Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/1.0 (+http://www.commoncrawl.org/bot.html)

Your IP address

(no reverse DNS resolution) [38.107.191.89]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 06 / 2007

System: Microsoft Windows
Topic: Vulnerability in Sun Java Web Start
Links: Sun Alert #102957, ESB-2007.0489
ID: ae-200706-096

A vulnerability in Java Web Start may allow an untrusted application to grant itself permissions to overwrite any file that is writable by the user running the application. This would include the user's .java.policy file which would allow the application to invoke applets or Java Web Start applications that can execute arbitrary code with the permissions of the user running the untrusted application. It's recommended to install an updated version, which is available now.

System: HP Tru64
Topic: Vulnerabilities in Secure Web Server
Links: HPSBTU02232, SSRT071429, ESB-2007.0484
ID: ae-200706-095

Several vulnerabilities have been reported on the PHP Hypertext Processing Engine provided with the Secure Web Server for HP Tru64 UNIX Powered by Apache (SWS) and HP Internet Express for Tru64 UNIX (IX). The vulnerabilities could be exploited by remote users to execute arbitrary code, read arbitrary files, or cause a Denial of Service (DoS). A patch is available now.

System: Sun Solaris
Topic: Vulnerabilities in TCP, kernel, and dtsession
Links: Sun Alert #102963, ESB-2007.0479,
Sun Alert #102918, ESB-2007.0481,
Sun Alert #102954, ESB-2007.0482, R-289
ID: ae-200706-094

An unprivileged local user may be able to exhaust all available kernel memory and cause the system to hang due to a security vulnerability in the TCP Loopback/Fusion implementation in Solaris 10.
Due to security vulnerabilities related to the handling of memory buffers containing Secure Socket Layer (SSL) records, an unprivileged local or remote user may be able to panic a Solaris 10 system that has been configured to act as a SSL proxy.
An unprivileged local user may be able to execute arbitrary code or commands with the privileges of the dtsession(1X) Common Desktop Environment (CDE) Session Manager. The dtsession(1X) CDE Session Manager runs with root privileges.
Patches are available now.

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in shadow-utils, openoffice.org, openldap, mod_perl, pam, freetype, kdebase, krb5, evolution, gcc, fetchmail, gdb, and binutils
Links: SGI_20070602-01
ID: ae-200706-093

SGI has released the Security Update #77 for SGI Advanced Linux Environment 3. These updates fix an already known security related problems in shadow-utils, openoffice.org, openldap, mod_perl, pam, freetype, kdebase, krb5, evolution, gcc, fetchmail, gdb, and binutils.
So it's recommended to install this update.

System: Debian GNU/Linux
Topic: Vulnerability in hiki
Links: DSA-1324, CVE-2007-2836, ESB-2007.0486
ID: ae-200706-092

A vulnerability was found in hiki, a Wiki engine written in Ruby, which could allow a remote attacker to delete arbitary files which are writable to the Hiki user, via a specially crafted session parameter. Fixed packages are available now.

System: Sun Solaris
Topic: Vulnerabilities in openssl, libsldap, and Mozilla
Links: Sun Alert #102711, CVE-2006-3738, CVE-2006-4343, ESB-2007.0473,
Sun Alert #102926, ESB-2007.0474,
Sun Alert #102971, CVE-2006-3811, ESB-2007.0477
ID: ae-200706-091

Two security vulnerabilities in the OpenSSL product shipped with Solaris 10 may allow Denial of Service (DoS) attacks or execution of arbitrary code.
A security vulnerability in the Solaris libsldap library may allow a local unprivileged user to disable the Name Service Caching Daemon (see nscd(1M)) causing name service lookups to be slower.
A number of memory corruption vulnerabilities have been found in the Mozilla application.
Patches are available now.

System: Debian/GNU Linux
Topic: Vulnerabilities in the wireshark
Links: DSA-1322, CVE-2007-3390, CVE-2007-3392, CVE-2007-3393, ESB-2007.0478
ID: ae-200706-090

Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to denial of service. Fixed packages are available now.

System: Red Hat Enterprise Linux 5
Topic: Vulnerability in cman
Links: RHSA-2007-0559, CVE-2007-3374, R-290, ESB-2007.0483
ID: ae-200706-089

A flaw was found in the cman daemon. A local attacker could connect to the cman daemon and trigger a static buffer overflow leading to a denial of service or, potentially, an escalation of privileges. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Xythos Enterprise Document Manager
Links: SYMSA-2007-004, CVE-2007-3254, CVE-2007-3254, CVE-2007-3254, ESB-2007.0470
ID: ae-200706-088

Several vulnerabilities were found in Xythos Enterprise Document Manager (XEDM) and Xythos Digital Locker (XDL). Fixed software is available now.

System: Various
Topic: Vulnerability in RealNetworks RealPlayer/HelixPlayer
Links: iDefense, CVE-2007-3410, VU#770904, ESB-2007.0469, R-288, RHSA-2007-0605, ESB-2007.0476
ID: ae-200706-087

Remote exploitation of a buffer overflow within RealNetworks' RealPlayer and HelixPlayer allows attackers to execute arbitrary code in the context of the user. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in httpd
Links: RHSA-2007-0533, RHSA-2007-0534, RHSA-2007-0556, CVE-2006-5752, CVE-2007-1863, CVE-2007-3304, ESB-2007.0468
ID: ae-200706-086

Several vulnerabilities were found in the Apache HTTP Server.
A flaw was found in the Apache HTTP Server mod_status module. On sites where the server-status page is publicly accessible and ExtendedStatus is enabled this could lead to a cross-site scripting attack.
A bug was found in the Apache HTTP Server mod_cache module. On sites where caching is enabled, a remote attacker could send a carefully crafted request that would cause the Apache child process handling that request to crash.
A local attacker with the ability to run scripts on the Apache HTTP Server could manipulate the scoreboard and cause arbitrary processes to be terminated which could lead to a denial of service.
Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Kerberos
Links: MITKRB5-SA-2007-004, MITKRB5-SA-2007-005, iDefense, CVE-2007-2442, CVE-2007-2443, CVE-2007-2798, VU#356961, VU#365313, VU#554257, AL-2007.0078, RHSA-2007-0384, RHSA-2007-0562, ESB-2007.0466, R-287, MDKSA-2007:137, Sun Alert #102914, ESB-2007.0475, DSA-1323, ESB-2007.0485, Sun Alert #102985, ESB-2007.0480, SUSE-SA:2007:038
ID: ae-200706-085

Serveral vulnerabilities were found in the 'kadmind' of the MIT Kerberos 5 implementation. A remote unauthenticated attacker who could access kadmind could cause kadmind to crash or possibly execute arbitrary code. Fixed software is available now.

System: HP-UX
Topic: Vulnerabilities in Xserver
Links: HPSBUX02225, SSRT071295, CVE-2006-6101, CVE-2006-6102, CVE-2006-6103, ESB-2007.0464
ID: ae-200706-084

Security vulnerabilities have been identified with HP-UX running Xserver. These vulnerabilities could be exploited by a local user to create a Denial of Service (DoS). A patch is available now.

System: Red Hat Enterprise Linux 4
Topic: Several vulnerabilities in kernel fixed
Links: RHSA-2007-0488, CVE-2006-5158, CVE-2006-7203, CVE-2007-0773, CVE-2007-0958, CVE-2007-1353, CVE-2007-2172, CVE-2007-2525, CVE-2007-2876, CVE-2007-3104, ESB-2007.0467
ID: ae-200706-083

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 4 kernel are now available.

System: Unix / Linux
Topic: Vulnerability in Evolution Data Server
Links: CVE-2007-3257, DSA-1321, ESB-2007.0461, ESB-2007.0488, R-291, RHSA-2007-0509, RHSA-2007-0510, ESB-2007.0465, MDKSA-2007:136, SUSE-SA:2007:042
ID: ae-200706-082

It has been discovered that the IMAP code in the Evolution Data Server performs insufficient sanitising of a value later used an array index, which can lead to the execution of arbitrary code. An updated package solves this problem.

System: Some
Topic: Vulnerabilities in CA products with embedded Ingres data base
Links: CA, CVE-2007-3334, CVE-2007-3336, CVE-2007-3337, CVE-2007-3338, ESB-2007.0463
ID: ae-200706-081

Various CA products that embed Ingres products contain multiple vulnerabilities that can allow an attacker to potentially execute arbitrary code. CA has issued fixes, to address all of these vulnerabilities, for all supported CA products that may be affected.

System: Various
Topic: Vulnerability in F-Secure Anti-Virus products
Links: FSC-2007-05, CVE-2007-3300, ESB-2007.0462
ID: ae-200706-080

In Anti-Virus product from F-Secure scan bypass vulnerabilities in handling of specially crafted LHA and RAR archives have been found. An automatic update solves this problem.

System: Various
Topic: Vulnerabilities in Apple Safari 3 Beta
Links: Apple-SA-2007-06-22, CVE-2007-2398, CVE-2007-2399, CVE-2007-2400, CVE-2007-2401, ESB-2007.0456, R-281
ID: ae-200706-079

Apple Safari 3 Beta shows some vulnerabilities which might lead to the execution of arbitrary code, Cross-Site Scripting or Denial-of-Service. Safari 3 Beta Update 3.0.2 is available now.

System: Sun Solaris 10
Topic: Vulnerability in RSA Signature Verification
Links: Sun Alert 102970, CVE-2006-4790, ESB-2007.0453
ID: ae-200706-078

The GnuTLS library version prior to 1.4.4 is impacted by an RSA signature forgery vulnerability. This vulnerability, which affects applications which make use of the GnuTLS library to verify PKCS#1 signatures, allows a malicious user to make an altered PKCS#1 v1.5 signature appear to be correct thus forging the signature. A patch is available now.

System: Microsoft Windows
Topic: Vulnerabilities in Cerulean Studios Trillian
Links: iDefense #545, CVE-2007-2478, ESB-2007.0289, R-284
ID: ae-200706-077

Cerulean Studios Trillian is a multi-protocol chat application that supports IRC, ICQ, AIM and MSN protocols. Remote exploitation of multiple vulnerabilities in the Internet Relay Chat (IRC) module of Cerulean Studios' Trillian 3.1 could allow for the interception of private conversations or execution of code as the currently logged on user. Version 3.1.5.0 solves this problem.

System: Debian/GNU Linux
Topic: Vulnerabilities in tinymux, ekg, and maradns
Links: DSA-1317, CVE-2007-1655, ESB-2007.0457,
DSA-1318, CVE-2005-2370, CVE-2005-2448, CVE-2007-1663, CVE-2007-1664, CVE-2007-1665, ESB-2007.0458
DSA-1319, CVE-2007-3114, CVE-2007-3115, CVE-2007-3116, ESB-2007.0459
ID: ae-200706-076

Tinymux is a text-based multi-user virtual world server. It performs insufficient boundary checks when working with user-supplied data, which might lead to the execution of arbitary code.
Ekg is a console Gadu Gadu client. It was discovered that memory alignment errors may allow remote attackers to cause a Denial-of-Service on certain architectures such as sparc. Several endianess errors may allow remote attackers also to cause a Denial-of-Service. These two vulnerabilities only affect Debian Sarge. Debian Etch is shows three vulnerabilities which might lead to a Denial-of-Service. This is due to a memory leak in handling image messages, a null pointer deference in the token OCR code and a memory leak in the token OCR code itself.
MaraDNS is a simple security-aware Domain Name System server, which shows three vulnerabilities leading to a Denial-of-Service. All of them can be triggered by malformed DNS requests, leading to memory leaks.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerability in webmin
Links: MDKSA-2007:135, CVE-2007-3156, ESB-2007.0487
ID: ae-200706-075

Multiple cross-site scripting (XSS) vulnerabilities were discovered in pam_login.cgi in webmin prior to version 1.350, which could allow a remote attacker to inject arbitrary web script or HTML. Updated packages have been patched to prevent this issue.

System: SuSE Linux
Topic: Vulnerabilities in squirrelmail, OpenOffice, Blackdown JDK/JRE, gnash, libpng, python, pulseaudio, gd, otrs, and net-snmp
Links: SUSE-SR:2007:013, CVE-2005-2177, CVE-2007-1262, CVE-2007-1804, CVE-2005-2052, CVE-2007-2445, CVE-2007-2500, CVE-2005-2524, CVE-2007-2589, CVE-2007-2756
ID: ae-200706-074

The weekly SUSE Security Summary reports vulnerabilities in the packages squirrelmail, OpenOffice, Blackdown JDK/JRE, gnash, libpng, python, pulseaudio, gd, otrs, and net-snmp. Updated packages are available now and should be installed on vulnerable systems.

System: Apple OSX
Topic: Apple Security Update available
Links: Apple 2007-06, CVE-2007-2399, CVE-2007-2401, VU#845708, VU#389868, ESB-2007.0455
ID: ae-200706-073

Apple has published the security update for June 2007. It fixes two potential vulnerabilities. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. Additionally, Cross-Site Scripting attacks might be possible. It's recommended to install this update.

System: Sun Solaris
Topic: Vulnerabilities in gpdf
Links: Sun Alert 102972, CVE-2005-2097, CVE-2005-3191, CVE-2005-3192, CVE-2005-3193, CVE-2005-3624, CVE-2005-3625, CVE-2005-3626, CVE-2005-3627, ESB-2007.0451
ID: ae-200706-072

Multiple security vulnerabilities in the Solaris Gnome PDF Document Viewer (gpdf(1)) may allow a local or remote unprivileged user to cause the PDF Document Viewer application to crash or hang (potentially consuming excessive amounts of disk space, which may affect system performance), or may allow that user to execute arbitrary code with the privileges of the user opening a specially crafted PDF document with gpdf(1). A patch is not available yet.

System: Microsoft Windows
Topic: Vulnerability in Ingres Database
Links: CA, iDefense, CVE-2007-3334, ESB-2007.0448
ID: ae-200706-071

Several vulnerabilities were found in the Ingeress Database. A patch is available now.

System: Microsoft Windows
Topic: Vulnerability in HP Storage Management Appliance (SMA)
Links: HPSBST02231, SSRT071438, ESB-2007.0449
ID: ae-200706-070

The latest patches for Microsoft are needed to be installed when using the SMA. It's strongly recommended to install these hotfixes from Microsoft.

System: Mandriva Linux
Topic: Vulnerabilities in madwifi-source and xfsdump
Links: MDKSA-2007:132, CVE-2007-2829, CVE-2007-2830, CVE-2007-2831, MDKSA-2007:134, CVE-2007-2654
ID: ae-200706-069

Several vulnerabilities were found in MadWifi.
xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems.
Fixed packages are available now.

System: Various
Topic: Vulnerability in emacs
Links: CVE-2007-2833, DSA-1316, ESB-2007.0448, MDKSA-2007:133
ID: ae-200706-068

It has been discovered that emacs, the GNU Emacs editor, will crash when processing certain types of images. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in HP Help and Support Center
Links: HPSBPI02226, SSRT061274, CVE-2007-3180, ESB-2007.0447, R-283
ID: ae-200706-067

A security vulnerability has been identified in HP Help and Support Center running on HP Notebook Computers running with Windows XP. The vulnerability could be remotely exploited to allow unauthorized access to the system. A patch is available now.

System: Apple Mac OS X
Topic: Vulnerability in IPv6
Links: Apple, CVE-2007-2242, ESB-2007.0446
ID: ae-200706-066

A design issue exists in the IPv6 protocol's handling of type 0 routing headers. Remote attackers may be able to adversely affect network performance. A patch is available now.

System: Various
Topic: Vulnerability in Apache Tomcat
Links: Apache.org_tomcat4, Apache.org_tomcat5, Apache.org_tomcat6, CVE-2007-1355, ESB-2007.0444
ID: ae-200706-065

Web pages that display the Accept-Language header value sent by the client are susceptible to a cross-site scripting attack if they assume the Accept-Language header value conforms to RFC 2616. Fixed software is available now.

System: Sun Solaris 10
Topic: Vulnerability in BIND
Links: Sun Alert 102969, CVE-2007-0494, ESB-2007.0440
ID: ae-200706-064

A security vulnerability in Solaris 10 BIND DNSSEC may allow a local or remote unprivileged user the ability to cause the "named" BIND server process to exit. A patch is available now.

System: Microsoft Windows
Topic: Vulnerability in Cerulean Studios Trillian
Links: iDefense, VU#187033, ESB-2007.0437
ID: ae-200706-063

Remote exploitation of a heap overflow vulnerability in Cerulean Studios Trillian Instant Messenger could allow attackers to execute arbitrary code as the currently logged on user. A patch is available now.

System: Mandriva Linux
Topic: Vulnerability in proftpd
Links: MDKSA-2007:130, CVE-2007-2165, ESB-2007.0472
ID: ae-200706-062

The Auth API in ProFTPD, when multiple simultaneous authentication modules are configured, did not require that the module that checks authentication is the same module that retrieves authentication data, which could possibly be used to allow remote attackers to bypass authentication. Fixed packages are available now.

System: Debian/GNU Linux
Topic: Vulnerabilities in mplayer, open-iscsi, and libphp-phpmailer
Links: DSA-1313, CVE-2007-2948, ESB-2007.0441, R-280
DSA-1314, CVE-2007-3099, CVE-2007-3100, ESB-2007.0442
DSA-1315, CVE-2007-3215, ESB-2007.0443, R-282
ID: ae-200706-061

It was discovered that the MPlayer movie player performs insufficient boundary checks when accessing CDDB data, which might lead to the execution of arbitrary code.
Two flaws were discovered in open-iscsi. A local attacker could use these flaws to cause the server daemon to stop responding, leading to a denial of service.
It was discovered that libphp-phpmailer, an email transfer class for PHP, performs insufficient input validition if configured to use Sendmail. This allows the execution of arbitrary shell commands.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in apache and jasper
Links: MDKSA-2007:127, CVE-2007-1862, MDKSA-2007:129, CVE-2007-2721
ID: ae-200706-060

The recall_headers function in mod_mem_cache in Apache 2.2.4 does not properly copy all levels of header data, which can cause Apache to return HTTP headers containing previously-used data, which could be used to obtain potentially sensitive information by unauthorized users.
A function in the JasPer JPEG-2000 library could allow a remote user-assisted attack to cause a crash and possibly corrupt the heap via malformed image files.
Fixed packages are available now.

System: Debian/GNU Linux
Topic: Vulnerability in the libapache-mod-jk
Links: DSA-1312, CVE-2007-1860, ESB-2007.0435
ID: ae-200706-059

It was discovered that the Apache 1.3 connector for the Tomcat Java servlet engine decoded request URLs multiple times, which can lead to information disclosure. A patch addresses this issue.

System: Sun Solaris
Topic: Vulnerabilities in Xorg and IPv6
Links: Sun Alert #102901, ESB-2007.0426,
Sun Alert #102919, ESB-2007.0428
ID: ae-200706-058

A divide by zero security vulnerability exists in the X11 Render Extension to the X11 display server Xorg(1). By using specially crafted values for compositing or adding trapezoids, a local or remote unprivileged user who is able to display data on a running X11 server instance may cause the X11 display server Xorg(1) to crash.
An unprivileged local or remote user may be able to panic a Solaris 10 system which is configured to use IPv6 (ip6(7p)) but is not configured to use the IPsec stack (ipsec(7P)), therefore causing a Denial of Service to the system as a whole.
Patches are available now.

System: Debian/GNU Linux
Topic: Vulnerability in the PostgreSQL
Links: DSA-1309, DSA-1311, CVE-2007-2138, ESB-2007.0432, ESB-2007.0434
ID: ae-200706-057

It has been discovered that the PostgreSQL database performs insufficient validation of variables passed to privileged SQL statements, so called "security definers", which could lead to SQL privilege escalation. A patch addresses this issue.

System: Debian/GNU Linux
Topic: Vulnerabilities in the kernel
Links: DSA-1304, CVE-2005-4811, CVE-2006-4814, CVE-2006-4623, CVE-2006-5753, CVE-2006-6060, CVE-2006-6106, CVE-2006-6535, CVE-2007-0958, CVE-2007-1357, CVE-2007-1592, ESB-2007.0431
ID: ae-200706-056

An updated kernel fixes several vulnerabilities which might lead to a Denial-of-Service (DoS) or remote execution of arbitrary code.

System: Sun Solaris 9, 10
Topic: Vulnerabilities in Samba
Links: Sun Alert 102964, CVE-2007-2444, CVE-2007-2446, CVE-2007-2447, R-279, ESB-2007.0427
ID: ae-200706-055

Multiple security vulnerabilities in the Samba (samba(7)) software for Solaris may allow a local or remote user to issue unauthorized Samba operations or to execute arbitrary code or commands with elevated privileges. If this service is not needed, it should be turned off. The publication of a patch is pending.

System: Some
Topic: Vulnerabilities in Apache Tomcat
Links: Apache.org_tomcat4, Apache.org_tomcat5, Apache.org_tomcat6, CVE-2007-2449, CVE-2007-2450, ESB-2007.0423
ID: ae-200706-054

The JSP examples web application displays does not escape some user provided data before including it in the output. This enables a XSS attack. Additionally, the Manager and Host Manager web applications do not escape some user provided data before including it in the output. This enables a XSS attack. The user must be logged in to the Manager or Host Manager web application.
It's recommended to remove the examples and to close the browser after having completed the tasks.

System: Mandriva Linux
Topic: Vulnerability in spamassassin
Links: Apache.org, MDKSA-2007:125, CVE-2007-2873
ID: ae-200706-053

SpamAssassin 3.1.x, when running as root with unusual configuration options using vpopmail or virtual users, could allow local users to cause a Denial-of-Service (via corrupting arbitrary files) using a symlink attack on a file used by spamd. SpamAssassin 3.1.9 corrects this flaw.

System: SUSE Linux Enterprise Server 9, Novell Linux Desktop 9, Open Enterprise Server
Topic: Vulnerabilities in the kernel
Links: SUSE-SA:2007:035, CVE-2006-2936, CVE-2006-5749, CVE-2006-5753, CVE-2006-5754, CVE-2006-5871, CVE-2006-6106, CVE-2006-6535, CVE-2006-7203, CVE-2007-1353, CVE-2007-1357, CVE-2007-1592
ID: ae-200706-052

An updated kernel fixes several vulnerabilities which might lead to a Denial-of-Service (DoS). One of the vulnerabilities enables attackers to a remote DoS.

System: Debian/GNU Linux
Topic: Vulnerabilities in icedove and iceweasel
Links: DSA-1305, CVE-2007-1558, CVE-2007-2867, CVE-2007-2868,
DSA-1308, CVE-2007-1362, CVE-2007-2867, CVE-2007-2868, CVE-2007-2869, CVE-2007-2870, CVE-2007-2871, ESB-2007.0425
ID: ae-200706-051

The icedove mail client is an unbranded version of the Thunderbird client. It shows problems with APOP authentication, the possibility to execute arbitrary code via the network by crashes of the layout engine or the JavaScript engine.
The iceweasel web browser is an unbranded version of the Firefox browser. Also this software shows possibility to execute arbitrary code via the network by crashes of the layout engine or the JavaScript engine. Additionally, a Denial-of-Service (DoS) might occur due to an insufficient validation of cookies. Another vulnerability might lead to a DoS, too. Finally, Cross-Site Scripting might be possible as well as spoofing or phishing attacks.
For both programs, an update is available now.

System: Red Hat Enterprise Linux 5
Topic: Several vulnerabilities in kernel fixed
Links: RHSA-2007-0376, CVE-2006-7203, CVE-2007-1353, CVE-2007-2453, CVE-2007-2525, ESB-2007.0422
ID: ae-200706-050

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 5 kernel are now available. Please note that only one vulerability is exploitable remotely, leading to a Denial-of-Service.

System: Various
Topic: Vulnerability in Apache MyFaces Tomahawk JSF Framework
Links: iDEFENSE #544, CVE-2007-3101, ESB-2007.0421
ID: ae-200706-049

Java Server Faces, JSF, is a framework used to create server side GUI Web applications. Remote exploitation of an input validation vulnerability in Apache Software Foundation's MyFaces Tomahawk JSF framework could allow an attacker to perform a cross-site scripting (XSS) attack. The code responsible for parsing HTTP requests is vulnerable to an XSS vulnerability. When parsing the 'autoscroll' parameter from a POST or GET request, the value of this variable is directly inserted into JavaScript that is sent back to the client. This allows an attacker to run arbitrary JavaScript in the context of the affected domain of the MyFaces application being targeted. An update to MyFaces Tomahawk version 1.1.6 solves this issue.

System: Sun Solaris 10
Topic: Vulnerability in NFS XDR Handling
Links: Sun Alert 102965, R-278, ESB-2007.0420
ID: ae-200706-048

A security vulnerability in Solaris 10 related to the handling of XDR data within NFS requests may allow a local or remote unprivileged user to panic a Solaris system that is configured to run as an NFS server, resulting in a Denial-of-Service (DoS). A patch is available now.

System: Various
Topic: Vulnerability in Sun Java System Directory Server
Links: Sun Alert 102875 ESB-2007.0419, R-277
ID: ae-200706-047

A security vulnerability in Sun Java System Directory Server 5.2 and Enterprise Edition may allow a local or remote unprivileged user to obtain unauthorized access and perform specific data modifications in the directory server, which would normally require root access privileges. An update to solve this issue is available.

System: Various
Topic: Vulnerability in Mozilla Firefox
Links: VU#143297, R-274
ID: ae-200706-046

Mozilla Firefox allows cross-domain access to an iframe. This vulnerability could allow an attacker to interact with a web site in a different domain. The attacker could read content and cookies, capture keystrokes, and modify content. A patch is not available yet.

System: Mandriva Linux
Topic: Vulnerabilities in gd, libwmf, and tetex
Links: MDKSA-2007:122, MDKSA-2007:123, CVE-2007-2030 CVE-2007-2756
ID: ae-200706-045

A flaw in libgd2 was found by Xavier Roche where it would not correctly validate PNG callback results. If an application linked against libgd2 was tricked into processing a specially-crafted PNG file, it could cause a denial of service scenario via CPU resource consumption.
Also affected are the libwmf and tetex packages.
Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in mod_perl, spamassassin, kdebase and iscsi-initiator-utils
Links: RHSA-2007-0395, CVE-2007-1349, ESB-2007.0417,
RHSA-2007-0492, CVE-2007-2873, ESB-2007.0412,
RHSA-2007-0492, CVE-2007-2022, ESB-2007.0413,
RHSA-2007-0492, CVE-2007-3099, CVE-2007-3100, ESB-2007.0418
ID: ae-200706-044

If a server implemented a mod_perl registry module using the "namespace_from_uri" method, a remote attacker requesting a carefully crafted URI can cause resource consumption, which could lead to a denial of service .
A symlink issue was discovered in SpamAssassin that affects certain non-default configurations. A local user could use this flaw to create or overwrite files writable by the spamd process
A problem with the interaction between the Flash Player and the Konqueror web browser was found. The problem could lead to key presses leaking to the Flash Player applet instead of the browser.
Two flaws were discovered in open-iscsi. A local attacker could use these flaws to cause the server daemon to stop responding, leading to a denial of service
Updated packages address these issues.

System: Microsoft Windows
Topic: Vulnerability in Microsoft Win 32 API
Links: MS07-035, CVE-2007-2219, AL-2007.0075, R-268
ID: ae-200706-043

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Outlook Express and Windows Mail
Links: MS07-034, CVE-2006-2111, CVE-2007-1658, CVE-2007-2225, CVE-2007-2227, AL-2007.0077, R-269
ID: ae-200706-042

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer
Links: MS07-033, CVE-2007-0218, CVE-2007-1750, CVE-2007-3027, CVE-2007-1751, CVE-2007-1499, CVE-2007-2222, AL-2007.0074, R-270
ID: ae-200706-041

No further comment due to legal reasons

System: Microsoft Windows Vista
Topic: Vulnerability in Microsoft Windows Vista
Links: MS07-032, CVE-2007-2229, ESB-2007.0406, R-273
ID: ae-200706-040

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Schannel Security Package
Links: MS07-031, CVE-2007-2218, VU#810073, AL-2007.0076, R-271
ID: ae-200706-039

No further comment due to legal reasons

System: Microsoft Office
Topic: Vulnerabilities in Microsoft Visio
Links: MS07-030, CVE-2007-0934, CVE-2007-0936, ESB-2007.0405, R-272
ID: ae-200706-038

No further comment due to legal reasons

System: HP-UX
Topic: Vulnerabilities in BIND
Links: HPSBUX02219, SSRT061273, CVE-2006-4339, CVE-2007-0493, CVE-2007-0494, ESB-2007.0408
ID: ae-200706-037

Several vulnerabilities have been identified with HP-UX running BIND. The vulnerabilities could be exploited remotely to create a Denial of Service (DoS). A patch is available now.

System: Red Hat Enterprise Linux 3
Topic: Several vulnerabilities in kernel fixed
Links: RHSA-2007-0436, CVE-2006-4538, CVE-2006-4813, CVE-2006-4814, CVE-2006-5174, CVE-2006-5619, CVE-2006-5751, CVE-2006-5753, CVE-2006-5754, CVE-2006-5757, CVE-2006-5823, CVE-2006-6053, CVE-2006-6054, CVE-2006-6056, CVE-2006-6106, CVE-2006-6535, ESB-2007.0063, R-276
ID: ae-200706-036

Updated kernel packages that fix several security issues in the Red Hat Enterprise Linux 3 kernel are now available.

System: Various
Topic: Vulnerability in openoffice.org / StarOffice
Links: CVE-2007-0245, CVE-2007-0254, DSA-1307, ESB-2007.0409, RHSA-2007-0406, ESB-2007.0411, R-276, SUSE-SA:2007:037, MDKSA-2007:144,
Sun Alert 102917, Sun Alert 102967, ESB-2007.0430
ID: ae-200706-035

A heap overflow was discovered in the routines of OpenOffice.org and StarOffice that parse RTF files. A specially crafted RTF file could cause the filter to overwrite data on the heap, which may lead to the execution of arbitrary code. Fixed packages are available now.

System: Red Hat Enterprise Linux 3
Topic: Vulnerabilities in gdb and gcc
Links: RHSA-2007-0469, CVE-2006-4146, ESB-2007.0402,
RHSA-2007-0473, CVE-2006-3619, ESB-2007.0403
ID: ae-200706-034

GDB, the GNU debugger, allows debugging of programs written in C, C++, and other languages. Various buffer overflows and underflows were found in the DWARF expression computation stack in GDB. If an attacker could trick a user into loading an executable containing malicious debugging information into GDB, they may be able to execute arbitrary code with the privileges of the user.
The gcc packages include C, C++, Java, Fortran 77, Objective C, and Ada 95 GNU compilers and related support libraries. A directory traversal flaw in fastjar. An attacker could create a malicious JAR file which, if unpacked using fastjar, could write to any files the victim had write access to.
Updated packages address these issues.

System: Debian GNU/Linux
Topic: Vulnerabilities in gimp and lighttpd
Links: DSA-1301, CVE-2007-2356, ESB-2007.0399,
DSA-1303, CVE-2007-1870, CVE-2007-1869
ID: ae-200706-033

A buffer overflow has been identified in Gimp's SUNRAS plugin in versions prior to 2.2.15. This bug could allow an attacker to execute arbitrary code on the victim's computer by inducing the victim to open a specially crafted RAS file.
Two problems have been discovered with lighttpd, a fast webserver with minimal memory footprint. They could allow a remote Denial-of-Service.
Both vulnerabilities can be fixed by installing the appropriate update.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in Linux PAM
Links: RHSA-2007-0465, CVE-2004-0813, CVE-2007-1716, ESB-2007.0398
ID: ae-200706-032

Pluggable Authentication Modules (PAM) provide a system whereby administrators can set up authentication policies without having to recompile programs that handle authentication. A flaw was found in the way the Linux kernel handled certain SG_IO commands. Console users with access to certain device files had the ability to damage recordable CD drives. Another vulnerability has been found in the way pam_console set console device permissions. It is possible for various console devices to retain ownership of the console user after logging out, possibly leaking information to an unauthorized user. An update solves these potential problems.

System: Red Hat Enterprise Linux
Topic: Vulnerability in shadow-utils
Links: RHSA-2007-0431, CVE-2006-1174, ESB-2007.0397
ID: ae-200706-031

The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, as well as programs for managing user and group accounts. A flaw has been found in the useradd tool in shadow-utils. A new user's mailbox, when created, could have random permissions for a short period. This could allow a local attacker to read or modify the mailbox. An update addresses this issue.

System: Mac OS X
Topic: Vulnerability in Cisco Trust Agent (CTA)
Links: Cisco, ESB-2007.0396
ID: ae-200706-030

CTA installations on Mac OS X show a vulnerability which can allow an unauthorized user to access the "System Preferences" window which can be used to change passwords of all non-root user accounts including admin accounts. The "System Preferences" window becomes available to the unauthorized user because of the "user notifications" feature within CTA. These messages are sent from Cisco Secure Access Control Server (ACS) to CTA upon completion of initial posture validation or upon posture revalidation. These notifications are displayed as pop-up messages on the desktop, or login screen, of the system on which CTA is installed. CTA release 2.1.104.0 or later resolves this vulnerability. Workarounds are described in the advisory, too.

System: Red Hat Enterprise Linux
Topic: Vulnerability in openldap
Links: RHSA-2007-0430, CVE-2006-4600, ESB-2007.0395
ID: ae-200706-029

OpenLDAP is an open source suite of LDAP (Lightweight Directory Access Protocol) applications, libraries and development tools. A vulnerability has been found in the way OpenLDAP handles selfwrite access. Users with selfwrite access were able to modify the distinguished name of any user. Users with selfwrite access should only be able to modify their own distinguished name. A memory leak bug has been found in OpenLDAP's ldap_start_tls_s() function. An application using this function could result in an Out Of Memory (OOM) condition, crashing the application. Red Hat provides an update, which should be installed.

System: Various
Topic: Vulnerability in Mozilla Firefox
Links: Mozilla, CVE-2007-3089, VU#143297, ESB-2007.0404, Sun Alert #102955, ESB-2007.0401
ID: ae-200706-028

An iframe is an HTML element which allows an HTML document to be embedded inside a master HTML document. Mozilla Firefox 2.0.0.4 and earlier allows cross-domain access to an iframe. This vulnerability could allow an attacker to interact with a web site in a different domain. The attacker could read content and cookies, capture keystrokes, and modify content. Since there is no patch available at the moment, it's recommended to disable Java Script.

System: Turbo Linux
Topic: Vulnerability in cups
Links: TLSA-2007-31, CVE-2007-0720
ID: ae-200706-027

The CUPS service allows remote attackers to cause a denial of service via a "partially-negotiated" SSL connection. Fixed packages are available now.

System: Sun Solaris
Topic: Vulnerabilities in sshd and scp
Links: Sun Alert #102962, CVE-2006-4924, ESB-2007.0391, ESB-2007.0452,
Sun Alert #102961, CVE-2006-0225, ESB-2007.0392, ESB-2007.0454
ID: ae-200706-026

A security vulnerability which affects the sshd(1M) daemon when configured to use protocol version 1 may allow a remote user to cause the daemon to consume an excessive amount of CPU power.
Due to a security vulnerability in the way the scp(1) command executes helper applications, certain additional unintended commands may be executed at the same time.
Patches are available now.

System: Various
Topic: Vulnerability in freetype
Links: CVE-2007-2754, DSA-1302, ESB-2007.0400, RHSA-2007-0403, ESB-2007.0394, MDKSA-2007:12
ID: ae-200706-025

A problem was discovered with freetype, a FreeTyp2 font engine, which could allow the execution of arbitary code via an integer overflow in specially crafted TTF files. Fixed software is available now.

System: SUSE Linux, openSUSE
Topic: Vulnerabilities in Asterisk
Links: SUSE-SA:2007:034, CVE-2007-1306, CVE-2007-1561, CVE-2007-1594, CVE-2007-1595, CVE-2007-2294, CVE-2007-2297, CVE-2007-2488
ID: ae-200706-024

Several security related bugs were found in 'Asterisk' that allow attackers to remotely crash asterisk or cause information leaks. Fixed packages are available now.

System: Various
Topic: Vulnerability in libexif
Links: CVE-2007-2645, CVE-2007-4168, iDefense #543, ESB-2007.0415, MDKSA-2007:118, RHSA-2007-0501, ESB-2007.0416, DSA-1310, ESB-2007.0433, MDKSA-2007:128, SUSE-SA:2007:039
ID: ae-200706-023

Integer overflow in the exif_data_load_data_entry function in libexif allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted EXIF data. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in freetype and lighttpd
Links: DSA-1302, CVE-2007-2754,
DSA-1303, CVE-2007-1869, CVE-2007-1870, ESB-2007.0390
ID: ae-200706-022

A problem was discovered with freetype, a FreeTyp2 font engine, which could allow the execution of arbitary code via an integer overflow in specially crafted TTF files.
Two problems were discovered with lighttpd, a fast webserver with minimal memory footprint, which could allow denial of service.
Fixed packages are available now.

System: Sun Solaris
Topic: Vulnerabilities in Solaris Management Console
Links: Sun Alert #102902, R-264,
Sun Alert #102903, R-263
ID: ae-200706-021

Security vulnerabilities in the authentication mechanism and in the logging mechanism for Solaris Management Console (SMC) may allow a local or remote unprivileged user to gain unauthorized root access to a Solaris system. Patches are available now.

System: SGI Advanced Linux Environment
Topic: Vulnerabilities in mutt, seamonkey, and quagga
Links: SGI_20070601-01
ID: ae-200706-020

SGI has released the Security Update #76 for SGI Advanced Linux Environment 3. These updates fix an already known security related problems in mutt, seamonkey, and quagga.
So it's recommended to install this update.

System: Red Hat Enterprise Linux
Topic: Vulnerability in fetchmail
Links: RHSA-2007-0385, CVE-2007-1558, ESB-2007.0387
ID: ae-200706-019

The APOP functionality in fetchmail's POP3 client implementation was validating the APOP challenge too lightly, accepting random garbage as a POP3 server's APOP challenge, rather than insisting it conform to RFC-822 specifications. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in ipsec-tools
Links: DSA-1299, CVE-2007-2524, ESB-2007.0388
ID: ae-200706-018

It was discovered that a specially-crafted packet sent to the racoon ipsec key exchange server could cause a tunnel to crash, resulting in a denial of service. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerabilities in Symantec Ghost Solution Suite
Links: SYM07-013, iDefense, ESB-2007.0385
ID: ae-200706-017

Three remote denial of service vulnerabilities have been identified in Symantec Ghost Solution Suite. All three vulnerabilities affect both the client and server daemons. Each vulnerability is triggered by sending a malformed UDP Packet to ether the client or server daemon. A patch is available now.

System: Microsoft Windows
Topic: Vulnerabilities in Symantec AntiVirus
Links: SYM07-011, SYM07-012, CVE-2007-3021, CVE-2007-3022, ESB-2007.0384
ID: ae-200706-016

Two vulnerabilities were discovered in the Reporting Server component that comes with the Symantec AntiVirus Corporate Edition and Symantec Client Security products. Patches are available now.

System: HP-UX
Topic: Vulnerability in CIFS Server
Links: ESB-2007.0383, CVE-2007-2446, CVE-2007-2447
ID: ae-200706-015

Two vulnerabilities have been identified with HP-UX running CIFS Server (Samba). The vulnerabilities could be exploited remotely to execute arbitrary code. A patch is available now.

System: Various
Topic: Vulnerability in HP System Management Homepage
Links: HPSBMA02216, SSRT071310, VU#292457, R-265
ID: ae-200706-014

The HP System Management Homepage (SMH) server is a web-based interface that can manage HP servers running the Microsoft Windows or Linux operating systems. The SMH contains an unspecified cross-site scripting vulnerability. Fixed software is available now.

System: Sun Solaris
Topic: Vulnerability in GNOME Assistive Technology
Links: Sun Alert 102834, ESB-2007.0382, R-266
ID: ae-200706-013

If GNOME Assistive Technology support has been enabled on a system and a local user locks the terminal using xscreensaver(1) then it may be possible for an individual with physical access to the system to be able to execute arbitrary commands on the system with the privileges of the user running xscreensaver(1). A patch is available now.

System: Mandriva Linux
Topic: Vulnerabilities in file, libpng, and lha
Links: MDKSA-2007:114, CVE-2007-2026, CVE-2007-2799, MDKSA-2007:116, CVE-2007-2445, VU#684664, MDKSA-2007:117, CVE-2007-2030
ID: ae-200706-012

An attacker could create a carefully crafted file which, if examined by a victim using the file utility, could lead to arbitrary code execution.
A flaw how libpng handled malformed images was discovered. An attacker able to create a carefully crafted PNG image could cause an application linked with libpng to crash when the file was manipulated.
lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.
Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Symantec Storage Foundation for Windows
Links: Symantec, CVE-2007-2279, ESB-2007.0378
ID: ae-200706-011

An authentication bypass, remote code execution vulnerability has been identified and resolved in the Symantec Storage Foundation for Windows v5.0 Volume Manager Scheduler Service. Successful exploitation could result in potential compromise of the targeted system. A patch is available now.

System: Mandriva Linux
Topic: Vulnerabilities in php-pear, util-linux, and mplayer
Links: MDKSA-2007:110, CVE-2007-2519, MDKSA-2007:111, CVE-2006-7108, MDKSA-2007:112, CVE-2006-6172
ID: ae-200706-010

A security hole was discovered in all versions of the PEAR Installer and would allow a malicious package to install files anywhere in the filesystem.
login in util-linux skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok.
Buffer overflow in the asmrp_eval function for the Real Media input plugin allows remote attackers to cause a denial of service and possibly execute arbitrary code via a rulebook with a large number of rulematches.
Fixed packages are available now.

System: Various
Topic: Vulnerability in ClamAV
Links: CVE-2007-2650, MDKSA-2007:115, OpenBSD, SUSE-SA:2007:033, ESB-2007.0429, DSA-1320, ESB-2007.0460, R-285
ID: ae-200706-009

A vulnerability in the OLE2 parser in ClamAV was found that could allow a remote attacker to cause a denial of service via resource consumption with a carefully crafted OLE2 file. Fixed software is available now.

System: Various
Topic: Vulnerabilities in Sun Java Runtime Environment
Links: Sun Alert 102934, AL-2007.0071, R-261
ID: ae-200706-008

A buffer overflow vulnerability in the image parsing code in the Java Runtime Environment may allow an untrusted applet or application to elevate its privileges. A second vulnerability may allow an untrusted applet or application to cause the Java Virtual Machine to hang. Patches are available now.

System: Various
Topic: Vulnerabilities in mutt
Links: CVE-2006-5297, CVE-2007-1558, CVE-2007-2683, RHSA-2007-0386, ESB-2007.0379, MDKSA-2007:113
ID: ae-200706-007

Several vulnerabilities were found in mutt. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in PHP
Links: CVE-2007-2756, CVE-2007-2872, OpenPKG-SA-2007.020
ID: ae-200706-006

Two vulnerabilities were found in PHP. An infinite loop was discovered in the imagecreatefrompng function. An integer overflow was discovered inside the chunk_split() function. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in Logitech VideoCall
Links: CVE-2007-2918, VU#330289, R-256
ID: ae-200706-005

Logitech VideoCall ActiveX controls contain multiple stack buffer overflows, which could allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. A workaround is described in the advisory.

System: Apple Mac OS X
Topic: Vulnerability in Xserve Lights-Out Management Firmware
Links: Apple, CVE-2007-2387, ESB-2007.0376
ID: ae-200706-004

A remote user may be able to gain admin privileges on an Xserve system with IPMI configured in a particular manner. Fixed firmware is available now.

System: Linux
Topic: Vulnerabilities in MadWifi
Links: CVE-2007-2829, CVE-2007-2830, CVE-2007-2831, ESB-2007.0377
ID: ae-200706-003

Several denial of service vulnerabilities were found in MadWifi. Fixed software is available now.

System: Various
Topic: Vulnerability in locate
Links: CVE-2007-2452, ESB-2007.0375
ID: ae-200706-002

When GNU locate reads filenames from an old-format locate database, they are read into a fixed-length buffer allocated on the heap. Filenames longer than the 1026-byte buffer can cause a buffer overrun. The overrunning data can be chosen by any person able to control the names of filenames created on the local system. Fixed software is available now.

System: Sun Solaris
Topic: Vulnerabilities in Adobe Flash Player and snmpd
Links: Sun Alert #102932, ESB-2007.0373,
Sun Alert #102725, ESB-2007.0374
ID: ae-200706-001

Security vulnerabilities in the Adobe Flash Player product shipped with Solaris 10 may allow remote users who create applications that are viewed with the Flash Player to generate unauthorized HTTP requests from the affected host by inserting arbitrary HTTP headers.
A local or remote unprivileged user may be able to disable the snmpd(1M) daemon causing a Denial of Service (DoS) of the SNMP service.
Patches are available now.



(c) 2000-2010 AERAsec Network Services and Security GmbH