본문 바로가기

취약점 정보1

2014-04-11 취약점정리 PHP Fileinfo Component Remote Denial of Service Vulnerability 2014-04-10 http://www.securityfocus.com/bid/66406 OpenSSL TLS 'heartbeat' Extension Information Disclosure Vulnerability 2014-04-10 http://www.securityfocus.com/bid/66690 Samba 'pam_winbind' Configuration File Security Bypass Vulnerability 2014-04-10 http://www.securityfocus.com/bid/64101 Samba SAMR Server Password Lockout Bypass Info.. 더보기
WordPress 3.8.2 Security Release WordPress 3.8.2 is now available. This is an important security release for all previous versions and we strongly encourage you to update your sites immediately.This releases fixes a weakness that could let an attacker force their way into your site by forging authentication cookies. This was discovered and fixed by Jon Cave of the WordPress security team.It also contains a fix to prevent a user.. 더보기
2014-04-10 취약점 정리 Samba 'smbcacls' Command Security Bypass Vulnerability 2014-04-09 http://www.securityfocus.com/bid/66232 Samba SAMR Server Password Lockout Bypass Information Disclosure Weakness 2014-04-09 http://www.securityfocus.com/bid/66336 Samba 'pam_winbind' Configuration File Security Bypass Vulnerability 2014-04-09 http://www.securityfocus.com/bid/64101 Adobe Flash Player and AIR CVE-2014-0507 Unspecifi.. 더보기
MacOSX/XNU HFS Multiple Vulnerabilities MacOSX/XNU HFS Multiple VulnerabilitiesMaksymilian Arciemowiczhttp://cxsecurity.com/http://cifrex.org/ =================== On November 8th, I've reported vulnerability in hard links for HFS+(CVE-2013-6799) http://cxsecurity.com/issue/WLB-2013110059 The HFS+ file system does not apply strict privilege rules during thecreating of hard links. The ability to create hard links to directories iswrong .. 더보기
Bluetooth Text Chat 1.0 iOS - Code Execution Vulnerability Document Title:===============Bluetooth Text Chat v1.0 iOS - Code Execution Vulnerability References (Source):====================http://www.vulnerability-lab.com/get_content.php?id=1250 Release Date:=============2014-04-07 Vulnerability Laboratory ID (VL-ID):====================================1250 Common Vulnerability Scoring System:====================================9.1 Product & Service Int.. 더보기
PostgreSQL class D vulnerability in contrib module: CVE-2014-0066 PostgreSQL class D vulnerability in contrib module: CVE-2014-0066SeverityCVSSPublishedAddedModified4(AV:N/AC:L/Au:S/C:N/I:N/A:P)March 31, 2014April 01, 2014April 01, 2014DescriptionThe chkpass extension in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 does not properly check the return value of the crypt library function, which all.. 더보기
PostgreSQL class C vulnerability in core server, contrib: CVE-2014-0064 PostgreSQL class C vulnerability in core server, contrib: CVE-2014-0064SeverityCVSSPublishedAddedModified7(AV:N/AC:L/Au:S/C:P/I:P/A:P)March 31, 2014April 01, 2014April 01, 2014DescriptionMultiple integer overflows in the path_in and other unspecified functions in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authentica.. 더보기
PostgreSQL class C vulnerability in core server: CVE-2014-0065 PostgreSQL class C vulnerability in core server: CVE-2014-0065SeverityCVSSPublishedAddedModified7(AV:N/AC:L/Au:S/C:P/I:P/A:P)March 31, 2014April 01, 2014April 01, 2014DescriptionMultiple buffer overflows in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to have unspecified impact and attack vectors, .. 더보기
PostgreSQL class C vulnerability in core server: CVE-2014-0061 PostgreSQL class C vulnerability in core server: CVE-2014-0061SeverityCVSSPublishedAddedModified7(AV:N/AC:L/Au:S/C:P/I:P/A:P)March 31, 2014April 01, 2014April 01, 2014DescriptionThe validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allow remote authenticated users to gain privil.. 더보기
PostgreSQL class C vulnerability in core server: CVE-2014-0062 PostgreSQL class C vulnerability in core server: CVE-2014-0062SeverityCVSSPublishedAddedModified5(AV:N/AC:M/Au:S/C:P/I:P/A:N)March 31, 2014April 01, 2014April 01, 2014DescriptionRace condition in the (1) CREATE INDEX and (2) unspecified ALTER TABLE commands in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7, and 9.3.x before 9.3.3 allows remote authenticate.. 더보기