2010-10-01

Galaxyscriptz MyPhpAuction

ソフト名:Galaxyscriptz MyPhpAuction 2010
回避策:未対応
脆弱性:SQLインジェクション
ソース:
http://galaxyscriptz.com/products/MyPhpAuction-2010.html
http://www.exploit-db.com/exploits/15154/
http://www.securityfocus.com/bid/43591
危険性:Medium Risk

Drupal Memcache

ソフト名:Drupal Memcache 5.x-1.0~6.x-1.x-dev
回避策:SA-CONTRIB-2010-098にて対応
脆弱性:XSS, セキュリティの強度不足, 認証資格情報の奪取
ソース:
http://drupal.org/node/927016
http://www.securityfocus.com/bid/43606
http://secunia.com/advisories/41663
危険性:Medium Risk

Drupal Imagemenu

ソフト名:Drupal Imagemenu 4.7.x-1.0~6.x-1.2
回避策:SA-CONTRIB-2010-097にて対応
脆弱性:CSRF, XSS, Webキャッシュ汚染, 認証資格情報の奪取
ソース:
http://drupal.org/node/926734
http://www.securityfocus.com/bid/43598
http://secunia.com/advisories/41669
http://secunia.com/advisories/41676
危険性:Medium Risk

webSPEL

ソフト名:webSPELL 4.0~4.2.1
回避策:未対応
脆弱性:SQLインジェクション
ソース:
http://www.exploit-db.com/exploits/15151/
http://www.exploit-db.com/exploits/15152/
http://www.exploit-db.com/exploits/15153/
http://www.webspell.org/index.php?site=about
http://www.securityfocus.com/bid/43576
http://www.securityfocus.com/bid/43579
http://www.securityfocus.com/bid/43580
http://secunia.com/advisories/41668
危険性:Medium Risk

ClamAV

ソフト名:ClamAV 0.96.2
回避策:あり
脆弱性:DoS攻撃, アプリケーションのクラッシュ
ソース:
http://www.clamav.net/lang/en/
https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2226
http://git.clamav.net/gitweb?p=clamav-devel.git;a=commitdiff;h=dc5143b4669ae39c79c9af50d569c28c798f33da
http://www.securityfocus.com/bid/43555
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3434
CVE:CVE-2010-3434
危険性:Medium Risk

Linux Kernel, Red Hat Enterprise Linux

ソフト名:Linux Kernel 2.6.32~2.6.35, Red Hat Enterprise Linux 2.1 AS/4.5.z AS/4.6.z AS
回避策:未対応
脆弱性:機密情報の奪取, カーネルメモリの曝露, システムのクラッシュ
ソース:
http://www.exploit-db.com/exploits/15150/
https://bugzilla.redhat.com/show_bug.cgi?id=638085
http://www.securityfocus.com/bid/43551
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3437
CVE:CVE-2010-3437
危険性:Low Risk

Horde Groupware Webmail Edition

ソフト名:Horde Groupware Webmail Edition 1.2.6
回避策:アップデートにて対応
脆弱性:XSS, CSRF, 認証資格情報の奪取, Webキャッシュ汚染
ソース:
http://www.horde.org/webmail/
http://lists.horde.org/archives/announce/2010/000568.html
http://secunia.com/advisories/41579
http://www.vupen.com/english/advisories/2010/2525
危険性:Medium Risk

Horde Groupware

ソフト名:Horde Groupware 1.2.6
回避策:アップデートにて対応
脆弱性:XSS, CSRF, 認証資格情報の奪取, Webキャッシュ汚染
ソース:
http://www.horde.org/groupware/
http://lists.horde.org/archives/announce/2010/000567.html
http://www.vupen.com/english/advisories/2010/2524
危険性:Medium Risk

Horde Application Framework

ソフト名:Horde Application Framework 3.3.8
回避策:アップデートにて対応
脆弱性:XSS, CSRF, 認証資格情報の奪取, Webキャッシュ汚染
ソース:
http://www.horde.org/horde/
http://lists.horde.org/archives/announce/2010/000557.html
http://www.vupen.com/english/advisories/2010/2521
危険性:Medium Risk

Thorsten Rinne phpMyFAQ

ソフト名:Thorsten Rinne phpMyFAQ 2.6.0~2.6.8
回避策:アップデートにて対応
脆弱性:XSS, 認証資格情報の奪取
ソース:
http://www.phpmyfaq.de/advisory_2010-09-28.php
http://www.phpmyfaq.de/
http://www.securityfocus.com/bid/43560
http://secunia.com/advisories/41625
危険性:Medium Risk

Horde Gollem

ソフト名:Horde Gollem 1.1.1
回避策:アップデートにて対応
脆弱性:XSS, 認証資格情報の奪取
ソース:
http://www.horde.org/gollem/
http://lists.horde.org/archives/announce/2010/000565.html
http://secunia.com/advisories/41624
http://www.vupen.com/english/advisories/2010/2523
危険性:Medium Risk

VMware Server

ソフト名:VMware Server 1.0/2.0
回避策:未対応
脆弱性:特定されていない脆弱性, DoS攻撃
ソース:
http://www.infiltrated.net/mushroomcloud/
http://www.vmware.com/
http://www.securityfocus.com/bid/43456
危険性:Low Risk

Horde Dynamic IMP (DIMP)

ソフト名:Horde Dynamic IMP (DIMP) 1.1~1.1.4
回避策:アップデートにて対応
脆弱性:XSS, 認証資格情報の奪取
ソース:
http://www.horde.org/dimp/
http://lists.horde.org/archives/announce/2010/000561.html
http://secunia.com/advisories/41627
http://secunia.com/advisories/41639
http://www.vupen.com/english/advisories/2010/2522
危険性:Medium Risk

ISC Bind

ソフト名:ISC Bind 9.7.2
回避策:アップデートにて対応
脆弱性:セキュリティ制限の回避, DoS攻撃, キャッシュへのアクセス, サービスのクラッシュ
ソース:
http://ftp.isc.org/isc/bind9/9.7.2-P2/RELEASE-NOTES-BIND-9.7.2-P2.html
https://lists.isc.org/pipermail/bind-announce/2010-September/000655.html
http://www.securityfocus.com/bid/43573
http://secunia.com/advisories/41654
危険性:Medium Risk

MODx CMS MODx

ソフト名:MODx CMS MODx 2.0.2-pl
回避策:未対応
脆弱性:XSS, RFI, 認証資格情報の奪取
ソース:
http://www.johnleitch.net/Vulnerabilities/MODx.Revolution.2.0.2-pl.Reflected.Cross-site.Scripting/47
http://www.johnleitch.net/Vulnerabilities/MODx.Revolution.2.0.2-pl.Local.File.Inclusion/49
http://modxcms.com/
http://www.securityfocus.com/bid/43577
http://secunia.com/advisories/41638
危険性:Medium Risk