본문 바로가기

취약점 정보2

iptime 제품군 업데이트 권고 ◾ 펌웨어 버전: 9.98.4 ◾ 펌웨어 상태: 정식 버전 ◾ 배포 제품: 11AC 기가비트 제품군(전제품) A6004ns/A5004ns/A3004NS-BCM/A3004ns/A3004/A7NS/A3004ns-dual A3004-dual/A1004NS/A1004V/A1004ns/A1004/A2008/A2004R/A2004plus A2004NSplus/A2004NS-R/A2004ns/A2004 11AC 100Mbps 제품군(전제품) A1/A3/A104R/A604/A604V/A104ns/A104/A704NS-BCM 11n 듀얼밴드 제품군 N904V/N904plus/N904/N8004V/N8004R 11n 제품군 mini3/N6/N604Vplus/N604V/N604Rplus/N604R/N604plus/N5/N3.. 더보기
넷기어 R8000 공유기 제품군 업데이트 권고 Bug Fixes:Fixed the security issue about Security Advisory VU 582384.Firmware upgrade instructions:Note: To avoid disconnect issues during the firmware download process, NETGEAR recommends the firmware update be performed on a computer with wired connection.Write down all the settings which you changed from the default values, since you may need to reenter them manually.Using the Download Link b.. 더보기
VirtualBox 5.1.12 업데이트 권고 VirtualBox 5.1.12 (released 2016-12-20) This is a maintenance release. The following items were fixed and/or added:VMM: fixed VERR_IEM_ASPECT_NOT_IMPLEMENTED Guru Meditations with certain Linux guests if KVM paravirtualization is enabled (5.1 regression; bugs #15613 and #16251)VMM: fixed VERR_VMX_UNABLE_TO_START_VM Guru Meditations under rare conditionsGUI: prevent a crash under certain conditio.. 더보기
VMware ESXi updates address a cross-site scripting issue VMware Security Advisory Advisory ID:VMSA-2016-0023Severity:ImportantSynopsis:VMware ESXi updates address a cross-site scripting issueIssue date:2016-12-20Updated on:2016-12-20 (Initial Advisory)CVE numbers:CVE-2016-7463 1. Summary VMware ESXi updates address a cross-site scripting issue 2. Relevant ProductsVMware vSphere Hypervisor (ESXi) 3. Problem Descriptiona. Host Client stored cross-site s.. 더보기
삼성DVR credentials encoded in base64 in cookie header Product: Samsung DVR Impact: High Intro ~~~~~~~~~~~~~~~ Samsung DVR Web Viewer is by default using HTTP (port 80) and transmits the credentials encoded in the Cookie header using very bad security practice, just encoding the login and password in BASE64 codification. It is trivial to decode those values and gain access to Samsung DVR web interface to monitor and control IP cameras, if the defaul.. 더보기
tomcat7 보안 업데이트 권고 Package : tomcat7 CVE ID : CVE-2016-6816 CVE-2016-8735 CVE-2016-9774 CVE-2016-9775 Debian Bug : 802312 845385 845393 Multiple security vulnerabilities were discovered in the Tomcat servlet and JSP engine, as well as in its Debian-specific maintainer scripts. Those flaws allowed for privilege escalation, information disclosure, and remote code execution. As part of this update, several regression.. 더보기
libupnp security update Debian Security Advisory DSA-3736-1 security () debian org https://www.debian.org/security/ Sebastien Delafond December 16, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libupnp CVE ID : CVE-2016-6255 CVE-2016-8863 Debian Bug : 831857 842093 Two vulnerabilities were discovered in libupnp, a portable SDK for UPnP dev.. 더보기
ipTIME 유무선공유기 63종 펌웨어 9.98.2 정식 펌웨어 배포 ◾ 펌웨어 버전: 9.98.2 ◾ 펌웨어 상태: 정식 버전 ◾ 배포 제품: 11AC 기가비트 제품군(전제품) A6004ns/A5004ns/A3004NS-BCM/A3004ns/A3004/A7NS/A3004ns-dual A3004-dual/A1004NS/A1004V/A1004ns/A1004/A2008/A2004R/A2004plus A2004NSplus/A2004NS-R/A2004ns/A2004 11AC 100Mbps 제품군(전제품) A1/A3/A104R/A604/A604V/A104ns/A104/A704NS-BCM 11n 듀얼밴드 제품군 N904V/N904plus/N904/N8004V/N8004R 11n 제품군 mini3/N6/N604Vplus/N604V/N604Rplus/N604R/N604plus/N5/N3.. 더보기
QEMU/Xen Vulnerability UPDATES IN VERSION 3 ==================== Clarify the IMPACT description, by escalating privilege to that of the qemu process, not necesserily the host. Public release. ISSUE DESCRIPTION ================= The code in qemu which implements ioport read/write looks up the specified ioport address in a dispatch table. The argument to the dispatch function is a uint32_t, and is used without a range c.. 더보기
wireshark 2.2.3 업데이트 Bug FixesThe following vulnerabilities have been fixed:Arbitrary file deletion on Windows. (Bug 13217)The following bugs have been fixed:Saving all exported objects (SMB/SMB2) results in out of physical memory. (Bug 11133)Export HTTP Objects - Single file shows as multiple files in 2.0.2. (Bug 12230)Follow Stream and graph buttons remain greyed out in conversation window. (Bug 12893)Dicom list o.. 더보기