2010-10-05

Linux Kernel

ソフト名:Linux Kernel 2.6.18 8.1.8.El5
回避策:あり
脆弱性:DoS攻撃, ホストシステムのクラッシュ
ソース:
https://bugzilla.redhat.com/show_bug.cgi?id=620490
http://www.kernel.org/
http://www.securityfocus.com/bid/43578
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2938
CVE:CVE-2010-2938
危険性:Low Risk

webSPELL

ソフト名:webSPELL 4.0~4.2.1
回避策:アップデートにて対応
脆弱性:SQLインジェクション, 不正なメールリレー, 偽装された電子メールメッセージの送信
ソース:
http://www.webspell.org/index.php?site=news&show=Webspell%20Release
http://www.webspell.org/index.php?site=about
http://www.securityfocus.com/bid/43608
危険性:Medium Risk

Synology DiskStation Manager

ソフト名:Synology DiskStation Manager 2.2-0958
回避策:アップデートにて対応
脆弱性:機密情報の奪取
ソース:
http://archives.neohapsis.com/archives/fulldisclosure/2010-09/0375.html
http://www.synology.com/enu/products/features/index.php
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3684
CVE:CVE-2010-3684
危険性:Low Risk

GetSimple CMS

ソフト名:GetSimple CMS 2.01
回避策:未対応
脆弱性:XSS, 認証資格情報の奪取
ソース:
http://get-simple.info/
http://www.htbridge.ch/advisory/xss_vulnerability_in_getsimple_cms_1.html
http://www.securityfocus.com/bid/43593
危険性:Medium Risk

Drupal

ソフト名:Drupal 5.0~6.9
回避策:SA-CORE-2010-002にて対応
脆弱性:セキュリティ制限の回避, 認証の回避
ソース:
http://drupal.org/node/880480
http://drupal.org/node/880476
http://www.securityfocus.com/bid/42388
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3091
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3685
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3686
http://www.debian.org/security/2010/dsa-2113
CVE:CVE-2010-3091, CVE-2010-3685, CVE-2010-3686
危険性:Medium Risk

PHP

ソフト名:PHP 5.3/5.3.1/5.3.2
回避策:あり
脆弱性:フォーマットストリングエラー, リモートコード実行
ソース:
http://svn.php.net/viewvc?view=revision&revision=298667
http://www.php.net/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2950
CVE:CVE-2010-2950
危険性:High Risk

MPlayer

ソフト名:MPlayer 1.0 rc3
回避策:あり
脆弱性:リモートコード実行
ソース:
http://git.mplayerhq.hu/?p=ffmpeg;a=commit;h=16c592155f117ccd7b86006c45aacc692a81c23b
http://www.mplayerhq.hu/design7/news.html
http://www.ocert.org/advisories/ocert-2010-004.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3429
http://secunia.com/advisories/41626
http://secunia.com/advisories/41645
http://www.vupen.com/english/advisories/2010/2517
http://www.vupen.com/english/advisories/2010/2518
CVE:CVE-2010-3429
危険性:High Risk

FFmpeg

ソフト名:FFmpeg 0.6
回避策:あり
脆弱性:バッファオーバーフロー, リモートコード実行, アプリケーションのクラッシュ
ソース:
http://ffmpeg.org/
http://git.ffmpeg.org/?p=ffmpeg;a=commitdiff;h=16c592155f117ccd7b86006c45aacc692a81c23b
http://www.ocert.org/advisories/ocert-2010-004.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3429
http://secunia.com/advisories/41626
http://www.vupen.com/english/advisories/2010/2517
http://www.vupen.com/english/advisories/2010/2518
CVE:CVE-2010-3429
危険性:High Risk

2010-10-01

Linux Kernel

ソフト名:Linux Kernel 2.6.0
回避策:あり
脆弱性:バッファオーバーフロー, ローカルコード実行, システムのクラッシュ
ソース:
http://git.kernel.org/?p=linux/kernel/git/tiwai/sound-2.6.git;a=commitdiff;h=5591bf07225523600450edd9e6ad258bb877b779
http://secunia.com/advisories/41650
危険性:High Risk

pluck

ソフト名:pluck 4.6.3
回避策:未対応
脆弱性:CSRF, XSS, Webキャッシュ汚染
ソース:
http://www.htbridge.ch/advisory/xss_vulnerability_in_pluck.html
http://www.pluck-cms.org/?file=kop1.php
http://www.securityfocus.com/bid/43597
http://secunia.com/advisories/41619
危険性:Medium Risk

Zimplet

ソフト名:Zimplet 3.0
回避策:未対応
脆弱性:CSRF, XSS, Webキャッシュ汚染
ソース:
http://www.htbridge.ch/advisory/xsrf_csrf_in_zimplit.html
http://www.zimplit.com/index.html
http://secunia.com/advisories/41629
危険性:Medium Risk

Artica

ソフト名:Artica 1.4.090119
回避策:アップデートにて対応
脆弱性:ディレクトリトラバーサル, セキュリティ制限の回避, SQLインジェクション, 機密情報の奪取, XSS, 認証資格情報の奪取
ソース:
http://www.artica.fr/index.php/get-a-download-artica/nightly-builds
http://secunia.com/advisories/41675
危険性:Medium Risk

ASPMass Cart

ソフト名:ASPMass Cart 0.1
回避策:未対応
脆弱性:CSRF, XSS, Webキャッシュ汚染
ソース:
http://www.aspmass.com/
http://www.exploit-db.com/exploits/15160/
危険性:Medium Risk

JExtensions JE Guestbook

ソフト名:JExtensions JE Guestbook 1.0
回避策:未対応
脆弱性:RFI, SQLインジェクション
ソース:
http://www.joomlaextensions.co.in/
http://www.exploit-db.com/exploits/15157/
http://www.securityfocus.com/bid/43605
http://secunia.com/advisories/41651
危険性:Medium Risk

Linux Kernel

ソフト名:Linux Kernel 2.6.0
回避策:アップデートにて対応
脆弱性:機密情報の奪取
ソース:
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.35
http://www.exploit-db.com/exploits/15155/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2943
CVE:CVE-2010-2943
危険性:Low Risk