Security woes continue at Adobe, which is warning about a new unpatched zero-day flaw in its Flash media-player technology, which could enable a hacker to take control of a user's system.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2012-1573 Cryptographic Issues vulnerability
5.0
gnutls
Solaris 11
11/11 SRU 12.4
This notification describes vulnerabilities fixed in third-party components that are included in Oracle's product distributions.Information about vulnerabilities affecting Oracle products can be found on Oracle Critical Patch Updates and Security Alerts page.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-1944 Numeric Errors vulnerability
9.3
libxml2
Solaris 10
SPARC: 125731-07 X86: 125732-07
Solaris 9
Contact Support
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
I want to backup my SQL Server databases to a folder, but I want to minimize who has access to the folder. In other words, I want to make sure that members of the Windows Local Administrators group don't get to the backups without intentionally trying to bypass the security. How do I do that?
Is your SQL Database under Version Control?SSMS plug-in SQL Source Control connects SVN, TFS, Git, Hg and all others to SQL Server. Learn more.
I am trying to setup multiple Django instances on one Host with lighttpd. My problem is to get Djangos FCGI working on subdirectories served by my Webserver.
So my aim is the following:
www.myhost.org/django0 - django1.fcgi on localhost:3000
www.myhost.org/django1 - django2.fcgi on localhost:3001
www.myhost.org/django2 - django3.fcgi on localhost:3002
Unfortunately the following configuration doesn't even work for one:
$HTTP["url"] =~ "^/django0/static($|/)" {
server.document-root = "/home/django0/django/static/"
}
$HTTP["url"] =~ "^/django0/media($|/)" {
server.document-root = "/usr/lib/python2.7/dist-packages/django/contrib/admin/media/"
}
$HTTP["url"] =~ "^/django0($|/)" {
proxy.server = ( "" => ( (
"host" => "127.0.0.1",
"port" => "3001",
"check-local" => "disable",
) )
)
}
The only response I get is an 404 and even this takes a long time till I get this. I found nothing suspicious neither in the access.log nor in the error.log.
Embedded databases power back-end hardware, business applications, and portable devices everywhere. Find out how Oracle embedded
databases live and work at the core of hardware, software, and other devices—and deliver cash, health, and security.
Compromised informationwhether by a company's own employees or outside
attackhas both legal and financial consequences for organizations. See
how Oracle's database security and identity management solutions protect
data and control who has access to it.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-2728 Denial of Service Vulnerability
4.3
Perl
Solaris 10
SPARC: 146032-03 X86: 146033-03
Solaris 11
11/11 SRU 3
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2010-4008 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
4.3
libxml2
Solaris 10
SPARC: 125731-07 X86: 125732-07
Solaris 11
Contact Support
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
I've got one tomcat 7 server(kind of like a web server) trying to talk to a tomcat 6 server(acting as a document server on another machine) over ssl and keep getting this error
java.security.cert.CertificateException: No name matching rarity64 found.
Where rarity64 is the name of the document server. I've tried exporting keys from both tomcats keystores and importing them into the others keystores using java keytool. I've even tried adding them to the other machines cacerts keystore.
I've also used internet explorer to import both keys into the other machine. But nothing I try works.
If it matters the real webserver is IIS 7.5, which the tomcat "webserver" talks too with arr, and they don't use SSL. But the problem seems to between the two tomcat servers
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-2728 Denial of Service (DoS) vulnerability
4.3
Perl 5.6
Solaris 10
SPARC: 146032-03 X86: 146033-03
Solaris 9
Patches planned but not yet available
This notification describes vulnerabilities fixed in third-party components that are included in Oracle's product distributions.Information about vulnerabilities affecting Oracle products can be found on Oracle Critical Patch Updates and Security Alerts page.
<b>IT Wire:</b> "The new IPFire distribution seeks to take security to the highest level while also making things a breeze for the less experienced to set up."
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-3905 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
5.0
libxml2
Solaris 11
Contact Support
Solaris 10
SPARC: 125731-07 X86: 125732-07
Solaris 9
Contact Support
CVE-2011-3919 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
7.5
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-2821 Resource Management Errors vulnerability
7.5
libxml2
Solaris 11
Contact Support
Solaris 10
SPARC: 125731-07 X86: 125732-07
Solaris 9
Contact Support
CVE-2011-2834 Resource Management Errors vulnerability
6.8
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
A Word document with 9 pages, 3 section brakes next page (no odd and even breaks used) and inserted page numbers shows the correct sequence of pages when moving thru the document.
When I change the page numbers in section 2 to start from 1 (Section 1 is only one page numbered with a roman numeral.) Then two strange things happen:
The sequence in the status bar goes from 1 to 3.
Page 2 disappeared (no text is missing) and my total number of pages reads 10 when i actually only have 9.
The first page has a table of contents. Page 2 is listed, but when I press ctrl + click the shortcut it goes to page 4?
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2012-3461 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability
4.3
libotr
Solaris 11
11/11 SRU 12.4
This notification describes vulnerabilities fixed in third-party components that are included in Oracle's product distributions.Information about vulnerabilities affecting Oracle products can be found on Oracle Critical Patch Updates and Security Alerts page.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2009-2260 Information Exposure vulnerability
5.0
Stardict
Solaris 11
11/11 SRU 12.4
This notification describes vulnerabilities fixed in third-party components that are included in Oracle's product distributions.Information about vulnerabilities affecting Oracle products can be found on Oracle Critical Patch Updates and Security Alerts page.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2012-3524 Permissions, Privileges, and Access Controls vulnerability
6.9
libdbus
Solaris 11
11/11 SRU 12.4
This notification describes vulnerabilities fixed in third-party components that are included in Oracle's product distributions.Information about vulnerabilities affecting Oracle products can be found on Oracle Critical Patch Updates and Security Alerts page.
<b>Help Net Security:</b> "The latest version of Passware Kit Forensic has become the first commercially available software to break TrueCrypt hard drive encryption without applying a time-consuming brute-force attack. It was also the first product to decrypt BitLocker drives."
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2009-2409 Cryptographic Issues vulnerability
5.1
OpenSSL
Solaris 10
SPARC: 147707-02 X86: 146672-03
Solaris 9
Contact Support
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2009-4270 Denial of Service (DoS) vulnerability
9.3
Ghostscript
Solaris 10
SPARC: 122259-05 X86: 122260-05
CVE-2010-1628 Memory Corruption vulnerability
9.3
CVE-2010-1869 Buffer Overflow vulnerability
9.3
CVE-2010-2055 Arbitrary Code Execution vulnerability
7.2
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
The next patch Tuesday ( the second Tuesday of the month) is expcted to be big. Since several of the issues being fixed are already being exploited, the patches should be applied sooner rather than later.
http://www.microsoft.com/technet/security/Bulletin/MS11-feb.mspx
http://news.cnet.com/8301-1009_3-20030613-83.html?tag=mncol;title
http://www.computerworld.com/s/article/9208038/Microsoft_to_patch_22_bugs_3_zero_days_next_week?taxonomyId=17
Oracle Magazine September/October features articles on Oracle Database 11g, data security, Oracle embedded databases, Oracle Partitioning, Oracle SecureFiles, Oracle Migration Workbench, and much more.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-4619 Denial of Service (DoS) vulnerability
5.0
OpenSSL
Solaris 10
SPARC: 147707-03 X86: 146672-04
This notification describes vulnerabilities fixed in third-party components that are included in Sun's product distribution.Information about vulnerabilities affecting Oracle Sun products can be found on Oracle Critical Patch Updates and Security Alerts page.
CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-3102 Numeric Errors vulnerability
10.0
libxml2
Solaris 11
11/11 SRU 10.5
Solaris 10
SPARC : 125731-08 , x86 : 125732-08
Solaris 9
Contact Support
This notification describes vulnerabilities fixed in third-party components that are included in Oracle's product distributions.Information about vulnerabilities affecting Oracle products can be found on Oracle Critical Patch Updates and Security Alerts page.