Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-184-73-74-47.compute-1.amazonaws.com [184.73.74.47]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 10 / 2007

System: Unix / Linux
Topic: Vulnerability in CUPS
Links: CVE-2007-4351, VU#446897, RHSA-2007-1020, S-032, ESB-2007.0854, SUSE-SA:2007:058, MDKSA-2007:204
ID: ae-200710-094

The Common UNIX Printing System (CUPS) provides a portable printing layer for UNIX operating systems. A flaw has been found in the way CUPS handles certain Internet Printing Protocol (IPP) tags. A remote attacker who is able to connect to the IPP TCP port could send a malicious request causing the CUPS daemon to crash, or potentially execute arbitrary code. Please note that the default CUPS configuration doesn't allow remote hosts to connect to the IPP TCP port. An updated package fixes this vulnerability.

System: IBM AIX
Topic: Several vulnerabilities in IBM AIX
Links: iDefense #611, iDefense #612, iDefense #613, iDefense #614, iDefense #615, iDefense #616, iDefense #617, CVE-2007-4217, CVE-2007-4513, CVE-2007-4621, CVE-2007-4622, CVE-2007-4623, ESB-2007.0852, S-033
ID: ae-200710-093

Vulnerabilities were found in the swcons, lqueryvg, lquerypv, ftp, dig, bellmail, and crontab programs og IBM AIX. Patches are available now.

System: Various
Topic: Vulnerabilities in TikiWiki
Links: CVE-2007-5423, CVE-2007-5682, CVE-2007-5683, CVE-2007-5684, ESB-2007.0853
ID: ae-200710-092

Several vulnerabilities were found in TikiWiki. A patch is available now.

System: Sun Fire X2100 / X2200 M2 Server
Topic: Vulnerability in Sun Fire X2100 M2/X2200 M2 ELOM
Links: SUN Alert #103127, ESB-2007.0849
ID: ae-200710-091

A security vulnerability in the X2100 and X2200 M2 Embedded Lights Out Manager (ELOM) software may allow remote unprivileged users the ability to execute arbitrary commands with root privileges on the embedded Service Processor (SP). Fixed Firmware is available now.

System: Apple Mac OS X
Topic: Vulnerabilities in Xcode Developer Tools
Links: CVE-2006-2362, CVE-2006-5327, CVE-2006-5328, ESB-2007.0734
ID: ae-200710-090

Several vulnerabilities were found in 'gdb' and 'WebObjects', which are part of the Xcode Developer Tools. An update is available now.

System: Sun Solaris 10
Topic: Vulnerability in Internet Protocol
Links: SUN Alert #103087, ESB-2007.0850
ID: ae-200710-089

A security vulnerability in the Solaris 10 Internet Protocol (ip(7P)) may allow a local unprivileged user the ability to cause a system panic, thereby causing a Denial of Service (DoS) to the system as a whole. A patch is available now.

System: Sun Solaris 10
Topic: Vulnerability in sctp
Links: SUN Alert #103101, ESB-2007.0846
ID: ae-200710-088

A security vulnerability in Solaris 10 SCTP INIT processing (see sctp(7P)) may allow a privileged remote user to panic the system, resulting in a Denial of Service (DoS). A patch is available now.

System: SuSE Linux
Topic: Vulnerabilities in fetchmail, flac, opera, util-linux, and openssh
Links: SUSE-SR:2007:022
ID: ae-200710-087

A SUSE Security Summary reports vulnerabilities in the packages fetchmail, flac, opera, util-linux, and openssh. Updated packages are available now and should be installed on vulnerable systems.

System: Some
Topic: Vulnerabilities in RSA KEON Registration Authority
Links: gs07-02, VU#342793, S-031, ESB-2007.0845
ID: ae-200710-086

The RSA Keon Certificate Authority (CA) software is a digital certificate management system. The RSA KEON Registration Authority allows the CA to handle large numbers of certificate requests. The RSA KEON Registration Authority web interface contains multiple cross-site scripting vulnerabilities. So an attacker may be able to obtain sensitive data from the site running the RSA KEON Registration Authority software or use the vulnerability create spoofed content. RSA has released updates to address this issue.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in httpd
Links: RHSA-2007-0911, CVE-2007-3847, CVE-2007-4465, ESB-2007.0843
ID: ae-200710-085

Two vulnerabilities have been discovered in the Apache HTTP Server. They concern the mod_proxy module as well as the module mod_autoindex. Regarding the proxy, a remotely triggered Denial-of-Service is possible while the other vulnerability allows cross-site scripting under certrain circumstances.
Updated packages are available now, fixing the vulnerabilities.

System: Microsoft Windows
Topic: Vulnerability in products of Trend Micro
Links: iDEFENSE #609, CVE-2007-4277, Trend Micro #1035793, ESB-2007.0842
ID: ae-200710-084

The Trend Micro AntiVirus scan engine provides AntiVirus capabilities to desktop, server, and gateway systems. The engine is licensed to several of Trend Micro's OEM partners. Local exploitation of a buffer overflow vulnerability within Tmxpflt.sys, as included with Trend Micro's AntiVirus engine, could allow an attacker to execute arbitrary code in kernel context. This vulnerability specifically exists due to insecure permissions on the "\\.\Tmfilter" DOS device interface. The permissions on this device allow "Everyone" write access. This allows a locally logged-in user to access functionality intended for privileged use only. Additionally, the IOCTL handler of this DOS device interface for IOCTL 0xa0284403 does not validate the length of attacker-supplied content when copying to a fixed-size buffer. As such, it's possible to execute attacker-supplied code in the context of the kernel.
Trend Micro has addressed this vulnerability with the release of version 8.550-1001 of their scan engine.

System: Microsoft Windows CE
Topic: Vulnerability in Microsoft Windows CE IGMP
Links: SYMSA-2007-012, CVE-2006-0021, ESB-2007.0838
ID: ae-200710-083

There is a security vulnerability that could allow for Denial of Service (DoS) by sending a specifically crafted TCP/IP packet to the Microsoft Windows CE mobile device Fixed software is available now.

System: Various
Topic: Vulnerability in HP OpenView Configuration Management
Links: HPSBMA02279 SSRT071298, ESB-2007.0837
ID: ae-200710-082

A vulnerability has been identified with HP OpenView Configuration Management (CM) Infrastructure (Radia) and Client Configuration Manager (CCM) running httpd.tkd. The vulnerability could be exploited to allow remote unauthorized access to data. A patch is available now.

System: Debian/GNU Linux
Topic: Vulnerability in xen-utils
Links: DSA-1395, CVE-2007-3919, ESB-2007.0841
ID: ae-200710-081

It was discovered that xen-utils, a collection of XEN administrative tools, used temporary files insecurely within the xenmon tool allowing local users to truncate arbitrary files. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerabilities in IBM Lotus Notes
Links: iDefense, iDefense, CVE-2007-5544, S-029, ESB-2007.0836, ESB-2007.0839, ESB-2007.0840
ID: ae-200710-080

Several vulnerabilities have been found in IBM Lotus Notes. Fixed software is available now.

System: Various
Topic: Vulnerability in Java Runtime Environment Virtual Machine
Links: Sun Alert #103112, ESB-2007.0834, S-028
ID: ae-200710-079

A vulnerability in the Virtual Machine of the Java Runtime Environment may allow an untrusted applet to elevate its privileges. A patch is available now.

System: Red Hat Enerprise Linux
Topic: Vulnerabilities in libpng
Links: RHSA-2007-0992, CVE-2007-5269, ESB-2007.0833, S-024
ID: ae-200710-078

Several flaws were discovered in the way libpng handled various PNG image chunks. An attacker could create a carefully crafted PNG image file in such a way that it could cause an application linked with libpng to crash when the file was manipulated. Fixed packages are available now.

System: Debian/GNU Linux
Topic: Vulnerabilities in xfce4 and reprepro
Links: DSA-1393, CVE-2007-3770, S-026, ESB-2007.0828,
DSA-1394, CVE-2007-4739, S-025, ESB-2007.0829
ID: ae-200710-077

It was discovered that xfce-terminal, a terminal emulater for the xfce environment, did not correctly escape arguments passed to the processes spawned by "Open Link". This allowed malicious links to execute arbitary commands upon the local system.
It was discovered that reprepro, a tool to create a repository of Debian packages, when updating from a remote site only checks for the validity of known signatures, and thus does not reject packages with only unknown signatures.
Updated packages are available now.

System: Microsoft Windows
Topic: Vulnerabilities in Adobe Reader and Acrobat
Links: apsa07-04, CVE-2007-5020, ESB-2007.0824, S-030
ID: ae-200710-076

Critical vulnerabilities have been identified in Adobe Reader and Acrobat that could allow an attacker who successfully exploits these vulnerabilities to take control of the affected system. This issue only affects customers on Windows XP with Internet Explorer 7 installed. A malicious file must be loaded in Adobe Reader or Acrobat by the end user for an attacker to exploit these vulnerabilities. It's recommended that affected users update to Adobe Reader 8.1.1 or Acrobat 8.1.1.

System: Microsoft Windows
Topic: Vulnerability in CA Host-Based Intrusion Prevention System Server
Links: CA, CVE-2007-5472, ESB-2007.0819
ID: ae-200710-075

CA Host-Based Intrusion Prevention System (CA HIPS) contains a vulnerability in the Server installation that can allow a remote attacker to take unauthorized administrative action. A patch is available now.

System: Red Hat Enterprise Linux 5
Topic: Vulnerabilities in kernel
Links: RHSA-2007-0940, CVE-2007-3105, CVE-2007-3380, CVE-2007-3513, CVE-2007-3731, CVE-2007-3848, CVE-2007-3850, CVE-2007-4133, CVE-2007-4308, CVE-2007-4574, ESB-2007.0825
ID: ae-200710-074

Several vulnerabilities were found in the linux kernel. Fixed kernel packages are available now.

System: Sun Solaris
Topic: Vulnerabilities in Solaris Kernel Statistics
Links: SUN Alert #103064, ESB-2007.0815
ID: ae-200710-073

Security vulnerabilities in the implementation of the retrieval of Kernel statistics may allow a local unprivileged user to panic the system, causing a Denial of Service (DoS) condition. Patches are available now.

System: Microsoft Windows
Topic: Vulnerability in RealPlayer
Links: Real, VU#871673, ESB-2007.0823, S-023
ID: ae-200710-072

RealNetworks RealPlayer is a multimedia application that allows users to view local and remote audio/video content. The RealPlayer Database Component, which is provided by MPAMedia.dll, contains a stack buffer overflow in the handling of playlist names. The RealPlayer IERPCtl ActiveX control, which is provided by ierpplug.dll, can be used to import a local file into a specified playlist in RealPlayer. This can be used to trigger the buffer overflow vulnerability. The ActiveX control is present in RealPlayer version 9 (RealOne Player) and later. By convincing a user to view a specially crafted HTML document, a remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the user on a vulnerable system. So an update to the latest version is strongly recommended.

System: SuSE Linux
Topic: Vulnerabilities in hplip, kdelibs3, kdebase3, NX, festival Daemon, opal, and openssl
Links: SUSE-SR:2007:021
ID: ae-200710-071

A SUSE Security Summary reports vulnerabilities in the packages hplip, kdelibs3, kdebase3, NX, festival daemon, opal, and openssl. Updated packages are available now and should be installed on vulnerable systems.

System: SUSE Linux
Topic: Problems with Sun / IBM Java
Links: SUSE-SA:2007:055, CVE-2007-5232, CVE-2007-5236, CVE-2007-5237, CVE-2007-5238, CVE-2007-5239, CVE-2007-5240, CVE-2007-5273, CVE-2007-5274,
SUSE-SA:2007:056, CVE-2007-2788, CVE-2007-2789, CVE-2007-3004, CVE-2007-3005, CVE-2007-3655, CVE-2007-3922
ID: ae-200710-070

The Sun JAVA JDK 1.5.0 was upgraded to release 13, and the Sun JAVA SDK 1.4.2 was upgraded to update 16 to fix various bugs, includingthe security bugs. Due to the same reasons, the IBM Java JRE/SDK has been brought to release 1.5.0 SR5a and 1.4.2 SR 9.0. It's recommended to upgrade the systems.

System: Various
Topic: Vulnerabilities in Firefox, Thunderbird and Seamonkey
Links: MFSA2007-29, MFSA2007-30, MFSA2007-31, MFSA2007-32, MFSA2007-33, MFSA2007-34, MFSA2007-35, MFSA2007-36,
CVE-2007-5339, CVE-2007-5340, CVE-2007-1095, CVE-2007-2292, CVE-2007-3511, CVE-2007-2894, CVE-2007-5334, CVE-2007-5337, CVE-2007-5338, CVE-2007-4841,
VU#349217, VU#755513, VU#559977, ESB-2007.0814, RHSA-2007-0979, RHSA-2007-0980, RHSA-2007-0981, ESB-2007.0820, ESB-2007.0821, ESB-2007.0822, DSA-1391, DSA-1392, ESB-2007.0816, ESB-2007.0817, S-022, SUSE-SA:2007:057, DSA-1396, ESB-2007.0844, DSA-1401, ESB-2007.0870
ID: ae-200710-069

Eight security advisories have been found in Firefox 2.0.0.7 and earlier, Thunderbird 2.0.0.7 and earlier as well as SeaMonkey 1.1.4 and earlier. These vulnerabilities give attackers the possibility to execute arbitrary code / commands, to access to confidential data and to provide misleading information. Please update your systems since the latest versions don't show these vulnerabilities.

System: Debian/GNU Linux
Topic: Vulnerabilities in zoph and t1lib
Links: DSA-1389, CVE-2007-3905, ESB-2007.0812
DSA-1390, CVE-2007-4033, ESB-2007.0813, S-027
ID: ae-200710-068

It has been discovered that zoph, a web based photo management system, performs insufficient input sanitising, which allows SQL injection.
A buffer overflow the intT1_Env_GetCompletePath routine in t1lib, a Type 1 font rasterizer library. This flaw might allow an attacker to crash the application using the t1lib shared libraries, and potentially execute arbitrary code within such an application's security context.
For Debian updates are available, other systems might be vulnerable, too.

System: HP-UX
Topic: Vulnerability in OpenSSL
Links: HPSBUX02277, SSRT071453, CVE-2007-5536, ESB-2007.0809, S-021
ID: ae-200710-067

A potential security vulnerability has been identified with HP-UX OpenSSL. The vulnerability could be exploited locally to create a Denial-of-Service (DoS). HP has published an updated package now, it should be installed soon.

System: Microsoft Windows
Topic: Vulnerability in HP Storage Management Appliance (SMA)
Links: HPSBST02280 SSRT071480, ESB-2007.0808
ID: ae-200710-066

The latest patches for Microsoft are needed to be installed when using the SMA. It's strongly recommended to install these hotfixes from Microsoft.

System: Various
Topic: Vulnerability in tk
Links: CVE-2007-5137, ESB-2007.0806, MDKSA-2007:200
ID: ae-200710-065

It was discovered that Tk could be made to overrun a buffer when loading certain images. A patch is available now.

System: Various
Topic: Vulnerabilities in Oracle products
Links: Oracle, S-015
ID: ae-200710-064

Oracle has published a Critical Patch Update including 51 new security fixes across all products. So it's recommended to install it as soon as possible.

System: Various
Topic: Vulnerability in dhcp
Links: CVE-2007-5365, DSA-1388, ESB-2007.0811, S-019, RHSA-2007-0970, ESB-2007.0832
ID: ae-200710-063

It was discovered that dhcp, a DHCP server for automatic IP address assignment, didn't correctly allocate space for network replies. This could potentially allow a malicious DHCP client to execute arbitary code upon the DHCP server. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Cisco Unified Communications Web-based Management
Links: Cisco, ESB-2007.0805, S-020
ID: ae-200710-062

Unified Contact Center and Intelligent Contact Management products contain a vulnerability that may result in unauthorized access to the web-based reporting and script monitoring tool (Web View) and the web-based configuration tool (Web Admin). Updated software solves this problem.

System: Microsoft Windows
Topic: Vulnerabilities in Cisco Unified Communications Manager
Links: Cisco, ESB-2007.0807, S-017
ID: ae-200710-061

Cisco Unified Communications Manager (CUCM), formerly CallManager, contains two denial of service (DoS) vulnerabilities. Updated software solves this problem.

System: Various
Topic: Vulnerabilities in Cisco Firewall Services Module and Cisco PIX and ASA Appliances
Links: Cisco, Cisco, ESB-2007.0802, ESB-2007.0803, S-016, S-018
ID: ae-200710-060

Two crafted packet vulnerabilities exist in the Firewall Services Module (FWSM) and the Cisco PIX 500 Series Security Appliance (PIX) and the Cisco 5500 Series Adaptive Security Appliance (ASA) that may result in a reload of the device. Fixed software is available now.

System: Various
Topic: Vulnerability in IBM Lotus Domino Web Server
Links: CVE-2007-0067 ESB-2007.0801
ID: ae-200710-059

The IBM Lotus Domino Web Server service is vulnerable to a stack based buffer overflow which can be exploited remotely. A patch is available now.

System: Various
Topic: Vulnerability in Asterisk
Links: ASA-2007-023, CVE-2007-5488 ESB-2007.0800
ID: ae-200710-058

Therefore, a carefully crafted destination number sent to an Asterisk system running cdr_addon_mysql could escape out of a SQL data field and create another query. A workaround is described in the advisory.

System: Sun StorageTek 3510 FC Array
Topic: Vulnerability in FTP
Links: SUN Alert #103106, ESB-2007.0798
ID: ae-200710-057

A security vulnerability in the firmware FTP service of the Sun StorEdge 3510 FC Array may allow a remote unprivileged user who has access to the management network to which the array's management Ethernet interface is connected, to make the array unresponsive to data services. Fixed firmware is available now.

System: Red Hat Enerprise Linux
Topic: Vulnerabilities in java-1.5.0-bea
Links: RHSA-2007-0956, CVE-2007-0243, CVE-2007-2788, CVE-2007-2789, CVE-2007-3004, CVE-2007-3005, CVE-2007-3503, CVE-2007-3698, CVE-2007-4381, ESB-2007.0797
ID: ae-200710-056

Several vulnerabilities wer found in the BEA WebLogic JRockit JRE and SDK. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in IBM DB2
Links: ESB-2007.0793
ID: ae-200710-055

Several vulnerabilitiesy were found in the IBM DB2 Universal Database. Patches are available now.

System: Sun Solaris
Topic: Vulnerabilities in libtiff, mozilla, and librpcsvc
Links: SUN Alert #103099, CVE-2006-2193, CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, ESB-2007.0790,
SUN Alert #102943, CVE-2006-2779, CVE-2006-2780, ESB-2007.0791,
SUN Alert #103082, ESB-2007.0792
ID: ae-200710-054

Multiple security vulnerabilities in the Solaris Tag Image File Format library (libtiff(3)) may allow a local or remote unprivileged user to crash applications that dynamically link to the "libtiff" library and execute arbitrary code with the privileges of a local user.
A number of memory corruption vulnerabilities have been found in the Mozilla application.
A security vulnerability in the Solaris RPC services library (librpcsvc(3LIB)) may allow a local unprivileged user to crash the automountd(1M) daemon on a system.
Patches are available now.

System: Debian/GNU Linux
Topic: Vulnerability in librpcsecgss
Links: DSA-1387, CVE-2007-4743, ESB-2007.0795, S-014
ID: ae-200710-053

It has been discovered that the original patch for a buffer overflow in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (CVE-2007-3999, DSA-1368-1) was insufficient to protect from arbitrary code execution in some environments. Fixed packages are available now.

System: Cisco IOS
Topic: Vulnerability in Cisco IOS LPD
Links: Cisco, VU#230505, S-013
ID: ae-200710-052

The Cisco IOS Line Printer Daemon contains a buffer overflow vulnerability when checking the hostname of the router. If successfully exploited by e.g. using SNMP, this vulnerability may allow a remote attacker to execute arbitrary code or create a Denial-of-Service condition. Updated software solves this problem.

System: SuSE Linux
Topic: Vulnerabilities in TK GIF image loader, OpenSSL, hugin, lighttpd, novess-groupwise-client, and sylpheed-claws
Links: SUSE-SR:2007:020
ID: ae-200710-051

A SUSE Security Summary reports vulnerabilities in the packages TK GIF image loader, OpenSSL, hugin, lighttpd, novess-groupwise-client, and sylpheed-claws. Updated packages are available now and should be installed on vulnerable systems.

System: SUSE Linux, openSUSE, UnitedLinux, Novell Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2007:053, CVE-2006-4145, CVE-2006-6106, CVE-2007-0773, CVE-2007-2525, CVE-2007-2875, CVE-2007-2876, CVE-2007-3105, CVE-2007-3107, CVE-2007-3513, CVE-2007-3848, CVE-2007-3851, CVE-2007-4571, CVE-2007-4573
ID: ae-200710-050

Several local vulnerabilities have been discovered in the Linux kernel that may lead to a Denial-of-Service or the execution of arbitrary code with elevated rights. An updated package remedies these problems.

System: SUSE Linux, openSUSE
Topic: Vulnerabilities in XORG Server
Links: SUSE-SA:2007:054, CVE-2007-4730, CVE-2007-4989, CVE-2007-4990
ID: ae-200710-049

The Xorg server shows vulnerabilities in the X FontServer. These are an Integer Overflow and an Heap Overflow vulnerabilites. Additionally, a buffer overflow exists in the Composite extension. These can be exploited by logged in users to potentially execute code in the X server or xfs, which are running as root. So it's recommended to install patches, which are available now.

System: Various
Topic: Vulnerabilities in FLAC Library
Links: iDEFENSE #608, CVE-2007-4619, FLAC, RHSA-2007-0975, ESB-2007.0826
ID: ae-200710-048

Free Lossless Audio Codec (FLAC) is a popular file format for audio data compression. AOL Corp.'s Winamp media player has support for the FLAC format. Remote exploitation of multiple integer overflow vulnerabilities in libFLAC, as included with various vendor's software distributions, allows attackers to execute arbitrary code in the context of the curre These vulnerabilities specifically exist in the handling of malformed FLAC media files. In each case, an integer overflow can occur while calculating the amount of memory to allocate. As such, insufficient memory is allocated for the data that is subsequently read in from the file, and a heap based buffer overflow occurs. The FLAC maintainers have released version 1.2.1 of FLAC to address these vulnerabilities.

System: Microsoft Windows
Topic: Vulnerabilities in CA BrightStor ARCserve Backup
Links: CA, CVE-2007-5325, CVE-2007-5326, CVE-2007-5327, CVE-2007-5328, CVE-2007-5329, CVE-2007-5330, CVE-2007-5331, CVE-2007-5332, ESB-2007.0786
ID: ae-200710-047

A remote vulnerability in CA BrightStor ARCserve Backup Server allows an attacker to execute arbitrary code as SYSTEM without any user interaction. The exploit is extremely reliable and can be successfully delivered either across the Internet or within local networks via a random TCP port that is disclosed by the BrightStor portmapper service on TCP/111. Computer Associates has released patches for these vulnerabilities.

System: Various
Topic: Vulnerability in HP Select Identity
Links: HPSBMA02230, SSRT071436, ESB-2007.0785
ID: ae-200710-046

A potential security vulnerability has been identified with HP Select Identity. The vulnerability could be exploited to allow remote unauthorized access. HP has provided software patches to resolve the vulnerability. Please contact HP Support to receive the patches.

System: HP-UX
Topic: Further vulnerabilities in Apache for HP-UX solved
Links: HPSBUX02273, SSRT071476, CVE-2007-3847, CVE-2007-3304, ESB-2007.0784
ID: ae-200710-045

A potential security vulnerability has been identified with HP-UX Apache version 2.0.59. The vulnerability could be exploited remotely to create a Denial-of-Service (DoS). An updated package has been published by HP now, it should be installed soon.

System: Various
Topic: Vulnerabilities in Tomcat
Links: CVE-2007-1358, CVE-2007-2449, CVE-2007-2450, CVE-2007-3382, CVE-2007-3385, CVE-2007-3386, RHSA-2007-0876, ESB-2007.0783, HPSBTU02276 SSRT071472, ESB-2007.0799, RHSA-2007-0950, ESB-2007.0865
ID: ae-200710-044

Tomcat is a servlet container for Java Servlet and Java Server Pages technologies. It shows some possibilities for Cross-Site Scripting and therefore also access to confidential data. Exploiting these vulnerabilities do not require a local account. Updated packages solve these problems.

System: Red Hat Enerprise Linux 2.1
Topic: Vulnerabilities in libvorbis
Links: RHSA-2007-0912, CVE-2007-4066, CVE-2007-4065, CVE-2007-4029, CVE-2007-3106, ESB-2007.0782
ID: ae-200710-043

The libvorbis package contains runtime libraries for use in programs that support Ogg Voribs. Ogg Vorbis is a compressed audio format. Several flaws were found in the way libvorbis processea audio data. An attacker could create a carefully crafted OGG audio file in such a way that it could cause an application linked with libvorbis to crash or execute arbitrary code when it was opened. A fixed package is available now.

System: Unix / Linux
Topic: Vulnerability in hplip
Links: CVE-2007-5208, RHSA-2007-0960, S-012, ESB-2007.0781, MDKSA-2007:201
ID: ae-200710-042

The hplip (Hewlett-Packard Linux Imaging and Printing Project) package provides drivers for HP printers and multi-function peripherals. A flaw in the way the hplip hpssd daemon handles user input has been found. A local attacker could send a specially crafted request to the hpssd daemon, possibly allowing them to run arbitrary commands as the root user. For some systems an update is available now.

System: Sun Solaris 10
Topic: Vulnerability in BSM
Links: SUN Alert #103096, ESB-2007.0779
ID: ae-200710-041

A security vulnerability in the Solaris Auditing (BSM) included with Sun Solaris 10 may allow a local unprivileged user to cause a system panic on hosts which are configured to audit networking events. This will result in a Denial-of-Service (DoS) to the system as a whole. A patch solves this problem.

System: Various
Topic: Several vulnerabilities in VMware fixed
Links: VMSA-2007-0006, CVE-2006-4146, CVE-2006-3619, CVE-2007-1716, CVE-2004-0813, CVE-2006-4600, CVE-2006-1174, CVE-2007-1856, CVE-2007-4497, CVE-2007-4496, CVE-2007-4155, CVE-2007-4059, CVE-2007-0063, CVE-2007-0062, CVE-2007-0061, CVE-2007-2798, CVE-2007-2443, CVE-2007-2442, CVE-2007-0494, CVE-2007-2447, CVE-2007-2446, CVE-2007-4496, S-011
ID: ae-200710-040

Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player are available now. They fix possibilities for Denial-of-Service as well as remote code execution. So it's recommended to install the updates which are available now.

System: Microsoft Windows
Topic: Vulnerability in Kaspersky Lab Online Virus Scanner
Links: Kaspersky, iDEFENSE #606, CVE-2007-3675, ESB-2007.0777
ID: ae-200710-039

Kaspersky Lab Online Virus Scanner is a free online virus scanner service, enabling a user to scan their system for malicious code via their Web browser. Remote exploitation of a format string vulnerability in this virus scanner service could allow an attacker to execute arbitrary code within the security context of the targeted user. The reason is a vulnerable ActvieX Control. For further information, please refer to the advisory. Kaspersky Online Scanner version 5.0.98.0 corrects the high-risk vulnerability.

System: HP-UX
Topic: Vulnerabilities in Apache for HP-UX solved
Links: HPSBUX02181, SSRT061289, ESB-2007.0036
ID: ae-200710-038

Very many, mostly known vulnerabilities in Apache can be fixed now for this web server running on HP-UX. Since there are some critical vulnerabilities, an instant update is recommended.

System: Sun Solaris
Topic: Vulnerability in Solaris Trusted Extensions
Links: SUN Alert #103109, ESB-2007.0772
ID: ae-200710-037

Two Security Vulnerabilities in Solaris Trusted Extensions label daemon (labeld) may allow a local unprivileged user to stop Trusted Extensions services from running on a system. A patch is available now.

System: Sun Solaris
Topic: Vulnerability in Virtual File System
Links: SUN Alert #103088, ESB-2007.0771
ID: ae-200710-036

A security vulnerability in the Solaris 10 Virtual File System (VFS) may allow a local unprivileged user to exhaust all kernel memory, thereby causing a Denial of Service (DoS) to the system as a whole. A patch is available now.

System: Various
Topic: Vulnerability in HP System Management Homepage
Links: HPSBMA02274 SSRT071445, ESB-2007.0774, S-186
ID: ae-200710-035

Several security vulnerabilities have been identified HP System Management Homepage (SMH). These vulnerabilities could by exploited remotely to allow cross site scripting (XSS. Fixed software is available now.

System: Various
Topic: Vulnerability in Asterisk
Links: ASA-2007-022, ESB-2007.0770
ID: ae-200710-034

Two buffer overflows were found in the IMAP code of Asterisk. Fixed software is not available yet.

System: Various
Topic: Vulnerabilities in Adobe Illustrator CS3 and GoLive
Links: APSB07-16, APSB07-17, CVE-2007-2244, CVE-2007-2365, ESB-2007.0787
ID: ae-200710-033

Critical vulnerabilities have been identified in Illustrator CS3 and GoLive that could allow an attacker who successfully exploits these vulnerabilities to take control of the affected system. Patches are available now.

System: Microsoft Windows
Topic: Vulnerability in Adobe PageMaker
Links: APSB07-15, CVE-2007-5169, ESB-2007.0787
ID: ae-200710-032

A critical vulnerability has been identified in Adobe PageMaker that could allow an attacker who successfully exploits this vulnerability to take control of the affected system. Patches are available now.

System: CiscoWorks
Topic: Vulnerability in Cisco Wireless Control System Conversion Utility
Links: Cisco, ESB-2007.0775
ID: ae-200710-031

Customers who use the CiscoWorks Wireless LAN Solution Engine (WLSE) may use a conversion utility to convert over to a Cisco Wireless Control System (WCS). This conversion utility creates and uses administrative accounts with default credentials. Workarounds are described in the advisory.

System: Debian/GNU Linux
Topic: Vulnerabilities in Kernel
Links: DSA-1381, CVE-2007-4133, CVE-2007-4573, CVE-2007-5093, CVE-2007-5755, ESB-2007.0744
ID: ae-200710-030

Several local vulnerabilities have been discovered in the Linux kernel that may lead to a Denial-of-Service or the execution of arbitrary code. An updated package remedies these problems.

System: Sun Solaris
Topic: Vulnerability in vuidmice STREAMS Module
Links: SUN Alert #103065, ESB-2007.0768
ID: ae-200710-029

A security vulnerability in the vuidmice(7M) STREAMS modules may allow a local unprivileged user who has access to the system console device (console(7D)) to render the console unusable, which is a type of Denial-of-Service (DoS). A patch addresses this issue for all supported versions of Sun Solaris.

System: OpenBSD
Topic: Vulnerability in dhcpd
Links: OpenBSD_42_001, ESB-2007.0767
ID: ae-200710-028

A DHCP client with a carefully chosen maximum message size that is less than the minimum IP MTU could lead to a buffer overflow in dhcpd(8). This could cause the dhcpd to crash or could potentially result in remote code execution. This problem is specific for OpenBSD. Patches are available for OpenBSD 4.2, 4.1 and 4.0.

System: Microsoft Windows / Mac OS X
Topic: Vulnerability in Microsoft Word 2000/2002
Links: MS07-060, CVE-2007-3899, ESB-2007.0764, S-008
ID: ae-200710-027

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Windows SharePoint Services 3.0 and Office SharePoint Server 2007
Links: MS07-059, CVE-2007-2581, ESB-2007.0766, S-007
ID: ae-200710-026

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in RPC
Links: MS07-058, CVE-2007-2228, ESB-2007.0765, S-009
ID: ae-200710-025

No further comment due to legal reasons

System: Microsoft Windows
Topic: Cumulative security update for Microsoft Internet Explorer
Links: MS07-057, CVE-2007-3892, CVE-2007-3893, AL-2007.0116, S-006
ID: ae-200710-024

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Mail and Outlook Express
Links: MS07-056, CVE-2007-3897, iDEFENSE #607, S-005, AL-2007.0115
ID: ae-200710-023

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Kodak Image Viewer
Links: MS07-055, CVE-2007-2217, VU#180345, S-004, ESB-2007.0763
ID: ae-200710-022

No further comment due to legal reasons

System: Red Hat Enerprise Linux
Topic: Vulnerabilities in pwlib and opal
Links: RHSA-2007-0932, CVE-2007-4897, ESB-2007.0761,
RHSA-2007-0957, CVE-2007-4924, ESB-2007.0762
ID: ae-200710-021

A memory management flaw was discovered in PWLib. An attacker could use this flaw to crash an application, such as Ekiga, which is linked with pwlib
A flaw was discovered in the way opal handled certain Session Initiation Protocol (SIP) packets. An attacker could use this flaw to crash an application, such as Ekiga, which is linked with opal.
Fixed packages are available now.

System: Microsoft Windows XP
Topic: Vulnerability in Adobe Acrobat and Reader
Links: APSA07-04, CVE-2007-5020
ID: ae-200710-020

On Microsoft Windows XP Systems, that have Internet Explorer 7 installed, handling of "mailto:" URIs by Adobe Acrobat and Reader leady to unexpected results. A workaround is described in the advisory.

System: Red Hat Enerprise Linux
Topic: Vulnerabilities in kdebase and kdelibs
Links: RHSA-2007-0905, RHSA-2007-0905, CVE-2007-0242, CVE-2007-0537, CVE-2007-1308, CVE-2007-1564, CVE-2007-3820, CVE-2007-4224 CVE-2007-4569, ESB-2007.0759, ESB-2007.0760
ID: ae-200710-019

Several flaws were found in the packages 'kdebase' and 'kdelibs' of the K Desktop Environment (KDE). Fixed packages are available now.

System: Debian/GNU Linux
Topic: Vulnerabilities in gforge and xen-utils
Links: DSA-1383, CVE-2007-3918, ESB-2007.0756,
DSA-1384, CVE-2007-1320, CVE-2007-4993, ESB-2007.0757
ID: ae-200710-018

GForge is a collaborative development tool. Exploiting a Cross-Site Scripting vulnerability, it allows remote attackers to inject arbitrary web script or HTML in the context of a logged in user's session.
Several local vulnerabilities have been discovered in the Xen hypervisor packages which may lead to the execution of arbitrary code.
Updated packages are available now.

System: Various
Topic: Vulnerabilities in Sun Java JDK / JRE
Links: Sun Alert #103071, ESB-2007.0751,
Sun Alert #103072, ESB-2007.0752,
Sun Alert #103073, ESB-2007.0753,
Sun Alert #103078, ESB-2007.0754,
Sun Alert #103079, ESB-2007.0755, VU#336105, S-003, RHSA-2007-0963, ESB-2007.0789
ID: ae-200710-017

The Java Runtime Environment (JRE) may allow untrusted applets or applications to display an oversized window so the warning banner is not visible to the user. Some security vulnerabilities in Java Runtime Environment may allow network access restrictions to be circumvented.
An untrusted Java Web Start Application or Java Applet may move or copy arbitrary files by requesting the user to drag and drop a file from application or applet window to a desktop application. Further on, multiple security vulnerabilities in Java Web Start have been found regarding local file access.
It's recommended to upgrade to the latest version.

System: Unix / Linux
Topic: Vulnerability in Drupal
Links: DRUPAL-SA-2007-017, DRUPAL-SA-2007-018, ESB-2007.0750
ID: ae-200710-016

Drupal is an open source content management platform. Some vulnerabilities concerning Cross-Site Scripting have been found. Additionally cross site requests might be possible as well as remotely overwriting arbitrary files. New versions fix these problems.

System: Microsoft Windows
Topic: Vulnerability in Apple QuickTime 7.2 for Windows
Links: APPLE-SA-2007-10-03, CVE-2007-4673, ESB-2007.0748
ID: ae-200710-015

A command injection issue has been found in Apple QuickTime's handling of URLs in the qtnext field in files with QTL content. By enticing a user to open a specially crafted file, an attacker may cause an application to be launched with controlled command line arguments, which may lead to arbitrary code execution. A security update addresses the issue through improved handling of URLs. Mac OS X systems are not affected by this problem.

System: Debian/GNU Linux
Topic: Vulnerabilities in Kernel
Links: DSA-1381, CVE-2007-4133, CVE-2007-4573, CVE-2007-5093, CVE-2007-5755, ESB-2007.0744
ID: ae-200710-014

Several local vulnerabilities have been discovered in the Linux kernel that may lead to a Denial-of-Service or the execution of arbitrary code. An updated package remedies these problems.

System: Various
Topic: Vulnerabilities in OpenSSL
Links: CVE-2007-3108, CVE-2007-5135, MDKSA-2007:193, DSA-1379, ESB-2007.0740, S-001, FreeBSD-SA-07:08, ESB-2007.0749, OpenBSD, ESB-2007.0780, RHSA-2007-0964, ESB-2007.0788, RHSA-2007-0813, TLSA-2007-52
ID: ae-200710-013

An off-by-one error has been identified in the SSL_get_shared_ciphers() routine in the libssl library from OpenSSL, an implementation of Secure Socket Layer cryptographic libraries and utilities. This error could allow an attacker to crash an application making use of OpenSSL's libssl library, or potentially execute arbitrary code in the security context of the user running such an application. Additionally, in some implementations a flaw in how OpenSSL performed Montgomery multiplications has been discovered. This could allow a local attacker to reconstruct RSA private keys by examining another user's OpenSSL processes. Updated packages are available for some systems.

System: Sun Solaris
Topic: Vulnerability in Solaris Named Pipes
Links: SUN Alert #103061, iDEFENSE #603, ESB-2007.0745
ID: ae-200710-012

A security vulnerability in the Solaris Named Pipes (pipe(2)) may allow a local unprivileged user to gain access to unauthorized memory locations. This may allow a local unprivileged user to read potentially sensitive data in the kernel's memory layout or in the memory layouts of other processes running on the system. A patch addresses this issue.

System: Debian/GNU Linux
Topic: Vulnerability in quagga
Links: DSA-1382, CVE-2007-4826, ESB-2007.0746
ID: ae-200710-011

The bgpd daemon in Quagga allowes remote BGP peers to cause a denial of service crash via a malformed OPEN message or COMMUNITY attribute. Fixed packages are available now.

System: Turbolinux
Topic: Vulnerabilities in httpd
Links: TLSA-2007-48, CVE-2007-3304, CVE-2007-3847
ID: ae-200710-010

Two vulnerabilities discovered in Prefork MPM module and mod_proxy of Apache. Fixed packages solve these problems.

System: Various
Topic: Vulnerabilities in X Font Server
Links: iDEFENSE #602, CVE-2007-4568, ESB-2007.0743, DSA-1385, S-010, Sun Alert #103114, ESB-2007.0778
ID: ae-200710-009

Remote exploitation of a multiple vulnerabilities in X.Org Foundation's X Font Server, as included in various vendors' operating system distributions, could allow an attacker to execute arbitrary code. Fixed software is available now.

System: Various
Topic: Vulnerability in elinks
Links: CAN-2007-5034, S-002, DSA-1380, ESB-2007.0742, RHSA-2007:0933, ESB-2007.0747
ID: ae-200710-008

It was discovered that elinks, an advanced text-mode WWW browser, sent HTTP POST data in cleartext when using an HTTPS proxy server potentially allowing private information to be disclosed. New releases fix this vulnerability.

System: Red Hat Enerprise Linux
Topic: Vulnerabilities in xen and nfs-utils-lib
Links: RHSA-2007-0323, CVE-2007-1320, CVE-2007-1321 CVE-2007-4993, ESB-2007.0741,
RHSA-2007-0951, CVE-2007-3999, CVE-2007-4135, ESB-2007.0711
ID: ae-200710-007

Several flaws were found in the Xen virtual machine monitor.
A stack buffer overflow flaw was discovered in the RPC library used by nfs-utils-lib. A remote unauthenticated attacker who can access an application linked against nfs-utils-lib could trigger this flaw and cause the application to crash.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in libsndfile and mplayer
Links: MDKSA-2007:191, CVE-2007-4974,
MDKSA-2007:192, CVE-2007-4938
ID: ae-200710-006

A heap-based buffer overflow in libsndfile could allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data which contains a block with a size exceeding that of the previous block. The same may also happen when specially crafted .avi files are opened with the mplayer. Fixed packages solve these problems.

System: SuSE Linux
Topic: Vulnerabilities in star, cpio, emacs, krb5, pptpd, mysql, qt3, balsa, and id3lib
Links: SUSE-SR:2007:019
ID: ae-200710-005

A SUSE Security Summary reports vulnerabilities in the packages star, cpio, emacs, krb5, pptpd, mysql, qt3, balsa, and id3lib. Updated packages are available now and should be installed on vulnerable systems.

System: All
Topic: Vulnerability in Google Gmail fixed
Links: VU#571584, GNUCITIZEN
ID: ae-200710-004

Google Gmail is a web based mail service. According to a report on the GNUCITIZEN site, Gmail contained a cross-site request forgery (XSRF) vulnerability that allowed attackers to create mail filters and forward mail to arbitrary email addresses. So a remote attacker could have collected email addresses, emails, and attachments from a user's Gmail account. To exploit this vulnerability, an attacker would have had to convince a user to click or open a specially crafted hyperlink while the user was logged into their Gmail account. Google has addressed this vulnerability.

System: Sun Fire X2100 / X2200 M2 Server
Topic: Vulnerability in Sun Fire X2100 M2/X2200 M2 ELOM
Links: SUN Alert #102942, ESB-2007.0739
ID: ae-200710-003

A security vulnerability in the X2100 and X2200 M2 Embedded Lights Out Manager (ELOM) software may allow remote unprivileged users the ability to initiate unauthorized network traffic from the embedded service processor (SP). This may allow the SP to be used as a proxy to send unsolicited bulk e-mail (spam). Fixed Firmware is available now.

System: Various
Topic: Vulnerabilities in Sun Java System Access Manager
Links: Sun Alert 103069, ESB-2007.0737
ID: ae-200710-002

Two vulnerabilities were found when Sun Java System Access Manager is installed in a Sun Java System Application Server container. A patch is not available yet. A workaround is described in the advisory.

System: Various
Topic: Vulnerability in OpenSSL
Links: CAN-2007-5135, ESB-2007.0738, DSA-1379, ESB-2007.0740, S-001, FreeBSD-SA-07:08, ESB-2007.0749, MDKSA-2007:193
ID: ae-200710-001

A vunerability was found in openssl, which may result in the remote execution of code from via a off-by-one buffer overflow in the SSL_get_shared_ciphers function. New releases fix this vulnerability.



(c) 2000-2013 AERAsec Network Services and Security GmbH