Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-50-16-166-175.compute-1.amazonaws.com [50.16.166.175]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 08 / 2006

System: Various
Topic: Vulnerability in sendmail
Links: Sendmail, CVE-2006-4434, DSA-1164, ESB-2006.0627, MDKSA-2006:156, TLSA-2006-28
ID: ae-200608-098

If sendmail is used with the option "-bs" and a mail filter (milter) is configured, a Denial-of-Service can be triggered by sending very long header lines. A patch is available now.

System: Mandriva Linux
Topic: Vulnerability in musicbrainz
Links: MDKSA-2006:157, CVE-2006-4197
ID: ae-200608-097

Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a Denial-of-Service or the execution of arbitrary code. Updated packages address this issue.

System: Debian GNU/Linux
Topic: Vulnerability in gtetrinet
Links: DSA-1163, CVE-2006-3125, ESB-2006.0626
ID: ae-200608-096

Gtetrinet is a multiplayer Tetris-like game. Due to several potential out-of-bounds index accesses, an remote server might be able to execute arbitrary code on a vulnerable system. An updated package is available now.

System: Debian GNU/Linux
Topic: Vulnerability in libmusicbrainz
Links: DSA-1162, CVE-2006-4197, ESB-2006.0625
ID: ae-200608-095

Several buffer overflows have been found in libmusicbrainz, a CD index library. Due to this, remote attackers might cause a Denial-of-Service or execute arbitrary code. An updated package is available now.

System: Various
Topic: Vulnerability in Symantec Enterprise Security Manager
Links: SYMANTEC, ESB-2006.0624
ID: ae-200608-094

The Symantec Enterprise Security Manager 6.0 and 6.5.x is vulnerable to a race condition that can cause the application to lock up, resulting in a Denial-of-Service. This can be achieved by a specially crafted invalid request sent to the manager server to simulate an ESM agent. This causes both the ESM manager and ESM agent to lock up. A fix is available now.

System: Various
Topic: Vulnerability in SAP-DB/MaxDB WebDBM
Links: SYMSA-2006-009, CVE-2006-4305, ESB-2006.0623
ID: ae-200608-093

SAP-DB/MaxDB is a heavy-duty, SAP-certified open source database for OLTP and OLAP usage. A remotely exploitable vulnerability exists in MaxDB's WebDBM. Due to an input validation error, it is possible to execute arbitrary code with the privileges of the 'wahttp' process by sending a malformed HTTP request. Authentication is not required for successful exploitation to occur. This problem has been fixed in the latest release of the product, MaxDB 7.6.00.31.

System: VMware ESX Server
Topic: Vulnerability in VMware ESX Server
Links: esx-253-200606, VU#822476
ID: ae-200608-092

VMware ESX server includes a web interface that can be used for remote management. On affected versions, when a user changes their password, the new credentials are recorded in the server logs as plain text files in directories that all users can read. Vulnerable are VMware ESX prior to 2.5.3 upgrade patch 2, VMware ESX prior to 2.1.3 upgrade patch 1, and VMware ESX prior to 2.0.2 upgrade patch 1. For these versions, an upgrade patch is available.

System: Red Hat Enterprise Linux 4
Topic: Several vulnerabilities in kdegraphics fixed
Links: RHSA-2006-0648, CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465, ESB-2006.0620
ID: ae-200608-091

The kdegraphics package contains graphics applications for the K Desktop Environment. Updated kdegraphics packages that fix several security flaws in kfax are now available for Red Hat Enterprise Linux 2.1 and 3.

System: Debian GNU/Linux
Topic: Vulnerabilities in kdebase, ruby 1.8, and streamripper
Links: DSA-1156, CVE-2005-2449, ESB-2006-0614,
DSA-1157, CVE-2006-1931, CVE-2006-3964, ESB-2006.0615,
DSA-1158, CVE-2005-3124, ESB-2006-0616
ID: ae-200608-090

Kdm is the X display manager for KDE. It handles access to the session type configuration file insecurely, which may lead to the disclosure of arbitrary files through a symlink attack.
Ruby 1.8 is the interpreter for the Ruby language. Here, the use of blocking sockets can lead to Denial-of-Service. Additionally, it does not properly maintain "safe levels" for aliasing, directory accesses and regular expressions, which might lead to a bypass of security restrictions.
Streamripper is a utility to record online radio-streams. It performs insufficient sanitising of data received from the streaming server, which might lead to buffer overflows and the execution of arbitrary code.
Fixed packages are available now.

System: Sun Solaris 10
Topic: Vulnerability in pkgadd
Links: Sun Alert #102513, ESB-2006.0609, Q-301
ID: ae-200608-089

Pkgadd is a tool for adding and removing Software packages from a system. If a patch or package is installed which contains a pkgmap(4) with a "?" for the mode field of a file or directory onto a Solaris 10 system, pkgadd(1M) may incorrectly set the permissions of the corresponding file or directory to either 755 or 777. The permissions of 777 are a security risk since when applied to a file any user is then able to modify that file and when applied to a directory all files within that directory can modified by any user. A patch should be installed, so the expected behavior becomes true.

System: Mandriva Linux
Topic: Vulnerabilities in kernel fixed
Links: MDKSA-2006:151, CVE-2006-1066, CVE-2006-1863, CVE-2006-1864, CVE-2006-2934, CVE-2006-2935, CVE-2006-2936, CVE-2006-3468, CVE-2006-3745
ID: ae-200608-088

Updated kernel packages fixing several security issues in the Mandriva Linux kernel are available now.

System: OpenBSD
Topic: Schwachstellen in dhcpd, kernel, and isakmpd
Links: OpenBSD_2006.006, ESB-2006.0611,
OpenBSD_2006.007, ESB-2006.0612,
OpenBSD_2006.008
ID: ae-200608-087

New source code patches have been published for dhcpd, kernel, and isakmpd, fixing security related problems.

System: Various
Topic: Vulnerability in VMware ESX Server 2.5.3
Links: ESX-253-200606, CVE-2005-3620, Q-299, VU#822476
ID: ae-200608-086

VMware ESX Server 2.5.3 Upgrade Patch 2 has been published now. It resolves some issues, including the problem that Local users can read the passwords of any user who changed their password through the web interface. This patch is not applicable for SunFire X4100 or X4200 servers.

System: Various
Topic: Vulnerability in Sun Java System Content Delivery Server
Links: Sun Alert #102593, Q-300, ESB-2006.0608
ID: ae-200608-085

A security vulnerability in the Sun Java System Content Delivery Server may allow a local or remote unprivileged user to read data from any file on the system. A patch is available now.

System: Various
Topic: Further vulnerabilities in wireshark (ex ethereal)
Links: CVE-2006-4430, CVE-2006-4331, CVE-2006-4332, CVE-2006-4333, AA-2006.0067, MDKSA-2006:152
ID: ae-200608-084

Ethereal is a program for monitoring network traffic. Its name has changed to Wireshark. Several vulnerabilities have been found in this software, allowing the execution of arbitrary code or a Denial-of-Service. Newly published is Wireshark version 0.99.3, so only this version should be used.

System: Various
Topic: Vulnerabilities in MySQL
Links: CVE-2006-4031, CVE-2006-4226, MDKSA-2006:149
ID: ae-200608-083

MySQL 4.1 before 4.1.21 and 5.0 before 5.0.24 allows a local user to access a table through a previously created MERGE table, even after the user's privileges are revoked for the original table. MySQL 4.1 before 4.1.21, 5.0 before 5.0.25, and 5.1 before 5.1.12, when run on case-sensitive filesystems, allows remote authenticated users to create or access a database when the database name differs only in case from a database for which they have permissions. Updated packages address these issues.

System: Microsoft Windows
Topic: Revised patch for Microsoft Internet Explorer
Links: MS06-042 - updated, CVE-2006-3643, AU-2006.0031, AL-2006.0065
ID: ae-200608-082

No further comment due to legal reasons

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in gnupg, httpd, ruby, libtiff, and wireshark
Links: 20060801-01
ID: ae-200608-081

SGI has released the Security Update #62 for SGI Advanced Linux Environment 3. These updates fix security related problems in gnupg, httpd, ruby, libtiff, and wireshark (ethereal). So it's recommended to install this update.

System: Unix, Linux
Topic: Vulnerabilities in ImageMagick
Links: CVE-2004-3743, CVE-2006-3744, CVE-2006-4144, RHSA-2006-0633, Q-295, ESB-2006.0607, MDKSA-2006:155, SuSE-SA:2006:050
ID: ae-200608-080

ImageMagick(TM) is an image display and manipulation tool for the X Window System that can read and write multiple image formats. Several integer and buffer overflow flaws in the way ImageMagick decodes XCF, SGI, and Sun bitmap graphic files have been found. Attackers might execute arbitrary code on a victim's machine if they were able to trick the victim into opening a specially crafted image file. An update addresses this issue.

System: Unix
Topic: Vulnerability in ppp
Links: CVE-2006-4304, FreeBSD-SA-06:08, ESB-2006.0604, NetBSD-SA2006-019, ESB-2006.0605, OpenBSD 2006.009, ESB-2006.0629
ID: ae-200608-079

A problem has been identified in the in-kernel PPP code shared by ISDN PPP interfaces ippp(4) and pppoe(4). Insufficient checking of options presented by the peer may cause writing of copies of the malicious input beyond the end of a buffer allocated for that purpose. This could cause kernel memory corruption and therefore a Denial-of-Service. A patch is available for FreeBSD and NetBSD.

System: Cisco
Topic: Vulnerability in Cisco Firewalls
Links: Cisco, ESB-2006.0603, Q-297
ID: ae-200608-078

Certain versions of the software for the Cisco PIX 500 Series Security Appliances, the Cisco ASA 5500 Series Adaptive Security Appliances (ASA), and the Firewall Services Module (FWSM) are affected by a software bug that may cause the EXEC password, passwords of locally defined usernames, and the enable password in the startup configuration to be changed without user intervention. Unauthorized users can take advantage of this bug to try to gain access to a device that has been reloaded after passwords in its startup configuration have been changed. In addition, authorized users can be locked out and lose the ability to manage the affected device. Cisco has made free software available to address this vulnerability.

System: Cisco
Topic: Vulnerabilities in Cisco VPN 3000 Concentrator
Links: Cisco, ESB-2006.0602, Q-298
ID: ae-200608-077

The Cisco VPN 3000 series concentrators are affected by two vulnerabilities when file management via File Transfer Protocol (FTP) is enabled. It might allow authenticated or unauthenticated attackers to execute certain FTP commands and delete files on the concentrator. Cisco has made free software available to address these vulnerabilities.

System: Various
Topic: Vulnerability in sendmail
Links: Sendmail, CVE-2006-1173, VU#146718, Sun Alert #102460, ESB-2006.0419, DSA-1155, ESB-2006.0606, OpenBSD_2006.005, ESB-2006.0610
ID: ae-200608-076

Sendmail is a widely used mail transfer agent (MTA). Sendmail fails to properly handle malformed mulitpart MIME messages. This vulnerability may be triggered by sending a specially crafted message to a vulnerable Sendmail MTA. It might lead to a Denial-of-Service. A patch as well as an updated version is available.

System: Red Hat Enterprise Linux 4
Topic: Several vulnerabilities in kernel fixed
Links: RHSA-2006-0617, CVE-2004-2660, CVE-2006-1858, CVE-2006-2444, CVE-2006-2932, CVE-2006-2935, CVE-2006-2936, CVE-2006-3468, CVE-2006-3745, ESB-2006.0598, Q-293
ID: ae-200608-075

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 4 kernel are now available.

System: Various
Topic: Vulnerability in PHP
Links: CVE-2006-4020, MDKSA-2006:144, TLSA-2006-23
ID: ae-200608-074

PHP is an HTML-embedded scripting language. A vulnerability has been discovered in the sscanf function. It might allow an attacker to execute arbitrary code by a buffer overflow. Updated versions are available now.

System: Various
Topic: Vulnerability in Java Plug-in and Java Web Start
Links: Sun Alert #102557, ESB-2006.0601
ID: ae-200608-073

The Java Plug-in and Java Web Start both allow applets and applications to specify the version of the Java Runtime Environment (JRE) to run with. Some versions of Java Web Start and the Java Plug-in may allow applets or applications to run with a specified version of the JRE that does not have the latest security fixes. It's recommended to install the latest versions which are available now.

System: Various
Topic: Vulnerabilities in SAP Internet Graphics Service (IGS)
Links: CYBSEC, CYBSEC, CVE-2006-4133, CVE-2006-4134, AL-2006.0071
ID: ae-200608-072

SAP IGS is a server archtitecture for accessing a SAP system via HTML. It's installed with the SAP Web Application Server since version 6.30. A remote attacker may run a specially crafted HTTP request to execute arbitrary code as either the SAP system administrator account on Linux systems or the SYSTEM account on Windows systems. Additionally, with specially crafted HTTP requests a Denial-of-Service is possible. SAP provides a patch to solve this issue.

System: Linux
Topic: Vulnerability in X.org
Links: CVE-2006-3467, RHSA-2006-0634, MDKSA-2006:148
ID: ae-200608-071

X.org is an implementation of the X Window System, which provides the core functionality for the Linux graphical desktop. An integer overflow flaw in the way the X.org server processes PCF files was discovered. A malicious authorized client could exploit this issue to X.org XFree86 server. An update is available now.

System: Red Hat Enterprise Linux 2.1 / 3
Topic: Vulnerability in XFree86
Links: RHSA-2006-0635, CVE-2006-3467, ESB-2006.0597, Q-292
ID: ae-200608-070

XFree86 is an implementation of the X Window System, which provides the core functionality for the Linux graphical desktop. An integer overflow flaw in the way the XFree86 server processes PCF files was discovered. A malicious authorized client could exploit this issue to cause a Denial-of-Service (crash) or potentially execute arbitrary code with root privileges on the XFree86 server. An update is available now.

System: Sun Solaris 8 / 9
Topic: Vulnerability in Role-Based Access Control (RBAC) and format
Links: Sun Alert #102514, Sun Alert #102519, Q-289, Q-291, ESB-2006.0599, ESB-2006.0600
ID: ae-200608-069

A security vulnerability in the default Role-Based Access Control (RBAC) configuration associated with the "File System Management" profile may allow a local user who has been assigned that profile to execute arbitrary commands with the privileges of the user root. Additonally, a security vulnerability in the format(1M) command may allow local users who have been granted the "File System Management" RBAC profile to write to the device files associated with local disks with the privileges of the user root.
Patches are available for SPARC and x86 Platform.

System: Sun Solaris 10
Topic: Vulnerability in libnsl / TLI/XTI API
Links: Sun Alert #102576, ESB-2006.0595, ESB-2006.0718
ID: ae-200608-068

A race condition may cause listener programs for databases or other network aware applications to cease to respond if those listeners are coded using routines from libnsl(3LIB) or TLI/XTI APIs. A patch is available now.

System: Debian GNU/Linux
Topic: Vulnerability in clamav
Links: DSA-1153, CVE-2006-4018, ESB-2006.0594, Q-288
ID: ae-200608-067

A heap overflow vulneravility in the UPX unpacker of the ClamAV anti-virus toolkit might allow remote attackers to execute arbitrary code or cause Denial-of-Service. An updated package is available now.

System: Microsoft Windows
Topic: Problems with Intel 2100 Pro mini-PCI WiFi adapter
Links: CS-023067, VU#824500
ID: ae-200608-066

A security vulnerability exists in the Microsoft Windows drivers for the Intel 2100 PRO/Wireless Network Connection Hardware because of the way that driver handles certain requests by applications. The vulnerability could potentially be exploited by injecting specially crafted malicious frames into the driver and with the aid of an application loaded on the local system kernel level privileges could potentially be obtained. Updates address this issue.

System: Debian GNU/Linux
Topic: Vulnerability in trac
Links: DSA-1152, CVE-2006-3695, ESB-2006.0593
ID: ae-200608-065

Trac is an enhanced Wiki and issue tracking system for software development projects. A vulnerability can be used to disclose arbitrary local files because user provided input isn't checked enough. To fix this problem, the packet python-docutils needs to be updated as well as the packet trac.

System: Microsoft Windows / IBM Laptops
Topic: Vulnerability in eGatherer ActiveX control
Links: eEye#AD20060816, ESB-2006.0592, VU#380277
ID: ae-200608-064

eEye Digital Security has discovered a security vulnerability in IBM's eGatherer ActiveX control (delivered with IBM laptops) which can lead to remote code execution.
A new version is available now.

System: IBM AIX
Topic: Vulnerability in setlocale
Links: ESB-2006.0591,
ID: ae-200608-063

In AIX 5 up to version 5.3 a vulnerability in 'setlocale' may allow local users to execute arbitrary code with root privileges.
A patch is available now.

System: Mac OS X
Topic: Vulnerability in Xsan filesytem
Links: APPLE, CVE-2006-3506, ESB-2006.0590, VU#737294, Q-290
ID: ae-200608-062

Xsan filesytem version 1.4 is now available which fixes also a buffer overflow in the path name handling. A malicious user with write access can trigger a system crash or arbitrary code execution.

System: HP-UX
Topic: Vulnerability in LP subsystem
Links: ITRC; HPSBUX02139, SSRT5981, ESB-2006.0589
ID: ae-200608-061

A potential security vulnerability has been identified with HP-UX running the LP subsystem. The vulnerability could be exploited by a remote user to create a Denial-of-Service (DoS). An updated package is available now.

System: Various
Topic: Vulnerability in Squirrelmail
Links: SquirrelMail, CVE-2006-4019, ESB-2006.0588, DSA-1154, ESB-2006.0596
ID: ae-200608-060

A logged in user could overwrite random variables in compose.php of SquirrelMail, which might make it possible to read/write other users' preferences or attachments. The function that the bug was in, was actually broken in the latest release of SquirrelMail. A new patch restores the functionality.

System: Various
Topic: Vulnerability in Symantec NetBackup PureDisk
Links: SYM06-015, ESB-2006.0587
ID: ae-200608-059

Symantec discovered a security issue in Symantec's Veritas NetBackup 6.0 PureDisk Remote Office Edition. An unauthorized user with access to the network and the server hosting the management interface can potentially bypass the management interface authentication to gain access and elevate their privileges on the system. So it's strongly recommended to install the Maintenance Pack NB_PDE_60_MP1_P01.

System: Various
Topic: Vulnerabilities in wireshark (ex ethereal)
Links: CVE-2006-3627, CVE-2006-3628, CVE-2006-3629, CVE-2006-3630, CVE-2006-3631, CVE-2006-3632, RHSA-2006-0602, ESB-2006.0586
ID: ae-200608-058

Ethereal is a program for monitoring network traffic. In May 2006, Ethereal changed its name to Wireshark. Several vulnerabilities have been found in this program. They are fixed in Wireshark version 0.99.2, so only this version should be used.

System: Unix / Linux
Topic: Vulnerability in X.Org server
Links: X.Org, CVE-2006-0745, VU#837857, MDKSA-2006:056, Sun Alert #102252
ID: ae-200608-057

The X.Org server program provides several command-line options that are meant to be parsed only when the program is running as root only, and not by unprivileged users. A flaw exists in the way the server enforces this restriction because it evaluates the address of the geteuid function instead of the result of executing the function (i.e., "geteuid" versus "geteuid()"). This test is flawed because the address of geteuid is guaranteed to be nonzero. As a result, an unprivileged user can load modules from any location on the filesystem with root privileges or overwrite critical system files with the server log. For most systems, a patch is available.

System: HP-UX
Topic: Vulnerability in HP-UX in Trusted mode
Links: HPSBUX02141, SSRT51153, ESB-2006.0585
ID: ae-200608-056

A potential security vulnerability has been identified in HP-UX B.11.23, B.11.11 and B.11.00 running in Trusted Mode. The potential vulnerability could be exploited by a local authorized user to create a Denial-of-Service (DoS). A patch is available now.

System: Microsoft Windows
Topic: Vulnerability in McAfee Subscription Manager ActiveX control
Links: eEye, McAfee #407052, CVE-2006-3961, VU#481212
ID: ae-200608-055

McAfee Security Center is a console for managing McAfee products. It provides a "safe for scripting" ActiveX control that contains a buffer overflow. The ActiveX object is called McSubMgr and is provided by the file mcsubmgr.dll. By convincing a user to view a specially crafted HTML document, an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause the Internet Explorer to crash. SecurityCenter 6.0.23 solves this problem.

System: Unix / Linux
Topic: Vulnerabilities in MIT Kerberos (krb5) ftpd and ksu
Links: MITKRB5-SA-2006-001, CVE-2006-3084, VU#401660
ID: ae-200608-054

The MIT krb 5 ftpd and ksu programs contain multiple privilege escalation vulnerabilities. These vulnerabilities are dependent on the host operating system's implementation of the setuid() system call and result when seteuid() can fail due to resource exhaustion while changing to an unprivileged user ID. Due to this, an authenticated user might be able to execute code with elevated permissions. Some implementations of seteuid() do not expose the vulnerability. For all others, an update should be installed.

System: Linux
Topic: Vulnerability in heartbeat
Links: CVE-2006-3121, DSA-1151, ESB-2006.0584, MDKSA-2006:142
ID: ae-200608-053

Heartbeat is a subsystem for High-Availability Linux. Here, an out-of-boundary memory access might be possible. This could be used by a remote attacker to cause a Denial-of-Service. An updated package is available now.

System: Various
Topic: Vulnerability in Ruby on Rails
Links: RubyOnRails VU#699540, AA-2006.0058
ID: ae-200608-052

Ruby on Rails is a web application programming framework. It contains an unspecified vulnerability that may allow a remote attacker to execute arbitrary code on a vulnerable system. This vulnerability has been addressed in Ruby on Rails 1.1.6.

System: Various
Topic: Vulnerability in HP OpenView Storage Data Protector
Links: HPSBMA02138, SSRT061184, ESB-2006.0583, VU#673228, Q-296
ID: ae-200608-051

A potential security vulnerability has been identified with HP OpenView Storage Data Protector 5.5 and 5.1 running on HP-UX, IBM AIX, Linux, Microsoft Windows, and Sun Solaris. This vulnerability could allow a remote unauthorized user to execute arbitrary commands. So it's recommended to install the appropriate patch.

System: Microsoft Windows
Topic: Vulnerability in Symantec Backup Exec for Windows Server
Links: SYM06-014, ESB-2006.0582, Q-286, VU#647796
ID: ae-200608-050

The Backup Exec for Windows Server and Remote Agents for Window Server, also used by the Continuous Protection Server and Backup Exec for Netware Server, are vulnerable to heap overflows from specifically formatted internal network calls to RPC interfaces. A patch is available now.

System: Sun Solaris
Topic: Vulnerability in Sun Solaris 10
Links: Sun Alert #102569, ESB-2006.0581
ID: ae-200608-049

On Solaris 10 a system panic may result due to a race condition between netstat(1M) (or snmp queries) and ifconfig(1M) Patches are available now.

System: NetBSD
Topic: Vulnerabilities in sail, dm, and tetris
Links: NetBSD-SA2006-018, CVE-2006-1539, CVE-2006-1744
ID: ae-200608-048

The sail, dungeon master arbiter and tetris games all contain buffer overflows. These programs are installed sgid games, and when successfully exploited the vulnerabilities may allow an attacker to elevate their privileges to the games group. Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerability in shadow
Links: DSA-1150, CVE-2006-2194, ESB-2006.0579, Q-287
ID: ae-200608-047

In several packages that execute the setuid() system call a problem has been detected. There is a lack of checking for success when trying to drop privileges, which may fail with some PAM configurations. Updated packages for shadow, login and passwd solve this problem.

System: Turbolinux
Topic: Vulnerability in vixie-cron
Links: TLSA-2006-21, CVE-2006-2607
ID: ae-200608-046

The vixie-cron package contains the Vixie version of cron. Cron is a standard UNIX daemon that runs specified programs at scheduled times. Vixie cron does not check the return code of a setuid call. This vulnerability may allow local users to obtain root privileges. An updated package solves this issue.

System: Red Hat Enterprise Linux 4
Topic: Vulnerabilities in elfutils, ntp, kernel, kdebase, and perl
Links: RHSA-2006-0354, CVE-2005-1704,
RHSA-2006-0393, CVE-2005-2496, ESB-2006.0575,
RHSA-2006-0575, CVE-2005-3055, CVE-2005-3623, CVE-2006-0038, CVE-2006-0456, CVE-2006-0457, CVE-2006-0742, CVE-2006-1052, CVE-2006-1056, CVE-2006-1242, CVE-2006-1343, CVE-2006-2275, CVE-2006-2446, CVE-2006-2448, CVE-2006-2934, ESB-2006.0576,
RHSA-2006-0582, CVE-2005-2494, ESB-2006.0577,
RHSA-2006-0605, CVE-2006-3813, ESB-2006.0578
ID: ae-200608-045

The elfutils packages contain a number of utility programs and libraries related to the creation and maintenance of executable code. Some of the tools crash when given corrupted input files.
The NTP daemon (ntpd), when run with the -u option and using a string to specify the group, uses the group ID of the user instead of the group, which causes ntpd to run with different privileges than intended.
The Linux kernel handles the basic functions of the operating system. Updated kernel packages are now available as part of ongoing support and maintenance of Red Hat Enterprise Linux version 4. This is the eighth regular update and solves several security related issues.
Alock file handling flaw was discovered in kcheckpass. If the directory /var/lock is writable by a user who is allowed to run kcheckpass, that user could gain root privileges.
A flaw was discovered in sperl, the Perl setuid wrapper, which can cause debugging information to be logged to arbitrary files. By setting an environment variable, a local user could cause sperl to create, as root, files with arbitrary filenames, or append the debugging information to existing files.
Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in Apache
Links: RHSA-2006-0618, RHSA-2006-0619, ESB-2006.0567, CVE-2006-3918
ID: ae-200608-044

A bug was found in Apache where an invalid Expect header sent to the server was returned to the user in an unescaped error message. This could allow an attacker to perform a cross-site scripting attack if a victim was tricked into connecting to a site and sending a carefully crafted Expect header. Fixed packages are available now.

System: Suse Linux
Topic: Vulnerabilities in fbi, gimp, libwmf, x.org, zope, and horde
Links: SUSE-SR:2006:019, CVE-2006-1695, CVE-2006-3119, CVE-2006-3376, CVE-2006-3404, CVE-2006-3458, CVE-2006-3548, CVE-2006-3549
ID: ae-200608-043

The weekly SUSE Security Summary reports vulnerabilities in the packages fbi, gimp, libwmf, x.org, zope, and horde Updated packages are available now and should be installed on vulnerable systems.

System: Sun Ray Server
Topic: Vulnerability in Sun Ray Utility utxconfig
Links: Sun Alert #101924, Q-284, ESB-2006.0568
ID: ae-200608-042

A security vulnerability in the Sun Ray Server 3.x software utxconfig(1) utility may allow a local unprivileged user the ability to create or overwrite arbitrary files on the system. Patches are available now.

System: Various
Topic: Vulnerability in ColdFusion
Links: APSB06-10, CVE-2006-3979, ESB-2006.0572
ID: ae-200608-041

The AdminAPI of ColdFusion MX 7 provides programmatic access to all ColdFusion Administrator functionality. All calls to the adminAPI require an authentication test before calling any other adminAPI functionality. The authentication test could be bypassed. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in drupal and gallery
Links: DSA-1147, CVE-2006-4002, ESB-2006-0570,
DSA-1148, CVE-2005-2734, CVE-2006-0330, CVE-2006-4030 ESB-2006-0571
ID: ae-200608-040

Drupal, a dynamic website platform, performs insufficient input sanitising in the user module, which might lead to cross-site scripting.
Several remote vulnerabilities have been discovered in gallery, a web-based photo album.
Fixed packages are available now.

System: Various
Topic: Vulnerability in ncompress
Links: CVE-2006-1168, DSA-1149, ESB-2006.0573, Q-285, MDKSA-2006:140
ID: ae-200608-039

A missing boundary check was discovered in ncompress, the original Lempel-Ziv compress and uncompress programs, which allows a specially crafted datastream to underflow a buffer with attacker controlled data. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows Kernel
Links: MS06-051, CVE-2006-3443, CVE-2006-3648, VU#337244, VU#411516, Q-273, AL-2006.0067
ID: ae-200608-038

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Hyperlink Object Library
Links: MS06-050, CVE-2006-3086, CVE-2006-3438, VU#683612, ESB-2006.0564, Q-280
ID: ae-200608-037

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilityin Microsoft Windows Kernel
Links: MS06-049, CVE-2006-3444, AL-2006.0067, Q-279
ID: ae-200608-036

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft PowerPoint
Links: MS06-048, CVE-2006-3449, CVE-2006-3590, VU#884252, Q-275, AL-2006.0066
ID: ae-200608-035

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Visual Basic for Applications
Links: MS06-047, CVE-2006-3649, VU#159484, Q-274, ESB-2006.0562
ID: ae-200608-034

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows HTML Help
Links: MS06-046, CVE-2006-3357, Q-272, ESB-2006.0561, AA-2006.0059, Cisco
ID: ae-200608-033

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Explorer
Links: MS06-045, CVE-2006-3281, Q-276, ESB-2006.0560, ESB-2006.0563
ID: ae-200608-032

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Management Console
Links: MS06-044, CVE-2006-3643, VU#927548, Q-269, ESB-2006.0559
ID: ae-200608-031

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Outlook Express
Links: MS06-043, CVE-2006-2766, VU#891204, Q-278, ESB-2006.0558
ID: ae-200608-030

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer
Links: MS06-042, CVE-2004-1166, CVE-2006-3280, CVE-2006-3450, CVE-2006-3451, CVE-2006-3637, CVE-2006-3638, CVE-2006-3639, CVE-2006-3640, VU#252764, Q-277, AL-2006.0065, VU#821156
ID: ae-200608-029

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows DNS Resolution
Links: MS06-041, CVE-2006-3440, CVE-2006-3441, VU#794580, VU#908276, ISS Advisory, ISS Advisory, ISS Advisory, Q-271, ESB-2006.0557
ID: ae-200608-028

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Server Service
Links: MS06-040, CVE-2006-3439, Q-270, ISS Alert, AL-2006.0064, AU-2006.0029
ID: ae-200608-027

No further comment due to legal reasons

System: Various
Topic: Vulnerability in ClamAV
Links: CVE-2006-4018, MDKSA-2006:138, SUSE-SA:2006:046, DSA-1153
ID: ae-200608-026

A boundary error was discovered in the UPX extraction module in ClamAV, which is used to unpack PE Windows executables. This could be abused to cause a Denial of Service issue and potentially allow for the execution of arbitrary code with the permissions of the user running clamscan or clamd. Fixed software is available now.

System: Various
Topic: Vulnerabilities in MIT Kerberos 5 and Heimdal Kerberos
Links: MITKRB5-SA-2006-001, Heimdal, CVE-2006-3083, CVE-2006-3084, VU#401660, VU#580124, ESB-2006.0565, ESB-2006.0574, Q-283, DSA-1146, ESB-2006.0569, RHSA-2006-0612, ESB-2006.0566, MDKSA-2006:139
ID: ae-200608-025

In certain application programs packaged in the MIT Kerberos 5 source distribution, calls to setuid() and seteuid() are not always checked for success and which may fail with some PAM configurations. A local user could exploit one of these vulnerabilities to result in privilege escalation. Patches are available now.

System: Microsoft Windows
Topic: Vulnerability in multiple McAfee Products
Links: McAfee, eEye, ESB-2006.0556
ID: ae-200608-024

A vulnerability was discovered in McAfee Security Center that ships with all McAfee consumer products. There is a remote code execution vulnerability that allows an attacker to take complete control of a remote computer by exploiting a vulnerability found in the Subscription Manager ActiveX control. A patch is available now.

System: Turbo Linux
Topic: Vulnerabilities in samba and httpd
Links: TLSA-2006-19, CAN-2006-3403,
TLSA-2006-20, CAN-2006-3437
ID: ae-200608-023

Samba provides file and printer sharing services to SMB/CIFS clients. A denial of service bug was found in the way the smbd daemon tracks active connections to shares. It was possible for a remote attacker to cause the smbd daemon to consume a large amount of system memory by sending carefully crafted smb requests.
A vulnerability in a common Apache HTTP server module, mod_rewrite, could allow a remote attacker to execute arbitrary code on an affected web server.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in chmlib and freeradius
Links: DSA-1144, CVE-2006-3178, ESB-2006-0554,
DSA-1145, CVE-2005-4745, CVE-2006-4746, ESB-2006-0555, Q-281
ID: ae-200608-022

It was discovered that one of the utilities shipped with chmlib, a library for dealing with Microsoft CHM files, performs insufficient sanitising of filenames, which might lead to directory traversal.
Several remote vulnerabilities have been discovered in freeradius, a high-performance RADIUS server, which may lead to SQL injection or denial of service.
Fixed packages are available now.

System: Various
Topic: Vulnerability in MySQL
Links: MySQL, ESB-2006.0553
ID: ae-200608-021

If a user has access to MyISAM table t, that user can create a MERGE table m that accesses t. However, if the user's privileges on t are subsequently revoked, the user can continue to access t by doing so through m. If this behavior is undesirable, you can start the server with the new --skip-merge option to disable the MERGE storage engine.

System: Debian GNU/Linux
Topic: Vulnerability in dhcp
Links: DSA-1143, CVE-2006-3122, ESB-2006.0552
ID: ae-200608-020

A bug was discovered in dhcp, the DHCP server for automatic IP address assignment, which causes the server to unexpectedly exit. Fixed packages are available now.

System: Barracuda Spam Firewall
Topic: Vulnerabilities in Barracuda Spam Firewall
Links: SecurityFocus, ESB-2006.0551, VU#199348
ID: ae-200608-019

Several information and file disclosure vulnerabilities were found in the Barracuda Spam Firewall. Patches are available now.

System: HP-UX
Topic: Vulnerability in Xserver
Links: HPSBUX02137, SSRT051024, ESB-2006.0550
ID: ae-200608-018

A security vulnerability has been identified in the Xserver running on HP-UX. The vulnerability could be exploited by a local user to execute arbitrary code with the privileges of the Xserver. Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerability in freeciv
Links: DSA-1142, CVE-2006-3913
ID: ae-200608-017

In the game 'freeciv' a buffer overflow was found, which allow remote attackers to cause a denial of service.
A fixed package is available now.

System: HP Procurve Switches
Topic: Remote Denial of Service possible against Series 3500yl, 6200yl and 5400zl Switches
Links: PSBGN02136 SSRT061173, ESB-2006.0546
ID: ae-200608-016

HP ProCurve Series 3500yl, 6200yl and 5400zl Switches are vulnerable against a remote Denial of Service.
HP provides new Firmware.

System: Cisco
Topic: Vulnerability in IOS CallManager Express (CME)
Links: CISCO
ID: ae-200608-015

In the IOS CallManager Express (CME) a vulnerabilities in the SIP implemetation was found which can lead attackers to discover the names of users stored in the SIP user database.
Cisoc is currently working on this issue.

System: Debian GNU/Linux
Topic: Vulnerabilities in Mozilla Thunderbird, gpdf and cfs
Links: DSA-1134, ae-200607-060 ESB-2006.0537, ESB-2006.0618,
DSA-1136, CVE-2005-2097 ESB-2006.0540, Q-267,
DSA-1138, CVE-2006-3123, ESB-2006.0545
ID: ae-200608-014

Vulnerabilities already found in 'Mozilla' and 'Firefox' have also impact on 'Thunderbird' and fixed now.
Several buffer overflows already fixed for 'xpdf' were now also fixed in 'gpdf', the Gnome PDF viewer.
An integer overflow in the cryptographic filesystem 'cfs' was found which allows local users to crash the encryption daemon.
Updated packages should be installed.

System: Red Hat Enterprise Linux 4
Topic: Vulnerabilities in Seamonkey (Mozilla)
Links: RHSA-2006-0609, ESB-2006.0544, CVE-2006-2776, CVE-2006-2778, CVE-2006-2779, CVE-2006-2780, CVE-2006-2781, CVE-2006-2782, CVE-2006-2783, CVE-2006-2784, CVE-2006-2785, CVE-2006-2786, CVE-2006-2787, CVE-2006-2788, CVE-2006-3113, CVE-2006-3677, CVE-2006-3801, CVE-2006-3802, CVE-2006-3803, CVE-2006-3804, CVE-2006-3805, CVE-2006-3806, CVE-2006-3807, CVE-2006-3808, CVE-2006-3809, CVE-2006-3810, CVE-2006-3811, CVE-2006-3812
ID: ae-200608-013

Several security bugs in 'Seamonkey', the successor of 'Mozilla' were found.
Fixed packages are available now.

System: Various
Topic: Vulnerability in GnuPG
Links: GnuPG, CVE-2006-3746, RHSA-2006-0615, Q-266, ESB-2006.0543, DSA-1140, DSA-1141, ESB-2006.0549, MDKSA-2006:141
ID: ae-200608-012

Two more possible memory allocation attacks were found in GnuPG. This bug can easily be be exploted for a DoS; remote code execution is not entirely impossible. Fixed software is available now.

System: Various
Topic: Vulnerabilities in libtiff
Links: CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465, RHSA-2006-0603, DSA-1137, ESB-2006.0541, MDKSA-2006:137, SUSE-SA:2006:044
ID: ae-200608-011

A number of flaws were discovered in libtiff during a security audit. An attacker could create a carefully crafted TIFF file in such a way that it was possible to cause an application linked with libtiff to crash or possibly execute arbitrary code. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Symantec On-Demand Protection
Links: SYM06-013, ESB-2006.0536
ID: ae-200608-010

Symantec On-Demand Agent (SODA) and Symantec On-Demand Protection (SODP) provide a Virtual Desktop environment to secure Web-based applications and services. Files created while in the virtual desktop are encrypted as they are saved to a hard drive or removable media, if that option is enabled in the policy configuration. Symantec is aware of a method which could potentially be used to defeat the encryption on these files. A patch is available now.

System: Mac OS X
Topic: Security Update 2006-004
Links: APPLE-SA-2006-04, ESB-2006.0535 Q-265, AU-2006.0028 VU#776628, VU#651844, VU#605908, VU#575372, VU#566132, VU#527236, VU#514740, VU#180692, VU#172244, VU#168020, CVE-2006-1473, CVE-2006-3495, CVE-2006-3496, CVE-2006-3497, CVE-2006-3498, CVE-2006-3499, CVE-2006-3500, CVE-2005-2335, CVE-2005-3088, CVE-2005-4348, CVE-2006-0321, CVE-2005-0988, CVE-2005-1228, CVE-2006-0392, CVE-2006-3501, CVE-2006-3502, CVE-2006-3503, CVE-2006-3504, CVE-2006-0393, CVE-2005-0488, CVE-2006-3505, CVE-2006-3459, CVE-2006-3461, CVE-2006-3462, CVE-2006-3465
ID: ae-200608-009

Several security issues in AFP Server, AppKit, Bluetooth Setup Assistant, Bom, DHCP, dyld, fetchmail, gunzip, Image RAW, ImageIO, LaunchServices, OpenSSH, telnet, and WebKit are fixed and bundled in the Security Update 2006-004, which is available now.

System: Sun Solaris
Topic: Vulnerability in crypto provider
Links: Sun Alert #102543, Q-264, ESB-2006.0539
ID: ae-200608-008

The crypto provider in Solaris 10 3/05 HW2 when running on Sun Fire T2000 platforms might incorrectly verify a DSA signature. Applications which depend on the results of this DSA signature verification might be vulnerable to trusting data which could have been tampered with. Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in mantis and libtunepimp
Links: DSA-1133, CVE-2006-0664, CVE-2006-0665, CVE-2006-0841, CVE-2006-1577, ESB-2006.0534, ESB-2006-0538, DSA-1135, CVE-2006-3600
ID: ae-200608-007

Several remote vulnerabilities have been discovered in the Mantis bug tracking system, which may lead to the execution of arbitrary web script.
Several stack-based buffer overflows were discovered in the LookupTRM::lookup function in libtunepimp, a MusicBrainz tagging library, which allows remote attacers to cause a denial of service or execute arbitrary code.
Fixed packages are available now.

System: Suse Linux
Topic: Vulnerabilities in mysql, Sun Java, dia, ruby, NetworkManager, and libextractor
Links: SUSE-SR:2006:012, CVE-2006-1516, CVE-2006-1517, CVE-2006-1518, CVE-2006-1931, CVE-2006-2426, CVE-2006-2453, CVE-2006-2458, CVE-2006-2480
ID: ae-200608-006

The weekly SUSE Security Summary reports vulnerabilities in the packages mysql, Sun Java, dia, ruby, NetworkManager, and libextractor Updated packages are available now and should be installed on vulnerable systems.

System: Debian GNU/Linux
Topic: Vulnerability in sitebar
Links: DSA-1130, CVE-2006-3320, Q-262, ESB-2006.0533
ID: ae-200608-005

In 'sitebar', a web based bookmark manager written in PHP, a cross-site scripting vulnerability was found.
Fixed Software is available now.

System: VMWare ESX Server
Topic: Vulnerability in VMWare ESX products
Links: CVE-2005-3618, ESB-2006.0529, c051114-001,
CVE-2005-3620, ESB-2006.0530, c051114-003, VU#822476,
CVE-2006-2481, ESB-2006.0531, c060512-001
ID: ae-200608-004

Several vulnerabilities were found in the VMware ESX server, which can lead to inappropriate access to system or privileged data.
An upgrade to newer versions than the affected ones fix this issues.

System: Various
Topic: Vulnerability in Symantec Brightmail AntiSpam
Links: Symantec, ESB-2006.0528
ID: ae-200608-003

Symantec Brightmail Antispam for Linux, Solaris and Windows has multiple security vulnerabilities. Confidential system information can be read or modified by combining this issues.
Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in freeciv
Links: MDKSA-2006:135, CVE-2006-3913
ID: ae-200608-002

In the game 'freeciv' a buffer overflow was found, which allow remote attackers to cause a denial of service.
A fixed package is available now.

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in elfutils, openssh, samba, seamonkey and squirrelmail
Links: SGI-20060703-01
ID: ae-200608-001

SGI has released the Security Update #61 for SGI Advanced Linux Environment 3. These updates fix security related problems in elfutils, openssh, samba, seamonkey and squirrelmail. So it's recommended to install this update.



(c) 2000-2013 AERAsec Network Services and Security GmbH