-us/124929
CVE-2025-43300

+ ISC BIND 9.20.12, 9.18.39 released
https://downloads.isc.org/isc/bind9/9.20.12/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.18.39/doc/arm/html/notes.html

+ MSSQL Database Privilege Elevation From ALTER ANY LOGIN To SYSADMIN
https://cxsecurity.com/issue/WLB-2025080019

JVNVU#94286093 富士フイルムヘルスケアアメリカ製Synapse MobilityにおけるWebパラメタの外部制御による権限昇格の脆弱性
https://jvn.jp/vu/JVNVU94286093/index.html

JVN#76729865 Movable Typeにおける複数の脆弱性
https://jvn.jp/jp/JVN76729865/index.html

JVNVU#96783966 複数のRockwell Automation製品における複数の脆弱性
https://jvn.jp/vu/JVNVU96783966/index.html

JVNVU#98646422 EG4 Electronics製EG4インバーターにおける複数の脆弱性
https://jvn.jp/vu/JVNVU98646422/index.html

JVNVU#92169998 Siemens製品に対するアップデート(2025年8月)
https://jvn.jp/vu/JVNVU92169998/index.html

ニュース&リポート
地銀法人口座からの不正送金が急増 手口はボイスフィッシング
25年1~3月の被害は16億円、前年同期の120倍に
https://xtech.nikkei.com/atcl/nxt/mag/nc/18/020800017/080801301/?ST=nxt_thmit_security

基礎から分かるローカルブレークアウト
第2回
ローカルブレークアウトの仕組みを解説、「直接通信」を仕分ける3つのやり方
https://xtech.nikkei.com/atcl/nxt/column/18/03293/080800002/?ST=nxt_thmit_security

Black Hat USA 2025現地リポート
第3回
LLMでマルウエアの「追跡」、バイナリー解析も Black Hat注目の4講演
https://xtech.nikkei.com/atcl/nxt/column/18/03295/081800004/?ST=nxt_thmit_security

2025年8月20日水曜日

20日 水曜日、友引

+ RHSA-2025:14075 Moderate: xterm security update
https://access.redhat.com/errata/RHSA-2025:14075
CVE-2022-24130

+ Google Chrome 139.0.7258.138/.139, 138.0.7204.243 released
https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_19.html
https://chromereleases.googleblog.com/2025/08/extended-stable-updates-for-desktop_19.html

+ Mozilla Firefox 142.0 released
https://www.firefox.com/en-US/firefox/142.0/releasenotes/

+ Mozilla Foundation Security Advisory 2025-64 Security Vulnerabilities fixed in Firefox 142
https://www.mozilla.org/en-US/security/advisories/mfsa2025-64/
CVE-2025-9179
CVE-2025-9180
CVE-2025-9181
CVE-2025-9186
CVE-2025-9182
CVE-2025-9183
CVE-2025-9187
CVE-2025-9184
CVE-2025-9185

+ Zabbix 7.2.12, 6.0.41 released
https://www.zabbix.com/rn/rn7.2.12
https://www.zabbix.com/rn/rn6.0.41

+ watchOS 11.6.1 released
https://support.apple.com/ja-jp/100100

+ Mozilla Foundation Security Advisory 2025-70 Security Vulnerabilities fixed in Thunderbird 142
https://www.mozilla.org/en-US/security/advisories/mfsa2025-70/
CVE-2025-9179
CVE-2025-9180
CVE-2025-9181
CVE-2025-9182
CVE-2025-9187
CVE-2025-9184
CVE-2025-9185

+ Mozilla Thunderbird 142.0 released
https://www.thunderbird.net/en-US/thunderbird/142.0/releasenotes/

+ Postfix stable release 3.10.4 and legacy releases 3.9.5, 3.8.11, 3.7.16
https://www.postfix.org/announcements/postfix-3.10.4.html

+ JVNVU#95006047 Apache TomcatのRewrite Valve機能におけるセッション固定の脆弱性(CVE-2025-55668)
https://jvn.jp/vu/JVNVU95006047/index.html
CVE-2025-55668

+ Linux Kernelの脆弱性(CVE-2025-38948?CVE-2025-38615)
https://security.sios.jp/vulnerability/kernel-security-vulnerability-20250820/
CVE-2025-38498
CVE-2025-38499
CVE-2025-38500
CVE-2025-38501
CVE-2025-38502
CVE-2025-38503
CVE-2025-38504
CVE-2025-38505
CVE-2025-38506
CVE-2025-38507
CVE-2025-38508
CVE-2025-38509
CVE-2025-38510
CVE-2025-38511
CVE-2025-38512
CVE-2025-38513
CVE-2025-38514
CVE-2025-38515
CVE-2025-38516
CVE-2025-38517
CVE-2025-38518
CVE-2025-38519
CVE-2025-38520
CVE-2025-38521
CVE-2025-38522
CVE-2025-38523
CVE-2025-38524
CVE-2025-38525
CVE-2025-38526
CVE-2025-38527
CVE-2025-38528
CVE-2025-38529
CVE-2025-38530
CVE-2025-38531
CVE-2025-38532
CVE-2025-38533
CVE-2025-38534
CVE-2025-38535
CVE-2025-38536
CVE-2025-38537
CVE-2025-38538
CVE-2025-38539
CVE-2025-38540
CVE-2025-38541
CVE-2025-38542
CVE-2025-38543
CVE-2025-38544
CVE-2025-38545
CVE-2025-38546
CVE-2025-38547
CVE-2025-38548
CVE-2025-38549
CVE-2025-38550
CVE-2025-38551
CVE-2025-38552
CVE-2025-38553
CVE-2025-38554
CVE-2025-38555
CVE-2025-38556
CVE-2025-38557
CVE-2025-38558
CVE-2025-38559
CVE-2025-38560
CVE-2025-38561
CVE-2025-38562
CVE-2025-38563
CVE-2025-38564
CVE-2025-38565
CVE-2025-38566
CVE-2025-38567
CVE-2025-38568
CVE-2025-38569
CVE-2025-38570
CVE-2025-38571
CVE-2025-38572
CVE-2025-38573
CVE-2025-38574
CVE-2025-38575
CVE-2025-38576
CVE-2025-38577
CVE-2025-38578
CVE-2025-38579
CVE-2025-38580
CVE-2025-38581
CVE-2025-38582
CVE-2025-38583
CVE-2025-38584
CVE-2025-38585
CVE-2025-38586
CVE-2025-38587
CVE-2025-38588
CVE-2025-38589
CVE-2025-38590
CVE-2025-38591
CVE-2025-38592
CVE-2025-38593
CVE-2025-38594
CVE-2025-38595
CVE-2025-38596
CVE-2025-38597
CVE-2025-38598
CVE-2025-38599
CVE-2025-38600
CVE-2025-38601
CVE-2025-38602
CVE-2025-38603
CVE-2025-38604
CVE-2025-38605
CVE-2025-38606
CVE-2025-38607
CVE-2025-38608
CVE-2025-38609
CVE-2025-38610
CVE-2025-38611
CVE-2025-38612
CVE-2025-38613
CVE-2025-38614
CVE-2025-38615

VU#706118 Workhorse Software Services, Inc. software prior to version 1.9.4.48019, default deployment is vulnerable to multiple issues.
https://www.kb.cert.org/vuls/id/706118

勝村幸博の「今日も誰かが狙われる」
スマホアプリの画面表示を「透明」に偽装、ユーザーを危険な操作に誘導する新手口
https://xtech.nikkei.com/atcl/nxt/column/18/00676/080400203/?ST=nxt_thmit_security

ニュース解説
AIコード生成の幻覚は「エージェント型」で減少、トレンドマイクロが調査
https://xtech.nikkei.com/atcl/nxt/column/18/00001/10987/?ST=nxt_thmit_security

Black Hat USA 2025現地リポート
第2回
AIエージェント神話にセキュリティー専門家が反論、Black HatのAI特化イベントで
https://xtech.nikkei.com/atcl/nxt/column/18/03295/081500003/?ST=nxt_thmit_security

基礎から分かるローカルブレークアウト
第1回
じわり広がる「ローカルブレークアウト」とは何なのか、誰がいつ導入すべきか
https://xtech.nikkei.com/atcl/nxt/column/18/03293/080800001/?ST=nxt_thmit_security

JVN#89385114 Seagate Toolkitにおける引用符で囲まれていないファイルパスの脆弱性
https://jvn.jp/jp/JVN89385114/index.html

2025年8月19日火曜日

19日 火曜日、先勝

+ RHSA-2025:13960 Important: kernel security update
https://access.redhat.com/errata/RHSA-2025:13960
CVE-2025-22097
CVE-2025-37914
CVE-2025-38250
CVE-2025-38380

+ RHSA-2025:13940 Important: go-toolset:rhel8 security update
https://access.redhat.com/errata/RHSA-2025:13940
CVE-2025-4674

+ RHSA-2025:13962 Important: kernel security update
https://access.redhat.com/errata/RHSA-2025:13962
CVE-2024-28956
CVE-2025-21867
CVE-2025-38084
CVE-2025-38085
CVE-2025-38124
CVE-2025-38159
CVE-2025-38250
CVE-2025-38380
CVE-2025-38471

+ RHSA-2025:13935 Important: golang security update
https://access.redhat.com/errata/RHSA-2025:13935
CVE-2025-4674

+ iOS 18.6.1 released
https://support.apple.com/en-us/100100

+ Tcl/Tk 8.6.17 released
https://www.tcl-lang.org/software/tcltk/8.6.html

世界的なセキュリティーイベント「Black Hat」 講演採択は狭き門、日本人3人登壇
https://xtech.nikkei.com/atcl/nxt/column/18/03295/081400001/?ST=nxt_thmit_security

メルセデス・ベンツ日本、システムの設定不備で顧客情報が7日間閲覧可能な状態に
https://xtech.nikkei.com/atcl/nxt/column/18/00598/041800328/?ST=nxt_thmit_security

英Coltテクノロジー、サイバーインシデントで一部サービスが利用できない状態
https://xtech.nikkei.com/atcl/nxt/news/24/02759/?ST=nxt_thmit_security

UPDATE: JVNVU#91819309 複数のブラザー製Windows版ドライバーインストーラーにおける権限昇格につながる脆弱性
https://jvn.jp/vu/JVNVU91819309/index.html

JVNVU#92409854 トレンドマイクロ製企業向けエンドポイントセキュリティ製品における複数のOSコマンドインジェクションの脆弱性
https://jvn.jp/vu/JVNVU92409854/index.html

JVN#46919949 PgManageにおけるインジェクションの脆弱性
https://jvn.jp/jp/JVN46919949/index.html

2025年8月18日月曜日

18日 月曜日、赤口

+ Microsoft Edge Renderer Process (Mojo IPC) Sandbox Escape
https://cxsecurity.com/issue/WLB-2025080016

VU#209095 SMM Memory Corruption Vulnerability in the AMI Aptio's SMM Module Across Multiple Devices
https://www.kb.cert.org/vuls/id/209095

JVNVU#92169998 Siemens製品に対するアップデート(2025年8月)
https://jvn.jp/vu/JVNVU92169998/index.html

UPDATE: JVNVU#97295618 Guralp Systems製Guralp FMUS SeriesおよびGuralp MIN Seriesにおける重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/vu/JVNVU97295618/index.html

2025年8月15日金曜日

15日 金曜日、先負

+ PostgreSQL 17.6, 16.10, 15.14, 14.19, 13.22, and 18 Beta 3 Released!
https://www.postgresql.org/about/news/postgresql-176-1610-1514-1419-1322-and-18-beta-3-released-3118/
https://www.postgresql.org/docs/17/release-17-6.html
https://www.postgresql.org/docs/16/release-16-10.html
https://www.postgresql.org/docs/15/release-15-14.html
https://www.postgresql.org/docs/14/release-14-19.html
https://www.postgresql.org/docs/13/release-13-22.html

JVN#89385114 Seagate Toolkitにおける引用符で囲まれていない検索パスの脆弱性
https://jvn.jp/jp/JVN89385114/index.html

JVNVU#90372902 Intel製品に複数の脆弱性(2025年8月)
https://jvn.jp/vu/JVNVU90372902/index.html

2025年8月14日木曜日

14日 木曜日、友引

+ RHSA-2025:13780 Important: webkit2gtk3 security update
https://access.redhat.com/errata/RHSA-2025:13780
CVE-2025-6558
CVE-2025-31273
CVE-2025-31278
CVE-2025-43211
CVE-2025-43212
CVE-2025-43216
CVE-2025-43227
CVE-2025-43240
CVE-2025-43265

+ RHSA-2025:13676 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2025:13676
CVE-2025-8027
CVE-2025-8028
CVE-2025-8029
CVE-2025-8030
CVE-2025-8031
CVE-2025-8032
CVE-2025-8033
CVE-2025-8034
CVE-2025-8035

+ RHSA-2025:13675 Important: java-1.8.0-ibm security update
https://access.redhat.com/errata/RHSA-2025:13675
CVE-2025-30749
CVE-2025-30754
CVE-2025-30761
CVE-2025-50106

+ RHSA-2025:13782 Important: webkit2gtk3 security update
https://access.redhat.com/errata/RHSA-2025:13782
CVE-2025-6558
CVE-2025-31273
CVE-2025-31278
CVE-2025-43211
CVE-2025-43212
CVE-2025-43216
CVE-2025-43227
CVE-2025-43240
CVE-2025-43265

+ RHSA-2025:13673 Important: toolbox security update
https://access.redhat.com/errata/RHSA-2025:13673
CVE-2025-23266

+ RHSA-2025:13671 Moderate: Updated 7.1 container image is now available in the Red Hat Ecosystem Catalog
https://access.redhat.com/errata/RHSA-2025:13671
CVE-2022-29458
CVE-2024-47081
CVE-2025-5222
CVE-2025-6965
CVE-2025-7425
CVE-2025-8058
CVE-2025-22871
CVE-2025-40909

+ Google Chrome 139.0.7258.127/.128, 138.0.7204.235 released
https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop_12.html
https://chromereleases.googleblog.com/2025/08/extended-stable-updates-for-desktop_12.html

+ nginx 1.29.1 released
https://nginx.org/en/CHANGES

+ 2025 年 8 月のセキュリティ更新プログラム (月例)
https://msrc.microsoft.com/blog/2025/08/202508-security-update/

VU#767506 HTTP/2 implementations are vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames
https://www.kb.cert.org/vuls/id/767506

JVNVU#92169998 Siemens製品に対するアップデート(2025年8月)
https://jvn.jp/vu/JVNVU92169998/index.html

JVNVU#92888248 複数のAshlar-Vellum製品における複数の脆弱性
https://jvn.jp/vu/JVNVU92888248/index.html

JVNVU#99021467 複数のJohnson Controls製品における複数の脆弱性
https://jvn.jp/vu/JVNVU99021467/index.html

JVNVU#90148644 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU90148644/index.html

JVNVU#91044952 AVEVA製PI Integratorにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91044952/index.html

JVNVU#97403994 Santesoft製Sante PACS Serverにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97403994/index.html

JVNVU#97905990 MegaSys Computer Technologies製Telenium Online Web Applicationにおける不適切な入力検証の脆弱性
https://jvn.jp/vu/JVNVU97905990/index.html

2025年8月12日火曜日

12日 火曜日、赤口

+ RHSA-2025:13589 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2025:13589
CVE-2021-47670
CVE-2024-56644
CVE-2025-21727
CVE-2025-21759
CVE-2025-38085
CVE-2025-38159

+ RHSA-2025:13602 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2025:13602
CVE-2025-38079
CVE-2025-38292

+ RHSA-2025:13578 Moderate: python3.11-setuptools security update
https://access.redhat.com/errata/RHSA-2025:13578
CVE-2025-47273

+ Mozilla Firefox 141.0.3 released
https://www.firefox.com/en-US/firefox/141.0.3/releasenotes/

+ FreeBSD-SA-25:07.libarchive Integer overflow in libarchive leading to double free
https://www.freebsd.org/security/advisories/FreeBSD-SA-25:07.libarchive.asc
CVE-2025-5914

+ GCC 15.2 released
https://gcc.gnu.org/onlinedocs/15.2.0/

UPDATE: JVNVU#94499889 - Instantel製Micromateにおける重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/vu/JVNVU94499889/index.html

JVNVU#98989635 Delta Electronics製DIAViewにおける‘.../...//’ = ‘.../...//‘に関するパストラバーサルの脆弱性
https://jvn.jp/vu/JVNVU98989635/index.html

JVNVU#97933962 複数のJohnson Controls製品における脆弱なサードパーティコンポーネントへの依存の脆弱性
https://jvn.jp/vu/JVNVU97933962/index.html

JVNVU#98201292 Burk Technology製ARC Soloにおける重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/vu/JVNVU98201292/index.html

JVNVU#97486818 Rockwell Automation製Arena Simulationにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97486818/index.html

JVNVU#97241178 複数のDreame Technology製品における不正な証明書検証の脆弱性
https://jvn.jp/vu/JVNVU97241178/index.html

JVNVU#98646422 EG4 Electronics製EG4インバーターにおける複数の脆弱性
https://jvn.jp/vu/JVNVU98646422/index.html

JVNVU#99875984 複数のYealink製品における複数の脆弱性
https://jvn.jp/vu/JVNVU99875984/index.html

JVN#21048820 WordPress用プラグインAdvanced Custom FieldsにおけるHTMLインジェクションの脆弱性
https://jvn.jp/jp/JVN21048820/index.html

JVN#39636188 ムービット製Powered BLUE 870における複数の脆弱性
https://jvn.jp/jp/JVN39636188/index.html

2025年8月8日金曜日

8日 金曜日、友引

+ RHSA-2025:13315 Moderate: gdk-pixbuf2 security update
https://access.redhat.com/errata/RHSA-2025:13315
CVE-2025-7345

+ RHSA-2025:13269 Moderate: Satellite 6.17.3 Async Update
https://access.redhat.com/errata/RHSA-2025:13269
CVE-2024-49761

+ RHSA-2025:13428 Moderate: libxml2 security update
https://access.redhat.com/errata/RHSA-2025:13428
CVE-2025-32414
CVE-2025-32415

+ Apache Tomcat 11.0.10, 10.1.44, 9.0.108 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.10_(markt)
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.44_(schultz)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.108_(remm)

JVNVU#91363496 複数のセイコーエプソン製品における脆弱な認証情報の使用の脆弱性
https://jvn.jp/vu/JVNVU91363496/index.html

2025年8月7日木曜日

7日 木曜日、先勝

+ RHSA-2025:13234 Moderate: python-requests security update
https://access.redhat.com/errata/RHSA-2025:13234
CVE-2024-47081

+ RHSA-2025:13203 Moderate: libxml2 security update
https://access.redhat.com/errata/RHSA-2025:13203
CVE-2025-32415

JVNVU#96364629 三菱電機製GENESIS64、MC Works64およびGENESISの複数のプロセスにWindowsショートカットの不適切な扱いの脆弱性
https://jvn.jp/vu/JVNVU96364629/index.html

JVNVU#92409854 トレンドマイクロ製企業向けエンドポイントセキュリティ製品における複数のOSコマンドインジェクションの脆弱性
https://jvn.jp/vu/JVNVU92409854/index.html

JVN#16547726 サトー製ラベルプリンタCL4/6NX-J PlusおよびCL4/6NX Plusシリーズにおける複数の脆弱性
https://jvn.jp/jp/JVN16547726/index.html

JVNVU#99518249 Tigo Energy製Cloud Connect Advancedにおける複数の脆弱性
https://jvn.jp/vu/JVNVU99518249/index.html

2025年8月6日水曜日

6日 水曜日、赤口

+ RHSA-2025:12980 Moderate: glibc security update
https://access.redhat.com/errata/RHSA-2025:12980
CVE-2025-8058

+ RHSA-2025:12976 Important: kpatch-patch-5_14_0-570_17_1 security update
https://access.redhat.com/errata/RHSA-2025:12976
CVE-2025-38089

+ RHSA-2025:12834 Moderate: python3.12-setuptools security update
https://access.redhat.com/errata/RHSA-2025:12834
CVE-2025-47273

+ RHSA-2025:12831 Moderate: opentelemetry-collector security update
https://access.redhat.com/errata/RHSA-2025:12831
CVE-2025-22871

+ RHSA-2025:12746 Important: kernel security update
https://access.redhat.com/errata/RHSA-2025:12746
CVE-2022-49788
CVE-2025-21727
CVE-2025-21928
CVE-2025-21929
CVE-2025-21962
CVE-2025-22020
CVE-2025-37890
CVE-2025-38052
CVE-2025-38087

+ RHSA-2025:12519 Moderate: python-requests security update
https://access.redhat.com/errata/RHSA-2025:12519
CVE-2024-47081

+ Google Chrome 139.0.7258.66/67, 138.0.7204.224 released
https://chromereleases.googleblog.com/2025/08/stable-channel-update-for-desktop.html
https://chromereleases.googleblog.com/2025/08/extended-stable-updates-for-desktop.html

+ Mozilla Firefox 141.0.2 released
https://www.firefox.com/en-US/firefox/141.0.2/releasenotes/

+ Mozilla Thunderbird 140.1.1 released
https://www.thunderbird.net/en-US/thunderbird/140.1.1esr/releasenotes/

JVNVU#96364629 三菱電機製GENESIS64、MC Works64およびGENESISの複数のプロセスにWindowsショートカットの不適切な扱いの脆弱性
https://jvn.jp/vu/JVNVU96364629/index.html

JVNVU#90283680 三菱電機製エコガイドTABにおける複数の脆弱性
https://jvn.jp/vu/JVNVU90283680/index.html

JVNVU#93838985 三菱電機製GENESIS64、MC Works64、GENESISの複数のサービス実行時に必要以上に高い権限が割り当てられている脆弱性
https://jvn.jp/vu/JVNVU93838985/index.html

JVNVU#97735345 TP-Link製ルーターArcher C50におけるハードコードされた暗号鍵使用の脆弱性
https://jvn.jp/vu/JVNVU97735345/index.html

2025年8月5日火曜日

5日 火曜日、大安

JVNVU#93897456 富士フイルムビジネスイノベーション製複合機(MFP)における境界外書き込みの脆弱性
https://jvn.jp/vu/JVNVU93897456/index.html

2025年8月4日月曜日

4日 月曜日、仏滅

+ RHSA-2025:12450 Important: libxml2 security update
https://access.redhat.com/errata/RHSA-2025:12450
CVE-2025-7425

+ RHSA-2025:12447 Important: libxml2 security update
https://access.redhat.com/errata/RHSA-2025:12447
CVE-2025-7425

+ Microsoft Virtual Hard Disk (VHDX) 11 Remote Code Execution
https://cxsecurity.com/issue/WLB-2025080002
CVE-2025-49683

VU#317469 Partner Software/Partner Web uses does not sanitize Report files and Note content, allowing for XSS and RCE
https://www.kb.cert.org/vuls/id/317469

JVNVU#97295618 Guralp Systems製Guralp FMUS Seriesにおける重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/vu/JVNVU97295618/index.html

JVNVU#93035955 複数のRockwell Automation製品における複数の脆弱性
https://jvn.jp/vu/JVNVU93035955/index.html

2025年8月1日金曜日

1日 金曜日、先勝

+ PHP 8.4.11, 8.3.24 released
https://www.php.net/ChangeLog-8.php#8.4.11
https://www.php.net/ChangeLog-8.php#8.3.24

+ Microsoft Excel LTSC 2024 Remote Code Execution
https://cxsecurity.com/issue/WLB-2025070040
CVE-2025-27751
CVE-2025-47957

JVN#66546573 ZXHN-F660TおよびZXHN-F660Aに機器共通の認証情報が設定されている問題
https://jvn.jp/jp/JVN66546573/index.html

JVNVU#93412964 PowerCMSにおける複数の脆弱性
https://jvn.jp/vu/JVNVU93412964/index.html

2025年7月31日木曜日

31日 木曜日、赤口

+ RHSA-2025:12280 Important: jackson-annotations, jackson-core, jackson-databind, jackson-jaxrs-providers, and jackson-modules-base security update
https://access.redhat.com/errata/RHSA-2025:12280
CVE-2025-52999

+ Google Chrome 139.0.7258.66 released
https://chromereleases.googleblog.com/2025/07/early-stable-update-for-desktop.html

+ Zabbix 7.4.1 released
https://www.zabbix.com/rn/rn7.4.1

JVNVU#93412964 PowerCMSにおける複数の脆弱性
https://jvn.jp/vu/JVNVU93412964/index.html

2025年7月30日水曜日

30日 水曜日、大安

+ RHSA-2025:12010 Important: sqlite security update
https://access.redhat.com/errata/RHSA-2025:12010
CVE-2025-6965

+ RHSA-2025:12006 Important: redis:6 security update
https://access.redhat.com/errata/RHSA-2025:12006
CVE-2025-32023
CVE-2025-48367

+ RHSA-2025:11884 Important: unbound security update
https://access.redhat.com/errata/RHSA-2025:11884
CVE-2025-5994

+ RHSA-2025:11805 Moderate: perl security update
https://access.redhat.com/errata/RHSA-2025:11805
CVE-2025-40909

+ RHSA-2025:11803 Important: nodejs:22 security update
https://access.redhat.com/errata/RHSA-2025:11803
CVE-2025-6965

+ RHSA-2025:12187 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2025:12187
CVE-2025-8027
CVE-2025-8028
CVE-2025-8029
CVE-2025-8030
CVE-2025-8031
CVE-2025-8032
CVE-2025-8033
CVE-2025-8034
CVE-2025-8035

+ RHSA-2025:12100 Moderate: libtpms security update
https://access.redhat.com/errata/RHSA-2025:12100
CVE-2025-49133

+ RHSA-2025:12083 Moderate: icu security update
https://access.redhat.com/errata/RHSA-2025:12083
CVE-2025-5222

+ RHSA-2025:12008 Important: redis:7 security update
https://access.redhat.com/errata/RHSA-2025:12008
CVE-2025-27151
CVE-2025-32023
CVE-2025-48367

+ RHSA-2025:11992 Important: sqlite security update
https://access.redhat.com/errata/RHSA-2025:11992
CVE-2025-6965

+ About the security content of iOS 18.6 and iPadOS 18.6
https://support.apple.com/en-us/124147
CVE-2025-31229
CVE-2025-43217
CVE-2025-43186
CVE-2025-43223
CVE-2025-43277
CVE-2025-43210
CVE-2025-43230
CVE-2025-43209
CVE-2025-43226
CVE-2025-43202
CVE-2025-7425
CVE-2025-7424
CVE-2025-31276
CVE-2025-43234
CVE-2025-43224
CVE-2025-31281
CVE-2025-43228
CVE-2025-43227
CVE-2025-31278
CVE-2025-31273
CVE-2025-43214
CVE-2025-43212
CVE-2025-43211
CVE-2025-43265
CVE-2025-43216
CVE-2025-6558

+ About the security content of iPadOS 17.7.9
https://support.apple.com/en-us/124148

+ About the security content of macOS Sequoia 15.6
https://support.apple.com/en-us/124149

+ About the security content of macOS Sonoma 14.7.7
https://support.apple.com/en-us/124150

+ About the security content of macOS Ventura 13.7.7
https://support.apple.com/en-us/124151

+ About the security content of watchOS 11.6
https://support.apple.com/en-us/124155

+ About the security content of tvOS 18.6
https://support.apple.com/en-us/124153

+ About the security content of visionOS 2.6
https://support.apple.com/en-us/124154

+ Google Chrome 138.0.7204.183/.184 released
https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_29.html

VU#554637 TP-Link Archer C50 router is vulnerable to configuration-file decryption
https://www.kb.cert.org/vuls/id/554637

UPDATE: JVNVU#96471539 三菱電機製空調管理システムにおける認証回避の脆弱性
https://jvn.jp/vu/JVNVU96471539/index.html

JVNVU#90163061 Lakeside Software製SysTrackにおけるファイル検索パスの制御不備の脆弱性
https://jvn.jp/vu/JVNVU90163061/index.html

JVN#59585716 スマートフォンアプリ「SwitchBot」におけるログファイルへの機微な情報の出力の脆弱性
https://jvn.jp/jp/JVN59585716/index.html

2025年7月29日火曜日

29日 火曜日、仏滅

+ JVNVU#95131187 Apache HTTP ServerにおけるRewriteCondディレクティブの実装不備
https://jvn.jp/vu/JVNVU95131187/index.html
CVE-2025-54090

+ Sudo chroot 1.9.17 Local Privilege Escalation
https://cxsecurity.com/issue/WLB-2025070037
CVE-2025-32463

+ glibc 2.42 released
https://ftp.gnu.org/gnu/glibc/?C=M;O=A

JVNVU#90163061 Lakeside Software製SyStrackにおけるファイル検索パスの制御不備の脆弱性
https://jvn.jp/vu/JVNVU90163061/index.html

2025年7月28日月曜日

28日 月曜日、先負

+ Sudo 1.9.17p2 released
https://www.sudo.ws/releases/stable/#1.9.17p2

VU#335798 SyStrack LsiAgent.exe contains an improper DLL search order, allowing an attacker to execute arbitrary code and priv esc
https://www.kb.cert.org/vuls/id/335798

JVNVU#94313834 Honeywell製Experion PKSにおける複数の脆弱性
https://jvn.jp/vu/JVNVU94313834/index.html

JVNVU#97372937 LG Innotek製Camera Model LNV5110Rにおける代替パスまたはチャネルを使用した認証回避の脆弱性
https://jvn.jp/vu/JVNVU97372937/index.html

JVNVU#97399886 Medtronic製MyCareLink Patient Monitorにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97399886/index.html

JVNVU#96480474 三菱電機製GENESIS64およびMC Works64における複数の脆弱性
https://jvn.jp/vu/JVNVU96480474/index.html

JVNVU#97303438 TP-Link製VIGI NVR1104H-4PおよびVIGI NVR2016H-16MPにおけるOSコマンドインジェクションの脆弱性
https://jvn.jp/vu/JVNVU97303438/index.html

2025年7月25日金曜日

25日 金曜日、赤口

+ RHSA-2025:11747 Important: firefox security update
https://access.redhat.com/errata/RHSA-2025:11747
CVE-2025-8027
CVE-2025-8028
CVE-2025-8029
CVE-2025-8030
CVE-2025-8031
CVE-2025-8032
CVE-2025-8033
CVE-2025-8034
CVE-2025-8035

+ RHSA-2025:11749 Important: Updated 8.1 container image is now available: security and bug fix update
https://access.redhat.com/errata/RHSA-2025:11749
CVE-2024-24557
CVE-2024-45338
CVE-2024-53382
CVE-2025-22865
CVE-2025-22868
CVE-2025-22871
CVE-2025-30204

+ RHSA-2025:11748 Important: firefox security update
https://access.redhat.com/errata/RHSA-2025:11748
CVE-2025-8027
CVE-2025-8028
CVE-2025-8029
CVE-2025-8030
CVE-2025-8031
CVE-2025-8032
CVE-2025-8033
CVE-2025-8034
CVE-2025-8035

+ Microsoft PowerPoint 2019 Remote Code Execution (RCE)
https://cxsecurity.com/issue/WLB-2025070032
CVE-2025-47175

■PowerDNS Recursorの脆弱性情報が公開されました(CVE-2025-30192)
https://jprs.jp/tech/security/2025-07-24-powerdns-recursor.html

JVNVU#91648232 Flexera InstallShield によって生成されたインストーラに DLL 読み込みに関する脆弱性
https://jvn.jp/vu/JVNVU91648232/index.html

JVNVU#92506407 三菱電機製MELSOFT Update Managerに7-Zipに起因する複数の脆弱性
https://jvn.jp/vu/JVNVU92506407/index.html

JVNVU#97972347 三菱電機製MELSEC iQ-Fシリーズにおけるサービス運用妨害(DoS)の脆弱性
https://jvn.jp/vu/JVNVU97972347/index.html

JVN#39913189 TP-Link製Archer C1200におけるクリックジャッキングの脆弱性
https://jvn.jp/jp/JVN39913189/index.html

2025年7月24日木曜日

24日 木曜日、大安

+ Zabbix 7.0.17 released
https://www.zabbix.com/rn/rn7.0.17

+ Mozilla Thunderbird 128.13.0 released
https://www.thunderbird.net/en-US/thunderbird/128.13.0esr/releasenotes/

+ Apache HTTP Server 2.4.65 released
https://downloads.apache.org/httpd/Announcement2.4.html
https://downloads.apache.org/httpd/CHANGES_2.4.65

■Knot Resolverの脆弱性情報が公開されました
https://jprs.jp/tech/security/2025-07-23-knotresolver.html

JVNVU#92348195 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU92348195/index.html

JVNVU#91835971 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU91835971/index.html

JVNVU#96062789 DuraComm製SPM-500 DP-10iN-100-MUにおける複数の脆弱性
https://jvn.jp/vu/JVNVU96062789/index.html

JVNVU#99100666 Lantronix製Provisioning ManagerにおけるXML外部エンティティ参照(XXE)の不適切な制限の脆弱性
https://jvn.jp/vu/JVNVU99100666/index.html

JVNVU#99891704 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU99891704/index.html

JVN#21177718 バスロケーションシステムにおける数値の入力に対する不適切な検証の脆弱性
https://jvn.jp/jp/JVN21177718/index.html

2025年7月23日水曜日

23日 水曜日、仏滅

+ RHSA-2025:11534 Important: git security update
https://access.redhat.com/errata/RHSA-2025:11534
CVE-2024-50349
CVE-2024-52006
CVE-2025-27613
CVE-2025-27614
CVE-2025-46835
CVE-2025-48384
CVE-2025-48385

+ Google Chrome 138.0.7204.168/.169 released
https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_22.html

+ Mozilla Foundation Security Advisory 2025-56 Security Vulnerabilities fixed in Firefox 141
https://www.mozilla.org/en-US/security/advisories/mfsa2025-56/
CVE-2025-8027
CVE-2025-8028
CVE-2025-8041
CVE-2025-8042
CVE-2025-8029
CVE-2025-8036
CVE-2025-8037
CVE-2025-8030
CVE-2025-8043
CVE-2025-8031
CVE-2025-8032
CVE-2025-8038
CVE-2025-8039
CVE-2025-8033
CVE-2025-8044
CVE-2025-8034
CVE-2025-8040
CVE-2025-8035

+ Zabbix 7.2.11 released
https://www.zabbix.com/rn/rn7.2.11

+ Mozilla Foundation Security Advisory 2025-61 Security Vulnerabilities fixed in Thunderbird 141
https://www.mozilla.org/en-US/security/advisories/mfsa2025-61/
CVE-2025-8027
CVE-2025-8028
CVE-2025-8029
CVE-2025-8036
CVE-2025-8037
CVE-2025-8030
CVE-2025-8043
CVE-2025-8031
CVE-2025-8032
CVE-2025-8038
CVE-2025-8039
CVE-2025-8033
CVE-2025-8044
CVE-2025-8034
CVE-2025-8040
CVE-2025-8035

+ Mozilla Thunderbird 141.0, 140.1.0 released
https://www.thunderbird.net/en-US/thunderbird/141.0/releasenotes/
https://www.thunderbird.net/en-US/thunderbird/140.1.0esr/releasenotes/

+ Mozilla Firefox 141.0 released
https://www.firefox.com/en-US/firefox/141.0/releasenotes/

JVNVU#91615135 エレコム製無線LANルータにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91615135/index.html

JVN#07825095 Androidアプリ「region PAY」にログファイルへの機微な情報の出力の脆弱性
https://jvn.jp/jp/JVN07825095/index.html

2025年7月22日火曜日

22日 火曜日、先負

+ RHSA-2025:10862 Important: java-1.8.0-openjdk security update
https://access.redhat.com/errata/RHSA-2025:10862
CVE-2025-30749
CVE-2025-30754
CVE-2025-30761
CVE-2025-50106

+ RHSA-2025:11463 Moderate: fence-agents security update
https://access.redhat.com/errata/RHSA-2025:11463
CVE-2025-47273

+ RHSA-2025:11462 Important: git security update
https://access.redhat.com/errata/RHSA-2025:11462
CVE-2024-50349
CVE-2024-52006
CVE-2025-27613
CVE-2025-27614
CVE-2025-46835
CVE-2025-48384
CVE-2025-48385

+ RHSA-2025:11411 Important: kernel security update
https://access.redhat.com/errata/RHSA-2025:11411
CVE-2024-58002
CVE-2025-38089

+ Microsoft Edge XSS Filter Bypass PoC
https://cxsecurity.com/issue/WLB-2025070025

■Unboundの脆弱性情報が公開されました(CVE-2025-5994)
https://jprs.jp/tech/security/2025-07-18-unbound.html

JVNVU#95751016 複数のJohnson Controls製品における複数の脆弱性
https://jvn.jp/vu/JVNVU95751016/index.html

JVNVU#90664983 複数のLeviton製品におけるクロスサイトスクリプティングの脆弱性
https://jvn.jp/vu/JVNVU90664983/index.html

2025年7月18日金曜日

18日 金曜日、大安

+ ■BIND 9.20.xの脆弱性(DNSサービスの停止)について(CVE-2025-40777)
  - バージョンアップを強く推奨 -
https://jprs.jp/tech/security/2025-07-17-bind9-vuln-serve-stale.html
CVE-2025-40777

+ RHSA-2025:10862 Important: java-1.8.0-openjdk security update
https://access.redhat.com/errata/RHSA-2025:10862
CVE-2025-30749
CVE-2025-30754
CVE-2025-30761
CVE-2025-50106

+ JVNVU#92566795 ISC BINDにおける複数の脆弱性(2025年7月)
https://jvn.jp/vu/JVNVU92566795/index.html
CVE-2025-40776
CVE-2025-40777

+ Sudo 1.9.17 Host Option Elevation of Privilege
https://cxsecurity.com/issue/WLB-2025070022
CVE-2025-32462

2025年7月17日木曜日

17日 木曜日、仏滅

+ RHSA-2025:11333 Important: tomcat security update
https://access.redhat.com/errata/RHSA-2025:11333
CVE-2024-56337
CVE-2025-31650

+ RHSA-2025:11327 Moderate: glib2 security update
https://access.redhat.com/errata/RHSA-2025:11327
CVE-2024-34397
CVE-2024-52533
CVE-2025-4373

+ RHSA-2025:11324 Important: cloud-init security update
https://access.redhat.com/errata/RHSA-2025:11324
CVE-2024-6174

+ RHSA-2025:11298 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2025:11298
CVE-2022-49058
CVE-2022-49788
CVE-2024-57980
CVE-2024-58002
CVE-2025-21991
CVE-2025-22004
CVE-2025-23150
CVE-2025-37738

+ RHSA-2025:11335 Important: tomcat security update
https://access.redhat.com/errata/RHSA-2025:11335
CVE-2024-56337
CVE-2025-31650

+ Mozilla Firefox 140.0.4 released
https://www.firefox.com/en-US/firefox/140.0.4/releasenotes/

+ Wireshark 4.4.8 released
https://www.wireshark.org/docs/relnotes/wireshark-4.4.8.html

+ ISC BIND 9.20.11, 9.18.38 released
https://downloads.isc.org/isc/bind9/9.20.11/doc/arm/html/notes.html
https://downloads.isc.org/isc/bind9/9.18.38/doc/arm/html/notes.html

UPDATE: JVNVU#91918160 複数のSchneider Electric製品における複数の脆弱性
https://jvn.jp/vu/JVNVU91918160/index.html

JVNVU#93628914 複数のHitachi Energy製品における複数の脆弱性
https://jvn.jp/vu/JVNVU93628914/index.html

JVNVU#96956655 ABB製RMC-100における複数の脆弱性
https://jvn.jp/vu/JVNVU96956655/index.html

JVNVU#94493213 複数のLITEON製品におけるパスワードの平文保存の脆弱性
https://jvn.jp/vu/JVNVU94493213/index.html

JVN#44419726 ゼクセロン製ZWX-2000CSW2-HN、ZWX-2000CS2-HNにおけるハードコードされた認証情報の使用の脆弱性
https://jvn.jp/jp/JVN44419726/index.html

JVNVU#96526886 複数のトレンドマイクロ株式会社製品の脆弱性に対するアップデート(2025年6月)
https://jvn.jp/vu/JVNVU96526886/index.html

2025年7月16日水曜日

16日 水曜日、先負

+ RHSA-2025:10867 Important: java-17-openjdk security update
https://access.redhat.com/errata/RHSA-2025:10867
CVE-2025-30749
CVE-2025-30754
CVE-2025-50059
CVE-2025-50106

+ RHSA-2025:11043 Moderate: python3.11-setuptools security update
https://access.redhat.com/errata/RHSA-2025:11043
CVE-2025-47273

+ RHSA-2025:11042 Moderate: socat security update
https://access.redhat.com/errata/RHSA-2025:11042
CVE-2024-54661

+ RHSA-2025:11030 Moderate: emacs security update
https://access.redhat.com/errata/RHSA-2025:11030
CVE-2024-53920

+ RHSA-2025:10991 Moderate: microcode_ctl security update
https://access.redhat.com/errata/RHSA-2025:10991
CVE-2024-28956

+ RHSA-2025:10977 Important: kpatch-patch-4_18_0-553, kpatch-patch-4_18_0-553_16_1, kpatch-patch-4_18_0-553_30_1, kpatch-patch-4_18_0-553_40_1, and kpatch-patch-4_18_0-553_53_1 security update
https://access.redhat.com/errata/RHSA-2025:10977
CVE-2022-49846

+ RHSA-2025:11140 Moderate: glib2 security update
https://access.redhat.com/errata/RHSA-2025:11140
CVE-2024-52533
CVE-2025-4373

+ RHSA-2025:10981 Important: kpatch-patch-5_14_0-570_17_1 security update
https://access.redhat.com/errata/RHSA-2025:10981
CVE-2022-49846

+ RHSA-2025:10848 Important: cloud-init security update
https://access.redhat.com/errata/RHSA-2025:10848
CVE-2024-6174

+ RHSA-2025:10837 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2025:10837
CVE-2025-21991

+ Google Chrome 138.0.7204.157/.158 released
https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html

+ Oracle Critical Patch Update Advisory - July 2025
https://www.oracle.com/security-alerts/cpujul2025.html

2025年7月15日火曜日

15日 火曜日、友引

+ GnuPG 2.5.9 with Debian packages released
https://lists.gnupg.org/pipermail/gnupg-announce/2025q3/000495.html

+ JVNVU#91930855 Apache HTTP Server 2.4における複数の脆弱性に対するアップデート
https://jvn.jp/vu/JVNVU91930855/index.html
CVE-2024-42516
CVE-2024-43204
CVE-2024-43394
CVE-2024-47252
CVE-2025-23048
CVE-2025-49630
CVE-2025-49812
CVE-2025-53020

+ JVNVU#91378143 Apache Tomcatにおける複数の脆弱性
https://jvn.jp/vu/JVNVU91378143/index.html
CVE-2025-52434
CVE-2025-52520
CVE-2025-53506

JVNVU#90910360 Gigabyte製UEFIファームウェアモジュールにシステム管理モードのコールアウトの脆弱性
https://jvn.jp/vu/JVNVU90910360/index.html

JVN#20474768 リコー製Web Image Monitorを実装している複数のレーザープリンタおよび複合機(MFP)における反射型クロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN20474768/index.html

JVNVU#96149970 オムロン製NJ/NXシリーズおよびSysmac Studioにおける最小権限の原則に違反する脆弱性
https://jvn.jp/vu/JVNVU96149970/index.html

JVNVU#97396252 KUNBUS製Revolution Piにおける複数の脆弱性
https://jvn.jp/vu/JVNVU97396252/index.html

2025年7月14日月曜日

14日 月曜日、先勝

+ GCC 12.5 released
https://gcc.gnu.org/gcc-12/changes.html

VU#746790 SMM callout vulnerabilities identified in Gigabyte UEFI firmware modules
https://www.kb.cert.org/vuls/id/746790

JVNVU#94641440 Delta Electronics製DTM Softにおける信頼できないデータのデシリアライゼーションの脆弱性
https://jvn.jp/vu/JVNVU94641440/index.html

JVNVU#95615009 Advantech製iViewにおける複数の脆弱性
https://jvn.jp/vu/JVNVU95615009/index.html

JVNVU#98587239 KUNBUS製Revolution Piにおける認証アルゴリズムの不適切な実装の脆弱性
https://jvn.jp/vu/JVNVU98587239/index.html

JVNVU#91657555 Firebox T15における非公開機能を悪用される問題
https://jvn.jp/vu/JVNVU91657555/index.html

JVNVU#99667406 Siemens製品に対するアップデート(2025年7月)
https://jvn.jp/vu/JVNVU99667406/index.html

JVNVU#96959731 IDEC製品における複数の脆弱性
https://jvn.jp/vu/JVNVU96959731/index.html

2025年7月11日金曜日

11日 金曜日、仏滅

+ Oracle Critical Patch Update Pre-Release Announcement - July 2025
https://www.oracle.com/security-alerts/cpujul2025.html

+ Apache HTTP Server 2.4.64 released
https://downloads.apache.org/httpd/Announcement2.4.html
https://downloads.apache.org/httpd/CHANGES_2.4.64

+ Postfix stable release 3.10.3 released
http://www.postfix.org/announcements/postfix-3.10.3.html

JVNVU#96617900 複数のRUCKUS製品における複数の脆弱性
https://jvn.jp/vu/JVNVU96617900/index.html

2025年7月10日木曜日

10日 木曜日、先負

+ RHSA-2025:10742 Moderate: gnome-remote-desktop security update
https://access.redhat.com/errata/RHSA-2025:10742
CVE-2025-5024

+ RHSA-2025:10698 Important: libxml2 security update
https://access.redhat.com/errata/RHSA-2025:10698
CVE-2025-6021
CVE-2025-49794
CVE-2025-49796

+ RHSA-2025:10672 Moderate: go-toolset:rhel8 security update
https://access.redhat.com/errata/RHSA-2025:10672
CVE-2025-4673

+ RHSA-2025:10669 Important: kernel security update
https://access.redhat.com/errata/RHSA-2025:10669
CVE-2022-49111
CVE-2022-49136
CVE-2022-49846

+ RHSA-2025:10618 Moderate: jq security update
https://access.redhat.com/errata/RHSA-2025:10618
CVE-2024-23337
CVE-2025-48060

+ RHSA-2025:10551 Important: container-tools:rhel8 security update
https://access.redhat.com/errata/RHSA-2025:10551
CVE-2025-6032

+ RHSA-2025:10699 Important: libxml2 security update
https://access.redhat.com/errata/RHSA-2025:10699
CVE-2025-6021
CVE-2025-49794
CVE-2025-49796

+ RHSA-2025:10676 Moderate: golang security update
https://access.redhat.com/errata/RHSA-2025:10676
CVE-2025-4673

+ RHSA-2025:10674 Important: kpatch-patch-5_14_0-570_17_1 security update
https://access.redhat.com/errata/RHSA-2025:10674
CVE-2025-37799

+ Mozilla Thunderbird 140.0.1 released
https://www.thunderbird.net/en-US/thunderbird/140.0.1/releasenotes/

+ 2025 年 7 月のセキュリティ更新プログラム (月例)
https://msrc.microsoft.com/blog/2025/07/202507-security-update/

+ Mozilla Firefox 140.0.4 released
https://www.mozilla.org/en-US/firefox/140.0.4/releasenotes/

JVNVU#99667406 Siemens製品に対するアップデート(2025年7月)
https://jvn.jp/vu/JVNVU99667406/index.html

JVNVU#94611939 Emerson製ValveLinkにおける複数の脆弱性
https://jvn.jp/vu/JVNVU94611939/index.html

UPDATE: JVNVU#95499848 Siemens 製品に対するアップデート(2020年4月)
https://jvn.jp/vu/JVNVU95499848/index.html

2025年7月9日水曜日

9日 水曜日、友引

+ RHSA-2025:10631 Moderate: gnome-remote-desktop security update
https://access.redhat.com/errata/RHSA-2025:10631
CVE-2025-5024

+ RHSA-2025:10585 Moderate: jq security update
https://access.redhat.com/errata/RHSA-2025:10585
CVE-2024-23337
CVE-2025-48060

+ RHSA-2025:10407 Moderate: python-setuptools security update
https://access.redhat.com/errata/RHSA-2025:10407
CVE-2025-47273

+ RHSA-2025:10379 Important: kernel security update
https://access.redhat.com/errata/RHSA-2025:10379
CVE-2022-49846
CVE-2025-21759
CVE-2025-21887
CVE-2025-22004
CVE-2025-37799

+ Google Chrome 138.0.7204.100/.101 released
https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop.html

VU#613753 Ruckus Virtual SmartZone (vSZ) and Ruckus Network Director (RND) contain multiple vulnerabilities
https://www.kb.cert.org/vuls/id/613753

2025年7月8日火曜日

8日 火曜日、先勝

+ Microsoft Outlook Remote Code Execution Vulnerability - ACE
https://cxsecurity.com/issue/WLB-2025070011
CVE-2025-47176

JVNVU#93543156 Epson Web Installer(Mac版)における重要な機能に対する認証の欠如の脆弱性
https://jvn.jp/vu/JVNVU93543156/index.html

JVN#88251376 Nimesa Backup and Recoveryにおける複数の脆弱性
https://jvn.jp/jp/JVN88251376/index.html

JVNVU#94870570 トレンドマイクロ製ウイルスバスター クラウド(Windows版)におけるWindowsショートカット(.LNK)の不適切な取扱い(CVE-2025-52521)
https://jvn.jp/vu/JVNVU94870570/index.html

2025年7月7日月曜日

7日 月曜日、赤口

+ Apache Tomcat 11.0.9, 10.1.43, 9.0.107 released
https://tomcat.apache.org/tomcat-11.0-doc/changelog.html#Tomcat_11.0.9_(markt)
https://tomcat.apache.org/tomcat-10.1-doc/changelog.html#Tomcat_10.1.43_(schultz)
https://tomcat.apache.org/tomcat-9.0-doc/changelog.html#Tomcat_9.0.107_(remm)

+ libpng 1.6.50 released
http://www.libpng.org/pub/png/src/libpng-1.6.50-README.txt

JVNVU#94870570 トレンドマイクロ製ウイルスバスター クラウド(Windows版)におけるWindowsショートカット(.LNK)の不適切な取扱い(CVE-2025-52521)
https://jvn.jp/vu/JVNVU94870570/index.html

JVNVU#94011267 富士電機製V-SFTおよびTELLUSにおけるヒープベースのバッファオーバフローの脆弱性
https://jvn.jp/vu/JVNVU94011267/index.html

JVNVU#93974687 複数のHitachi Energy製品における複数の脆弱性
https://jvn.jp/vu/JVNVU93974687/index.html

2025年7月4日金曜日

4日 金曜日、先負

+ FreeBSD-SA-25:06.xz Use-after-free in multi-threaded xz decoder
https://www.freebsd.org/security/advisories/FreeBSD-SA-25:06.xz.asc
CVE-2025-31115

+ PHP 8.4.10, 8.3.23, 8.2.29, 8.1.33 released
https://www.php.net/ChangeLog-8.php#8.4.10
https://www.php.net/ChangeLog-8.php#8.3.23
https://www.php.net/ChangeLog-8.php#8.2.29
https://www.php.net/ChangeLog-8.php#8.1.33

+ JVNVU#91298012 OpenSSL x509アプリケーションにおける、拒否設定の代わりに信頼設定を付加してしまう問題(OpenSSL Security Advisory [22nd May 2025])
https://jvn.jp/vu/JVNVU91298012/index.html

JVNVU#91134474 トレンドマイクロ製パスワードマネージャー(Windows版)における複数の脆弱性(CVE-2025-48443、CVE-2025-52837)
https://jvn.jp/vu/JVNVU91134474/index.html

2025年7月3日木曜日

3日 木曜日、友引

+ RHSA-2025:10217 Moderate: ruby:3.3 security update
https://access.redhat.com/errata/RHSA-2025:10217
CVE-2025-25186
CVE-2025-27219
CVE-2025-27221

+ RHSA-2025:10196 Important: thunderbird security update
https://access.redhat.com/errata/RHSA-2025:10196
CVE-2025-5986

+ RHSA-2025:10189 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2025:10189
CVE-2024-12718
CVE-2025-4138
CVE-2025-4330
CVE-2025-4435
CVE-2025-4517

+ RHSA-2025:10148 Important: python3.11 security update
https://access.redhat.com/errata/RHSA-2025:10148
CVE-2024-12718
CVE-2025-4138
CVE-2025-4330
CVE-2025-4435
CVE-2025-4517

+ RHSA-2025:10136 Important: python3.9 security update
https://access.redhat.com/errata/RHSA-2025:10136
CVE-2024-12718
CVE-2025-4138
CVE-2025-4330
CVE-2025-4435
CVE-2025-4517

+ Mozilla Foundation Security Advisory 2025-54 Security Vulnerabilities fixed in Thunderbird 140
https://www.mozilla.org/en-US/security/advisories/mfsa2025-54/
CVE-2025-6424
CVE-2025-6425
CVE-2025-6426
CVE-2025-6427
CVE-2025-6429
CVE-2025-6430
CVE-2025-6432
CVE-2025-6433
CVE-2025-6434
CVE-2025-6435
CVE-2025-6436

+ Mozilla Thunderbird 140.0 released
https://www.thunderbird.net/en-US/thunderbird/140.0/releasenotes/

JVNVU#97192309 複数のFesto Didactic製品およびFesto製品における複数の脆弱性
https://jvn.jp/vu/JVNVU97192309/index.html

JVNVU#94963532 Voltronic PowerおよびPowerShield製の複数のUPSモニタリングソフトウェアにおける複数の脆弱性
https://jvn.jp/vu/JVNVU94963532/index.html

JVNVU#94973485 複数のHitachi Energy製品における複数の脆弱性
https://jvn.jp/vu/JVNVU94973485/index.html

2025年7月2日水曜日

2日 水曜日、先勝

+ RHSA-2025:10128 Important: python3 security update
https://access.redhat.com/errata/RHSA-2025:10128
CVE-2024-12718
CVE-2025-4138
CVE-2025-4330
CVE-2025-4435
CVE-2025-4517

+ RHSA-2025:10110 Important: sudo security update
https://access.redhat.com/errata/RHSA-2025:10110
CVE-2025-32462

+ RHSA-2025:10074 Important: firefox security update
https://access.redhat.com/errata/RHSA-2025:10074
CVE-2025-6424
CVE-2025-6425
CVE-2025-6429
CVE-2025-6430

+ RHSA-2025:10031 Important: python3.12 security update
https://access.redhat.com/errata/RHSA-2025:10031
CVE-2024-12718
CVE-2025-4138
CVE-2025-4330
CVE-2025-4435
CVE-2025-4517

+ RHSA-2025:10027 Important: pam security update
https://access.redhat.com/errata/RHSA-2025:10027
CVE-2025-6020

+ RHSA-2025:10026 Important: python3.11 security update
https://access.redhat.com/errata/RHSA-2025:10026
CVE-2024-12718
CVE-2025-4138
CVE-2025-4330
CVE-2025-4435
CVE-2025-4517

+ RHSA-2025:9878 Important: libblockdev security update
https://access.redhat.com/errata/RHSA-2025:9878
CVE-2025-6019

+ RHSA-2025:10072 Important: firefox security update
https://access.redhat.com/errata/RHSA-2025:10072
CVE-2025-6424
CVE-2025-6425
CVE-2025-6429
CVE-2025-6430

+ RHSA-2025:9978 Important: sudo security update
https://access.redhat.com/errata/RHSA-2025:9978
CVE-2025-32462

+ RHSA-2025:9880 Moderate: kernel security update
https://access.redhat.com/errata/RHSA-2025:9880
CVE-2023-52933

+ RHSA-2025:9877 Moderate: glibc security update
https://access.redhat.com/errata/RHSA-2025:9877
CVE-2025-5702

+ Zabbix 7.4.0 released
https://www.zabbix.com/rn/rn7.4.0

+ Mozilla Thunderbird 128.12.0 released
https://www.thunderbird.net/en-US/thunderbird/128.12.0esr/releasenotes/

JVNVU#92266386 コンテック製CONPROSYS HMI System(CHS)における複数の脆弱性
https://jvn.jp/vu/JVNVU92266386/index.html

2025年7月1日火曜日

1日 火曜日、赤口

+ Google Chrome 138.0.7204.97 released
https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop_30.html

+ Sudo 1.9.17p1 released
https://www.sudo.ws/releases/stable/#1.9.17p1
CVE-2025-32462
CVE-2025-32463

JVNVU#93850661 コニカミノルタ製bizhubシリーズにおけるPass-Back攻撃が可能になる脆弱性
https://jvn.jp/vu/JVNVU93850661/index.html

JVNVU#95470660 コニカミノルタ製複合機(MFP)のWeb Connectionにおける複数の脆弱性
https://jvn.jp/vu/JVNVU95470660/index.html

JVN#24333956 RICOH Streamline NXの管理ツールのヘルプドキュメントシステムにおける反射型クロスサイトスクリプティングの脆弱性
https://jvn.jp/jp/JVN24333956/index.html