2010-10-20

IBM Rational Quality Manager

ソフト名:IBM Rational Quality Manager 7.9
回避策:アップデートにて対応
脆弱性:リモートコード実行
ソース:
http://download4.boulder.ibm.com/sar/CMA/RAA/013m6/0/Rules-Update-749.exe
https://www.ibm.com/developerworks/rational/products/testmanager/
http://www.zerodayinitiative.com/advisories/ZDI-10-214/
http://www.securityfocus.com/bid/44172
http://securitytracker.com/alerts/2010/Oct/1024601.html
危険性:High Risk

Tastydir

ソフト名:Tastydir 1216
回避策:未対応
脆弱性:セキュリティ制限の回避, 機密情報の奪取, フォルダ操作
ソース:
http://www.exploit-db.com/exploits/15269/
http://codecanyon.net/item/tastydir-an-ajax-file-manager-and-dir-listing/117167
危険性:Medium Risk

JnSHosts PHP Hosting Directory

ソフト名:JnSHosts PHP Hosting Directory 2.0
回避策:未対応
脆弱性:機密情報の奪取, バックアップファイルのダウンロード
ソース:
http://jnshosts.com/php-hosting-directory.html
http://www.exploit-db.com/exploits/15264/
危険性:Medium Risk

Real RealPlayer, Real RealPlayer Enterprise, Real RealPlayer SP

ソフト名:Real RealPlayer 11.0~11.1, Real RealPlayer 2.1.2 Enterprise, Real RealPlayer SP 1.0.0~1.1.4
回避策:アップデートにて対応
脆弱性:リモートコード実行, ヒープオーバーフロー, スタックオーバーフロー
ソース:
http://service.real.com/realplayer/security/10152010_player/en/
http://www.zerodayinitiative.com/advisories/ZDI-10-209/
http://www.zerodayinitiative.com/advisories/ZDI-10-210/
http://www.zerodayinitiative.com/advisories/ZDI-10-211/
http://www.zerodayinitiative.com/advisories/ZDI-10-212/
http://www.zerodayinitiative.com/advisories/ZDI-10-213/
http://www.securityfocus.com/bid/44144
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2578
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2998
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3747
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3748
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3749
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3750
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3751
http://secunia.com/advisories/41096
http://secunia.com/advisories/41743
http://www.vupen.com/english/advisories/2010/2698
CVE:CVE-2010-2578, CVE-2010-2998, CVE-2010-3747, CVE-2010-3748, CVE-2010-3749, CVE-2010-3750, CVE-2010-3751
危険性:High Risk

Liuxz Software FTP Synchronizer

ソフト名:Liuxz Software FTP Synchronizer 4.0.73.274
回避策:未対応
脆弱性:バッファオーバーフロー, リモートコード実行, サーバのクラッシュ
ソース:
http://www.ftpsynchronizer.com/
http://www.corelan.be:8800/index.php/2010/10/12/death-of-an-ftp-client/
http://secunia.com/advisories/41860
危険性:High Risk

GNU glibc

ソフト名:GNU glibc 2.0~2.3.5
回避策:未対応
脆弱性:権限の昇格
ソース:
http://www.gnu.org/software/libc/
http://www.exploit-db.com/exploits/15274/
http://www.securityfocus.com/bid/44154
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3847
http://secunia.com/advisories/41795
CVE:CVE-2010-3847
危険性:High Risk

Rocket U2 UniData

ソフト名:Rocket U2 UniData 7.2.7 Build 3806
回避策:未対応
脆弱性:DoS攻撃, アプリケーションのクラッシュ, プロセスのクラッシュ
ソース:
http://aluigi.org/adv/unirpcd_1-adv.txt
http://www.exploit-db.com/exploits/15260/
http://www.rocketsoftware.com/u2/products/unidata/
http://www.securityfocus.com/bid/44159
http://secunia.com/advisories/41867
危険性:Low Risk

BlueCoat ProxySG

ソフト名:BlueCoat ProxySG 4~6
回避策:あり
脆弱性:セキュリティ制限の回避, JAVAスクリプト検出エラー
ソース:
https://kb.bluecoat.com/index?page=content&id=SA48&actp=LIST
https://hypersonic.bluecoat.com/
http://secunia.com/advisories/41887
http://www.vupen.com/english/advisories/2010/2699
危険性:Medium Risk

ASP Indir Kisisel Radyo Script

ソフト名:ASP Indir Kisisel Radyo Script
回避策:未対応
脆弱性:機密情報の奪取, SQLインジェクション, ファイルのダウンロード
ソース:
http://aspindir.com/goster/6097
http://www.exploit-db.com/exploits/15270/
http://www.securityfocus.com/bid/44155
http://secunia.com/advisories/41816
危険性:Medium Risk

Opera Software Opera

ソフト名:Opera Software Opera 10.63
回避策:未対応
脆弱性:DoS攻撃, ブラウザのクラッシュ
ソース:
http://www.exploit-db.com/exploits/15273/
http://www.opera.com/
危険性:Low Risk

ConvexSoft DJ Audio Mixer

ソフト名:ConvexSoft DJ Audio Mixer
回避策:未対応
脆弱性:DoS攻撃, アプリケーションのクラッシュ
ソース:
http://www.convexsoft.com/dj_audio.html
http://www.exploit-db.com/exploits/15263/
http://www.securityfocus.com/bid/44151
危険性:Low Risk

DATAC Control International RealWin SCADA Server

ソフト名:DATAC Control International RealWin SCADA Server 2.1 Build 6.1.8.10
回避策:未対応
脆弱性:バッファオーバーフロー, リモートコード実行, サーバのクラッシュ
ソース:
http://www.dataconline.com/software/realwin.php
http://aluigi.org/adv/realwin_1-adv.txt
http://www.exploit-db.com/exploits/15259/
http://www.securityfocus.com/bid/44150
http://secunia.com/advisories/41849
http://www.vupen.com/english/advisories/2010/2714
危険性:High Risk

Novell eDirectory

ソフト名:Novell eDirectory 8.8 SP3
回避策:未対応
脆弱性:バッファオーバーフロー, リモートコード実行, アプリケーションのクラッシュ
ソース:
http://www.novell.com/products/edirectory/
http://www.exploit-db.com/exploits/15267/
危険性:High Risk

Clever Micro DJ Legend

ソフト名:Clever Micro DJ Legend 6.01
回避策:未対応
脆弱性:DoS攻撃, アプリケーションのクラッシュ
ソース:
http://www.clevermicro.com/
http://www.exploit-db.com/exploits/15258/
http://www.securityfocus.com/bid/44147
危険性:Low Risk

XLRstats

ソフト名:XLRstats 2.0.1/2.0.2
回避策:未対応
脆弱性:SQLインジェクション
ソース:
http://www.exploit-db.com/exploits/15251/
http://www.xlrstats.com/site/
危険性:Medium Risk