今日のセキュリティホール情報

セキュリティホール情報

■SIDfm - セキュリティ情報提供サービス

telnet クライアントに複数のバッファオーバーフローの問題
SUSE Linux の Kernel に複数のセキュリティホール
Red Hat Linux (v.3/v.2) の Mozilla に複数のセキュリティホール

■Secunia - Security and Virus Information

Sacred Player Logging Buffer Overflow Vulnerability
TinCat Player Logging Buffer Overflow Vulnerability
Gentoo update for mpg321
Tkai's Shoutbox "query" Cross-Site Scripting Vulnerability
FreeBSD update for telnet
The Settlers: Heritage of Kings Player Logging Buffer Overflow
EncapsBB "root" File Inclusion Vulnerability
Conectiva update for ethereal
Red Hat update for grip
Red Hat update for telnet
Red Hat update for mysql
Sun Solaris Telnet Client Buffer Overflow Vulnerabilities
Fedora update for kernel
Ubuntu update for telnet/telnetd
CPG Dragonfly CMS Two Cross-Site Scripting Vulnerabilities
Fedora update for squirrelmail
MIT Kerberos Telnet Client Buffer Overflow Vulnerabilities
ACS Blog BBcode Script Insertion Vulnerability
PhotoPost PHP Pro Cross-Site Scripting and SQL Injection
Symantec Norton AntiVirus Denial of Service Vulnerabilities
E-Data Personal Information Script Insertion Vulnerability
Debian update for mc
Debian update for netkit-telnet-ssl
Smail-3 "Mail From" Buffer Overflow and Signal Handling Vulnerabilities
NetComm NB1300 Denial of Service
Horde Page Title Cross-Site Scripting Vulnerability
Smarty "regex_replace" Modifier Template Security Bypass
Debian update for netkit-telnet
Antigen File Processing Denial of Service Vulnerabilities
E-Store Kit-2 PayPal Edition Cross-Site Scripting and File Inclusion
BugTracker.NET Multiple SQL Injection Vulnerabilities
WackoWiki Multiple Cross-Site Scripting Vulnerabilities
Valdersoft Shopping Cart Cross-Site Scripting and SQL Injection
WebAPP Unspecified File Content Disclosure Vulnerability
Linux Kernel Multiple Vulnerabilities
Esmi Studio Products Cross-Site Scripting and SQL injection

■SecurityFocus

SecurityFocus Newsletter #294
SecurityFocus Microsoft Newsletter #234
SecurityFocus Linux Newsletter #229

■U.S. DOE-CIAC (Computer Incident Advisory Capability) Website

P-163 Kerberos 5 Telnet Client Buffer Overflow (Released 03/29/2005)
P-164 MySQL Security Update (Released 03/29/2005)

JPCERT/CC

JPCERT/CC REPORT 2005-03-30
 [1] Mozilla Foundation ソフトウェアのバッファオーバーフロー脆弱性
 [2] Apple Mac OS Xバッファオーバーフロー等の複数の脆弱性
 [3] McAfee ウィルススキャンエンジンの脆弱性に関する追加情報
 [4] Java Web Start脆弱性
 [5] Sun Java System Application Server のクロスサイトスクリプティング脆弱性

■N.S.L. Security Report
(Linux/Unix)
Linux Kernel の bluez_sock_create() 関数に権限昇格の脆弱性
Sendmail 8.13.4 リリース