Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-54-234-126-92.compute-1.amazonaws.com [54.234.126.92]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 02 / 2007

System: Turbolinux
Topic: Vulnerabilities in bind and php
Links: TLSA-2007-9, CVE-2007-0494, TLSA-2007-11, CVE-2007-0455
ID: ae-200702-077

Bind may allow remote attackers to cause a denial of service via a type * (ANY) DNS query response that contains multiple RRsets, which triggers an assertion error, aka the "DNSSEC Validation" vulnerability.
Buffer overflow vulnerability exists in php GD Graphics Library.
Patches are available now.

System: Microsoft Windows
Topic: Vulnerability in HP Storage Management Appliance (SMA)
Links: HPSBST02194, SSRT071306, ESB-2007.0133
ID: ae-200702-076

The latest patches for Microsoft are needed to be installed when using the SMA. It's strongly recommended to install these hotfixes from Microsoft.

System: Sun Solaris
Topic: Vulnerabilities in X Font Server
Links: Sun Alert #102803, CAN-2003-0730, CAN-2006-6101, CAN-2006-6102, CAN-2006-6103
ID: ae-200702-075

Multiple security vulnerabilities in the X Font Server (xfs(1)) and the X Render and DBE extensions, which are part of the X11 servers Xsun(1) and Xorg(1), may allow a local or remote unprivileged user to elevate their privileges to root and execute arbitrary code resulting in memory corruption or a Denial of Service (DoS) condition. A patch is available now.

System: Red Hat Enterprise Linux 4
Topic: Several vulnerabilities in kernel fixed
Links: RHSA-2007-0085, CVE-2007-0001, CVE-2007-0006, ESB-2007.0134
ID: ae-200702-074

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 4 kernel are now available.

System: Various
Topic: Vulnerabilities in Mozilla Firefox, Mozilla Thunderbird, and Mozilla Seamonkey
Links: Mozilla, CVE-2006-6077, CVE-2007-0008, CVE-2007-0009, CVE-2007-0775, CVE-2007-0777, CVE-2007-0778, CVE-2007-0779, CVE-2007-0780, CVE-2007-0800, CVE-2007-0981, CVE-2007-0995, CVE-2007-0996, VU#269484, VU#393921, VU#551436, VU#761756, AL-2007.0028, R-163, RHSA-2007-0077, RHSA-2007-0079, ESB-2007.0130, R-164, R-165, MDKSA-2007:050, MDKSA-2007:050-1, RHSA-2007-0078, ESB-2007.0141, MDKSA-2007:052, TLSA-2007-12, TLSA-2007-13, SUSE-SA:2007:019, DSA-1265, ESB-2007.0155, SUSE-SA:2007:022
ID: ae-200702-073

The Mozilla web browser and derived products contain several vulnerabilities, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in Macrovision / InstallShield Update Service Web Agent
Links: VU#847993, CVE-2007-0321, R-157
ID: ae-200702-072

The InstallShield Update Service, now known as Macrovision FLEXnet Connect, contains an ActiveX control called Update Service Agent. This ActiveX control is a component that is included with some Macrovision and InstallShield Windows software installers and is provided by the file isusweb.dll. The Update Service Agent ActiveX control contains a buffer overflow vulnerability in the Download() method. By convincing a user to view a specially crafted HTML document, an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause Internet Explorer to crash. Disabling the vulnerable ActiveX Control or active scripting avoids this vulnerability as an upgrade to the appropriate version does.

System: Various
Topic: Vulnerabilities in PHP
Links: mfsa2007-06, CVE-2007-0906, CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988, MDKSA-2007:048, OpenPKG-SA-2007.010 RHSA-2007-0076
ID: ae-200702-071

Multiple vulnerabilities have been found in the programming language PHP, version up to and including 5.2.0. Some of them might lead to a Denial-of-Service, other allow remote attackers the exection of arbitrary code. So it's strongly recommended to use version 5.2.1 only.

System: Various
Topic: Vulnerabilities in Mozilla Network Security Services (NSS) SSLv2
Links: mfsa2007-06, iDEFENSE #482, iDEFENSE #483, CVE-2007-0008, CVE-2007-0009, VU#377812, VU#592796, ESB-2007.0132
ID: ae-200702-070

Network Security Services (NSS) is a set of libraries designed to support cross-platform development of security-enabled client and server applications. SSL clients such as Firefox and Thunderbird can suffer a buffer overflow if a malicious server presents a certificate with a public key that is too small to encrypt the entire "Master Secret". Exploiting this overflow appears to be unreliable but possible if the SSLv2 protocol is enabled. Servers that use NSS for the SSLv2 protocol can be exploited by a client that presents a "Client Master Key" with invalid length values in any of several fields that are used without adequate error checking. This can lead to a buffer overflow that presumably could be exploitable.
Support for SSLv2 is disabled in Firefox 2 due to other known weaknesses in the protocol; Firefox 2 is not vulnerable unless the user has modified hidden internal NSS settings to re-enable SSLv2 support. It's recommended to check if SSLv2 is disabled in the browser.

System: Various
Topic: Vulnerability in Mozilla JavaScript Engine
Links: Bugzilla#371312, VU#393921, VU#269484, R-162, RHSA-2007-0077, RHSA-2007-0079
ID: ae-200702-069

The JavaScript 'onUnload' event is executed when the browser exits a web page. An event handler can be installed via JavaScript to trap and process this event. Mozilla Firefox fails to properly handle JavaScript onUnload events. Specifically, Firefox may not correctly handle freed data structures modified in the onUnload event handler possibly leading to memory corruption. By convincing a user to view a specially crafted HTML document, an attacker may be able to execute arbitrary code with the privileges of the user. An update to version 2.0.0.2 solves this problem. If an update isn't possible, JavaScript should not be active.

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in ImageMagick, bind, fetchmail, gnomemeeting, php, samba, postgesql, and squirrelmail
Links: SGI_20070201-01
ID: ae-200702-068

SGI has released the Security Update #70 for SGI Advanced Linux Environment 3. These updates fix already known security related problems in ImageMagick, bind, fetchmail, gnomemeeting, php, samba, postgesql, and squirrelmail.
So it's recommended to install this update.

System: Microsoft Windows
Topic: Vulnerability in Google Desktop
Links: VU#615857, ESB-2007.0131
ID: ae-200702-067

A cross-site scripting vulnerability exists in the Google Desktop Search application. A remote unauthenticated attacker may be able to perform any action that the Google Desktop Search engine is capable of performing. This includes executing code that is already on a vulnerable system, searching and viewing files and exfiltrating sensitive data. Google has addressed this issue in the most recent version of the Google Desktop Search, which can be updated automatically.

System: Microsoft Windows
Topic: Vulnerability in Macrovision / InstallShield InstallFromTheWeb
Links: VU#181041, CVE-2007-0321, R-159
ID: ae-200702-066

InstallShield InstallFromTheWeb is a web-based software installation product for Microsoft Windows systems. InstallFromTheWeb is available as an ActiveX control for Internet Explorer and also as a Netscape-style plug-in for other web browsers. The ActiveX control is provided by the file iftw.dll, and the plug-in is provided by the file npiftw32.dll. InstallFromTheWeb contains multiple buffer overflows. Note that InstallShield has been acquired by Macrovision. The InstallFromTheWeb product is no longer supported by Macrovision, so a patch won't be available. It's recommended to remove the software or to disable active scripting in the browser.

System: Mandriva Linux
Topic: Vulnerabilities in kernel
Links: MDKSA-2007:047, CVE-2006-5701, CVE-2006-5823, CVE-2007-0006
ID: ae-200702-065

Some vulnerabilities were discovered and corrected in the Linux 2.6 kernel. A double free vulnerability in the squashfs module could allow a local user to cause a Denial-of-Service by mounting a crafted squashfs filesystem The zlib_inflate function allows local users to cause a crash via a malformed filesystem that uses zlib compression that triggers memory corruption. The key serial number collision avoidance code in the key_alloc_serial function in kernels 2.6.9 up to 2.6.20 allows local users to cause a crash using vectors that trigger a null dereference. In addition to these security fixes, other fixes have been included in an updated package.

System: Microsoft Windows
Topic: Problems with SupportSoft SmartIssue ActiveX Control
Links: iDEFENSE #478, CVE-2006-6490, VU#441785, SupportSoft, SYM07-002, ESB-2007.0128, R-161
ID: ae-200702-064

Remote exploitation of a buffer overflow vulnerability in a SupportSoft ActiveX control allows attackers to execute arbitrary code in the context of the current user. The ActiveX affected control can be identified by the ProgId of "SPRT.SmartIssue" or the CLSID of "01010e00-5e80-11d8-9e86-0007e96c65ae". This ActiveX control is marked safe for scripting as it is intended to be used in a web browser. When installed with Norton Internet Security (NIS) 2006, the code responsible for implementing the control can be found in "C:\Program Files\Common Files\Symantec Shared\tgctlsi.dll". An updated version is available.

System: Microsoft Windows
Topic: Vulnerability in VeriSign ConfigChk ActiveX Control
Links: iDEFENSE #479, ESB-2007.0129, VU#308087, R-158
ID: ae-200702-063

The ConfigChk ActiveX Control is part of VeriSign Inc.'s MPKI, Secure Messaging for Microsoft Exchange and Go Secure! products. It looks for the Microsoft Enhanced Cryptographic Provider in order to support 1024-bit cryptography. Remote exploitation of a buffer overflow vulnerability in VeriSign Inc.'s ConfigChk ActiveX Control could allow an attacker to execute arbitrary code within the security context of the victim. The ActiveX control in question, identified by CLSID 08F04139-8DFC-11D2-80E9-006008B066EE, is marked as being safe for scripting. The vulnerability specifically exists when processing lengthy parameters passed to the VerCompare() method. If either of the two parameters passed to this method are longer than 28 bytes, stack memory corruption will occur. This amounts to a trivially exploitable stack-based buffer overflow. VeriSign has addressed this vulnerability by releasing a patch which corrects the security issues found in the affected .dll file.

System: Various
Topic: Vulnerabilities in IBM DB2 Universal Database
Links: iDEFENSE #480, iDEFENSE #481
ID: ae-200702-062

Local exploitation of a file creation vulnerability in IBM Corp.'s DB2 Universal Database could allow attackers to elevate privileges to the superuser. This vulnerability exists due to unsafe file access from within several setuid-root binaries. Specifically, when supplying the DB2INSTANCE environment variable, the setuid-root DB2 administration binaries will use the home directory of the specified user for loading configuration data. This vulnerability is addressed in DB2 9 Fixpack 2.
Further on, local exploitation of a multiple vulnerabilities in IBM Corp.'s DB2 Universal Database allow attackers to cause a Denial-of-Service condition or elevate privileges to root. Several vulnerabilities exist due to unsafe file access from within several setuid-root binaries. Specifically, when supplying certain environment variables, the DB2 administration binaries will use the specified filename for saving data. This allows an attacker to create or append to arbitrary files as root. A heap-based buffer overflow vulnerability can occur when copying data from an environment variable. The variable contents are copied to a static BSS segment buffer without ensuring proper NUL termination. Consequently, this allows an attacker to cause a heap overflow in a later function call. A stack-based buffer overflow can occur when an environment variable contains a long string. By specifying a specially crafted value, it is possible to overwrite the return address of a function and execute arbitrary code. This vulnerability is addressed in DB2 9 Fixpack 2.

System: Various
Topic: Vulnerability in Java 2 Platform
Links: Sun Alert #102686, CVE-2006-4339, ESB-2007.0127
ID: ae-200702-061

The Java Runtime Environment and the Java Secure Socket Extension may verify incorrect RSA PKCS #1 v1.5 signatures if the RSA public key exponent is 3. This may allow applets or applications that are signed by forged signing certificates and web sites with forged web server certificates to be verified as valid. An update is available now.

System: Red Hat Enterprise Linux 2.1
Topic: Vulnerability in KOffice
Links: RHSA-2007-0010, CVE-2006-6120, R-152
ID: ae-200702-060

KOffice is a collection of productivity applications for the K Desktop Environment (KDE) GUI desktop. An integer overflow has been found in KOffice's PPT file processor. An attacker might create a malicious PPT file that could cause KOffice to execute arbitrary code if the file was opened by a victim. An updated package addresses this issue.

System: Linux
Topic: Vulnerability in spamassassin
Links: CVE-2007-0451, RHSA-2007-0074, ESB-2007.0126, MDKSA-2007:049
ID: ae-200702-059

A possible denial of service was found in 'spamassassin' because of a special crafted HTML email containing URIs could cause consumtion of ressources.
Fixed packages are available now.

System: Cisco
Topic: Vulnerabilities in Cisco Secure Services Client (CSSC)
Links: cisco-sa-20070221-supplicant, R-154, ESB-2007.0124
ID: ae-200702-058

The Cisco Secure Services Client (CSSC) is a software client for 802.1X authentication. Multiple vulnerabilities including privlege escalations and information disclosure were found.
Updates are provided now.

System: Cisco
Topic: Vulnerabilities in Unified IP Conference Station and IP Phone
Links: cisco-sa-20070221-phone, R-153, ESB-2007.0125
ID: ae-200702-057

Cisco Unified IP Conference Station 7935 and 7936 devices do not require a password when a URL is accessed directly via the administrator HTTP interface.
There is a workaround for this vulnerability.

Some Cisco Unified IP Phone devices contain a hard coded default user account with a default password which is remotely accessible via a Secure Shell (SSH) server enabled on the phone. This user account can not be disabled, removed or have its password changed.
Updates are provided now.

System: Mandriva Linux
Topic: Vulnerabilities in ekiga and gnucash
Links: MDKSA-2007:044, CVE-2007-1006,
MDKSA-2007:046, CVE-2007-0007
ID: ae-200702-056

A format string flaw has been discovered in how ekiga (ex GnomeMeeting) processes certain messages, which could permit a remote attacker that can connect to ekiga to potentially execute arbitrary code with the privileges of the user running ekiga.
Gnucash 2.0.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on the gnucash.trace, qof.trace, and qof.trace.[PID] temporary files.
Updated package have been patched to correct this issue.

System: Turbolinux
Topic: Vulnerabilities in Seamonkey
Links: TLSA-2007-7
ID: ae-200702-055

Seamonkey is an open-source web browser. Turbolinux points out that several vulnerabilities in this program can be fixed now and recommends to use version 1.0.7-1.

System: SuSE Linux
Topic: SUSE Security Summary Report
Links: SuSE_Summary_2007_3, CVE-2006-5456, CVE-2006-5867, CVE-2006-5074, CVE-2007-0003, CVE-2007-0104, CVE-2007-0619, CVE-2007-0770,
SUSE-SA:2007:015
ID: ae-200702-054

The latest SuSE Summary Support points out some vulnerabities, which have been fixed now. Vulnerabilities were found in chmlib, GraphicsMagick and ImageMagick, various PDF viewers and in pam_unix login. Additionally, a vulnerability in AppArmor can be fixed now.

System: Various
Topic: Vulnerabilities in Trend Micro OfficeScan Web-Deployment and Server Protect
Links: TrendMicro-1034288, VU#784369, CVE-2007-0325, AA-2007.0009, R-149,
TrendMicro-1034290, VU#730433, VU#349393, VU#466609, VU#630025, CVE-2007-1070, ESB-2007.0123, iDEFENSE #477, R-156
ID: ae-200702-053

The Trend Micro OfficeScan Web-Deployment SetupINICtrl ActiveX control contains multiple buffer overflows, which could allow a remote attacker to execute arbitrary code on a vulnerable system.
Vulnerabilities were found in Trend Micro Server Protect which allow also a remote attacker to execute arbitrary code on a vulnerable system.
Patches and a workaround are available now.

System: Various
Topic: Vulnerability in Snort DCE/RPC preprocessor
Links: Snort-2007-02-19, CVE-2006-5276, XForce#257, R-146, VU#196240, AL-2007.0027
ID: ae-200702-052

The DCE/RPC preprocessor (enabled by default, detecting SMB traffic) does not properly reassemble SMB 'Write AndX' commands. An attacker can exploit this vulnerability and execute code with the same privileges as the Snort binary.
Fixed software is available now.

System: Red Hat Enterprise Linux 3.x, 4.x
Topic: Vulnerabilities in PHP and GnomeMeeting
Links: RHSA-2007-0076, CVE-2007-0906, CVE-2007-0907, CVE-2007-0908, CVE-2007-0909, CVE-2007-0910, CVE-2007-0988, ESB-2007.0120, AL-2007.0005, R-150,
RHSA-2007-0086, CVE-2007-1007, ESB-2007.0121, R-151
ID: ae-200702-051

Several important security holes where again found in PHP. An attacker could possible execute arbitrary code as the 'apache' user.
A critical security hole was found in GnomeMeeting. A remote attacer could potentially execute arbitrary code with the privileges of the user.
Fixed packages are available now.

System: Various
Topic: Vulnerability in Snort
Links: CVE-2006-6931, ESB-2007.0118, MDKSA-2007:051
ID: ae-200702-050

It was discovered that the rule matching algorithm of Snort can be exploited in a way known as a "backtracking attack" to perform numerous time-consuming operations. Fixed software is available now.

System: Mac OS X
Topic: Apple Security Update 2007-002
Links: APPLE-SA-2007-02-15, CVE-2007-0197, CVE-2007-0614, CVE-2007-0710, CVE-2007-0021, CVE-2007-0023, ESB-2007.0112, VU#315856, R-148
ID: ae-200702-049

Several security issues in Finder, iChat, and UserNotification are fixed and bundled in the Security Update 2007-002, which is available now.

System: Linux
Topic: Vulnerability in HP ServiceGuard for Linux
Links: HBSBGN02189, SSRT071297, ESB-2007.0114, R-142
ID: ae-200702-048

A security vulnerability has been identified with HP ServiceGuard for Linux that may allow remote unauthorized access. A patch is available now.

System: Various
Topic: Vulnerabilities in Clamav
Links: iDefense, iDefense, CVE-2007-0897, CVE-2007-0898, ESB-2007.0115, MDKSA-2007:043, SUSE-SA:2007:017, DSA-1263, ESB-2007.0146
ID: ae-200702-047

Clam AntiVirus is a multi-platform GPL anti-virus toolkit. A file descriptor leak was found in clamav when extracting CAB archives. This may be used in denial of service attacks. A vulnerability exists due to the lack of validation of the id parameter string taken from a MIME header. An attacker can create or overwrite an arbitrary file owned by the clamd process. Fixed software is available now.

System: Cisco
Topic: Vulnerabilities in Cisco PIX, Cisco ASA, and Cisco FWSM
Links: Cisco, Cisco, AL-2007.0023, ESB-2007.0104, R-144, R-147
ID: ae-200702-046

Multiple vulnerabilities are found in Cisco PIX 500 Series Security Appliances and the Cisco ASA 5500 Series Adaptive Security Appliances. They affect inspection of malformed Hypertext Transfer Protocol (HTTP) traffic, malformed Session Initiation Protocol (SIP) packets, malformed Transmission Control Protocol (TCP) packets and privilege escalation. Some vulnerabilities also affect Cisco Firewall Services Module (FWSM). Cisco has made free software available to address this vulnerability.

System: Various
Topic: Vulnerabilities in Adobe ColdFusion MX and Adobe JRun
Links: apsb07-03, CVE-2006-5859, ESB-2007.0109,
apsb07-04, CVE-2007-0817, ESB-2007.0110,
apsb07-05, CVE-2006-5860, ESB-2007.0111
ID: ae-200702-045

A specially crafted URL could be used to create a cross-site scripting attack on ColdFusion when Global Script Protection is not enabled. A vulnerability in ColdFusion.s default error page could allow an attacker to bypass ColdFusion.s cross-site scripting protection. A specially crafted request sent to the ColdFusion server could result in the attacker being able to conduct cross site scripting attacks.
A vulnerability in JRun.s administrator console could allow a cross-site scripting attack. A specially crafted URL sent to the JRun administrator application could result in the attacker being able to conduct cross site scripting attacks.
Fixed software is available now.

System: Sun Solaris
Topic: Vulnerability in in.telnetd
Links: Sun Alert #102802, CVE-2007-0882 ESB-2007.0101, R-139, ISS Alert
ID: ae-200702-044

A security vulnerability in the in.telnetd(1M) daemon may allow a local or remote unprivileged user who is able to connect to a host using the telnet(1) service to gain unauthorized access to that host by connecting as any user on the system, allowing them to execute arbitrary commands with the privileges of that user. A patch is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in fetchmail and imagemagick
Links: DSA-1259, CVE-2006-5867, ESB-2007.0105,
DSA-1260, CVE-2007-0770, ESB-2007.0106
ID: ae-200702-043

It was discovered that fetchmail, a popular mail retrieval and forwarding utility, insufficiently enforces encryption of connections, which might lead to information disclosure.
It was discovered that the fix for a vulnerability in the PALM decoder of Imagemagick, a collection of image manipulation programs, was ineffective.
Fixed packages are available now.

System: Cisco IOS
Topic: Vulnerabilities in Cisco IOS IPS
Links: Cisco, ESB-2007.0099, R-140
ID: ae-200702-042

Two vulnerabiliies were found in the Intrusion Prevention System (IPS) feature set of Cisco IOS: Fragmented IP packets may be used to evade signature inspection. IPS signatures utilizing the regular expression feature of the ATOMIC.TCP signature engine may cause a router to crash resulting in a denial of service. Cisco has made free software available to address this vulnerability.

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer
Links: MS07-016, CVE-2006-4697, CVE-2007-0217, CVE-2007-0219, AL-2007.0022, R-138, ISS Alert
ID: ae-200702-041

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Office
Links: MS07-015, CVE-2006-3877, CVE-2007-0671, AL-2007.0021, R-131
ID: ae-200702-040

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Word
Links: MS07-014, CVE-2006-5994, CVE-2006-6456, CVE-2006-6561, CVE-2007-0208, CVE-2007-0209, CVE-2007-0515, AL-2007.0020, R-132
ID: ae-200702-039

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft RichEdit
Links: MS07-013, CVE-2006-1311, ESB-2007.0098, R-133
ID: ae-200702-038

No further comment due to legal reasons

System: Microsoft Windows, Microsoft Visual Studio
Topic: Vulnerability in Microsoft MFC
Links: MS07-012, CVE-2007-0025, ESB-2007.0097, R-134
ID: ae-200702-037

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft OLE Dialog
Links: MS07-011, CVE-2007-0026, ESB-2007.0096, R-127
ID: ae-200702-036

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Windows Live OneCare, Microsoft Antigen, Microsoft Windows Defender, and Microsoft Forefront Security
Links: MS07-010, CVE-2006-5270, AL-2007.0019, R-128, ISS Advisory
ID: ae-200702-035

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Data Access Components
Links: MS07-009, CVE-2006-5559, ESB-2007.0092, R-129
ID: ae-200702-034

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft HTML Help ActiveX Control
Links: MS07-008, CVE-2007-0214, AL-2007.0018, R-130
ID: ae-200702-033

No further comment due to legal reasons

System: Microsoft Windows XP
Topic: Vulnerability in Microsoft Windows Image Acquisition Service
Links: MS07-007, CVE-2007-0210, ESB-2007.0095, R-135
ID: ae-200702-032

No further comment due to legal reasons

System: Microsoft Windows XP, 2003
Topic: Vulnerability in Microsoft Windows Shell
Links: MS07-006, CVE-2007-0211, ESB-2007.0094, R-136
ID: ae-200702-031

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Step-by-Step Interactive Training
Links: MS07-005, CVE-2006-3448, ESB-2007.0093, R-137
ID: ae-200702-030

No further comment due to legal reasons

System: Mandriva Linux
Topic: Vulnerability in MIMEDefang
Links: Roaring Penguin, AL-2007.0016
ID: ae-200702-029

A buffer overflow was found with MIMEDefang hich could lead to a denial-of-service attack, or possibly even arbitrary code execution as the "defang" user. A fixed software version is available now.

System: Mandriva Linux
Topic: Vulnerabilities in smb4k
Links: MDKSA-2007:042, CVE-2007-0472, CVE-2007-0473, CVE-2007-0474, CVE-2007-0475
ID: ae-200702-028

Several vulnerabilities and security weaknesses were discovered in 'smb4k'. Fixed packages are available now.

System: Sun Solaris
Topic: Vulnerability in rm
Links: Sun Alert #102782, CVE-2002-0435 ESB-2007.0091
ID: ae-200702-027

A race condition vulnerability in handling recursive directory deletion via the rm(1) command with either the "-r" or "-R" option may lead to deletion of files or directories external to the argument directory hierarchy. A patch is available now.

System: Various
Topic: Vulnerability in TWiki
Links: TWiki, CVE-2007-0669, OpenPKG-SA-2007.009
ID: ae-200702-026

A vulnerability exists in the SessionPlugin extension of the Wiki engine TWiki, version up to and including 4.1.0. This vulnerability allows local users to cause TWiki to execute arbitrary Perl code with the privileges of the web server process by creating CGI session files on the local filesystem. An upgrade solves this potential problem.

System: Various
Topic: Vulnerability in ImageMagick
Links: CVE-2007-0770, MDKSA-2007:041, DSA-1260, ESB-2007.0106, RHSA-2007-0015, R-141, ESB-2007.0116
ID: ae-200702-025

A buffer overflow in GraphicsMagick and ImageMagick allows user-assisted attackers to cause a Denial-of-Service and possibly execute execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. An update solves this problem.

System: Various
Topic: Vulnerability in Sun Network Security Services (NSS)
Links: Sun Alert #102670, VU#594904
ID: ae-200702-024

The NSS libraries used in the Sun One Application Server and the Sun Java System web server contain an unspecified vulnerability that may allow an attacker to create a Denial-of-Service condition. Sun has released updates to address this issue.

System: Various
Topic: Vulnerabilities in Trend Micro AntiVirus Scan Engine
Links: iDEFENSE #469, CVE-2007-0856, TrendMicro, VU#276432, VU#666800, VU#282240, R-125, R-126, ESB-2007.0082
ID: ae-200702-023

Remote exploitation of a buffer overflow vulnerability within Trend Micro's AntiVirus engine could allow an attacker to crash the scan engine or execute arbitrary code. Additionally, a vulnerability in the Trend Micro Anti-Rootkit Common Module may allow a local attacker to gain elevated privileges. Patches are available now.

System: HP-UX, Sun Solaris
Topic: Vulnerability in HP OpenView Storage Data Protector
Links: HPSBMA02190, SSRT071300, R-124, ESB-2007.0036
ID: ae-200702-022

A security vulnerability has been identified with HP OpenView Storage Data Protector running on HP-UX and Solaris. The vulnerability could be exploited by a local user to execute arbitrary code. HP has made an updated package available.

System: Various
Topic: Vulnerability in HP Mercury Products
Links: HPSBGN02187, SSRT061280, R-123, ESB-2007.0087
ID: ae-200702-021

A security vulnerability has been identified with the Mercury LoadRunner Agent, Performance Center Agent, and Monitor over Firewall. The vulnerability could be exploited by a remote unauthenticated user to execute arbitrary code. Patches are available now.

System: Turbolinux
Topic: Vulnerabilities in fetchmail, xpdf, ImageMagick, and AdobeReader
Links: TLSA-2007-3, CVE-2005-3088, CVE-2005-4348, CVE-2006-5867, TLSA-2007-4, CVE-2007-0104, TLSA-2007-5, CVE-2006-3743, CVE-2006-3744, CVE-2006-4144, CVE-2006-5456, CVE-2006-5868, TLSA-2007-6, CVE-2006-5857, CVE-2007-0045, CVE-2007-0046, CVE-2007-0047, CVE-2007-0048
ID: ae-200702-020

Turbolinux has published patches for known vulnerabilities in fetchmail, xpdf, ImageMagick, and AdobeReader. It's recommended to install these updates.

System: IBM AIX
Topic: Vulnerability in r-commands
Links: ESB-2007.0085
ID: ae-200702-019

A buffer overflow vulnerability in various r-commands may allow a local user to gain root privileges. This vulnerability may be exploited through the rsh, rcp, rlogin and rdist commands. A patch is available now.

System: Various
Topic: Vulnerability in unrar
Links: iDefense, ESB-2007.0083
ID: ae-200702-018

Unrar is a command line archive extractor for Windows and Linux. Exploitation of a stack based buffer overflow vulnerability in RARLabs Unrar may allow an attacker to execute arbitrary code with the privileges of the user opening the archive. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in dbus
Links: RHSA-2007-0008, CVE-2006-6107, ESB-2007.0086
ID: ae-200702-017

A flaw was discovered in the way D-BUS processes certain messages. It is possible for a local unprivileged D-BUS process to disrupt the ability of another D-BUS process to receive messages. Fixed packages are available now.

System: Mandirva Linux
Topic: Problems with Kernel
Links: MDKSA-2007:040, CVE-2006-4814, CVE-2006-5749, CVE-2006-5753, CVE-2006-6053
ID: ae-200702-016

Several vulnerabilities have been found and fixed now in the kernel. It's recommended to install the update which is available now.

System: Mandriva Linux
Topic: Vulnerabilities in gd, libwmf, and php
Links: MDKSA-2007:035, MDKSA-2007:036, MDKSA-2007:038, CVE-2007-0455, CVE-2006-6383
ID: ae-200702-015

Buffer overflow in the gdImageStringFTEx function in gdft.c in the GD Graphics Library allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font. Also affected are the libwmf and php packages. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in PostgreSQL
Links: CVE-2007-0555, CVE-2007-0556, ESB-2007.0079, MDKSA-2007:037, MDKSA-2007:037-1, RHSA-2007-0064, ESB-2007.0080, DSA-1261, ESB-2007.0113, TLSA-2007-10, Sun Alert #102825, ESB-2007.0138, R-167
ID: ae-200702-014

It was discovered that the PostgreSQL server did not sufficiently check data types of SQL function arguments in some cases. A user could then exploit this to crash the database server or read out arbitrary locations of the server's memory. The query planner does not verify that a table is still compatible with a previously-generated query plan, which could be exploted to read out arbitrary locations of the server's memory by using ALTER COLUMN TYPE during query execution. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in BlueCoat WinProxy
Links: IDefense, ESB-2007.0077
ID: ae-200702-013

A vulnerability in Blue Coat Systems Inc.'s WinProxy can be triggered by sending an overly long HTTP CONNECT request to WinProxy's HTTP proxy service. Exploitation allows an attacker to cause a denial of service condition or potentially execute arbitrary code. A patch is available now.

System: Various
Topic: Vulnerabilities in Samba
Links: Samba, Samba, Samba, CVE-2007-0452, CVE-2007-0453, CVE-2007-0454, VU#649732, ESB-2007.0075, R-122, DSA-1257, ESB-2007.0076, MDKSA-2007:034, RHSA-2007-0060, ESB-2007.0117, SuSE:2007_16
ID: ae-200702-012

Several vulnerabilities were discovered in samba, a free implementation of the SMB/CIFS protocol. Incorrect handling of deferred file open calls may lead to an infinite loop, which results in denial of service. A buffer overflow in the nss_winbind.so.1 library on Solaris can allow execution of arbitrary code. It was discovered that the AFS ACL mapping VFS plugin performs insecure format string handling, which may lead to the execution of arbitrary code Fixed software is available now.

System: Sun Solaris
Topic: Vulnerability in Loopback FileSystem
Links: Sun Alert #102699, ESB-2007.0073
ID: ae-200702-011

Local privileged users inside a non-global zone may be able to move or rename files which are part of a read-only mounted loopback file system. A patch is available now.

System: Various
Topic: Vulnerability in bugzilla
Links: ESB-2007.0072
ID: ae-200702-010

Bugzilla does not properly escape some fields in generated Atom feeds, which leads to the potential for cross-site scripting in feed readers that support javascript and properly implement the Atom feed specification. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in mpg123
Links: CVE-2007-0578, MDKSA-2007:032
ID: ae-200702-009

The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a Denial-of-Service (infinite loop) by closing the HTTP connection early. An updated package has been patched to correct this issue.

System: Mandriva Linux
Topic: Vulnerability in kdelibs
Links: CVE-2007-0537, MDKSA-2007:031
ID: ae-200702-008

Konqueror 3.5.5 does not properly parse HTML comments in title tags, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment. An updated package has been patched to correct this issue.

System: Various
Topic: Vulnerabilities in wireshark
Links: wnpa-sec-2007-01, CVE-2007-0456, CVE-2007-0457, CVE-2007-0458, CVE-2007-0459, ESB-2007.0074, MDKSA-2007:033
ID: ae-200702-007

Wireshark, formerly Ethereal, contains Vulnerabilities in the LLT, IEEE 802.11, HTTP, and TCP dissectors. They were discovered in versions of wireshark less than 0.99.5, as well as various other bugs. An update provides wireshark 0.99.5 which is not vulnerable to these issues.

System: Turbolinux
Topic: Problems with Kernel
Links: TLSA-2007-2, CVE-2006-0038, CVE-2006-0039
ID: ae-200702-006

Several vulnerabilities have been found and fixed now in the kernel. It's recommended to install the update which is available now.

System: Microsoft Windows
Topic: Vulnerability in PGP Desktop
Links: VU#102465, R-119
ID: ae-200702-005

A vulnerability was discovered in PGP Desktop which can allow a remote authenticated attacker to execute arbitrary code on a system on which PGP Desktop is installed. A patch is available now.

System: Sun Solaris
Topic: Vulnerability in ICMP
Links: Sun Alert #102697, VU#967236, ESB-2007.0071
ID: ae-200702-004

A security vulnerability in the Solaris 10 ICMP handling process may allow a remote unprivileged user to panic the system, resulting in a Denial of Service (DoS) condition. A patch is available now.

System: Cisco IOS
Topic: Vulnerability in Cisco IOS Devices Not Configured for SIP
Links: Cisco, VU#438176, ESB-2007.0070, R-118
ID: ae-200702-003

Cisco devices running IOS which support voice and are not configured for Session Initiated Protocol (SIP) are vulnerable to a crash under yet to be determined conditions, but isolated to traffic destined to Port 5060. Cisco has made free software available to address this vulnerability.

System: Debian GNU/Linux
Topic: Vulnerability in libgtop2
Links: DSA-1255, CVE-2007-0235, ESB-2007.0067, R-121
ID: ae-200702-002

It was discovered that the GNOME gtop library performs insufficient sanitising when parsing the system's /proc table, which may lead to the execution of arbitrary code. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in fetchmail and squirrelmail
Links: RHSA-2007-0018, CVE-2005-4348, CVE-2006-5867, ESB-2007.0069
RHSA-2007-0022, CVE-2006-6142, ESB-2007.0068
ID: ae-200702-001

A denial of service flaw was found when Fetchmail was run in multidrop mode. A malicious mail server could send a message without headers which would cause Fetchmail to crash. An other flaw was found in the way Fetchmail used TLS encryption to connect to remote hosts. Fetchmail provided no way to enforce the use of TLS encryption and would not authenticate POP3 protocol connections properly.
Several cross-site scripting bugs were discovered in SquirrelMail. An attacker could inject arbitrary Javascript or HTML content into SquirrelMail pages by tricking a user into visiting a carefully crafted URL.
Fixed packages are available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH