Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/1.0 (+http://www.commoncrawl.org/bot.html)

Your IP address

(no reverse DNS resolution) [38.107.191.86]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 10 / 2006

System: Mandriva Linux
Topic: Vulnerabilities in ImageMagick and PostgreSQL
Links: MDKSA-2006:193, CVE-2006-4561,
MDKSA-2006:194, CVE-2006-5540, CVE-2006-5541, CVE-2006-5542
ID: ae-200610-065

Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.
A vulnerability in PostgreSQL 8.1.x allowed remote authenticated users to cause a Denial of Service (daemon crash) via certain aggregate functions in an UPDATE statement which were not handled correctly. Another DoS issue in PostgreSQL 7.4.x, 8.0.x, and 8.1.x allowed remote authenticated users to crash the daemon via a coercion of an unknown element to ANYARRAY. Finally, another vulnerability in 8.1.x could allow a remote authenticated user to cause a DoS related to duration logging of V3-protocol Execute message for COMMIT and ROLLBACK statements.
Fixed packages are available now.

System: Several
Topic: Vulnerability in QT
Links: CVE-2006-4811, DSA-1200, ESB-2006.0792, RHSA-2006-0725, ESB-2006.0800
ID: ae-200610-064

An integer overflow has been found in the pixmap handling routines in the Qt GUI libraries. This could allow an attacker to cause a denial of service and possibly execute arbitrary code by providing a specially crafted image file and inducing the victim to view it in an application based on Qt. Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in xsupplicant, mutt, screen, and ruby
Links: MDKSA-2006:189, CVE-2006-5601, CVE-2006-5602,
MDKSA-2006:190, CVE-2006-5297, CVE-2006-5298
MDKSA-2006:191, CVE-2006-4573,
MDKSA-2006:192, CVE-2006-5467
ID: ae-200610-063

A stack overflow in Xsupplicant might be exploited by a remote, authenticated user to gain root priviledges on a vulnerable system. An updated package fixes this problem. Additional code cleanups to fix potential memory leaks are also included.
A race condition in the safe_open function in the Mutt mail client 1.5.12 and earlier, when creating temporary files in an NFS filesystem, allows local users to overwrite arbitrary files due to limitations of the use of the O_EXCL flag on NFS filesystems. The mutt_adv_mktemp function in the Mutt mail client 1.5.12 and earlier doesn't properly verify that temporary files have been created with restricted permissions, which might allow local users to create files with weak permissions via a race condition between the mktemp and safe_fopen function calls. Both vulnerability can be fixed with an updated package.
Multiple unspecified vulnerabilities in the "utf8 combining characters handling" (utf8_handle_comb function in encoding.c) in screen before 4.0.3 allows user-assisted attackers to cause a Denial-of-Service (crash or hang) via certain UTF8 sequences. So it's recommended to install the updated package.
The CGI library in Ruby 1.8 allows a remote attacker to cause a Denial-of-Service via an HTTP request with a multipart MIME body that contains an invalid boundary specifier, which would result in an infinite loop and CPU consumption. Also this problem can be solved by installing an updated package.

System: Suse Linux
Topic: Vulnerabilities in OpenPBS, mailman, python, and libmusicbrainz
Links: SUSE-SR:2006:025
ID: ae-200610-062

The weekly SUSE Security Summary reports vulnerabilities in the packages OpenPBS, mailman, python, and libmusicbrainz. Updated packages are available now and should be installed on vulnerable systems.

System: Microsoft Windows
Topic: Vulnerability in Microsoft Internet Explorer
Links: Microsoft, VU#589272
ID: ae-200610-061

The Execute() function of the ADODB.Connection ActiveX object contains an unspecified vulnerability. This may allow a remote, unauthenticated attacker to cause Internet Explorer to crash or possibly execute arbitrary code. A patch isn't available yet, so it's recommended to disable ActiveX, at least this control. How to do this is described in the CERT Vulnerability Note.

System: SGI Advanced Linux Environment
Topic: Vulnerability in kdelibs
Links: 20061002-01
ID: ae-200610-060

SGI has released the Security Update #65 for SGI Advanced Linux Environment 3. This update fixes already a known security related problem in kdelibs.
So it's recommended to install this update.

System: Sun Java Enterprise System
Topic: Vulnerability in OpenSSL
Links: Sun Alert ID 102656, CVE-2006-4339, ESB-2006.0791
ID: ae-200610-059

A vulnerability was found in OpenSSL. If an RSA key with exponent 3 is used it may be possible to forge a PKCS #1 v1.5 signature signed by that key. Patches are available now.

System: Turbolinux
Topic: Vulnerabilities in seamonky
Links: TLSA-2006-35
ID: ae-200610-058

The Mozilla Seamonky Suite contains several vulnerabilities, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerabilities in Winamp
Links: iDefense, iDefense, ESB-2006.0779
ID: ae-200610-057

The two vulnerabilities potentially allow a remote attacker to compromise computers by launching malicious Ultravox content in Winamp from the user's web browser when the user visits a malicious web page. Fixed packages are available now.

System: Linux
Topic: Vulnerability in Cisco Security Agent for Linux
Links: CISCO, ESB-2006.0787
ID: ae-200610-056

Cisco Security Agent (CSA) for Linux contains a denial of service vulnerability involving port scans. By performing a port scan against a system running a vulnerable version of CSA, it is possible to cause the system to become unresponsive. Fixed software is available now.

System: Several
Topic: Vulnerability in Symantec Software
Links: ae-200610-013, SYM06-022, CVE-2006-3455, R-024
ID: ae-200610-055

Next problems were found in the device drivers of several Anti-Virus and Internet Security products.
Symantec has released updated device drivers via LiveUpdate to address this issue.

System: Sun
Topic: Vulnerability in Sun Java System Messaging Server 6.0 and Planet Messaging Server 5.2
Links: Sun Alert ID 102497, ESB-2006.0441, R-025, ESB-2006.0790
ID: ae-200610-054

A remote user can create a specific message containing Javascript which would be executed in the end user's browsers. This can be used for a cross-site scripting attack.
Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in webmin
Links: DSA-1199, CVE-2005-3912, CVE-2006-3392, CVE-2006-4542, ESB-2006.0786, R-026
ID: ae-200610-053

Several vulnerabilities have been identified in webmin, a web-based administration toolkit.
A format string vulnerability in miniserv.pl could allow an attacker to cause a denial of service by crashing the application or exhausting system resources, and could potentially allow arbitrary code execution.
Improper input sanitization in miniserv.pl could allow an attacker to read arbitrary files on the webmin host by providing a specially crafted URL path to the miniserv http server.
Improper handling of null characters in URLs in miniserv.pl could allow an attacker to conduct cross-site scripting attacks, read CGI program source code, list local directories, and potentially execute arbirary code.
Fixed packages are available now.

System: Various
Topic: Vulnerability in Adobe Flash Player
Links: APSA06-01, CVE-2006-5330, ESB-2006.0783, R-020
ID: ae-200610-052

Several vulnerabilities in Adobe Flash Player would allow remote attackers to modify HTTP headers of client requests and conduct HTTP Request Splitting attacks. This may allow an attacker to disrupt, or insert commands into, some internet or network applications. Fixed software versions are available now.

System: Various
Topic: Vulnerabilities in Novell eDirectory
Links: iDefense, iDefense, iDefense, CVE-2006-4177, CVE-2006-4509, CVE-2006-4510, AL-2006.0096
ID: ae-200610-051

Three critical vulnerabilities were found in Novell eDirectory, that could allow an remote attacker to execute arbitrary code in the context of the running daemon. Patches are available now.

System: HP-UX / HP Tru64 UNIX
Topic: Vulnerability in dtmail
Links: HPSBUX02162, SSRT061223, HPSBTU02163, ESB-2006.0780, R-021
ID: ae-200610-050

A security vulnerability has been identified with HP-UX and Tru64 UNIX running dtmail. The vulnerability could be exploited by a local, authorized user to execute arbitrary code as a member of the 'mail' group. Patches are available now.

System: Microsoft Windows
Topic: Vulnerabilities in HP Storage Management Appliance
Links: HPSBST02161, SSRT061264, ESB-2006.0779, CVE-2006-3730, CVE-2006-3942, CVE-2006-4685, CVE-2006-4686, CVE-2006-4696
ID: ae-200610-049

Various security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Fixed packages are available now.

System: Red Hat Enterprise Linux 3
Topic: Several vulnerabilities in kernel fixed
Links: RHSA-2006-0710, CVE-2006-1864, CVE-2006-2071, CVE-2006-2935, CVE-2006-4342, CVE-2006-4997, CVE-2006-5174, ESB-2006.0777
ID: ae-200610-048

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 3 kernel are now available.

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in gzip, openssh, openssl, php, python, and squirrelmail
Links: 20061001-01
ID: ae-200610-047

SGI has released the Security Update #64 for SGI Advanced Linux Environment 3. These updates fix already known security related problems in gzip, openssh, openssl, php, python, and squirrelmail.
So it's recommended to install this update.

System: Microsoft Windows
Topic: Vulnerability in Kaspersky Anti-Virus
Links: iDefense, CVE-2006-4926, ESB-2006.0778
ID: ae-200610-046

Local exploitation of a design error vulnerability in Kaspersky Labs Anti-Virus allows an attacker to execute arbitrary code with kernel privileges. Updates are available now.

System: Various
Topic: Oracle Critical Security Update - October 2006
Links: Oracle, TA06-291A, ESB-2006.0774, VU#642868, HPSBMA02133, SSRT061201, ESB-2006.0789
ID: ae-200610-045

Oracle has released Critical Patch Updates for serveral products. A Critical Patch Update is a collection of patches for multiple security vulnerabilities.

System: Various
Topic: Vulnerability in Breeze Licensed Server
Links: APSB06-16, CVE-2006-5200, ESB-2006.0771
ID: ae-200610-044

Due to an issue with URL parsing in Breeze 5.0 Licensed Server and Breeze 5.1 Licensed Server, a malicious user could retrieve the contents of an arbitrary file from the drive on which Breeze is installed. A fixed software version is available now.

System: Various
Topic: Vulnerability in Asterisk
Links: Asterisk, ESB-2006.0776, OpenPKG-SA-2006.024, VU#521252
ID: ae-200610-043

The Asterisk Skinny channel driver for Cisco SCCP phones chan_skinny.so) incorrectly validates a length value in the packet header. An integer wrap-around leads to heap overwrite, and arbitrary remote code execution as root. A fixed software version is available now.

System: Various
Topic: Vulnerability in Opera Web Browser
Links: Opera, iDefense, CVE-2006-4819, AL-2006.0095, SUSE-SA:2006:061, VU#484380
ID: ae-200610-042

Remote exploitation of a heap overflow vulnerability within version 9 of Opera Software's Opera Web browser could allow an attacker to execute arbitrary code on the affected host. A fixed software version is available now.

System: Various
Topic: Vulnerability in kdelibs and qt
Links: CVE-2006-4811, RHSA-2006-0720, ESB-2006.0769, R-019, MDKSA-2006:186, MDKSA-2006:187
ID: ae-200610-041

An integer overflow flaw was found in the way Qt handled pixmap images. The KDE khtml library uses Qt in such a way that untrusted parameters could be passed to Qt, triggering the overflow. An attacker could for example create a malicious web page that when viewed by a victim in the Konqueror browser would cause Konqueror to crash or possibly execute arbitrary code with the privileges of the victim. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in clamav
Links: iDefense, iDefense, CVE-2006-4182, CVE-2006-5295, ESB-2006.0767, MDKSA-2006:184, DSA-1196, ESB-2006.0775 R-022, SUSE-SA:2006:060, OpenBSD
ID: ae-200610-040

An integer overflow in previous versions of ClamAV could allow a remote attacker to cause a Denial of Service (scanning service crash) and execute arbitrary code via a Portable Executable (PE) file. Another vulnerability could allow a remote attacker to cause a DoS via a crafted compressed HTML (CHM) file that causes ClamAV to read an invalid memory location. A fixed software version is available now.

System: Suse Linux
Topic: Vulnerabilities in OpenSSL, OpenSSH, and BIND9
Links: SUSE-SR:2006:024
ID: ae-200610-039

The weekly SUSE Security Summary reports vulnerabilities in the packages openssl, openssh, and bind9. Updated packages are available now and should be installed on vulnerable systems.

System: Microsoft Windows
Topic: Vulnerabilities in HP Storage Management Appliance
Links: HPSBST02160, SSRT061254, ESB-2006.0764, CVE-2006-3866, MS06-055
ID: ae-200610-038

Various security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Fixed packages are available now.

System: Various
Topic: Vulnerability in Apache mod_tcl
Links: iDefense, CVE-2006-4154, VU#366020, ESB-2006.0762, R-031
ID: ae-200610-037

Remote exploitation of a format string vulnerability in the mod_tcl module for the Apache httpd v2.x could allow attackers to execute arbitrary code in the context of the httpd. A fixed software version is available now.

System: Microsoft Windows
Topic: Vulnerability in TrendMicro OfficeScan
Links: Layerd Defense Research, R-017
ID: ae-200610-036

A format string vulnerability was discovered within Trendmicro OfficeScan Corporate Edition. If successfully exploited, this could allow the user to execute code of the attackers choice on the system running the ActiveX Management Console. A patch is available now.

System: Various
Topic: Vulnerability in HP Version Control Agent
Links: HPSBMA02158, SSRT061251, R-016, ESB-2006.0760
ID: ae-200610-035

A security vulnerability has been identified with HP Version Control Agent. The vulnerability could be exploited by an authorized user to gain unauthorized access possibly leading to elevation of privilege. Patches are available now.

System: Various
Topic: Vulnerability in PHP
Links: Hardened-PHP Project, ESB-2006.0756, OpenPKG-SA-2006.023, MDKSA-2006:185
ID: ae-200610-034

It was discovered that an integer overflow can be triggered when user input is passed to the unserialize() function. The successful exploitation of this integer overflow will result in arbitrary code execution. A patch is available now.

System: Cisco Series Wireless Location Appliances
Topic: Default Password in Cisco Wireless Location Appliance
Links: CISCO, CISCO, ESB-2006.0758
ID: ae-200610-033

The Cisco Wireless Location Appliance software contains a default password for the 'root' administrative account. Fixed software is available now.

System: Sun Solaris
Topic: Vulnerabilities in Apache 2.0, Apache 1.3, Sendmail, and NSRP
Links: Sun Alert ID 102662, Sun Alert ID 102663, CVE-2005-3352, CVE-2005-3357, CVE-2006-3747, ESB-2006.0751, ESB-2006.0761,
Sun Alert ID 102664, CVE-2006-4434, ESB-2006.0752,
Sun Alert ID 102658, CVE-2006-4842, ESB-2006.0755, R-018
ID: ae-200610-032

Several security vulnerabilities have been found in the Apache HTTP server which affect the Apache 1.3 web server bundled with Solaris 8, 9, and 10 and the Apache 2.0 web server bundled with Solaris 10.
A "use-after-free" security vulnerability in sendmail(1M) relating to the handling of long header lines may allow a local or remote unprivileged user to fill up a disk if sendmail(1M) is configured to write unique core files.
Local exploitation of a design error vulnerability in the Netscape Portable Runtime (NSPR) API, as included with Sun Microsystems Solaris 10, allows attackers to create or overwrite arbitrary files on the system.
Patches are available now.

System: Various
Topic: Vulnerability in ColdFusion MX 7
Links: APSB06-17, CVE-2006-3978, R-015, ESB-2006.0772
ID: ae-200610-031

A potential vulnerability in a third party library included with ColdFusion MX 7 could allow a malicious local user to execute arbitrary code with the privilege level of the local SYSTEM. Fixed software is available now.

System: Mandriva Linux
Topic: Several vulnerabilities in kernel fixed
Links: MDKSA-2006:182, CVE-2006-3741, CVE-2006-4145, CVE-2006-4535, CVE-2006-4623
ID: ae-200610-030

Updated kernel packages that fix several security issues in the Linux kernel are now available.

System: Microsoft Windows
Topic: Vulnerability in Windows Object Packager
Links: MS06-065, CVE-2006-4692, AA-2006.0081, R-014
ID: ae-200610-029

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in TCP/IP IPv6
Links: MS06-064, CVE-2004-0230, CVE-2004-0790, CVE-2005-0688, AA-2006.0080
ID: ae-200610-028

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Server Service
Links: MS06-063, CVE-2006-3942, CVE-2006-4696, AA-2006.00790
ID: ae-200610-027

No further comment due to legal reasons

System: Microsoft Office
Topic: Vulnerabilities in Microsoft Office
Links: MS06-062, CVE-2006-3434, CVE-2006-3650, CVE-2006-3864, CVE-2006-3868, AL-2006.0093, R-012
ID: ae-200610-026

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft XML Core Services
Links: MS06-061, CVE-2006-4685, CVE-2006-4686, R-011, AU-2006.0039
ID: ae-200610-025

No further comment due to legal reasons

System: Microsoft Office
Topic: Vulnerabilities in Microsoft Word
Links: MS06-060, CVE-2006-3647, CVE-2006-3651, CVE-2006-4534, CVE-2006-4693, AL-2006.0091, R-010
ID: ae-200610-024

No further comment due to legal reasons

System: Microsoft Office
Topic: Vulnerabilities in Microsoft Excel
Links: MS06-059, CVE-2006-2387, CVE-2006-3431, CVE-2006-3867, CVE-2006-3875, AL-2006.0090, R-009
ID: ae-200610-023

No further comment due to legal reasons

System: Microsoft Office
Topic: Vulnerabilities in Microsoft PowerPoint
Links: MS06-058, CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, CVE-2006-4694, AL-2006.0089, R-008
ID: ae-200610-022

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Shell
Links: MS06-057, CVE-2006-3730, AL-2006.0088, R-007
ID: ae-200610-021

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft .NET Framework
Links: MS06-056, CVE-2006-3436, ESB-2006.0748, R-013
ID: ae-200610-020

No further comment due to legal reasons

System: Debian GNU/Linux
Topic: Vulnerabilities in xfree86 and libwmf
Links: DSA-1193, CVE-2006-3467, CVE-2006-3739, CVE-2006-3740, CVE-2006-4447, ESB-2006.0745, R-005,
DSA-1194, CVE-2006-3376, ESB-2006.0746, Q-252
ID: ae-200610-019

Several vulnerabilities have been discovered in the X Window System, which may lead to the execution of arbitrary code or denial of service.
It was discovered that an integer overflow in libwmf, the library to read Windows Metafile Format files, can be exploited to execute arbitrary code if a crafted WMF file is parsed.
Fixed packages are available now.

System: Various
Topic: Vulnerability in python
Links: CVE-2006-4980, RHSA-2006-0668, ESB-2006.0747, R-006, MDKSA-2006:181, DSA-1197, DSA-1198, ESB-2006.0781, R-023
ID: ae-200610-018

A flaw was discovered in the way that the Python repr() function handled UTF-32/UCS-4 strings. If an application written in Python used the repr() function on untrusted data, this could lead to a denial of service or possibly allow the execution of arbitrary code with the privileges of the Python application. Fixed packages are available now.

System: Sun Solaris 10
Topic: Vulnerability in Link Aggregation
Links: Sun Alert #102606, ESB-2006.0740
ID: ae-200610-017

A security vulnerability resulting from incorrect and insufficient permission checks in the default Solaris 10 configuration may allow a local unprivileged user to create a raw socket on a Solaris link aggregation, resulting in unrestricted access to network packets.
Patches are available now.

System: Various
Topic: Vulnerability in PHP
Links: Hardened-PHP Project, ESB-2006.0738, SUSE-SA:2006:059
ID: ae-200610-016

The design of the open_basedir feature of PHP that is meant to disallow access to files outside a set of configured directories is vulnerable to race conditions. Obviously there is a little span of time between the check and the actual open call. During this time span the checked path could have been altered and point to a file that is forbidden to be accessed due to open_basedir restrictions. Workarounds are described in the advisory.

System: OpenBSD
Topic: Vulnerability in systrace
Links: OpenBSD #014
ID: ae-200610-015

Systrace(4) shows an integer overflow in the STRIOCREPLACE support. This could be exploited for DoS, limited kmem reads or local privilege escalation. A source code patch addresses this issue.

System: Apple Mac
Topic: Vulnerability in skype
Links: skype-sb-2006-002, VU#202604 CVE-2006-5084
ID: ae-200610-014

Skype software provides telephone service over IP networks. Skype for Mac contains a format string vulnerability in the handling of URIs. By sending a specially crafted URI to Skype, a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the user. Such a URI can be sent to Skype by convincing a user to view a specially crafted HTML document. The attacker could also cause Skype to crash.
This vulnerability is addressed in Skype for Mac release 1.5.*.80 or later.

System: Several
Topic: Vulnerability in Symantec Software
Links: iDefense #417, SYM06-020, CVE-2006-4927, VU#946820
ID: ae-200610-013

Symantec has a wide range of Anti-Virus and Internet Security products to protect users from viruses and other harmful software. A vulnerability has been found in the two device drivers NAVENG and NAVEX15. Exploiting this vulnerability, an attacker can overwrite a user supplied address, including code segments, with a constant double word value by supplying a specially crafted Irp to the IOCTL handler function. Successful exploitation allows a local attacker to obtain elevated privileges by exploiting the kernel. This could allow the attacker to gain control of the affected system. Symantec has released updated device drivers via LiveUpdate to address this issue.

System: Sun Solaris
Topic: Vulnerability in mod_ssl
Links: Sun Alert #102640, CVE-2005-3357, ESB-2006.0734
ID: ae-200610-012

When the Apache 2 Web Server shipped with Solaris 10 is configured to support the Secure Sockets Layer (SSL), it may be possible for a local or remote unprivileged user to cause a Denial of Service (DoS) to the Apache application.
Patches are available now.

System: Red Hat Enterprise Linux 4
Topic: Several vulnerabilities in kernel fixed
Links: RHSA-2006-0689, CVE-2005-4811, CVE-2006-0039, CVE-2006-2071, CVE-2006-3741, CVE-2006-4093, CVE-2006-4535, CVE-2006-4623, CVE-2006-4997, ESB-2006.0737
ID: ae-200610-011

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 4 kernel are now available.

System: Debian GNU/Linux
Topic: Vulnerability in maxdb
Links: DSA-1190, CVE-2006-4305, ESB-2006.0733
ID: ae-200610-010

It was discovered that the WebDBM frontend of the MaxDB database performs insufficient sanitising of requests passed to it, which might lead to the execution of arbitrary code. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in phpMyAdmin
Links: Hardened-PHP Project, ESB-2006.0730
ID: ae-200610-009

It was discovered that phpMyAdmin's protection against Cross Site Request Forgeries (CSRF) can be bypassed in multiple ways. Patches are available now.

System: Microsoft Windows
Topic: Vulnerability in McAfee ePolicy Orchestrator
Links: ESB-2006.0727, VU#842452
ID: ae-200610-008

A buffer overflow vulnerability has been found in ePolicy Orchestrator and ProtectionPilot from McAfee that may allow an attacker to exploit the vulnerability by constructing a specially crafted HTTP request that could potentially allow remote code execution. An attacker who successfully exploited this vulnerability could take complete control of an affected system. A patch is available now.

System: HP-UX
Topic: Vulnerabilities in SLP and Ignite-UX Server
Links: HPSBUX02129. SSRT061149, CVE-2005-0769, ESB-2006.0725, R-002, HPSBUX02157, SSRT061220, ESB-2006.0726, R-003
ID: ae-200610-007

A security vulnerability has been identified in HP-UX when running Service Locator Protocol (SLP).The vulnerability could be exploited by a remote user of Service Locator Protocol (SLP) for unauthorized access.
A security vulnerability has been identified in HP-UX running the Ignite-UX server. The vulnerability could be exploited to allow a remote unauthorized user to gain root access to the system running the Ignite-UX server.
Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in mailman
Links: DSA-1188, CVE-2006-3636, CVE-2006-4624, ESB-2006.0731
ID: ae-200610-006

Several cross-site scripting problems were discovered in malman, the the web-based GNU mailing list manager, that could allow remote attackers to inject arbitrary web script or HTML. It was discovered that a remote attacker can inject arbitrary strings into the logfile. Fixed packages are available now.

System: Mac OS X
Topic: Apple Security Update 2006-006
Links: APPLE-SA-2006-006, AL-2006.0085, R-004
ID: ae-200610-005

Several security issues in CFNetwork, Flash Player, ImageIO, Kernel, LoginWindow, Preferences, QuickDraw Manager, SASL, WebCore, and Workgroup Manager are fixed and bundled in the Security Update 2006-006, which is available now.

System: Sun Solaris
Topic: Vulnerability in IPv6
Links: Sun Alert ID 102144, ESB-2006.0723
ID: ae-200610-004

On Solaris 8, 9 and 10 systems utilizing an IPv6 address, a remote unprivileged user may be able to panic the system, causing a Denial of Service (DoS) condition.
Patches are available now.

System: Various
Topic: Vulnerabilities in Sun Secure Global Desktop Software
Links: Sun Alert ID 102650, ESB-2006.0722
ID: ae-200610-003

Two Cross Site Scripting vulnerabilities in the Sun Secure Global Desktop (SSGD) software may allow a local or remote unprivileged user to execute arbitrary script commands in another user's context, potentially allowing an unprivileged remote user to steal cookie information, hijack sessions, or cause a loss of data privacy between a client and the server. Patches are available now.

System: Suse Linux
Topic: Vulnerabilities in kernel
Links: SUSE-SA:2006:057, CVE-2006-3468, CVE-2006-3745, CVE-2006-4093
ID: ae-200610-002

Several vulnerabilities were discovered in the Linux kernel. Fixed kernel packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in cscope
Links: DSA-1186, CVE-2006-4262, ESB-2006.0721
ID: ae-200610-001

Several buffer overflows were discovered in cscope, a source browsing tool, which might lead to the execution of arbitrary code. Fixed packages are available now.



(c) 2000-2010 AERAsec Network Services and Security GmbH