Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/1.0 (+http://www.commoncrawl.org/bot.html)

Your IP address

(no reverse DNS resolution) [38.107.191.87]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 07 / 2008

System: Various
Topic: Vulnerability in Drupal
Links: DRUPAL-SA-2008-046, ESB-2008.0752
ID: ae-200807-060

A vulnerability was found in Drupal. Fixed software is available now.

System: Various
Topic: Vulnerabilities in phpMyAdmin
Links: PMASA-2008-6, ESB-2008.0751
ID: ae-200807-059

Several vulnerabilities were found in phpMyAdmin. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in ffmpeg
Links: MDVSA-2008:157, CVE-2008-3162
ID: ae-200807-058

A vulnerability was found in how ffmpeg handled STR file demuxing. If a user were tricked into processing a malicious STR file, a remote attacker could execute arbitrary code with user privileges via applications linked against ffmpeg Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2008:038
ID: ae-200807-057

Several vulnerabilities have been found in the kernel of SUSE Linux Enterprise 10 have been found. Fixed kernel packages are available now.

System: Various
Topic: Vulnerability in Oracle/BEA Weblogic Server
Links: BEA, VU#716387, CVE-2008-3257, ESB-2008.0748, S-367
ID: ae-200807-056

Oracle Weblogic Server and Weblogic Express applicaiton servers can be integrated with the Apache webserver using the Weblogic Apache connector plugin (mod_wl). A buffer overflow exists in Weblogic Server and Weblogic Express due to the way that the Apache connector plugin handles specially crafted POST requests. A remote, unauthenticated attacker may be able to execute arbitrary code. Fixed software is available now.

System: VMware ESX Server
Topic: Vulnerabilities in VMware ESX
Links: CVE-2006-4814, CVE-2007-5001, CVE-2007-6151, CVE-2007-6206, CVE-2008-0007, CVE-2008-1105, CVE-2008-1367, CVE-2008-1375, CVE-2008-1669, ESB-2008.0747
ID: ae-200807-055

Serveral vulnerabilities were found in the VMware ESX Service Console. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in HP OpenView Internet Services
Links: HPSBMA02353, SSRT080066, CVE-2008-1667, ESB-2008.0746, ESB-2008.0749, iDEFENSE #728
ID: ae-200807-054

A vulnerability has been identified with HP OpenView Internet Services running Probe Builder. The vulnerability could be exploited remotely to create a Denial of Service (DoS). A successful exploit could cause the system running HP OpenView Internet Services to crash. Patches are available now.

System: NetApp
Topic: Vulnerabilities in NetApp Data ONTAP
Links: VU#329772, ESB-2008.0745
ID: ae-200807-053

NetApp Data ONTAP contains multiple vulnerabilities. The most severe of these vulnerabilities may allow an attacker to execute commands, view sensitive data, or cause a system to crash. Fixed maintenance releases are available now.

System: Mandriva Linux
Topic: Vulnerability in libpng
Links: MDVSA-2008:156, CVE-2008-1382
ID: ae-200807-052

A flaw was discovered in how libpng handles zero-length unknown chunks in PNG files, which could lead to memory corruption in applications that make use of certain functions. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerabilities in RealPlayer
Links: RealNetworks, ZDI-08-046, ZDI-08-047, CVE-2007-5400, CVE-2008-1309, CVE-2008-3064, CVE-2008-3066, VU#298651, VU#461187, ESB-2008.0744, RHSA-2008-0812, ESB-2008.0756, S-368
ID: ae-200807-051

Several vulnerabilities were found in the RealNetworks RealPlayer. RealNetworks has published a new version of the RealPlayer.

System: Debian GNU/Linux
Topic: Vulnerabilities in refpolicy, ruby1.9, and python 2.5
Links: DSA-1617, CVE-2008-1447, ESB-2008.0739,
DSA-1618, CVE-2008-2376, CVE-2008-2662, CVE-2008-2663, CVE-2008-2664, CVE-2008-2725, CVE-2008-2726, ESB-2008.0740,
DSA-1620, CVE-2007-2052, CVE-2007-4965, CVE-2008-1679, CVE-2008-1721, CVE-2008-1887, ESB-2008.0742
ID: ae-200807-050

Regarding the vulnerabilities in DNS, Debian also has updated their packet refpolicy. Several vulnerabilities have been discovered and fixed in the interpreter for the Ruby language, which may lead to Denial-of-Service or the execution of arbitrary code. Further on, several vulnerabilities have been fixed in the interpreter for the Python language.

System: SuSE Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2008:037
ID: ae-200807-049

Several vulnerabilities in the kernel of openSUSE 11.0 have been found. They should be fixed now by intstalling the appropriate update.

System: Red Hat Enterprise Linux 4
Topic: Vulnerabilities in kernel, nss_ldap, mysql, and coreutils
Links: RHSA-2008-0665, CVE-2006-4145, CVE-2008-2812, ESB-2008.0735,
RHSA-2008-0715, CVE-2007-5794, ESB-2008.0736,
RHSA-2008-0768, CVE-2006-3469, CVE-2006-4031, CVE-2007-2691, CVE-2008-2079, ESB-2008.0734,
RHSA-2008-0715, CVE-2008-1946, ESB-2008.0737
ID: ae-200807-048

Several vulnerabilities were found in the linux kernel of Red Hat Enterprise Linux 4.
A race condition was discovered in nss_ldap, which affected certain applications that make LDAP connections, such as Dovecot. This could cause nss_ldap to answer a request for information about one user with the information about a different user.
Several vulnerabilities were found in the 'mysql' packages.
The coreutils packages were found to not use the pam_succeed_if Pluggable Authentication Module (PAM) correctly in the configuration file for the "su" command. Any local user could use this command to change to a locked or expired user account if the target account's password was known to the user running "su".
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in clamav
Links: DSA-1616, CVE-2008-2713, ESB-2008.0731, S-364
ID: ae-200807-047

A vulnerability was discoveredin the ClamAV anti-virus toolkit's parsing of Petite-packed Win32 executables. The weakness leads to an invalid memory access, and could enable an attacker to crash clamav by supplying a maliciously crafted Petite-compressed binary for scanning. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in rdesktop and vsftpd
Links: RHSA-2008-0575, RHSA-2008-0576, RHSA-2008-0725, CVE-2008-1801, CVE-2008-1803, ESB-2008.0732,
RHSA-2008-0597, RHSA-2008-0680, CVE-2008-2375, ESB-2008.0733
ID: ae-200807-046

An integer underflow vulnerability was discovered in the rdesktop. If an attacker could convince a victim to connect to a malicious RDP server, the attacker could cause the victim's rdesktop to crash or, possibly, execute an arbitrary code.
The version of vsftpd as shipped in Red Hat Enterprise Linux 3 and 4 when used in combination with Pluggable Authentication Modules (PAM) had a memory leak on an invalid authentication attempt.
Fixed packages are available now.

System: Red Hat Enterprise Linux 4
Topic: Vulnerability in the Kernel
Links: RHSA-2008-0607, CVE-2008-0598, CVE-2008-1367, CVE-2008-2365, CVE-2008-2729, ESB-2008.0646, S-331
ID: ae-200807-045

Updated kernel packages that fix various known security issues and several bugs in the Red Hat Enterprise Linux 4 kernels are now available.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in acroread
Links: RHSA-2008-0641, CVE-2008-0883, CVE-2008-2641, ESB-2008.0718
ID: ae-200807-044

Several vulnerabilities were found in the Adobe Acrobat Reader. Fixed packages are available now.

System: Various
Topic: Vulnerability in Red Hat Certificate System
Links: RHSA-2008-0566, CVE-2007-4994, ESB-2008.0719
ID: ae-200807-043

It was discovered that new revocations, performed while a Certificate Revocation List (CRL) was being generated, could potentially cause revoked certificates at the upper end of the serial number range to not appear on the CRL for a period of time. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in ruby1.8 and libgd2
Links: DSA-1612, CVE-2008-2376, CVE-2008-2662, CVE-2008-2663, CVE-2008-2664, CVE-2008-2725, CVE-2008-2726, ESB-2008.0720, S-365,
DSA-1613, CVE-2007-2445, CVE-2007-3476, CVE-2007-3477, CVE-2007-3996, ESB-2008.0723
ID: ae-200807-042

Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may lead to denial of service or the execution of arbitrary code.
Multiple vulnerabilities have been identified in libgd2, a library for programmatic graphics creation and manipulation.
Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in BlackBerry Enterprise Server
Links: BlackBerry, VU#289235, ESB-2008.0717, S-369
ID: ae-200807-041

A security vulnerability exists in the PDF distiller of some released versions of the BlackBerry Attachment Service. This vulnerability could enable a malicious individual to send an email message containing a specially crafted PDF file, which when opened for viewing on a BlackBerry smartphone, could cause memory corruption and possibly lead to arbitrary code execution on the computer that the BlackBerry Attachment Service runs on. Patches are available now.

System: Sun Solaris
Topic: Vulnerability in System Management Agent
Links: Sun Alert #239785, CVE-2008-2292, ESB-2008.0716
ID: ae-200807-040

A security vulnerability in the System Management Agent (SMA) SNMP daemon (snmpd(1M)) that ships with Solaris may allow a local or remote unprivileged user to execute arbitrary code with the privileges of the SNMP daemon, or crash the SNMP daemon, which is a type of Denial of Service (DoS). A patch is available now.

System: SuSE Linux
Topic: Vulnerabilities in moodle, clamav, zypper, mercurial, and poppler
Links: SUSE-SR:2008:015
ID: ae-200807-039

A SUSE Security Summary reports about vulnerabilities in the packages moodle, clamav, zypper, mercurial, and poppler. Updated packages are available now and should be installed on vulnerable systems.

System: Microsoft Windows
Topic: Vulnerabilities in HP Select Identity Active Director
Links: HPSBMA02346 SSRT080097, CVE-2008-1665, ESB-2008.0712
ID: ae-200807-038

Several security vulnerabilities have been identified with HP Select Identity Active Directory Bidirectional LDAP Connector . The vulnerabilities could be exploited to allow remote unauthorized access. Patches are available now.

System: OpenBSD
Topic: Vulnerabilities in X.Org
Links: OpenBSD, CVE-2008-1377, CVE-2008-1379, CVE-2008-2360, CVE-2008-2361, CVE-2008-2362
ID: ae-200807-037

Multiple vulnerabilities have been discovered in X.Org. A source code patch is available now.

System: Debian GNU/Linux
Topic: Vulnerability in afuse
Links: DSA-1611, CVE-2008-2232, ESB-2008.0714, S-370
ID: ae-200807-036

It was discovered that afuse, an automounting file system in user-space, does not properly escape meta characters in paths. This allows a local attacker with read access to the filesystem to execute commands as the owner of the filesystem. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Mozilla Firefox, Thunderbird, and Seamonkey
Links: Mozilla, CVE-2008-2785, CVE-2008-2933, VU#130923, AU-2008.0016, RHSA-2008-0597, RHSA-2008-0598, RHSA-2008-0599, RHSA-2008-0616, ESB-2008.0711, ESB-2008.0712, ESB-2008.0730, MDVSA-2008:148, TLSA-2008-28, DSA-1614, DSA-1615, ESB-2008.0727, ESB-2008.0728, MDVSA-2008:155, MDVSA-2008:155-1, DSA-1621, ESB-2008.0743
ID: ae-200807-035

Multiple vulnerabilities were found in the Mozilla Firefox browser. Also affected are Thunderbird and Seamonkey. Fixed software is available now.

System: Many
Topic: Oracle Critical Patch Update
Links: Oracle, iDEFENSE #725, iDEFENSE #726, iDEFENSE #727, AL-2008.0081, HPSBMA02133 SSRT061201, ESB-2008.0713, S-361
ID: ae-200807-034

A critical patch update for Oracle products is available now. This update includes no less than 45 patches for products from Oracle. 13 of them affect the Oracle Database Server, including version 11g. Please refer to the advisory for more information and how to get this patch update.

System: HP Network Appliance
Topic: Vulnerabilities in HP Storage Management Appliance
Links: HPSBST02350 SSRT080102, ESB-2008.0707
ID: ae-200807-033

Various potential security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Some of these vulnerabilities may be pertinent to the SMA, please check the information in the advisory.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in php
Links: RHSA-2008-0544, RHSA-2008-0545, ESB-2008.0709, CVE-2007-4782, CVE-2007-5898, CVE-2007-5899, CVE-2008-2051, CVE-2008-2107, CVE-2008-2108, RHSA-2008-0582, ESB-2008.0724
ID: ae-200807-032

Several vulnerabilities were found in php. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in lighttpd and gaim
Links: DSA-1609, CVE-2008-0983, CVE-2008-3948, ESB-2008.0705,
DSA-1610, CVE-2008-2927, ESB-2008.0706, S-366
ID: ae-200807-031

Several local/remote vulnerabilities have been discovered in lighttpd, a fast webserver with minimal memory footprint.
It was discovered that gaim, an multi-protocol instant messaging client, was vulnerable to several integer overflows in its MSN protocol handlers. These could allow a remote attacker to execute arbitrary code.
Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-sun and java-1.5.0-sun
Links: RHSA-2008-0594, RHSA-2008-0595, RHSA-2008-0790, CVE-2008-3103, CVE-2008-3104, CVE-2008-3105, CVE-2008-3106, CVE-2008-3107, CVE-2008-3109, CVE-2008-3111, CVE-2008-3112, CVE-2008-3113, CVE-2008-3114, ESB-2008.0702, ESB-2008.0703, S-360
ID: ae-200807-030

Several vulnerabilities were found in the Java Runtime Environment (JRE). Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in ruby
Links: RHSA-2008-0561, RHSA-2008-0562, CVE-2006-6303, CVE-2008-2376, CVE-2008-2662, CVE-2008-2663, CVE-2008-2664, CVE-2008-2725, CVE-2008-2726, ESB-2008.0700, S-344
ID: ae-200807-029

Multiple integer overflows leading to a heap overflow were discovered in the array- and string-handling code used by Ruby. An attacker could use these flaws to crash a Ruby application or, possibly, execute arbitrary code with the privileges of the Ruby application using untrusted inputs in array or string operations. Fixed packages are available now.

System: Various
Topic: Vulnerability in bluez
Links: CVE-2008-2374, RHSA-2008-0581, ESB-2008.0701, MDVSA-2008:145
ID: ae-200807-028

An input validation flaw was found in the Bluetooth Session Description Protocol (SDP) packet parser used by the Bluez Bluetooth utilities. A Bluetooth device with an already-established trust relationship, or a local user registering a service record via a UNIX socket or D-Bus interface, could cause a crash, or possibly execute arbitrary code with privileges of the hcid daemon. Fixed software is available now.

System: Various
Topic: Vulnerability in mysql
Links: CVE-2008-2079, DSA-1608, ESB-2008.0695, S-346, MDVSA-2008:149
ID: ae-200807-027

It was discovered that MySQL, a widely-deployed database server, did not properly validate optional data or index directory paths given in a CREATE TABLE statement, nor would it (under proper conditions) prevent two databases from using the same paths for data or index files. This permits an authenticated user with authorization to create tables in one database to read, write or delete data from tables subsequently created in other databases, regardless of other GRANT authorizations. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Microsoft Office Snapshot Viewer
Links: Microsoft #955179, CVE-2008-2463, VU#837785
ID: ae-200807-026

Microsoft Snapshot Viewer is a viewer for snapshots created with Microsoft Access. It's available as an ActiveX control, which is provided by snapview.ocx, or as a stand-alone application. A race condition might allow a remote, unauthenticated attacker to download arbitrary files to arbitrary locations on a vulnerable system. It's recommended to set the corresponding kill bit for the ActiveX Control.

System: Mandriva Linux
Topic: Vulnerabilities in ruby, pidgin, and OpenLDAP
Links: MDVSA-2008:141, MDVSA-2008:142, CVE-2008-1145, CVE-2008-1891, CVE-2008-2376, CVE-2008-2662, CVE-2008-2663, CVE-2008-2664, CVE-2008-2725, CVE-2008-2726,
MDVSA-2008:143, CVE-2008-2927,
MDVSA-2008:144, CVE-2008-2952,
ID: ae-200807-025

Multiple vulnerabilities have been found in the Ruby interpreter and in Webrick, the webserver bundled with Ruby. They e.g. allow directory traversal as well as the execution of arbitrary code due to integer overflows.
An integer overflow in Pidgin's MSN protocol handler might allow the execution of arbitrary code if a user received a malicious MSN message.
A Denial-of-Service vulnerability has been discovered in the way the OpenLDAP slapd daemon processes certain network messages. An unauthenticated remote attacker could send a specially crafted request that would crash the slapd daemon.
These vulnerabilities can be patched by installing updated packages.

System: Various
Topic: Vulnerability in Novell eDirectory
Links: iDefense, CVE-2008-1809, ESB-2008.0688
ID: ae-200807-024

Remote exploitation of a heap buffer overflow vulnerability in Novell Inc.'s eDirectory could allow an attacker to execute arbitrary code with the privileges of the affected service. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in Adobe RoboHelp Server
Links: APSB08-16, CVE-2008-2991, ESB-2008.0678
ID: ae-200807-023

A specially crafted URL could be used to create a cross-site scripting attack on RoboHelp Server 6 and RoboHelp Server 7 installations. Patches are available now.

System: Microsoft Windows
Topic: Vulnerability in HP OpenView Network Node Manager
Links: HPSBMA02349 SSRT080043, CVE-2008-0068, ESB-2008.0687, S-340
ID: ae-200807-022

A vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to gain unauthorized access to data. Patches are available now.

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft SQL Server
Links: MS08-040, CVE-2008-0085, CVE-2008-0086, CVE-2008-0107, CVE-2008-0107, iDefense, ESB-2008.0677, S-334
ID: ae-200807-021

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Outlook Web Access
Links: MS08-039, CVE-2008-2247, CVE-2008-2248, ESB-2008.0676, S-339
ID: ae-200807-020

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Windows Explorer
Links: MS08-038, CVE-2008-1435, ESB-2008.0675, S-333
ID: ae-200807-019

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows DNS
Links: MS08-037, CVE-2008-1447, CVE-2008-1454, ESB-2008.0674, S-332
ID: ae-200807-018

No further comment due to legal reasons

System: Debian GNU/Linux
Topic: Vulnerability in poppler
Links: DSA-1606, CVE-2008-1693, ESB-2008.0685, S-342
ID: ae-200807-017

It was discovered that poppler, a PDF rendering library, did not properly handle embedded fonts in PDF files, allowing attackers to execute arbitrary code via a crafted font object. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in openldap and pidgin
Links: RHSA-2008-0583, CVE-2008-2952, ESB-2008.0681,
RHSA-2008-0583, CVE-2008-2927, ESB-2008.0682
ID: ae-200807-016

A denial of service flaw was found in the way the OpenLDAP slapd daemon processed certain network messages. An unauthenticated remote attacker could send a specially crafted request that would crash the slapd daemon.
An integer overflow flaw was found in Pidgin's MSN protocol handler. If a user received a malicious MSN message, it was possible to execute arbitrary code with the permissions of the user running Pidgin.
Fixed packages are available now.

System: Various
Topic: Vulnerability in DNS
Links: TA08-190B, VU#800113, CVE-2008-1447, AL-2008.0080, AL-2008.0082, ISC, DSA-1603, DSA-1604, ESB-2008.0672, DSA-1605, ESB-2008.0673, RHSA-2008-0533, ESB-2008.0680, MDVSA-2008:139, Cisco, ESB-2008.0671, S-341, MS08-037, ESB-2008.0674, S-332 Sun Alert 239392, ESB-2008.0684, SUSE-SA:2008:033, FreeBSD-SA-08:06, ESB-2008.0693, TLSA-2008-26, TLSA-2008-30, HPSBUX02351 SSRT080058, ESB-2008.0715, OpenBSD, NetBSD-SA2008-009, ESB-2008.0738, DSA-1619, ESB-2008.0741, DSA-1623, ESB-2008.0754, ESB-2008.0769, AU-2008.0017, HPSBTU02358, ESB-2008.0804, S-358
ID: ae-200807-015

Deficiencies in the DNS protocol and common DNS implementations facilitate DNS cache poisoning attacks. Effective attack techniques against these vulnerabilities have been demonstrated. Fixed software is available now.

System: SuSE Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2008:032
ID: ae-200807-014

Several vulnerabilities in the kernel of SUSE Linux Enterprise 10 SP1 have been found. They should be fixed now by intstalling the appropriate update.

System: SuSE Linux
Topic: Vulnerabilities in sudo, courier-authlib, gnome-screensaver, clamav, php5, ImageMagick, mtr, bind, pcre, tomcat, squid and freetype2
Links: SUSE-SR:2008:014
ID: ae-200807-013

A SUSE Security Summary reports about vulnerabilities in the packages sudo, courier-authlib, gnome-screensaver, clamav, php5, ImageMagick, mtr, bind, pcre, tomcat, squid, and freetype2. Updated packages are available now and should be installed on vulnerable systems.

System: Debian GNU/Linux
Topic: Vulnerabilities in wordpress and pcre3
Links: DSA-1601, CVE-2007-1599, CVE-2008-0664, ESB-2008.0669,
DSA-1602, CVE-2008-2371, ESB-2008.0670, S-336
ID: ae-200807-012

Several remote vulnerabilities have been discovered in Wordpress, the weblog manager.
It was discovered that PCRE, the Perl-Compatible Regular Expression library, may encounter a heap overflow condition when compiling certain regular expressions involving in-pattern options and branches, potentially leading to arbitrary code execution.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in php
Links: MDVSA-2008:127, CVE-2007-5898, CVE-2007-5899, CVE-2008-0599, CVE-2008-2051, CVE-2008-2107, CVE-2008-2108, CVE-2008-2829
ID: ae-200807-011

A number of vulnerabilities have been found in PHP. Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2008:031
ID: ae-200807-010

Several vulnerabilities were found in the Linux kernel of SUSE SLES 9, Novell Linux Desktop 9, and Novell Linux POS 9. Fixed packages are available now.

System: Various
Topic: Vulnerability in Red Hat Certificate System
Links: RHSA-2008-0500, RHSA-2008-0577, CVE-2008-1676, ESB-2008.0667
ID: ae-200807-009

A flaw was found in the way Red Hat Certificate System handled Extensions in the certificate signing requests (CSR). All requested Extensions were added to the issued certificate even if constraints were defined in the Certificate Authority (CA) profile. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in Red Hat Application Stack
Links: RHSA-2008-0505, RHSA-2008-0510, CVE-2007-4782, CVE-2007-5898, CVE-2007-5899, CVE-2008-0599, CVE-2008-2051, CVE-2008-2079, CVE-2008-2107, CVE-2008-2108, ESB-2008.0666
ID: ae-200807-008

Several vulnerabilities were found in the Red Hat Application Stack which includes JBoss Enterprise Application Platform (EAP). Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Mozilla Firefox, Thunderbird, and Seamonkey
Links: Mozilla, CVE-2008-2798, CVE-2008-2799, CVE-2008-2800, CVE-2008-2801, CVE-2008-2802, CVE-2008-2803, CVE-2008-2805, CVE-2008-2807, CVE-2008-2808, CVE-2008-2809, CVE-2008-2810, CVE-2008-2811, VU#607267, RHSA-2008-0547, RHSA-2008-0549, RHSA-2008-0569, ESB-2008.0665, S-335, TLSA-2008-25, MDVSA-2008:136, DSA-1607, ESB-2008.0694, SUSE-SA:2008:034, ESB-2008.0697
ID: ae-200807-007

Multiple vulnerabilities were found in the Mozilla Firefox browser. Also affected are Thunderbird and Seamonkey. Fixed software is available now.

System: Microsoft Windows / Linux
Topic: Vulnerability in HP System Management Homepage
Links: HPSBMA02345 SSRT080039, CVE-2008-1663, ESB-2008.0664
ID: ae-200807-006

A security vulnerability has been identified with HP System Management Homepage (SMH) for Linux and Windows. This vulnerability could by exploited remotely to allow cross site scripting (XSS). Patches are available now.

System: Sun Solaris
Topic: Vulnerabilities in Tomcat
Links: Sun Alert #239312, CVE-2002-1148, CVE-2002-1394, CVE-2002-2006, CVE-2003-0866, CVE-2005-2090, CVE-2005-3164, CVE-2005-3510, CVE-2006-3835, CVE-2007-0450, CVE-2007-1355, CVE-2007-1358, CVE-2007-2450, CVE-2007-5461, ESB-2008.0653
ID: ae-200807-005

Several vulnerabilities were found in the Tomcat JSP/Servlet container. A patch is available now.

System: Debian GNU/Linux
Topic: Vulnerability in sympa
Links: DSA-1600, CVE-2008-1648, ESB-2008.0662
ID: ae-200807-004

It was discovered that sympa, a modern mailing list manager, would crash when processing certain types of malformed messages. Fixed packages are available now.

System: Apple Mac OS X
Topic: New Apple Security Update available
Links: Apple Security Update 2008-004, ESB-2008.0660, S-338
ID: ae-200807-003

Apple has published the security update for Mac OS X. It fixes multiple vulnerabilities in Alias Manager, CoreTypes, c++filt, Dock, Launch Services, Net-SNMP, Ruby, SMB File Server, System Configuration, Tomcat, VPN, and WebKit. It's recommended to install this update.

System: Mac OS X
Topic: Safari 3.1.2 available
Links: Apple_HT2165 CVE-2008-2307, VU#361043, ESB-2008.0659, S-343
ID: ae-200807-002

When using Safari, visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution due to a memory corruption issue in WebKit's handling of JavaScript arrays. Safari 3.1.2 is now available for Mac OS X v10.4.11 and addresses this issue.

System: Many
Topic: Vulnerability in HP OpenView Network Node Manager
Links: HPSBMA02338, SSRT080024, CVE-2008-1842, ESB-2008.0592
ID: ae-200807-001

A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely execute arbitrary code or to create a Denial-of-Service (DoS). HP has made archive files and patches available to resolve the vulnerability.



(c) 2000-2010 AERAsec Network Services and Security GmbH