No Image

USN-2954-1: MySQL vulnerabilities

2016-04-25 KENNETH 0

USN-2954-1: MySQL vulnerabilities Ubuntu Security Notice USN-2954-1 25th April, 2016 mysql-5.7 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.04 LTS Summary Several security issues were fixed in MySQL. Software description mysql-5.7 – MySQL database Details Multiple security issues were discovered in MySQL and this update includesnew upstream MySQL versions to fix these issues. MySQL has been updated to 5.7.12 in Ubuntu 16.04 LTS. In addition to security fixes, the updated packages contain bug fixes,new features, and possibly incompatible changes. Please see the following for more information:http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-12.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html Update instructions The problem can be corrected by updating your system to the following package version: Ubuntu 16.04 LTS: mysql-server-5.7 5.7.12-0ubuntu1 To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades. In general, a standard system update will make all the necessary changes. References CVE-2016-0639, CVE-2016-0642, CVE-2016-0643, CVE-2016-0647, CVE-2016-0648, [ more… ]

No Image

CISCO 제품 보안 업데이트 권고

2016-04-25 KENNETH 0

□ 개요 o CISCO 관련 제품에 대한 다수 취약점을 해결한 보안 업데이트 권고 발표[1][2][3][4][5] □ 설명 o 시스코 무선 랜 컨트롤러 관리 인터페이스 DoS 취약점(CVE-2016-1362)[1] o 시스코 ASA 소프트웨어(Adaptive Security Applicance) DHCPv6 릴레이 DoS 취약점(CVE-2016-1367)[2] o 시스코 무선랜 컨트롤러 DoS 취약점(CVE-2016-1364)[3] o 시스코 무선랜 컨트롤러 http 파싱 DoS 취약점(CVE-2016-1363)[4] o 시스코 제품 libSRTP DoS 취약점(CVE-2015-6360)[5] □ 영향 받는 버전 o 참고사이트에 명시되어 있는 ‘Affected Products’를 통해 취약한 제품 확인 □ 해결 방안 o 운영자는 유지보수 업체를 통하여 패치 적용 및 참고사이트 참조 □ 기타 문의사항 o 한국인터넷진흥원 인터넷침해대응센터: 국번없이 118 [참고사이트] [1] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-wlc [2] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-asa-dhcpv6 [3] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-bdos [4] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-htrd [5] https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20160420-libsrtp

No Image

RHSA-2016:0685-1: Moderate: nss, nspr, nss-softokn, and nss-util security, bug fix, and enhancement update

2016-04-25 KENNETH 0

RHSA-2016:0685-1: Moderate: nss, nspr, nss-softokn, and nss-util security, bug fix, and enhancement update Red Hat Enterprise Linux: An update for nss, nspr, nss-softokn, and nss-util is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-1978, CVE-2016-1979 Source: RHSA-2016:0685-1: Moderate: nss, nspr, nss-softokn, and nss-util security, bug fix, and enhancement update

No Image

RHSA-2016:0684-1: Moderate: nss and nspr security, bug fix, and enhancement update

2016-04-25 KENNETH 0

RHSA-2016:0684-1: Moderate: nss and nspr security, bug fix, and enhancement update Red Hat Enterprise Linux: An update for nss and nspr is now available for Red Hat Enterprise Linux 5. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-1978, CVE-2016-1979 Source: RHSA-2016:0684-1: Moderate: nss and nspr security, bug fix, and enhancement update