Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-107-21-186-38.compute-1.amazonaws.com [107.21.186.38]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 05 / 2006

System: IBM AIX
Topic: Vulnerability in lsmcode
Links: ESB-2006.0377, Q-215
ID: ae-200605-067

A vulnerability in lsmcode may allow local users to execute arbitrary code with root privileges. A patch is available now.

System: Mandriva Linux
Topic: Vulnerabilities in dia
Links: MDKSA-2006:093, CVE-2006-2453, CVE-2006-2480
ID: ae-200605-066

Several format string vulnerabilities were found in Dia. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in motor
Links: DSA-1083, CVE-2005-3863, ESB-2006.0379
ID: ae-200605-065

A buffer overflow was discovered in the ktools library which is used in motor, an integrated development environment for C, C++ and Java, which may lead local attackers to execute arbitrary code. Fixed packages are available now.

System: Various
Topic: Vulnerability in HP OpenView Network Node Manager
Links: HPSBMA02098, SSRT5911, ESB-2006.0369
ID: ae-200605-064

Vulnerabilities have been identified with HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely by an unauthorized user to gain privileged access, execute arbitrary commands, or create arbitrary files. Patches are available now.

System: Various
Topic: Vulnerability in HP OpenView Storage Data Protector
Links: HPSBMA02121, SSRT061157, ESB-2006.0367
ID: ae-200605-063

A security vulnerability has been identified with HP OpenView Storage Data Protector running on HP-UX, IBM AIX, Linux, Microsoft Windows, and Solaris. This vulnerability could allow a remote unauthorized user to execute arbitrary commands. Patches are available now.

System: HP-UX
Topic: Vulnerabilities in Motif, Kernel, and Software Distributor
Links: HPSBUX02119, SSRT4848, CVE-2004-0687, CVE-2004-0688, ESB-2006.0364,
HPSBUX02120, SSRT051057, CVE-2006-2551, ESB-2006.0365,
HPSBUX02114, SSRT061115, CVE-2006-2574, ESB-2006.0368
ID: ae-200605-062

Security vulnerabilities have been identified with Motif applications running on HP-UX. The vulnerabilities could be exploited to allow remote execution of arbitrary code or Denial for Service (DoS).
A security vulnerability has been identified in the HP-UX kernel. The potential vulnerability could be exploited by a local authorized user to create a Denial of Service (DoS).
Security vulnerabilities have been identified with HP-UX running Software Distributor. These vulnerabilities could be exploited by a local authorized user to gain elevated privileges.
HP has released patches now.

System: Various
Topic: Vulnerability in Sun ONE / Java System Application Server
Links: Sun Alert #102164, ESB-2006.0363
ID: ae-200605-061

A Cross Site Scripting (XSS) vulnerability in various releases of the Sun Java System Web Server and Sun Java System Application Server may allow an unprivileged local or remote user to steal cookie information, hijack sessions, or cause a loss of data privacy between a client and the server. Patches are available now.

System: Sun Solaris
Topic: Vulnerability in in.ftpd
Links: Sun Alert #102356, ESB-2006.0362
ID: ae-200605-060

A security vulnerability in the Solaris 9 in.ftpd(1M) server may allow local or remote unprivileged users to access directories outside of their home directory or to log in with their $HOME directory set to "/" (slash). Patches are not available yet. A workaround is described in the advisory.

System: Debian GNU/Linux
Topic: Vulnerabilities in dovecot and libextractor
Links: DSA-1080, CVE-2006-2414, ESB-2006.0375,
DSA-1081, CVE-2006-2458, ESB-2006.0374, Q-211
ID: ae-200605-059

A problem has been discovered in the IMAP component of Dovecot, a secure mail server that supports mbox and maildir mailboxes, which can lead to information disclosure via directory traversal by authenticated users.
A buffer overflow was discovered in the processing of ASF files in libextractor, a library to extract arbitrary meta-data from files, which can lead to the execution of arbitrary code.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerability in mpg123
Links: MDKSA-2006:092, CVE-2006-1655
ID: ae-200605-058

An unspecified vulnerability in mpg123 0.59r allows user-complicit attackers to trigger a segmentation fault and possibly have other impacts via a certain MP3 file, as demonstrated by mpg1DoS3. An updated package is available now.

System: Debian GNU/Linux
Topic: Vulnerability in TIFF
Links: DSA-1078, CVE-2004-2120
ID: ae-200605-057

A problem in the TIFF library may allow an attacker with a specially crafted TIFF image with Yr/Yg/Yb values that exceed the YCR/YCG/YCB values to crash the library and hence the surrounding application. An updated package is available now.

System: Microsoft Windows
Topic: Vulnerability in Symantec Client Security / AntiVirus
Links: eEYE, Symantec, AL-2006.0042
ID: ae-200605-056

Symantec Client Security and Symantec AntiVirus Corporate Edition are susceptible to a potential stack overflow. Exploiting this overflow successfully could potentially cause a system crash, or allow a remote or local attacker to execute arbitrary code with System level rights on the affected system. New versions are available, so it's strongly recommended to install the updated version.

System: Debian GNU/Linux
Topic: Vulnerability in lynx / lynx ssl
Links: DSA-1076, DSA-1077, DSA-1085, CVE-2004-1617, ESB-2006.0376
ID: ae-200605-055

Lynx is a popular text-mode WWW Browser. It's not able to grok invalid HTML including a TEXTAREA tag with a large COLS value and a large tag name in an element that is not terminated, and loops forever trying to render the broken HTML. An updated package solves this problem.

System: Linux
Topic: Vulnerability in binutils
Links: OpenPKG-SA-2006.009, CVE-2006-2362
ID: ae-200605-054

A buffer overflow in "libbfd" of GNU Binutils, as used by GNU strings, allows context-dependent attackers to cause a Denial-of-Service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character. An updated package fixes this problem.

System: Debian GNU/Linux
Topic: Vulnerability in awstats
Links: DSA-1075, ESB-2006.0372
ID: ae-200605-053

It has been discovered that specially crafted web requests can cause awstats, a powerful and featureful web server log analyzer, to execute arbitrary commands. A fixed package is available now.

System: Mandriva Linux
Topic: Vulnerabilities in kernel, hostapd, kphone, shadow-utils, and php
Links: MDKSA-2006:087, CVE-2006-2444, MDKSA-2006:088, CVE-2006-2213, MDKSA-2006:089, CVE-2006-2442, MDKSA-2006:090, CVE-2006-1174, MDKSA-2006:091, CVE-2006-1990, CVE-2006-1991
ID: ae-200605-052

In the kernel, a memory corruption can be triggered remotely when the ip_nat_snmp_basic module is loaded and traffic on port 161 or 162 is NATed. Hostapd 0.3.7 allows remote attackers to cause a Denial-of-Service (segmentation fault) via an unspecified value in the key_data_length field of an EAPoL frame. Kphone creates .qt/kphonerc with world-readable permissions, which allows local users to read usernames and SIP passwords. A potential security problem has been found in the useradd tool when it creates a new user's mailbox due to a missing argument to the open() call, resulting in the first permissions of the file being some random garbage found on the stack, which could possibly be held open for reading or writing before the proper fchmod() call is executed. In PHP, an integer overflow in the wordwrap() function could allow attackers to execute arbitrary code via certain long arguments that cause a small buffer to be allocated, triggering a heap-based buffer overflow. Additionally, the substr_compare() function in PHP 5.x and 4.4.2 could allow attackers to cause a Denial-of-Service (memory access violation) via an out-of-bounds offset argument.
Updated packages solve these issues.

System: Debian GNU/Linux
Topic: Vulnerability in mpg123
Links: DSA-1074, CVE-2006-1655, ESB-2006.0371
ID: ae-200605-051

Mpg123 is a command-line player for MPEG audio files. Due to insufficient validation of MPEG 2.0 layer 3 files several possibilities for buffer overflows are present. An updated package solves this problem.

System: Microsoft Windows
Topic: Problem with Cisco VPN Client
Links: Cisco, ESB-2006.0358, Q-209
ID: ae-200605-050

The Cisco VPN Client for Windows is affected by a local privilege escalation vulnerability that allows non-privileged users to gain administrative privileges. A user needs to authenticate and start an interactive Windows session to be able to exploit this vulnerability. This issue is not related to any known issues in Microsoft Windows itself. Cisco has made free software available to address this vulnerability for affected customers.

System: Sun Solaris 10
Topic: Vulnerability in Xorg
Links: Sun Alert #102339, CVE-2006-1526, ESB-2006.0320
ID: ae-200605-049

The Xorg X server is one of the X Window System display servers available on the Solaris x86 platform. A buffer overflow in the X Render extension may allow an unprivileged local or remote user who is a client of the Xorg X server the ability to execute arbitrary code with the privileges of the Xorg server. The Xorg X server runs with root privileges on Solaris. So it's recommended to update the system immediately.

System: Red Hat Enterprise Linux 2.1
Topic: Vulnerabilities in PHP
Links: RHSA-2006-0501, CVE-2005-2933, CVE-2006-0208, CVE-2006-0996, CVE-2005-1990, Q-208
ID: ae-200605-048

PHP is an HTML-embedded scripting language commonly used with the Apache HTTP Web server. he phpinfo() PHP function doesn't properly sanitize long strings. An attacker might use this to perform cross-site scripting attacks against sites that have publicly-available PHP scripts that call phpinfo(). The error handling output was found to not properly escape HTML output in certain cases. An attacker could use this flaw to perform cross-site scripting attacks against sites where both display_errors and html_errors are enabled. A buffer overflow flaw was discovered in uw-imap, the University of Washington's IMAP Server. php-imap is compiled against the static c-client libraries from imap and therefore needed to be recompiled against the fixed version. The wordwrap() PHP function did not properly check for integer overflow in the handling of the "break" parameter. An attacker who could control the string passed to the "break" parameter could cause a heap overflow.
Users of PHP should upgrade to these updated packages, which contain backported patches that resolve these issues.

System: HP Tru64 UNIX
Topic: Vulnerabilities in Firefox fixed
Links: HP, CVE-2006-1993, Q-205, ESB-2006.0361
ID: ae-200605-047

Potential security vulnerabilities have been identified in Firefox for HP Tru64 UNIX and in the Mozilla Application Suite for HP Tru64 UNIX. The vulnerabilities might result in remote execution of arbitrary code or Denial-of-Service (DoS). Please install to the latest versions: Mozilla 1.7.13 Application Suite, Firefox 1.5.0.3 and Firefox 1.0.8.

System: Mac OS X
Topic: Vulnerability in Xcode Tools
Links: CVE-2006-1466, Apple, ESB-2006.0354
ID: ae-200605-046

If the WebObjects developer tools are installed, remote attackers may be able to obtain or modify WebObjects projects while Xcode is running. Fixed software is available now.

System: Red Hat Enterprise Linux 4
Topic: Vulnerabilities in kernel
Links: RHSA-2006-0493, Q-206, ESB-2006.0359
ID: ae-200605-045

Several vulnerabilities were found in the linux kernel. Fixed kernel packages are available now.

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in ethereal, ipsec-tools, libtiff, php, and squirrelmail
Links: SGI-20060501-01
ID: ae-200605-044

SGI has released the Security Update #58 for SGI Advanced Linux Environment 3. These updates fix security related problems in ethereal, ipsec-tools, libtiff, php, and squirrelmail. So it's recommended to install this update.

System: OpenPKG
Topic: Vulnerability in openldap
Links: OpenPKG-SA-2006.008
ID: ae-200605-043

A weakness exists in OpenLDAP which is caused due to a boundary error in slurpd(8) within the handling of the status file. This can be exploited to cause a stack-based buffer overflow via an overly long hostname read from the status file. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in xscreensaver and postgresql
Links: RHSA-2006-0498, CVE-2003-1294, CVE-2004-2655, ESB-2006.0355,
RHSA-2006-0526, CVE-2006-0591, CVE-2006-2313, CVE-2006-2314, Q-207, ESB-2006.0356
ID: ae-200605-042

Several flaws were found in the way various XScreenSaver screensavers create temporary files. It may be possible for a local attacker to create a temporary file in way that could overwrite a different file to which the user running XScreenSaver has write permissions.
A bug was found in the way PostgreSQL's PQescapeString function escapes strings when operating in a multibyte character encoding. It is possible for an attacker to provide an application a carefully crafted string containing invalidly-encoded characters, which may be improperly escaped, allowing the attacker to inject malicious SQL.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in nagios
Links: DSA-1071, CVE-2006-2162, CVE-2006-2489, ESB-2006.0353
ID: ae-200605-041

A buffer overflow has been discovered in nagios, a host, service and network monitoring and management system, that could be exploited by remote attackers to execute arbitrary code. Fixed packages are available now.

System: SCO UnixWare
Topic: Vulnerability in sendmail
Links: SCOSA-2006.24, CVE-2006-0058, ESB-2006.0370
ID: ae-200605-040

Sendmail is a multi purpose Mailserver. It might allow a remote attacker to execute arbitrary code as root, caused by a signal race vulnerability. An updated package solves this problem.

System: Debian GNU/Linux
Topic: Vulnerabilities in MySQL
Links: DSA-1071, DSA-1073, DSA-1079, CVE-2006-0903, CVE-2006-1516, CVE-2006-1517, CVE-2006-1518, Q-203, ESB-2006.0352, ESB-2006.0366
ID: ae-200605-039

Several vulnerabilities have been discovered in MySQL, a popular SQL database. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in quagga, Kernel, popfile, kphone, phpgroupware, cscope, hostapd, phpbb2, and fbi
Links: DSA-1059, CVE-2006-2223, CVE-2006-2224, CVE-2006-2276, ESB-2006.0344,
DSA-1060, CVE-2006-2110, ESB-2006.0345,
DSA-1061, CVE-2006-0876, ESB-2006.0346,
DSA-1062, CVE-2006-2442, ESB-2006.0347,
DSA-1063, CVE-2005-2781, ESB-2006.0348,
DSA-1064, CVE-2004-2541, ESB-2006.0349,
DSA-1065, CVE-2006-2213, ESB-2006.0350,
DSA-1066, CVE-2006-1896, ESB-2006.0351,
DSA-1067, DSA-1069, DSA-1070, DSA-1082, ESB-2006.0342, Q-204, ESB-2006.0373,
DSA-1068, CVE-2006-1695, ESB-2006.0343
ID: ae-200605-038

Several vulnerabilities have been found in the packages above. Some are critical, so updated packages should be installed.

System: Microsoft Windows
Topic: Zero-day attacks against Microsoft Word 2003/2003
Links: SANS, VU#446012, Microsoft, AL-2006.0041, Q-202, TA06-139A, AU-2006.0017
ID: ae-200605-037

Since yesterday, many mails with an attachment have been found in the Internet. The attachment is a file in doc-format, exploiting a newly found vulnerability in Microsoft Word. If opened, a trojan is installed. Since there is no hotfix available, it's recommended to update the Anti-Virus Software and to be careful with attachments.

System: Sun Solaris
Topic: Vulnerability in Sun N1 System Manager
Links: Sun Alert #102024, Q-200, ESB-2006.0360
ID: ae-200605-036

A security vulnerability in Sun N1 System Manager 1.1 may allow a local unprivileged user to access internal System Manager passwords. A patch is available now.

System: Mandriva Linux
Topic: Vulnerabilities in kernel
Links: MDKSA-2006:086, CVE-2006-0744, CVE-2006-1052, CVE-2006-1242, CVE-2006-1522, CVE-2006-1525, CVE-2006-1527, CVE-2006-2071, CVE-2006-2271, CVE-2006-2272
ID: ae-200605-035

A number of vulnerabilities were discovered and corrected in the Linux 2.6 kernel, so a kernel update should be installed as soon as possible.

System: Debian GNU/Linux
Topic: Vulnerability in awstats
Links: DSA-1058, CVE-2006-2237, ESB-2006.0341, Q-201
ID: ae-200605-034

It has been discovered that specially crafted web requests can cause awstats, a powerful and featureful web server log analyzer, to execute arbitrary commands. A fixed package is available now.

System: Microsoft Windows
Topic: Vulnerability in freeSSHd
Links: SA19846, VU#477960
ID: ae-200605-033

A vulnerability was discovered in FreeSSHd, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. An updated version solves this problem.

System: Various
Topic: Vulnerability in Sun Java System Directory Server
Links: Sun Alert #102345, ESB-2006.0340, Q-199
ID: ae-200605-032

A security vulnerability in Sun Java System Directory Server 5.2 may allow a local or remote user to gain unauthorized administrative access to the Directory Server by logging in to the Directory Server console. Workaround is to manually change the administrative user password.

System: Some
Topic: Vulnerabilities in phpLDAPadmin
Links: CVE-2006-2016, DSA-1057, ESB-2006.0338, Q-198
ID: ae-200605-031

PhpLDAPadmin is a web based interface for administering LDAP servers. Due to several cross-site scripting vulnerabilities, remote attackers might be able to inject arbitrary web script or HTML. An updated package is available now.

System: Debian GNU/Linux
Topic: Vulnerability in webcalendar
Links: DSA-1056, CVE-2006-2247, ESB-2006.0337
ID: ae-200605-030

webcalendar, a PHP-Based multi-user calendar, returns different error messages on login attempts for an invalid password and a non-existing user, allowing remote attackers to gain information about valid usernames. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in RealVNC
Links: frSIRT_1790, ISS Alert, Q-210
ID: ae-200605-029

A vulnerability has been identified in RealVNC Free Edition Version 4.1.1 and Personal/Enterprise Version 4.2.2, respectively. It might be exploited by remote attackers to compromise a vulnerable system. This flaw is due to a design error in the authentication process that doesn't properly validate passwords, which could be exploited by remote unauthenticated attackers to gain unauthorized access to a vulnerable system via a specially crafted request. An updated version solves this problem.

System: Microsoft Windows
Topic: Vulnerability in Verisign i-Nav ActiveX Control
Links: ZDI-06-014, ESB-2006.0336
ID: ae-200605-028

A vulnerability in the Verisign i-Nav ActiveX control allows remote attackers to execute arbitrary code on vulnerable installations. A patch is available now.

System: Windows / Mac OS X
Topic: Multiple vulnerabilities in Apple QuickTime
Links: Apple, VU#289705, VU#570689, ESB-2006.0335, Q-197
ID: ae-200605-027

Several security vilnerabilities were found in Apple QuickTime. Fixed software is available now.

System: Mac OS X
Topic: Security Update 2006-003
Links: APPLE-SA-2006-03, AL-2006.0039, Q-198
ID: ae-200605-026

Several security issues in Safari, Mail, LaunchServices, QuickTime Streaming Server, MySQL Manager, FTPServer, Flash Player, Finder, CoreGraphics, ClamAV, BOM, AppKit, CFNetwork, CoreFoundation, ImageIO, Keychain, libcurl, Preview, QuickDraw, and Ruby are fixed and bundled in the Security Update 2006-003, which is available now.

System: SCO UnixWare
Topic: Vulnerability in GhostScript
Links: SCOSA-2006.23, ESB-2006.0287
ID: ae-200605-025

Ghostscript is affected by an insecure temporary file creation vulnerability. This issue is likely due to a design error that causes the application to fail to verify the existence of a file before writing to it. An attacker may leverage this issue to overwrite arbitrary files with the privileges of an unsuspecting user that activates the vulnerable application. Updated packages solve this issue.

System: Cisco
Topic: Vulnerability in Cisco Application Velocity System
Links: Cisco, ESB-2006.0333
ID: ae-200605-024

Cisco Application Velocity System's (AVS) default configuration allows transparent relay of TCP connections to any reachable destination TCP port if the receiving TCP service can process requests embedded in a HTTP POST method message. Cisco has released a fixed version now.

System: Various
Topic: Vulnerability in Adobe Dreamweaver
Links: APSB06-07, CVE-2006-2042
ID: ae-200605-023

Code generated by Dreamweaver server behaviors for the ColdFusion, PHP mySQL, ASP, ASP.NET, and JSP server models could allow SQL Injection by an attacker. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in xine-ui
Links: MDKSA-2006:085, CVE-2006-1905
ID: ae-200605-022

Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file. Fixed packages are available now.

System: Microsoft Windows XP
Topic: Vulnerability in Macromedia Flash Player
Links: MS06-020, CVE-2006-0024, CVE-2006-2628, Q-193, AL-2006.0038, TA06-129A
ID: ae-200605-021

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Exchange Server
Links: MS06-019, CVE-2006-0027, VU#303452, Q-194, ISS Alert 221, AL-2006.0037, Symantec, TA06-129A
ID: ae-200605-020

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Distributed Transaction Coordinator
Links: MS06-018, CVE-2006-0034, CVE-2006-1184, ESB-2006.0328, Q-195
ID: ae-200605-019

No further comment due to legal reasons

System: Mandriva Linux
Topic: Vulnerability in gdm
Links: MDKSA-2006:083, CVE-2006-1057
ID: ae-200605-018

A race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in ruby
Links: RHSA-2006-0427, CVE-2006-1931, ESB-2006.0330, Q-192
ID: ae-200605-017

A bug was found in the way Ruby creates its xmlrpc and http servers. The servers use a non blocking socket, which enables a remote user to cause a denial of service condition if they are able to transmit a large volume of information from the network server. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in libtiff
Links: CVE-2006-2024, CVE-2006-2025, CVE-2006-2026, CVE-2006-2120, DSA-1054, ESB-2006.0332 RHSA-2006-0425, ESB-2006.0329 Q-191, MDKSA-2006:082
ID: ae-200605-016

Several vulnerabilities were discovered in libtiff that can lead to remote Denial of Service attacks or tne execution of arbitrary code. Fixed software is available now.

System: z/OS
Topic: Vulnerability in multiple CA z/OS products using CAIRIM
Links: CA, CVE-2006-2201, ESB-2006.0326
ID: ae-200605-015

A vulnerability issue exists in the CA CAIRIM LMP solution for z/OS. CAIRIM is delivered as part of CA's z/OS Common Services, and the LMP component provides licensing services to many of CA's z/OS solutions. Patches are available now.

System: Sun Solaris
Topic: Vulnerability in libike
Links: Sun Alert #102246, ESB-2006.0327
ID: ae-200605-014

It may be possible for a remote privileged user to cause the in.iked(1M) daemon to crash or cause in.iked to send invalid data to a peer system, potentially causing that system's in.iked daemon to crash, when an IKE exchange with a malformed payload is attempted. Patches are available now.

System: Unix / Linux
Topic: Vulnerability in Nagios
Links: Nagios, CVE-2006-2162, ESB-2006.0321
ID: ae-200605-013

A buffer overflow was found in the HTTP content_length header handling of Nagios, that could affect the CGIs under certain web servers (although probably not Apache). Fixed software is available now.

System: Various
Topic: Vulnerabilities in PHP
Links: PHP, AL-2006.0035, SUSE-SA:2006:024
ID: ae-200605-012

Several vulnerabilities were found in PHP 5.1.3. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerability in cgiirc
Links: DSA-1052, CVE-2006-2148, ESB-2006.0322, Q-190
ID: ae-200605-011

Several buffer overflows have been discovered in cgiirc, a web-based IRC client, which could be exploited to execute arbitrary code. Fixed packages are available now.

System: Various
Topic: Mutiple patches for IBM Tivoli Directory Server, Tivoli Identity Manager and Websphere Application Server published
Links: ESB-2006.0319
ID: ae-200605-010

In April 2006 some patches concerning inappropriate access and other security related problems have been published. They address vulnerabilities which might be exploited unauthenticated and remote. There is one patch for the IBM Tivoli Directory Server, two for the IBM Tivoli Identity Manager, twelve for the WebSphere Application Server and three for the WebSphere Extended Deployment. Please refer to the advisory to get detailed information about the fixed problems.

System: Various
Topic: Vulnerabilities in MySQL
Links: CVE-2006-1516, CVE-2006-1517, VU#602457, AL-2006.0033, AU-2006.0013, MDKSA-2006:084
ID: ae-200605-009

MySQL contains several vulnerabilities which may allow unauthenticated information disclosure and the execution of arbitrary code by a remote, authenticated user. It's recommended, to use only MySQL 5.0.21, 5.1.10 or 4.1.19, respectively.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in dia, squirrelmail, and ethereal
Links: RHSA-2006-0280, CVE-2006-1550, ESB-2006.0314,
RHSA-2006-0283, CVE-2006-0188, CVE-2006-0195, CVE-2006-0377, ESB-2006.0316,
RHSA-2006-0420, CVE-2006-1932, CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940, ESB-2006.0315
ID: ae-200605-008

Three buffer overflow bugs were discovered in Dia's xfig file format importer. If an attacker is able to trick a Dia user into opening a carefully crafted xfig file, it may be possible to execute arbitrary code as the user running Dia.
Several vulnerabilities were found in SquirrelMail.
A number of vulnerabilities have been discovered in the Ethereal network analyzer.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in clamav
Links: DSA-1050, CVE-2006-1989, ESB-2006.0313
ID: ae-200605-007

A vulnerability was discovered in the protocol code of freshclam, a command line utility responsible for downloading and installing virus signature updates for ClamAV, the antivirus scanner for Unix. This could lead to a Denial-of-Service or potentially the execution of arbitrary code. A fixed package is available now.

System: Various
Topic: Vulnerability in X.Org X11 server
Links: X.Org, CVE-2006-1526, ESB-2006.0312, RHSA-2006-0451, ESB-2006.0317, Q-189, SUSE-SA:2006:023, MDKSA-2006:081-1, Sun Alert 102339, ESB-2006.0320
ID: ae-200605-006

A buffer overflow flaw in the X.org server RENDER extension was discovered. A malicious authorized client could exploit this issue to cause a denial of service (crash) or potentially execute arbitrary code with root privileges on the X.org server. Patches are available now.

System: Many
Topic: Vulnerability in Mozilla Firefox
Links: MFSA2006-30, VU#866300, AL-2006.0032, DSA-1053, ESB-2006.0331, DSA-1055, ESB-2006.0334
ID: ae-200605-005

The 'deleted object reference' vulnerability was now fixed in version 1.5.0.3 of Mozilla Firefox.
So it's recommended to update to the fixed version.

System: Various
Topic: Vulnerabilities in Symantec (dedicated) Scan Engine
Links: SYM06-008, Q-186, VU#118388, ESB-2006.0323
ID: ae-200605-004

Three vulnerabilities which can lead to remote access were found in Symantec Scan Engine, a dedicated TCP/IP server and programming interface for third party software.
Update to version 5.1 will solve the issues.

System: Debian GNU/Linux
Topic: Vulnerabilities in ethereal
Links: DSA-1049, CVE-2006-1932, CVE-2006-1933, CVE-2006-1934, CVE-2006-1935, CVE-2006-1936, CVE-2006-1937, CVE-2006-1938, CVE-2006-1939, CVE-2006-1940, ESB-2006.0311, Q-188
ID: ae-200605-003

Again a number of vulnerabilities have been discovered in the Ethereal network analyzer.
Fixed packages are available now.

System: Cisco
Topic: Vulnerability in Unity Express
Links: Cisco, ESB-2006.0310, Q-187
ID: ae-200605-002

A vulnerability resides in Cisco's Voice-over-IP-Modul 'Unity Express' (CUE) which allows arbitrary users to change a expired password of another user. This can lead in worse case to administrative access.
Cisco has released a fixed version now.

System: Debian GNU/Linux
Topic: Several vulnerabilities in asterisk
Links: DSA-1048, CVE-2005-3559, CVE-2006-1827, ESB-2006.0308
ID: ae-200605-001

Asterisk is an Open Source Private Branch Exchange (telephone control center). Due to missing input sanitising it's possible to retrieve recorded phone messages for a different extension. Additionally, an integer error might trigger a buffer overflow and hence allow the execution of arbitrary code. A patch addresses these issues.



(c) 2000-2013 AERAsec Network Services and Security GmbH