No Image

2016년 4월 Oracle Critical Patch Update 권고

2016-04-21 KENNETH 0

출처 : http://www.boho.or.kr/data/secNoticeView.do?bulletin_writing_sequence=24183   □ 개요 o 오라클社 CPU에서 자사 제품의 보안취약점 203개에 대한 패치를 발표[1][2][3] ※ CPU(Critical Patch Update) : 오라클 중요 보안 업데이트 o 영향 받는 버전의 사용자는 악성코드 감염에 취약할 수 있으므로, 아래 해결방안에 따라 최신버전으로 업데이트 권고 □ 영향 받는 소프트웨어 ㅇ Oracle Database Server, version(s) 11.2.0.4, 12.1.0.1, 12.1.0.2 ㅇ Oracle Database Server, version(s) 11.2.0.4, 12.1.0.1, 12.1.0.2 ㅇ Oracle API Gateway, version(s) 11.1.2.3.0, 11.1.2.4.0 ㅇ Oracle BI Publisher, version(s) 12.2.1.0.0 ㅇ Oracle Business Intelligence Enterprise Edition, version(s) 11.1.1.7.0, 11.1.1.9.0, 12.2.1.0.0 ㅇ Oracle Exalogic Infrastructure, version(s) 1.0, 2.0 ㅇ Oracle GlassFish Server, version(s) 2.1.1 ㅇ Oracle HTTP Server, version(s) 12.1.2.0, 12.1.3.0 ㅇ Oracle iPlanet Web Proxy Server, version(s) 4.0 ㅇ Oracle iPlanet Web Server, version(s) 7.0 ㅇ Oracle OpenSSO, version(s) 3.0-0.7 ㅇ Oracle Outside In Technology, version(s) 8.5.0, 8.5.1, 8.5.2 ㅇ Oracle Traffic Director, version(s) 11.1.1.7.0, 11.1.1.9.0 ㅇ Oracle [ more… ]

No Image

RHSA-2016:0650-1: Critical: java-1.8.0-openjdk security update

2016-04-20 KENNETH 0

RHSA-2016:0650-1: Critical: java-1.8.0-openjdk security update Red Hat Enterprise Linux: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-0686, CVE-2016-0687, CVE-2016-0695, CVE-2016-3425, CVE-2016-3426, CVE-2016-3427 Source: RHSA-2016:0650-1: Critical: java-1.8.0-openjdk security update

No Image

RHSA-2016:0651-1: Critical: java-1.8.0-openjdk security update

2016-04-20 KENNETH 0

RHSA-2016:0651-1: Critical: java-1.8.0-openjdk security update Red Hat Enterprise Linux: An update for java-1.8.0-openjdk is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. CVE-2016-0686, CVE-2016-0687, CVE-2016-0695, CVE-2016-3425, CVE-2016-3426, CVE-2016-3427 Source: RHSA-2016:0651-1: Critical: java-1.8.0-openjdk security update

No Image

USN-2917-3: Firefox regressions

2016-04-20 KENNETH 0

USN-2917-3: Firefox regressions Ubuntu Security Notice USN-2917-3 19th April, 2016 firefox regressions A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 15.10 Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary USN-2917-1 introduced several regressions in Firefox. Software description firefox – Mozilla Open Source web browser Details USN-2917-1 fixed vulnerabilities in Firefox. This update caused severalweb compatibility regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1950) Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo [ more… ]