Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-50-16-36-153.compute-1.amazonaws.com [50.16.36.153]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 06 / 2008

System: Red Hat Enterprise Linux 3 / 4
Topic: Vulnerabilities in components for Red Hat Network
Links: RHSA-2008-0523, ESB-2008.0656,
RHSA-2008-0524, ESB-2008.0657,
RHSA-2008-0525, ESB-2008.0658
ID: ae-200806-065

Red Hat Network Proxy Server as well as Red Hat Network Satellite Server version 4.2.3 is available now. The update includes fixes for a number of security issues in Red Hat Network Proxy Server, Satellite Server and in Red Hat Network Satellite Server Solaris client components.

System: Many
Topic: Vulnerability in phpMyAdmin
Links: PMASA-2008-4, ESB-2008.0661
ID: ae-200806-064

A XSS vulnerability has been found in phpMyAdmin. Cross-Site Scripting can be carried out when the PHP installation itself is insecure, e.g. register_globals is set to "on". It's recommended to upgrade to version 2.11.7.

System: Sun Solaris
Topic: Vulnerability in snmpXdmid
Links: Sun Alert #237985, ESB-2008.0654
ID: ae-200806-063

A security vulnerability in the Sun Solstice Enterprise SNMP-DMI mapper subagent daemon (snmpXdmid(1M)) running on Solaris may allow a local or remote unprivileged user to kill the daemon process by sending malformed packets, leading to a Denial-of-Service (DoS). A patch is available now.

System: Various
Topic: Vulnerabilities in Sun Java System Access Manager
Links: Sun Alert #201538, ESB-2008.0653
ID: ae-200806-062

The Sun Java System Access Manager may not securely process XSLT stylesheets which are contained inside XSLT Transforms in XML Signatures. A remote user who is able to create such an XML Signature which is viewed locally with Access Manager may be able to execute arbitrary code with the privileges of the Access Manager application. Fixed software is available now.

System: Various
Topic: Vulnerabilities in bzip2
Links: Sun Alert #200191, Sun Alert #103118, CVE-2005-0953, CVE-2005-1260, ESB-2008.0804
ID: ae-200806-061

Some time ago, two different vulnerabilities in bzip2 have been found. One of them may allow a user access to files when logs are rotated, if those logs are in a world writable directory. Log rotation is normally performed at a predictable time by root. Now fixes are available for Sun Solaris, too.

System: Many
Topic: Vulnerability in Squid 3.x
Links: SQUID-2008:1
ID: ae-200806-060

A bug exists in the ASN1 parser used in Squid's SNMP library of version 3.x, which has been fixed for earlier versions some years ago. The Squid code fails to fully validate certain fields in SNMP queries. A specially-crafted message may contain negative values, which Squid passes to the malloc() function. This may lead to a segmentation violation and cause Squid to restart. It's strongly recommended to upgrade Squid.

System: Microsoft Windows
Topic: Vulnerability in Internet Explorer
Links: CVE-2008-1573, CVE-2008-2306, CVE-2008-2307, CVE-2008-2540, VU#127185, ESB-2008.0635
ID: ae-200806-059

Microsoft Internet Explorer 6 is vulnerable to a cross-domain scripting violation, which can allow a remote, unauthenticated attacker to access the content of a web page in a different domain. Fixed software is not available yet.

System: Sun Solaris
Topic: Vulnerabilities in Adobe Reader
Links: Sun Alert #239286, CVE-2007-4768, CVE-2007-5659, CVE-2007-5666, CVE-2008-0655, CVE-2008-0667, CVE-2008-0726, CVE-2008-2042, ESB-2008.0651
ID: ae-200806-058

Multiple security vulnerabilities in the Adobe Reader may allow remote unprivileged users to execute arbitrary code with the permissions of the local user. A patch is not available yet.

System: Debian GNU/Linux
Topic: Vulnerability in dbus
Links: DSA-1599, CVE-2008-0595, ESB-2008.0650
ID: ae-200806-057

It was discovered that DBus, a simple interprocess messaging system, performs insufficient validation of security policies, which might allow local privilege escalation. Fixed packages are available now.

System: Turoblinux
Topic: Vulnerabilities in httpd
Links: TLSA-2008-24, CVE-2007-6203, CVE-2007-6420, CVE-2008-2364
ID: ae-200806-056

Several vulnerabilities were found in the Apache HTTP server. Fixed packages are available now.

System: Cisco
Topic: Vulnerabilities in Cisco Unified Communications Manager
Links: Cisco, CVE-2008-2061, CVE-2008-2062, CVE-2008-2730, ESB-2008.0649, S-330
ID: ae-200806-055

Cisco Unified Communications Manager (CUCM), formerly Cisco CallManager, contains a denial of service (DoS) vulnerability in the Computer Telephony Integration (CTI) Manager service that may cause an interruption in voice services and an authentication bypass vulnerability in the Real-Time Information Server (RIS) Data Collector that may expose information that is useful for reconnaissance. A software update remedies these problems.

System: Mandriva Linux
Topic: Vulnerability in imlib2
Links: MDVSA-2008:123, CVE-2008-2426
ID: ae-200806-054

Two buffer overflows were discovered in Imlib's image loaders for PNM and XPM images, which could possibly result in the execution of arbitrary code. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Adobe Reader and Acrobat
Links: APSB08-15, CVE-2008-2641, VU#788019, S-326.
Sun Alert #240106, ESB-2008.0770
ID: ae-200806-053

Adobe Reader and Acrobat contain an unspecified flaw in a JavaScript method, which can allow a remote, unauthenticated attacker to execute code on a vulnerable system. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in the Kernel
Links: RHSA-2008-0508, CVE-2008-0598, CVE-2008-1367, CVE-2008-2365, CVE-2008-2729, ESB-2008.0646, S-331
ID: ae-200806-052

Updated kernel packages that fix various known security issues and several bugs in the Red Hat Enterprise Linux 5 and 4 kernels are now available.

System: Red Hat Enterprise Linux 2.1
Topic: Vulnerabilities in IBMJava2
Links: RHSA-2008-0133, CVE-2007-3004, CVE-2007-3005, CVE-2007-3922, ESB-2008.0644, S-327
ID: ae-200806-051

Several vulnerabilities were found in the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in sblim
Links: RHSA-2008-0497, CVE-2008-1951, ESB-2008.0645, S-329
ID: ae-200806-050

It was discovered that certain sblim libraries had an RPATH (runtime library search path) set in the ELF (Executable and Linking Format) header. This RPATH pointed to a sub-directory of a world-writable, temporary directory. A local user could execute arbitrary code with the privileges of the user running an application that used sblim. Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in nasm and freetype2
Links: MDVSA-2008:119, CVE-2008-2696
ID: ae-200806-049

An off-by-one error was found in nasm 2.02 that allowes context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted file that triggers a stack-based buffer overflow.
Multiple vulnerabilities were discovered in FreeType's Printer Font Binary (PFB) font-file format parser. If a user were to load a carefully crafted font file with a program linked against FreeType, it could cause the application to crash or potentially execute arbitrary code.
Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Ruby
Links: Ruby, CVE-2008-1891, CVE-2008-2664, CVE-2008-2726, CVE-2008-2727, CVE-2008-2663, CVE-2008-2664, ESB-2008.0641
ID: ae-200806-048

Multiple vulnerabilities in Ruby may lead to a denial of service (DoS) condition or allow execution of arbitrary code. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in exiv2
Links: MDVSA-2008:119, CVE-2008-2696
ID: ae-200806-047

A flaw was found in exiv2 that would cause exiv2, or applictions linked to libexiv2, to crash on image files with certain metadata in the image. Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2008:030
ID: ae-200806-046

Several vulnerabilities in the kernel of openSUSE 10.2 and 10.3 have been found. They should be fixed now by intstalling the appropriate update.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in FreeType
Links: RHSA-2008-0556, CVE-2008-1806, CVE-2008-1807, CVE-2008-1808, ESB-2008.0639, S-328
ID: ae-200806-045

Multiple flaws were discovered in FreeType's Printer Font Binary (PFB) font-file format parser. If a user loaded a carefully crafted font-file with a program linked against FreeType, it could cause the application to crash, or possibly execute arbitrary code. Users of freetype should upgrade to updated packages which are available now.

System: Sun Solaris
Topic: Vulnerabilities in FreeType2
Links: Sun Alert #239006, CVE-2008-1806, CVE-2008-1807, CVE-2008-1808, ESB-2008.0637
ID: ae-200806-044

Multiple security vulnerabilities in the FreeType2 library for Printer Font Binary (PFB) or TrueType Font (TTF) format font files may lead to a denial of service (DoS) or allow execution of arbitrary code. A patch is not available yet.

System: Microsoft Windows
Topic: Vulnerabilities in Apple Safari for Windows
Links: CVE-2008-1573, CVE-2008-2306, CVE-2008-2307, CVE-2008-2540, VU#127185, ESB-2008.0635
ID: ae-200806-043

Several vulnerabilities were found in Apple Safari for Windows. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in fetchmail
Links: MDVSA-2008:117, CVE-2008-2711
ID: ae-200806-042

A flaw in fetchmail was discovered that allowed remote attackers to cause a denial of service (crash and persistent mail failure) via a malformed message with long headers. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in libtk-img
Links: DSA-1598, CVE-2008-0553, ESB-2008.0636
ID: ae-200806-041

It was discovered that a buffer overflow in the GIF image parsing code of Tk, a cross-platform graphical toolkit, could lead to denial of service and potentially the execution of arbitrary code. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Novell iPrint Client ActiveX
Links: VU#145313, ESB-2008.0629, S-321
ID: ae-200806-040

The Novell iPrint Client ActiveX control contains multiple stack buffer overflows, which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. A patch is available now.

System: Microsoft Windows
Topic: Vulnerability in Deterministic Network Enhancer
Links: VU#858993, ESB-2008.0630, S-322
ID: ae-200806-039

The Deterministic Network driver contains a privilege escalation vulnerability, which can allow a local attacker to execute code with kernel privileges. DNE is packaged with multiple applications, including the Cisco VPN Client. A patch is available now.

System: Microsoft Windows
Topic: Vulnerability in Adobe Flex 3
Links: APSB08-14, CVE-2008-2640, ESB-2008.0631
ID: ae-200806-038

A cross-site scripting vulnerability has been identified in code used by the Flex 3 History Management feature. Please note that this also affects applications that have been built using Flex. Fixed software is available now.

System: Cisco
Topic: Vulnerability in Cisco Intrusion Prevention System
Links: Cisco, CVE-2008-2060, ESB-2008.0627, S-319
ID: ae-200806-037

Certain Cisco IPS platforms contain a denial of service vulnerability in the handling of jumbo ethernet frames. When a specific series of jumbo Ethernet frames is received on a gigabit network interface of a vulnerable Cisco IPS platform that is deployed in inline mode, a kernel panic may occur that results in the complete failure of the platform and causes a network denial of service condition. Cisco has made free upgrade software available to address these vulnerabilities for affected customers.

System: HP Network Appliance
Topic: Vulnerabilities in HP Storage Management Appliance
Links: HPSBST02344 SSRT080087, ESB-2008.0625
ID: ae-200806-036

Various potential security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Some of these vulnerabilities may be pertinent to the SMA, please check the information in the advisory.

System: VMWare ESX Server
Topic: Vulnerabilities in Tomcat and Java JRE
Links: ESB-2008.0623
ID: ae-200806-035

Several vulnerabilities were found in the Tomcat and Java JRE software, that is part of VMare ESX Server. Patches are available now.

System: Turbolinux
Topic: Vulnerabilities in cups, krb5, openssh, and samba
Links: TLSA-2008-19.txt,
TLSA-2008-20.txt, CVE-2008-0062, CVE-2008-0063, CVE-2008-0947, CVE-2008-0948,
TLSA-2008-21.txt, CVE-2008-1657,
TLSA-2008-22.txt, CVE-2008-1105
ID: ae-200806-034

Several vulnerabilities were found in the packages cups, krb5, openssh, and samba of Turbolinux. Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in Mozilla Thunderbird, Mozilla xulrunner181, tkimg, cups, qemu, gstreamer010, pna, and libxslt
Links: SUSE-SR:2008:013
ID: ae-200806-033

A SUSE Security Summary reports about vulnerabilities in the packages Mozilla Thunderbird, Mozilla xulrunner181, tkimg, cups, qemu, gstreamer010, pna, and libxslt. Updated packages are available now and should be installed on vulnerable systems.

System: Sun Solaris 10
Topic: Vulnerabilities in Event Port Implementation, Kernel, and Fibre Channel Device Drivers
Links: Sun Alert #235122, ESB-2008.0612,
Sun Alert #238688, ESB-2008.0614,
Sun Alert #238630, ESB-2008.0616
ID: ae-200806-032

Several vulnerabilities were found in Sun Solaris. Affected are the vent Port Implementation, Kernel, and Fibre Channel Device Drivers. Patches are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in OpenOffice
Links: RHSA-2008-0537, RHSA-2008-0538, CVE-2008-2152, CVE-2008-2366, ESB-2008.0617
ID: ae-200806-031

A heap overflow flaw in the OpenOffice memory allocator. If a carefully crafted file was opened by a victim, an attacker could use the flaw to crash OpenOffice.org or, possibly, execute arbitrary code. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in typo3 and mt-daapd
Links: DSA-1596, ESB-2008.0610,
DSA-1597, CVE-2007-5824, CVE-2007-5825, CVE-2008-1771, ESB-2008.0611
ID: ae-200806-030

Because of a not sufficiently secure default value of the TYPO3 configuration variable fileDenyPattern, authenticated backend users could upload files that allowed to execute arbitrary code as the webserver user.
Three vulnerabilities have been discovered in the mt-daapd DAAP audio server (also known as the Firefly Media Server).
Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in perl
Links: RHSA-2008-0522, RHSA-2008-0532, CVE-2008-1927, ESB-2008.0604, ESB-2008.0624
ID: ae-200806-029

A flaw was found in Perl's regular expression engine. A specially crafted regular expression with Unicode characters could trigger a buffer overflow, causing Perl to crash, or possibly execute arbitrary code with the privileges of the user running Perl. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in X.org X server and XFree86
Links: iDefense, iDefense, iDefense, iDefense, iDefense, CVE-2008-1377, CVE-2008-1379, CVE-2008-2360, CVE-2008-2361, CVE-2008-2362, DSA-1595, ESB-2008.0601, S-325, RHSA-2008-0502, RHSA-2008-0503, RHSA-2008-0504, ESB-2008.0602, ESB-2008.0603, SUSE-SA:2008:027, MDVSA-2008:116, Sun Alert 238686, ESB-2008.0620
ID: ae-200806-028

Multiple vulnerabilities were found in the X.org and XFree86 X servers. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in imlib2
Links: DSA-1594, CVE-2008-2426, ESB-2008.0600, S-323
ID: ae-200806-027

Two buffer overflows were discovered in Imlib's - a powerful image loading and rendering library - image loaders for PNM and XPM images, which may result in the execution of arbitrary code. Fixed packages are available now.

System: Various
Topic: Vulnerability in SNMP Version 3 Authentication
Links: VU#878044, CVE-2008-0960, RHSA-2008-0528, RHSA-2008-0529, ESB-2008.0594, Cisco, ESB-2008.0593, S-315, Sun Alert 238865, ESB-2008.0622, MDVSA-2008:118
ID: ae-200806-026

A flaw was found in the way various SNMP implementations check an SNMPv3 packet's Keyed-Hash Message Authentication Code (HMAC). An attacker could use this flaw to spoof an authenticated SNMPv3 packet. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Pragmatic General Multicast
Links: MS08-036, CVE-2008-1440, CVE-2008-1441, ESB-2008.0598
ID: ae-200806-025

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Active Directory
Links: MS08-035, CVE-2008-1445, ESB-2008.0597
ID: ae-200806-024

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft WINS
Links: MS08-034, CVE-2008-1451, AA-2008.0128, S-313
ID: ae-200806-023

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft DirectX
Links: MS08-033, CVE-2008-0011, CVE-2008-0011, AL-2008.0076, S-312
ID: ae-200806-022

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Speech API
Links: MS08-032, CVE-2007-0675, ESB-2008.0609
ID: ae-200806-021

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer
Links: MS08-031, CVE-2008-1442, CVE-2008-1544, AL-2008.0075, S-311
ID: ae-200806-020

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Bluetooth Stack
Links: MS08-030, CVE-2008-1453, AL-2008.0074, S-314
ID: ae-200806-019

No further comment due to legal reasons

System: SuSE Linux
Topic: Vulnerabilities in xine, xemacs, emacs, opensuse-updater, libvorbis, vorbis-tools, pdns-recursor, and openswan
Links: SUSE-SR:2008:012
ID: ae-200806-018

A SUSE Security Summary reports vulnerabilities in the packages xine, xemacs, emacs, opensuse-updater, libvorbis, vorbis-tools, pdns-recursor, and openswan. Updated packages are available now and should be installed on vulnerable systems.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in net-snmp and ucd-snmp
Links: RHSA-2008-0528, RHSA-2008-0529, VU#878044, CVE-2008-0960, CVE-2008-2292, ESB-2008.0594
ID: ae-200806-017

A flaw was found in the way Net-SNMP checked an SNMPv3 packet's Keyed-Hash Message Authentication Code (HMAC). An attacker could use this flaw to spoof an authenticated SNMPv3 packet. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in tomcat5.5
Links: DSA-1593, CVE-2008-1947, ESB-2008.0591
ID: ae-200806-016

It was discovered that the Host Manager web application performed insufficient input sanitising, which could lead to cross-site scripting. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in the kernel
Links: DSA-1592, CVE-2008-1673, CVE-2008-2358, ESB-2008.0590
ID: ae-200806-015

Two vulnerabilities have been discovered in the Linux kernel 2.6. Fixed kernel packages are available now.

System: Sun Solaris 10
Topic: Vulnerability in svccfg
Links: Sun Alert #235681, ESB-2008.0589
ID: ae-200806-014

With Certain Solaris 10 patches installed, svccfg(1M) may remove External Dependencies and leave the system Unbootable. A patch is available now.

System: Microsoft Windows
Topic: Vulnerability in HP StorageWorks Storage Mirroring Software
Links: HPSBST02312, SSRT071428, CVE-2008-1661, S-308, ESB-2008.0578
ID: ae-200806-013

A potential security vulnerability has been identified in HP StorageWorks Storage Mirroring (SWSM) Software. This vulnerability could allow remote execution of arbitrary code. HP has made an update available, so this problem can be solved.

System: Microsoft Windows
Topic: Vulnerabilities in HP Instant Support
Links: HPSBMA02326 SSRT071490, CVE-2007-5604, CVE-2007-5605, CVE-2007-5606, CVE-2007-5607, CVE-2007-5608, CVE-2007-5610, CVE-2008-0952, CVE-2008-0953, AL-2008.0070, VU#998779, VU#857539, VU#949587, VU#190939, VU#221123, VU#526131, VU#558163, VU#754403
ID: ae-200806-012

Several security vulnerabilities have been identified with ActiveX controls in HP Instant Support HPISDataManager.dll running on Microsoft Windows. The vulnerabilities could be remotely exploited to allow remote execution of arbitrary code. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in CA ETrust Secure Content Manager Gateway
Links: iDefense, Kaspersky, CVE-2008-1518, ESB-2008.0584
ID: ae-200806-011

A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates eTrust Secure Content Manager. Fixed software is available now.

System: Various
Topic: Vulnerabilities in Sun Java System Active Server Pages
Links: Sun Alert 238184, iDefense, iDefense, iDefense, iDefense, iDefense, iDefense, AL-2008.0069, CVE-2008-2401, CVE-2008-2402, CVE-2008-2403, CVE-2008-2404, CVE-2008-2405, CVE-2008-2406
ID: ae-200806-010

Multiple vulnerabilities were found in Sun Java System Active Server Pages. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in Kaspersky Internet Security
Links: iDefense, Kaspersky, CVE-2008-1518, ESB-2008.0584
ID: ae-200806-009

Local exploitation of a stack-based buffer overflow in Kaspersky Lab's Internet Security could allow an attacker to execute arbitrary code in the context of the kernel. Fixed software is available now.

System: Various
Topic: Vulnerabilities in VMware Products
Links: AL-2008.0067, iDefense, iDefense, CVE-2006-1721, CVE-2007-4772, CVE-2007-5378, CVE-2007-5671, CVE-2008-0062, CVE-2008-0063, CVE-2008-0553, CVE-2008-0888, CVE-2008-0948, CVE-2008-0967, CVE-2008-2097, CVE-2008-2100
ID: ae-200806-008

Multiple vulnerabilities were found in VMware products. Fixed software is available now.

System: Sun Solaris
Topic: Vulnerabilities in Flash Player, rpc.ypupdated, Service Tag Registry, and inet_network
Links: Sun Alert #238305, ESB-2008.0580,
Sun Alert #238365, ESB-2008.0581,
Sun Alert #238414, ESB-2008.0586,
Sun Alert #237505, ESB-2008.0588
ID: ae-200806-007

Several vulnerabilities were found in Sun Solaris. Affected are the Flash Player, rpc.ypupdated, Service Tag Registry, and inet_network() library function. Patches are available now.

System: Some
Topic: Vulnerabilities in Asterisk
Links: AST-2008-008, CVE-2008-2119 ESB-2008.0579,
AST-2008-009, CVE-2008-2543 ESB-2008.0587,
ID: ae-200806-006

During pedantic SIP processing the From header value is passed to the ast_uri_decode function to be decoded. In two instances it is possible for the code to cause a crash as the From header value is not checked to be non-NULL before being passed to the function.
The ooh323 channel driver provided in Asterisk Addons used a TCP connection to pass commands internally. The payload of these packets included addresses of memory which were to be freed after the command was processed. By sending arbitrary data to the listening TCP socket, one could cause an almost certain crash since the command handler would attempt to free invalid memory. This problem was made worse by the fact that the listening TCP socket was bound to whatever IP address was specified by the "bindaddr" option in ooh323.conf
Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in cups
Links: RHSA-2008-0498, CVE-2008-1722, ESB-2008.0582, S-310
ID: ae-200806-005

An integer overflow flaw leading to a heap buffer overflow was discovered in the Portable Network Graphics (PNG) decoding routines used by the CUPS image converting filters "imagetops" and "imagetoraster". An attacker could create a malicious PNG file that could possibly execute arbitrary code as the "lp" user if the file was printed. Fixed packages are available now.

System: Cisco
Topic: Vulnerabilities in Cisco ASA and Cisco PIX
Links: Cisco, CVE-2008-2055, CVE-2008-2056, CVE-2008-2057, CVE-2008-2058, CVE-2008-2059, AL-2008.0066, S-307
ID: ae-200806-004

Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. Four of them may lead to a denial of service (DoS) condition and the fifth vulnerability may allow an attacker to bypass control-plane access control lists (ACL). Cisco has made free upgrade software available to address these vulnerabilities for affected customers.

System: Linux
Topic: Vulnerabilities in evolution
Links: CVE-2008-1108, CVE-2008-1109, RHSA-2008-0514, RHSA-2008-0515, RHSA-2008-0516, RHSA-2008-0517, ESB-2008.0583, S-309, SUSE-SA:2008:028
ID: ae-200806-003

A flaw was found in the way Evolution parsed iCalendar timezone attachment data. If the Itip Formatter plug-in was disabled and a user opened a mail with a carefully crafted iCalendar attachment, arbitrary code could be executed as the user running Evolution. Additionaly a heap-based buffer overflow flaw was found in the way Evolution parsed iCalendar attachments with an overly long "DESCRIPTION" property string. If a user responded to a carefully crafted iCalendar attachment in a particular way, arbitrary code could be executed as the user running Evolution. Fixed packages are available now.

System: Sun Solaris
Topic: Vulnerability in Sun/Solaris Cluster
Links: Sun Alert #200200, ESB-2008.0573
ID: ae-200806-002

In rare cases, small appending writes to a file located on a Sun Cluster filesystem may result in some data that was written to be lost and replaced with random data. A patch is available now.

System: Many
Topic: Vulnerabilities in BIND
Links: ISC, CVE-2008-0122, ESB-2008.0571
ID: ae-200806-001

The ISC has published the DNS server BIND in version 9.5.0. This release also fixes some security related problems, so only this version should be used from now on.



(c) 2000-2013 AERAsec Network Services and Security GmbH