Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/1.0 (+http://www.commoncrawl.org/bot.html)

Your IP address

(no reverse DNS resolution) [38.107.191.87]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 04 / 2007

System: Various
Topic: Vulnerability in Sun Java System Directory Server
Links: Sun Alert 102896 CVE-2006-3127, ESB-2007.0279
ID: ae-200704-076

A local or remote unprivileged user may be able to cause the Sun Java System Directory Server to become unresponsive or hang. This is a Denial of Service (DoS) due to a memory leak in the Network Security Services (NSS) software. A patch is not available yet.

System: SuSE Linux
Topic: Vulnerabilities in ipsec-tools, inkscape, rarpd, ImageMagick/GraphicsMagick, mod_perl, and dovecot
Links: SUSE-SR:2007:008, CVE-2007-1349, CVE-2007-1463, CVE-2007-1464, CVE-2007-1667, CVE-2007-1797, CVE-2007-1841, CVE-2007-2231
ID: ae-200704-075

The weekly SUSE Security Summary reports vulnerabilities in the packages ipsec-tools, inkscape, rarpd, ImageMagick/GraphicsMagick, mod_perl, and dovecot. Updated packages are available now and should be installed on vulnerable systems.

System: Microsoft Windows
Topic: Vulnerabilities in Symantec Norton Ghost 10
Links: iDEFENSE #519, iDEFENSE #520, SYM07-004, ESB-2007.0281
ID: ae-200704-074

Symantec Norton Ghost is a backup and recovery application designed to allow users to completely restore their systems to previous snapshots. Two vulnerabilities haven been detected.
Norton Ghost allows administrators and other power users to schedule snapshots of local disks for backup and recovery purposes. If these recovery points are set to save to a remote network share Ghost will prompt the user to enter a user name and password for the share. Password information entered into Ghost for this purpose is encrypted and saved to the local file system in the applications home directory which has read access allowed for all users. The encryption key used by Ghost to decrypt these stored credentials is derived from the MD5 hash of the plain text user name stored in the configuration file. Since every user on the system has read access to these configuration files, any user can decrypt the stored passwords.
Local exploitation of a buffer overflow vulnerability in Norton Ghost could allow local attackers to run code as the SYSTEM level user. Norton Ghost Service Manager is a Local Server COM object that allows privileged Ghost Backup Operators the ability to take and restore Ghost images of the system. A function within the Service Manager can be used to trigger a buffer overflow by supplying an overly long string.
Symantec has addressed these vulnerabilities with a software update. It is available via their LiveUpdate channels.

System: Various
Topic: Vulnerability in Novell eDirectory
Links: Novell, CVE-2006-4520, iDefense, ESB-2007.0274
ID: ae-200704-073

A vulernability exists in ncp that ships with Novell eDirectory that could allow an attacker to crash the eDirectory service resulting in a denial of service. Exploitation of this vulernability could also cause the eDirectory log to grow consuming disk space. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerabilities in CA BrightStor ARCserve Backup Media Server
Links: CVE-2007-1785, CVE-2007-2139, R-217, AL-2007.0051
ID: ae-200704-072

CA BrightStor ARCserve Backup Media Server contains multiple vulnerabilities that can allow a remote attacker to cause a denial of service or possibly execute arbitrary code. Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in php
Links: DSA-1282, DSA-1283, CVE-2007-1286, CVE-2007-1380, CVE-2007-1521, CVE-2007-1711, CVE-2007-1718, CVE-2007-1777, ESB-2007.272, ESB-2007.280
ID: ae-200704-071

Several remote vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language, which may lead to the execution of arbitrary code. Fixed packages are available now.

System: Sun Solaris
Topic: Vulnerabilities in libX11 and OpenSSL
Links: Sun Alert #102888, CVE-2007-1667, ESB-2007.0270,
Sun Alert #102747, CVE-2006-2937, CVE-2006-2940, ESB-2007.0271
ID: ae-200704-070

A buffer overflow vulnerability in libX11 may allow a local unprivileged user to be able to execute arbitrary code or commands with elevated privileges.
Two security vulnerabilities in the OpenSSL product shipped with Solaris 10 may lead to a Denial of Service (DoS) in applications which make use of this product.
Patches are available now.

System: Sun Cluster, Solaris Cluster
Topic: Vulnerability in Sun Cluster
Links: Sun Alert #102874, ESB-2007.0269
ID: ae-200704-069

A privileged user on a Sun Cluster node which is a current cluster member may be able to corrupt in-memory data structures of a sibling cluster node. A patch is available now.

System: Various
Topic: Vulnerability in Sun Java System Web Server
Links: Sun Alert 102833 CVE-2007-1488, ESB-2007.0254
ID: ae-200704-068

A security vulnerability in the Sun Java System Web Server may allow a local or remote user to gain unauthorized access to data stored on the host running the Sun Java System Web Server under certain conditions. A patch is available now.

System: Various
Topic: Vulnerability in Cisco NetFlow Collection Engine
Links: Cisco VU#127545, ESB-2007.0254, R-218
ID: ae-200704-067

Versions of Cisco Network Services (CNS) NetFlow Collection Engine (NFC) create and use default accounts with identical usernames and passwords. An attacker with knowledge of these accounts can modify the application configuration and, in certain instances, gain user access to the host operating system. A workaround is described in the advisory.

System: Red Hat Enterprise Linux
Topic: Vulnerability in IBM Java
Links: RHSA-2007-0167, CVE-2007-0243, ESB-2007.0267
ID: ae-200704-066

A flaw in GIF image handling was found in the IBM Java 2 Runtime Environment. An untrusted applet or application could use this flaw to elevate its privileges and potentially execute arbitrary code. Fixed packages are available now.

System: Various
Topic: Vulnerability in PostgreSQL
Links: PostgreSQL, CVE-2007-2138, ESB-2007.0277, MDKSA-2007:094, Sun Alert 102894, ESB-2007.0278, R-219, RHSA-2007-0336, RHSA-2007-0337, ESB-2007.0296
ID: ae-200704-065

A weakness in PostgreSQL was found in the security definer functions in which an authenticated but otherwise unprivileged SQL user could use temporary objects to execute arbitrary code with the privileges of the security-definer function. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in aircrack-ng
Links: DSA-1280, CVE-2007-2057, VU#349828, ESB-2007.0265
ID: ae-200704-064

It was discovered that aircrack-ng, a WEP/WPA security analysis tool, performs insufficient validation of 802.11 authentication packets, which allows the execution of arbitrary code. Fixed packages are available now.

System: HP-UX
Topic: Vulnerability in sendmail
Links: HPSBUX02183, SSRT061243, ESB-2007.0260, VU#349305
ID: ae-200704-063

A security vulnerability has been identified with HP-UX running sendmail. This vulnerability could allow a remote user to cause a Denial of Service (DoS). Patches are available now.

System: Various
Topic: Vulnerability in IPv6
Links: ESB-2007.261, FreeBSD-SA-07:03, ESB-2007.276
ID: ae-200704-062

IPv6 type 0 route headers can be used to mount a DoS attack against hosts and networks. This is a design flaw in IPv6. Patches that disable the handling of type 0 rote header are available now.

System: Mandriva Linux
Topic: Vulnerabilities in freeradius and zziplib
Links: MDKSA-2007:092, CVE-2005-4745, CVE-2005-4746, MDKSA-2007:093, CVE-2007-1614
ID: ae-200704-061

Multiple buffer overflows were found in the FreeRADIUS package that could allow a remote attacker to cause a crash. As well, an SQL injection vulnerability was also found in the rlm_sqlcounter that could allow a remote attacker to execute arbitrary SQL commands.
A stack-based buffer overflow in the ZZIPlib library could allow user-assisted remote attackers to cause an application crash (DoS) or execute arbitrary code via a long filename.
Fixed packages are available now.

System: Nortel VPN Router
Topic: Vulnerabilities in Nortel VPN Router
Links: AL-2007.0050
ID: ae-200704-060

Three potential security vulnerabilities have been discovered in Nortel VPN Routers. Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerability in webcalendar
Links: DSA-1279, CVE-2006-6669, ESB-2007.259
ID: ae-200704-059

It was discovered that WebCalendar, a PHP-based calendar application, performs insufficient sanitising in the exports handler, which allows injection of web script. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Check Point Zone Alarm
Links: iDEFENSE #517
ID: ae-200704-058

Zone Alarm products provide security solutions such as anti-virus, firewall, spy-ware, and ad-ware protection. Local exploitation of multiple design error vulnerabilities within multiple Check Point Zone Alarm products could allow an attacker to gain elevated privileges. The Zone Labs Security Team reports that these issues are fixed in versions 5.0.156.0 of the ZoneAlarm Spyware Removal Engine (SRE) and higher.

System: SuSE Linux
Topic: Vulnerabilities in ktorrent, cron, lighttpd, horde, MPlayer, avahi, and man
Links: SUSE-SR:2007:007, CVE-2005-1038, CVE-2006-4250, CVE-2006-6870, CVE-2007-1246, CVE-2007-1384, CVE-2007-1385, CVE-2007-1473, CVE-2007-1799, CVE-2007-1856, CVE-2007-1869, CVE-2007-1870
ID: ae-200704-057

The weekly SUSE Security Summary reports vulnerabilities in the packages ktorrent, cron, lighttpd, horde, MPlayer, avahi, and man. Updated packages are available now and should be installed on vulnerable systems.

System: Sun Solaris
Topic: Vulnerability in Mozilla 1.7
Links: Sun Alert #102885, CVE-2006-6497, ESB-2007.0257, R-215
ID: ae-200704-056

Multiple security vulnerabilities in the Layout Engine in Mozilla 1.7 may allow a remote user who is able to create pages that are viewed with the Mozilla browser to crash the application or execute arbitrary code with the privileges of the user running Mozilla. A patch is available now.

System: Mac OS X
Topic: Apple Security Update 2007-004
Links: APPLE-SA-2007-04-19, Apple, VU#312424, AL-2007.0049, VU#969969, VU#474969, R-216, ESB-2007.0288
ID: ae-200704-055

Several security issues in Apple File Protocol (AFP) client, AirPort driver, CarbonCore, diskdev_cmds, fetchmail, ftpd, tar, Help Viewer, IOKit HID interface, Installer, Kerberos, Libinfo, Login Window, network_cmds, SMB, System Configuration, URLMount, VideoConference, WebDAV, and WebFoundation are fixed and bundled in the Security Update 2007-004, which is available now.

System: SuSE Linux
Topic: Vulnerabilities in qt, kdelibs3, mediawiki, freetype2, xmms, and spamassassin
Links: SUSE-SR:2007:006, CVE-2006-7139, CVE-2007-0177, CVE-2007-0242, CVE-2007-0451, CVE-2007-0537, CVE-2007-0653, CVE-2007-0654, CVE-2007-1351, CVE-2007-1564
ID: ae-200704-054

The weekly SUSE Security Summary reports vulnerabilities in the packages qt, kdelibs3, mediawiki, freetype2, xmms, and spamassassin. Updated packages are available now and should be installed on vulnerable systems.

System: Microsoft Windows
Topic: Vulnerability in HP Storage Management Appliance (SMA)
Links: HPSBST02206, SSRT071354, ESB-2007.0255, HPSBST02208, SSRT071365, ESB-2007.0258
ID: ae-200704-053

The latest patches for Microsoft are needed to be installed when using the SMA. It's strongly recommended to install these hotfixes from Microsoft.

System: Various
Topic: Vulnerability in IBM Tivoli Monitoring Express
Links: ESB-2007.0254
ID: ae-200704-052

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Tivoli Monitoring Express. Authentication is not required to exploit this vulnerability. Fixed software is available now.

System: Various
Topic: Vulnerability in Novell Groupwise WebAccess
Links: ESB-2007.0253
ID: ae-200704-051

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell Groupwise WebAccess. Authentication is not required to exploit this vulnerability. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in McAfee VirusScan
Links: McAfee, iDefense, VU#324929, ESB-2007.0252
ID: ae-200704-050

Remote exploitation of a buffer overflow vulnerability in McAfee's VirusScan Antivirus application allows attackers to disable the On-Access scanner or potentially execute arbitrary code with SYSTEM privileges. Fixed software version is available now.

System: Various
Topic: Vulnerabilities in Oracle products
Links: Oracle, R-213, VU#809457, HPSBMA02133, SSRT061201, ESB-2007.0256
ID: ae-200704-049

A Critical Patch Update is a collection of patches for multiple security vulnerabilities. It also includes non-security fixes that are required (because of interdependencies) by those security patches. This Critical Patch Update contains 36 new security fixes across all products. Affected are Oracle Database, Oracle Secure Enterprise Search, Oracle Application Server, Oracle E-Business Suite, Oracle Enterprise Manager, Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne.

System: Mandriva Linux
Topic: Vulnerabilities in php and sqlite
Links: MDKSA-2007:087, MDKSA-2007:088, MDKSA-2007:089, MDKSA-2007:090, CVE-2007-1001, CVE-2007-1285, CVE-2007-1286, CVE-2007-1454, CVE-2007-1583, CVE-2007-1711, CVE-2007-1718, CVE-2007-1887,
MDKSA-2007:091, CVE-2007-1888
ID: ae-200704-048

Several security vulenrabilities were found in the PHP packages.
A buffer overflow in sqlite could allow context-dependent attackers to execute arbitrary code via an empty value of the 'in' parameter.
Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Akamai Download Manager ActiveX control
Links: iDefense, VU#120241, ESB-2007.0249
ID: ae-200704-047

Remote exploitation of a buffer overflow vulnerability in Akamai Technologies, Inc's Download Manager ActiveX Control could allow an attacker to execute arbitrary code within the security context of the targeted user. Fixed software version is available now.

System: Various
Topic: Vulnerability in ClamAV
Links: iDefense, CVE-2007-1997, ESB-2007.0248, SUSE-SA:2007:026, DSA-1281, ESB-2007.0266, ESB-2007.0340, R-220, MDKSA-2007:098
ID: ae-200704-046

Remote exploitation of a buffer overflow vulnerability in Clam AntiVirus' ClamAV allows attackers to execute arbitrary code with the privileges of the affected process. The vulnerability exists within the cab_unstore() function in libclamav, the library used by clamd to scan various file types. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerabilities in ipsec-tools and freeradius
Links: MDKSA-2007:084, CVE-2007-1841, MDKSA-2007:085, CVE-2007-2028
ID: ae-200704-045

The ipsec-tools package allows remote attackers to cause a Denial of Service (tunnel crash) via crafted DELTE and NOTIFY messages.
Memory leak in freeRADIUS allows remote attackers to cause a denial of service (memory consumption) via a large number of EAP-TTLS tunnel connections using malformed Diameter format attributes, which causes the authentication request to be rejected but does not reclaim VALUE_PAIR data structures.
Fixed packages are available now.

System: Various
Topic: Vulnerability in CUPS
Links: CVE-2007-0720, RHSA-2007-0123, ESB-2007.0245, MDKSA-2007:086
ID: ae-200704-044

A flaw was discovered in how CUPS handled SSL negotiation that could allow a remote attacker capable of connecting to the CUPS daemon to cause a DoS to other CUPS users. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in php
Links: RHSA-2007-0153, RHSA-2007-0155, CVE-2007-0455, CVE-2007-1001, CVE-2007-1285, CVE-2007-1286, CVE-2007-1583, CVE-2007-1711, CVE-2007-1718, ESB-2007.0247, R-214
ID: ae-200704-043

Several security vulenrabilities were found in the PHP packages. Fixed packages are available now.

System: Sun Solaris 8, 9
Topic: Vulnerability in IP
Links: Sun Alert #102866, ESB-2007.0244
ID: ae-200704-042

A security vulnerability in the Solaris 8 and 9 IP implementation may allow a remote unprivileged user to degrade the performance of a networked Solaris system by sending specially crafted IP packets. This could result in a mild Denial of Service (DoS) against network services provided by the system and/or local services, due to increased CPU usage. A patch is available now.

System: Microsoft Windows 2000 Server, Server 2003
Topic: Vulnerability in Windows DNS Server
Links: Microsoft, VU#555920, AL-2007.0047, R-212, ISS Alert #260
ID: ae-200704-041

An unpatched vulnerability in the DNS Server component of Windows Server 2003 and Windows 2000 Server potentially allows remote compromise of Windows DNS Servers. Workarounds are described in the advisory.

System: HP-UX
Topic: Vulnerability in pfs_mountd.rpc
Links: HPSBUX02203, iDefense #512, ESB-2007.0242
ID: ae-200704-040

Remote exploitation of a buffer overflow vulnerability in pfs_mountd.rpc included in multiple versions of Hewlett Packard Co. HP-UX allows for remote root access. A software update is not available.

System: Cisco Wireless Control System
Topic: Vulnerabilities in Cisco Wireless Control System
Links: Cisco, AL-2007.0045, R-207
ID: ae-200704-039

The Cisco Wireless Control System (WCS) works in conjunction with Cisco Aironet Lightweight Access Points, Cisco Wireless LAN Controllers, and the Cisco Wireless Location Appliance. Cisco WCS contains multiple vulnerabilities that can result in information disclosure, priviege escalation, and unathorized access through fixed authentication credentials. Cisco has made free software available to address this vulnerability.

System: Cisco Wireless LAN Controller, Cisco Lightweight Access Point
Topic: Vulnerabilities in Cisco Wireless LAN Controller and Cisco Lightweight Access Point
Links: Cisco, AL-2007.0046, R-206
ID: ae-200704-038

The Cisco Wireless LAN Controller (WLC) manages Cisco Aironet access points using the Lightweight Access Point Protocol (LWAPP). The WLC contains multiple vulnerabilities that could result in a denial of service (DoS) condition, information disclosure, or access control list changes, or allow an attacker to gain full administrative access. Cisco has made free software available to address this vulnerability.

System: Mandriva Linux
Topic: Vulnerabilities in madwifi and apache-mod_perl
Links: MDKSA-2007:082, CVE-2005-4835, CVE-2006-7177, CVE-2006-7178, CVE-2006-7179, CVE-2006-7180, MDKSA-2007:083, CVE-2007-1349
ID: ae-200704-037

Several vulnerabilities were found in madwifi-source and wpa_supplicant.
Apache mod_perl does not properly escape PATH_INFO before use in a regular expression, which allows remote attackers to cause a denial of service (resource consumption) via a crafted URI.
Fixed packages are available now.

System: Various
Topic: Vulnerability in StarOffice 8 Office Suite
Links: Sun Alert #102863, CVE-2007-0002, iDEFENSE #490 ESB-2007.0241
ID: ae-200704-036

Due to a security vulnerability in StarOffice/StarSuite 8, manipulated WordPerfect files, which may have been provided by a local or remote untrusted user, may lead to heap overflow and arbitrary code execution. A patch for Star Office 8 is available now, versions 6.0 and 7 are not impated by this issue.

System: Linux/Unix
Topic: Vulnerability in Adobe Flash Player and Opera
Links: apsb07-03
ID: ae-200704-035

Recently an Opera security advisory has been published, reporting an issue with Flash Player and the Opera browser on the Linux and Solaris platforms. Flash Player 9 users of Opera on Linux and Solaris should update to Opera 9.2 to address this vulnerability. Flash Player 7 users of Opera should update to Opera 9.2 and Flash Player 9 to address this vulnerability. Further information will follow.

System: Various
Topic: Vulnerabilities in Apache HTTPD suEXEC
Links: iDEFENSE #511, CVE-2007-1741, ESB-2007.0240
ID: ae-200704-034

The suexec binary is a helper application which is part of the Apache HTTP server package. It is designed to allow a script to run with the privileges of the owner of the script instead the privileges of the server. Some vulnerabilities have been found in this application. There are three path checking race condition vulnerabilities, a path checking design error and an error in input validation. If exploited, a local user might execute arbitrary code with the rights of another user. It's recommended to remove the set-uid bit from the binary file.

System: Macintosh
Topic: Vulnerability in Adobe Bridge
Links: apsb07-09, CVE-2007-1279
ID: ae-200704-033

There is a problem with the previous installer for Bridge update 1.0.3. A potential vulnerability occurs when the administrator attempts to install the patch. While the patch is being installed a local non-administrative user may be able to gain administrative privileges. It's recommended to update to version 1.0.4.

System: Linux/Unix
Topic: Vulnerability in Adobe Macromedia ColdFusion MX7
Links: apsb07-08, iDEFENSE #510, CVE-2007-1874, ESB-2007.0239
ID: ae-200704-032

Local exploitation of an insecure file and directory permissions vulnerability in Macromedia ColdFusion MX 7 may allow an attacker to execute code with root privileges. A patch was recently released to fix the vulnerabilities referenced in the Adobe Security Advisory APSB06-17. This patch was intended to correct insecure file permissions of multiple files within the Verity sub-directory of ColdFusion. Unfortunately, the patch archive creates an additional vulnerability. The vulnerability exists due to the directory permissions inside the directory structure of the patch. A corrected update is available now.

System: Microsoft Windows
Topic: Vulnerability in Windows Kernel
Links: MS07-022, CVE-2007-1206, VU#337953, ESB-2007.0236, R-203
ID: ae-200704-031

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in CSRSS
Links: MS07-021, CVE-2006-6696, CVE-2007-1209, CVE-2006-6797, VU#740636, VU#219848, AL-2007.0044, R-201
ID: ae-200704-030

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Agent
Links: MS07-020, CVE-2007-1205, VU#728057, AL-2007.0043, R-200
ID: ae-200704-029

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Universal Plug and Play
Links: MS07-019, CVE-2007-1204, ESB-2007.0235, iDEFENSE #509, ISS Alert #259, R-199
ID: ae-200704-028

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Content Management Server
Links: MS07-018, CVE-2007-0938, CVE-2007-0939, ESB-2007.00237, R-198
ID: ae-200704-027

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows GDI
Links: MS07-017, CVE-2006-5758, CVE-2007-1211, CVE-2007-1212, CVE-2007-1213, CVE-2007-1215, CVE-2006-5586, CVE-2007-0038
ID: ae-200704-026

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in AOL Instant Messenger and ICQ
Links: iDEFENSE #508, ESB-2007.0238
ID: ae-200704-025

AIM and ICQ are instant messaging applications that allow users to exchange messages and files. AIM and ICQ allow users to share and transfer files via a custom protocol. During file transfers, the sender is allowed to specify the display name of the file, and the filename used for the transfer. The recipient can only specify the folder in which to save the file. Due to an input validation flaw, the clients do not properly strip traversal characters from the filename the attacker supplies. By specially encoding the path attackers can force the file to be saved to a directory of their choosing when the victim accepts the file transfer. It's strongly recommended to update the software.

System: HP-UX
Topic: Vulnerability in CIFS-Server
Links: HPSBUX02204, SSRT071341, CVE-2007-0452, ESB-2007.0233
ID: ae-200704-024

A potential security vulnerability has been identified with HP-UX running CIFS Server (Samba). It may allow a remote unauthorized user to create a Denial-of-Service (DoS). HP has made software updates available to resolve the vulnerability.

System: Several
Topic: Vulnerability in Symantec Enterprise Security Manager
Links: SYM07-003, AL-2007.0041, R-202
ID: ae-200704-023

The Symantec Enterprise Security Manager Agent Software (6.5.2 and prior) accepts remote upgrade requests from any entity without correctly authenticating these. A remote attacker may gain root or Administrator privileges on computers running the agent. Symantec has released downloadable automated and manual fixes for all supported ESM agents.

System: Microsoft Windows
Topic: Vulnerability in Internet Pictures Corporation iPIX Image Well ActiveX Control
Links: VU#958609, CVE-2007-1687, R-208
ID: ae-200704-022

Internet Pictures Corporation has produced equipment and software to create 360 degree field-of-view images. The Internet Pictures Corporation iPIX Image Well ActiveX control, provided by iPIX-ImageWell-ipix.dll, contains several buffer overflow vulnerabilities. By convincing a user to view a specially crafted HTML document, an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause Internet Explorer to crash. A patch is not available, so the vulnerable ActiveX control should be disabled in Internet Explorer.

System: Microsoft Windows
Topic: Vulnerability in Yahoo! Messenger
Links: Yahoo, CVE-2007-1680, VU#388377, ESB-2007.0234, R-204
ID: ae-200704-021

The Yahoo! Messenger AudioConf ActiveX control contains a buffer overflow, which could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. It's recommended to install an update which is available now.

System: Apple Appliance
Topic: Vulnerabilities in AirPort Extreme Base Station
Links: Apple-SA-2007-04-09, CVE-2007-1338, CVE-2007-0734, ESB-2007.231
ID: ae-200704-020

Firmware version 7.1 is now available for the AirPort Extreme Base Station with 802.11n*, and addresses the following security issues:
The default configuration of an AirPort Extreme Base Station with 802.11n* allows incoming IPv6 connections. This may expose network services on hosts connected through an AirPort Extreme Base Station with 802.11n* to remote attackers. This update addresses the issue by changing the default setting to limit inbound IPv6 traffic to the local network.
AirPort Disk is a feature of AirPort Extreme Base Station with 802.11n* that allows the sharing of files from a USB hard drive connected to a compatible base station. Sharing options, including password protection, are available via the AirPort Disk Utility. An issue in the AirPort Disk feature allows users on the local network to view filenames (but not their contents) on a password-protected disk without providing a password. This update addresses the issue by performing additional validation on AirPort Disk access requests.

System: Debian GNU/Linux
Topic: Vulnerability in man-db
Links: DSA-1278, CVE-2006-4250, ESB-2007.232, R-210
ID: ae-200704-019

A buffer overflow has been dicovered in the man command that could allow an attacker to execute code as the man user by providing specially crafted arguments to the -H flag. This is likely to be an issue only on machines with the man and mandb programs installed setuid. An updated package solves this problem.

System: SGI Advanced Linux Environment
Topic: Vulnerability in krb5
Links: SGI_20070401-01
ID: ae-200704-018

SGI has released the Security Update #73 for SGI Advanced Linux Environment 3. These updates fix an already known security related problem in krb5.
So it's recommended to install this update.

System: Microsoft Windows
Topic: Problem with WLAN for Intel Centrino
Links: INTEL-SA-00001, VU#524332, R-197
ID: ae-200704-017

Microsoft Windows drivers for Intel Centrino wireless adapters fail to properly handle malformed frames. This vulnerability may allow an attacker to execute arbitrary code. Intel has released updates to address this issue.

System: Microsoft Windows
Topic: Vulnerability in AOL SuperBuddy ActiveX
Links: VU#478225
ID: ae-200704-016

The AOL SuperBuddy ActiveX control does not properly validate arguments to the LinkSBIcons() method. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. A patch is available now.

System: Various
Topic: Vulnerabilities in Asterisk
Links: CVE-2007-1561, CVE-2007-1594, ESB-2007.0230
ID: ae-200704-015

Asterisk is vulnerable to two Denial of Service issues in the SIP channel. Fixed software is available now.

System: VMWare ESX Server
Topic: Vulnerabilities in VMWare ESX Server
Links: VMSA-2007-0003, CVE-2003-0107, CVE-2005-1704, CVE-2005-1849, CVE-2005-2096, CVE-2005-3011, CVE-2006-4810, CVE-2007-1270, CVE-2007-1271, ESB-2007.0229
ID: ae-200704-014

Several vulnereabilities were found in VMware ESX Server. Patches are available now.

System: IBM AIX
Topic: Vulnerabilities in OpenSSH
Links: CVE-2006-4924, CVE-2006-5051, ESB-2007.0226
ID: ae-200704-013

Two vulnerabilities were found in OpenSSH. A remote attacker may cause a denial of service or execute arbitrary code. A patch is available now.

System: Various
Topic: Vulnerability in HP OpenView Network Node Manager
Links: HPSBMA02198, SSRT061177, ESB-2007.0210
ID: ae-200704-012

A vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). This vulnerability could be exploited remotely to gain unauthorized access to certain facilities of the NNM server. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in zope2.7 and xmms
Links: DSA-1275, CVE-2007-0240, ESB-2007.0211
DSA-1277, CVE-2007-0653, CVE-2007-0654, ESB-2007.0227, R-211
ID: ae-200704-011

A cross-site scripting vulnerability in zope, a web application server, could allow an attacker to inject arbitrary HTML and/or JavaScript into the victim's web browser.
Multiple errors have been found in the skin handling routines in xmms, the X Multimedia System. These vulnerabilities could allow an attacker to run arbitrary code as the user running xmms by inducing the victim to load specially crafted interface skin files.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in kernel
Links: MDKSA-2007:078, CVE-2006-6056, CVE-2007-0005, CVE-2007-0772, CVE-2007-0958, CVE-2007-1000, CVE-2007-1217, CVE-2007-1388, CVE-2007-1592, ESB-2007.0228
ID: ae-200704-010

Several vulnerabilities were discovered in the Linux 2.6 kernel. Fixed kernel packages are available now.

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows GDI
Links: ae-200703-054, MS07-017, CVE-2006-5586, CVE-2006-5758, CVE-2007-0038, CVE-2007-1211, CVE-2007-1212, CVE-2007-1213, CVE-2007-1215, ESB-2007.0215, R-192
ID: ae-200704-009

No further comment due to legal reasons

System: Mandriva Linux
Topic: Vulnerability in qt3, qt4, and kdelibs
Links: MDKSA-2007:074, MDKSA-2007:075, MDKSA-2007:076, CVE-2007-0242
ID: ae-200704-008

A bug was discovered in the UTF8 decoding of qt3, qt4, and kdelibs. Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in xine-lib, tomcat, unrar, squid, and file
Links: SUSE-SR:2007:005, CVE-2007-0450, CVE-2007-0855, CVE-2007-1246, CVE-2007-1536, CVE-2007-1560
ID: ae-200704-007

The weekly SUSE Security Summary reports vulnerabilities in the packages xine-lib, tomcat, unrar, squid, and file. Updated packages are available now and should be installed on vulnerable systems.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in squid and mysql
Links: RHSA-2007-0131, CVE-2007-1560, ESB-2007.0221,
RHSA-2007-0152, CVE-2006-4226, ESB-2007.0222
ID: ae-200704-006

A denial of service flaw was found in the way Squid processed the TRACE request method. It was possible for an attacker behind the Squid proxy to issue a malformed TRACE request, crashing the Squid daemon child process.
A flaw was found in the way MySQL handled case sensitive database names. A user with the ability to create databases could gain unauthorized access to other databases hosted by the MySQL server.
Fixed packages are available now.

System: Various
Topic: Vulnerabilities in X Server
Links: CVE-2007-1003, CVE-2007-1351, CVE-2007-1352, iDefense, iDefense, iDefense, AL-2007.0040, RHSA-2007-0125, RHSA-2007-0126, RHSA-2007-0127, RHSA-2007-0132, RHSA-2007-0150, RHSA-2007-0157, R-194, R-195, R-196, ESB-2007.0219, ESB-2007.0220, ESB-2007.0246, MDKSA-2007:079, MDKSA-2007:080, MDKSA-2007:081, OpenBSD, ESB-2007.0225, SUSE-SA:2007:027, Sun Alert 102886, ESB-2007.0275
ID: ae-200704-005

Several vulnerabilities were found in the X.org and XFree86 X Window servers. An attacker can potentially execute arbitrary code with the privileges of the X server. Fixed software is available now.

System: Various
Topic: Vulnerabilities in MIT Kerberos
Links: MITKRB5-SA-2007-001, MITKRB5-SA-2007-002, MITKRB5-SA-2007-003, CVE-2007-0956, CVE-2007-0957, CVE-2007-1216, VU#220816, VU#419344, VU#704024, iDefense, AL-2007.0040, RHSA-2007-0095, ESB-2007.0216, R-193, DSA-1276, ESB-2007.0217, MDKSA-2007:077, ESB-2007.0223, ESB-2007.0224, TLSA-2007-24, TLSA-2007-25, SUSE-SA:2007:025
ID: ae-200704-004

Several vulnerabilities were found in the MIT Kerberos implementation. A flaw was found in the username handling of the MIT krb5 telnet daemon (telnetd). A remote attacker who can access the telnet port of a target machine could log in as root without requiring a password. Buffer overflows were found which affect the Kerberos KDC and the kadmin server daemon. A double-free flaw was found in the GSSAPI library used by the kadmin server daemon. Fixed software is available now.

System: VMWare ESX Server
Topic: Vulnerabilities in VMWare ESX Server
Links: VMSA-2007-0002, CVE-2006-3739, CVE-2006-3740, CVE-2006-4334, CVE-2006-4335, CVE-2006-4336, CVE-2006-4337, CVE-2006-4338, CVE-2006-6097, ESB-2007.0208
ID: ae-200704-003

Several vulnereabilities were found in VMware ESX Server. Patches are available now.

System: Various
Topic: Vulnerabilities in Sun Java Enterprise System
Links: Sun Alert 102856, CVE-2007-0008, CVE-2007-0009, ESB-2007.0207
ID: ae-200704-002

Security vulnerabilities in the Network Security Services (NSS) implementation of SSL2 may affect both SSL clients (such as browsers) and SSL servers which make use of this library. As a result, the client or server may exit unexpectedly. Fixed software is available now.

System: Sun Solaris
Topic: Vulnerability in Mozilla
Links: Sun Alert #102865, CVE-2006-3805 ESB-2007.0206
ID: ae-200704-001

A security vulnerability Mozilla 1.7 for Solaris 8, 9 and 10 may allow a remote unprivileged user to run arbitrary code with the privileges of the user running Mozilla or create a Denial of Service (DoS) condition. A patch is available now.



(c) 2000-2010 AERAsec Network Services and Security GmbH