Monday, April 10, 2017

Weekly IT Security News Bulletin (3 April - 9 April 2017)


1. Apple iOS
https://support.apple.com/zh-hk/HT207688

2. Cisco Products
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-aironet
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ame
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-asr
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cfpw
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cfpw1
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cimc
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cli
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cli1
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cli2
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cme
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-cpi
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ios
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-iosxe
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-res
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ucm
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ucm1
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ucs
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ucs-director
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-ucs1
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-wlc
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-wlc1
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-wlc2
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20170405-wlc3

3. Debian
https://www.debian.org/security/2017/dsa-3825
https://www.debian.org/security/2017/dsa-3826

4. F5 products
https://support.f5.com/csp/article/K26311635

5. Mageia
http://advisories.mageia.org/MGASA-2017-0095.html
http://advisories.mageia.org/MGASA-2017-0096.html
http://advisories.mageia.org/MGASA-2017-0097.html
http://advisories.mageia.org/MGASA-2017-0098.html
http://advisories.mageia.org/MGASA-2017-0099.html
http://advisories.mageia.org/MGASA-2017-0100.html
http://advisories.mageia.org/MGASA-2017-0101.html
http://advisories.mageia.org/MGASA-2017-0102.html
http://advisories.mageia.org/MGASA-2017-0103.html
http://advisories.mageia.org/MGASA-2017-0104.html
http://advisories.mageia.org/MGASA-2017-0105.html

6. OpenSUSE
https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00000.html
https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00001.html
https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00002.html
https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00003.html
https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00007.html
https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00008.html
https://lists.opensuse.org/opensuse-security-announce/2017-04/msg00009.html

7. Oracle Linux
https://linux.oracle.com/errata/ELSA-2017-3533.html
https://linux.oracle.com/errata/ELSA-2017-3534.html
https://linux.oracle.com/errata/ELSA-2017-3535.html

8. Red Hat
https://access.redhat.com/errata/RHSA-2017:0847
https://access.redhat.com/errata/RHSA-2017:0854
https://access.redhat.com/errata/RHSA-2017:0855
https://access.redhat.com/errata/RHSA-2017:0860
https://access.redhat.com/errata/RHSA-2017:0861
https://access.redhat.com/errata/RHSA-2017:0862
https://access.redhat.com/errata/RHSA-2017:0863
https://access.redhat.com/errata/RHSA-2017:0864
https://access.redhat.com/errata/RHSA-2017:0867
https://access.redhat.com/errata/RHSA-2017:0869
https://access.redhat.com/errata/RHSA-2017:0872
https://access.redhat.com/errata/RHSA-2017:0873
https://access.redhat.com/errata/RHSA-2017:0879
https://access.redhat.com/errata/RHSA-2017:0880
https://access.redhat.com/errata/RHSA-2017:0881
https://access.redhat.com/errata/RHSA-2017:0882

9. Rockwell Automation Products
https://ics-cert.us-cert.gov/advisories/ICSA-17-094-03

10. Schneider Electric Wonderware InTouch Access Anywhere
https://ics-cert.us-cert.gov/advisories/ICSA-17-089-01
https://ics-cert.us-cert.gov/advisories/ICSA-17-089-02

11. Slackware
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2017&m=slackware-security.427595

12. SUSE
https://www.suse.com/support/update/announcement/2017/suse-su-20170899-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170901-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170912-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170913-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170914-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170918-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170940-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170945-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170946-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170948-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170950-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170951-1.html
https://www.suse.com/support/update/announcement/2017/suse-su-20170953-1.html

13. Ubuntu
https://www.ubuntu.com/usn/usn-3253-1/
https://www.ubuntu.com/usn/usn-3254-1/
https://www.ubuntu.com/usn/usn-3255-1/
https://www.ubuntu.com/usn/usn-3256-1/
https://www.ubuntu.com/usn/usn-3256-2/

14. Xen
http://xenbits.xen.org/xsa/advisory-212.html

Tuesday, April 4, 2017

Weekly IT Security News Bulletin (27 March– 2 April 2017)


1.    3S-Smart Software Solutions GmbH CODESYS Web Server https://ics-cert.us-cert.gov/advisories/ICSA-17-087-02

2.    Apple products https://support.apple.com/kb/HT207600 https://support.apple.com/kb/HT207615 https://support.apple.com/kb/HT207617 https://support.apple.com/zh-hk/HT207607

3.     CentOS
https://lists.centos.org/pipermail/centos-announce/2017-March/022347.html https://lists.centos.org/pipermail/centos-announce/2017-March/022349.html

4.     Debian
https://www.debian.org/security/2017/dsa-3817 https://www.debian.org/security/2017/dsa-3818 https://www.debian.org/security/2017/dsa-3819 https://www.debian.org/security/2017/dsa-3820 https://www.debian.org/security/2017/dsa-3821 https://www.debian.org/security/2017/dsa-3822 https://www.debian.org/security/2017/dsa-3823 https://www.debian.org/security/2017/dsa-3824

5.     F5 Products https://support.f5.com/csp/article/K18015201

6.     Gentoo Linux
https://security.gentoo.org/glsa/201703-04 https://security.gentoo.org/glsa/201703-05 https://security.gentoo.org/glsa/201703-06 https://security.gentoo.org/glsa/201703-07

7.     Google Chrome
https://chromereleases.googleblog.com/2017/03/stable-channel-update-for-desktop_29.html

8.    Huawei Video Content Management Products http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20170329-01-vcm-en

9.    IBM Notes http://www-01.ibm.com/support/docview.wss?uid=swg21990421 http://www-01.ibm.com/support/docview.wss?uid=swg21990658

10.    Mageia http://advisories.mageia.org/MGASA-2017-0083.html http://advisories.mageia.org/MGASA-2017-0084.html http://advisories.mageia.org/MGASA-2017-0085.html http://advisories.mageia.org/MGASA-2017-0086.html http://advisories.mageia.org/MGASA-2017-0087.html http://advisories.mageia.org/MGASA-2017-0088.html http://advisories.mageia.org/MGASA-2017-0089.html http://advisories.mageia.org/MGASA-2017-0090.html http://advisories.mageia.org/MGASA-2017-0091.html http://advisories.mageia.org/MGASA-2017-0092.html http://advisories.mageia.org/MGASA-2017-0093.html http://advisories.mageia.org/MGASA-2017-0094.html

11.    NTP http://support.ntp.org/bin/view/Main/SecurityNotice#March_2017_ntp_4_2_8p10_NTP_Secu https://www.hkcert.org/my_url/en/alert/17032701

12.    Oracle Linux https://linux.oracle.com/errata/ELSA-2017-3531.html https://linux.oracle.com/errata/ELSA-2017-0565.html https://linux.oracle.com/errata/ELSA-2017-0725.html https://linux.oracle.com/errata/ELSA-2017-0817.html https://linux.oracle.com/errata/ELSA-2017-0680.html https://linux.oracle.com/errata/ELSA-2017-0654.html https://linux.oracle.com/errata/ELSA-2017-0631.html https://linux.oracle.com/errata/ELSA-2017-0744.html https://linux.oracle.com/errata/ELSA-2017-0794.html https://linux.oracle.com/errata/ELSA-2017-0662.html https://linux.oracle.com/errata/ELSA-2017-0564.html https://linux.oracle.com/errata/ELSA-2017-0630.html https://linux.oracle.com/errata/ELSA-2017-0621.html https://linux.oracle.com/errata/ELSA-2017-0641.html https://linux.oracle.com/errata/ELSA-2017-0574.html https://linux.oracle.com/errata/ELSA-2017-0847.html

13.    Samba https://www.samba.org/samba/security/CVE-2017-2619.html https://www.hkcert.org/my_url/en/alert/17032702

14.    Schneider Electric Products https://ics-cert.us-cert.gov/advisories/ICSA-17-089-01 https://ics-cert.us-cert.gov/advisories/ICSA-17-089-02

15. Siemens RUGGEDCOM VPN Products
https://ics-cert.us-cert.gov/advisories/ICSA-17-087-01

16.    Slackware http://www.slackware.com/security/viewer.php?l=slackware-security&y=2017&m=slackwaresecurity.435262 http://www.slackware.com/security/viewer.php?l=slackware-security&y=2017&m=slackwaresecurity.438176 http://www.slackware.com/security/viewer.php?l=slackware-security&y=2017&m=slackwaresecurity.370121

17.    SUSE https://www.suse.com/support/update/announcement/2017/suse-su-20170839-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170841-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170848-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170853-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170855-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170858-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170859-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170860-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170862-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170864-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170865-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170866-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170867-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170868-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170869-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170870-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170871-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170872-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170873-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170874-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170875-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170876-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170877-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170878-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170879-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170880-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170881-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170882-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170883-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170884-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170885-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170886-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170887-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170888-1.html https://www.suse.com/support/update/announcement/2017/suse-su-20170889-1.html

18.    Ubuntu https://www.ubuntu.com/usn/usn-3233-1/ https://www.ubuntu.com/usn/usn-3239-3/ https://www.ubuntu.com/usn/usn-3244-1/ https://www.ubuntu.com/usn/usn-3245-1/ https://www.ubuntu.com/usn/usn-3246-1/ https://www.ubuntu.com/usn/usn-3247-1/ https://www.ubuntu.com/usn/usn-3236-1/ https://www.ubuntu.com/usn/usn-3248-1/ https://www.ubuntu.com/usn/usn-3249-1/ https://www.ubuntu.com/usn/usn-3249-2/ https://www.ubuntu.com/usn/usn-3250-1/ https://www.ubuntu.com/usn/usn-3250-2/ https://www.ubuntu.com/usn/usn-3251-1/ https://www.ubuntu.com/usn/usn-3251-2/ https://www.ubuntu.com/usn/usn-3216-2/ https://www.ubuntu.com/usn/usn-3242-2/

19.    VMware Products http://www.vmware.com/security/advisories/VMSA-2017-0006.html
20.    Windows Server 2003 IIS 6.0 https://nvd.nist.gov/vuln/detail/CVE-2017-7269
https://www.us-cert.gov/ncas/current-activity/2017/03/30/Internet-Information-Services-IIS-60Vulnerability

21.    Xen http://xenbits.xen.org/xsa/advisory-206.html