Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-23-20-196-179.compute-1.amazonaws.com [23.20.196.179]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 11 / 2009

System: Debian GNU/Linux
Topic: Vulnerabilities in wireshark
Links: DSA-1942, CVE-2009-2560, CVE-2009-3550, CVE-2009-3829, ESB-2009.1572
ID: ae-200911-085

Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer, which may lead to the execution of arbitrary code or denial of service. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Symantec Altiris
Links: SYM09-016, CVE-2009-3033, ESB-2009.1571
ID: ae-200911-084

Symantec ships an ActiveX control, AeXNSConsoleUtilities.dll with a vulnerable method in Symantecs Altiris Notification Server / Symantec Management Platform and with Symantecs Altiris Deployment Solution 6.9. The vulnerable control is downloaded during the initial connection to the web console on the management server to enable authorized admin access to the management server. An update addresses this issue.

System: Sun Solaris, OpenSolaris
Topic: Vulnerabilities in ldap_cachemgr
Links: Sun Alert #231402, ESB-2009.1570
ID: ae-200911-083

Multiple security vulnerabilities in the LDAP client configuration cache daemon (ldap_cachemgr(1M)) may allow a local unprivileged user to terminate the ldap_cachemgr daemon. On Solaris 9 and 10 systems this will prevent LDAP name service requests from succeeding. This is a type of Denial-of-Service (DoS) as LDAP name service requests will hang and users may no longer be able to login to LDAP client systems. On Solaris 8 systems, LDAP name service requests will be slower, as caching will not occur which is also a type of Denial-of-Service (DoS). Updates are available now.

System: HP-UX
Topic: Vulnerability in OpenSSL
Links: HPSBUX02482, SSRT090249, CVE-2009-3555, ESB-2009.1568, ESB-2009.1578
ID: ae-200911-082

The TLS/SSLv3 protocol as implemented in openssl isn't able to associate already sent data to a renegotiated connection. This allows a man-in-the-middle attack by injecting HTTP requests in a HTTPS session without being noticed. An update addresses this issue.

System: Microsoft Windows
Topic: Vulnerability in Microsoft Internet Explorer
Links: Microsoft Security Advisory, VU#515749, ESB-2009.1557
ID: ae-200911-081

Microsoft Internet Explorer (IE) does not safely reference CSS style elements. Using a specially crafted HTML page, an attacker can cause IE to crash and potentially execute arbitrary code. A hotfix is not available yet.

System: Various
Topic: Vulnerability in ISC BIND
Links: CVE-2009-4022, VU#418861, ESB-2009.1561, Sun Alert #273169, ESB-2009.1569, RHSA-2009-1620, ESB-2009.1577, SUSE-SA:2009:059, ESB-2009.1580
ID: ae-200911-080

A potential cache poisoning vulnerability was found in the BIND nameserver, in which data in the additional section of a response could be cached without proper DNSSEC validation. Fixed software is available now.

System: SuSE Linux
Topic: Vulnerabilities in cups, jetty5, libqt4/dbus-1-qt, opera, puretls/jessie, kdegraphics3-pdf, qemu, and udev
Links: SUSE-SR:2009:019, SUSE-SA:2009:020, ESB-2009.1562
ID: ae-200911-079

A new SUSE Security Summary reports about vulnerabilities in the packages cups, jetty5, libqt4/dbus-1-qt, opera, puretls/jessie, kdegraphics3-pdf, qemu, and udev. Updated packages are available now and should be installed on vulnerable systems.

System: Debian GNU/Linux
Topic: Vulnerabilities in libvorbis, php5, and poppler
Links: DSA-1939, CVE-2009-2663, CVE-2009-3379, ESB-2009.1563,
DSA-1940, CVE-2009-2626, CVE-2009-2687, CVE-2009-3291, CVE-2009-3292, ESB-2009.1567,
DSA-1941, CVE-2009-0755, CVE-2009-3903, CVE-2009-3904, CVE-2009-3905, CVE-2009-3906, CVE-2009-3907, CVE-2009-3908, CVE-2009-3909, CVE-2009-3938, ESB-2009.1566
ID: ae-200911-078

It was discovered that libvorbis, a library for the Vorbis general-purpose compressed audio codec, did not correctly handle certain malformed ogg files. An attacher could cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.
Several remote vulnerabilities have been discovered in the PHP 5 hypertext preprocessor.
Several integer overflows, buffer overflows and memory allocation errors were discovered in the Poppler PDF rendering library, which may lead to denial of service or the execution of arbitrary code if a user is tricked into opening a malformed PDF document.
Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in kdelibs
Links: RHSA-2009-1601, CVE-2009-0689, ESB-2009.1565
ID: ae-200911-077

A buffer overflow flaw was found in the kdelibs string to floating point conversion routines. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in php-mail
Links: DSA-1938, ESB-2009.1556
ID: ae-200911-076

It was discovered that php-mail, a PHP PEAR module for sending email, has insufficient input sanitising, which might be used to obtain sensitive data from the system that uses php-mail. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in HP Operations Manager
Links: HPSBMA02478, SSRT090251, CVE-2009-3843, ESB-2009.1554
ID: ae-200911-075

A security vulnerability has been identified with HP Operations Manager for Windows. The vulnerability could be exploited remotely to gain unauthorized access. A patch is available now.

System: Various
Topic: Vulnerabilities in VMware products
Links: VMSA-2009-0015, CVE-2009-2267, CVE-2009-3733, ESB-2009.1452
ID: ae-200911-074

Several vulnerabilities have been found in VMware vCenter, ESX, and vMA. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerability in gforge
Links: DSA-1937, CVE-2009-3303, ESB-2009.1552
ID: ae-200911-073

It was discovered that gforge, a collaborative development tool, is prone to a cross-site scripting (XSS) attack via the helpname parameter. Beside fixing this issue, an update also introduces some additional input sanitising.

System: SuSE Linux
Topic: Vulnerabilities in java-1_6_0-sun
Links: SUSE-SA:2009:058, CVE-2009-3864, CVE-2009-3865, CVE-2009-3866, CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877, ESB-2009.1551
ID: ae-200911-072

Several vulnerabilities were found in the Sun Java 6 JRE/SDK. Fixed packages are available now.

System: Appliance
Topic: Vulnerabilities in HP Color LaserJet M3530 and CP3525 Printers
Links: HPSBPI02472, SSRT090196, CVE-2009-3842, ESB-2009.1550
ID: ae-200911-071

A potential security vulnerability has been identified with certain HP Color LaserJet printers. The vulnerability could be exploited remotely to gain unauthorized access to data or to create a Denial-of-Service (DoS). A firmware update remedies this issue.

System: Various
Topic: Vulnerability in Bugzilla
Links: Bugzilla 529416, CVE-2009-3386, ESB-2009.1549
ID: ae-200911-070

Bugzilla is a Web-based bug-tracking system. When a bug is in a group, none of its information should be visible to users outside that group. It has been discovered that as of 3.3.2, Bugzilla is showing the alias of the bug to users outside of the group, if the protected bug ended up in the "Depends On" or "Blocks" list of any other bug. An update is available now.

System: Microsoft Windows
Topic: Vulnerabilities in Wyse Simple Imager
Links: VU #632633, CVE-2002-2226, CVE-2002-2237, CVE-2002-2353, CVE-2006-0328, CVE-2006-6141
ID: ae-200911-069

Wyse Simple Imager (WSI) includes older versions version of TFTPD32 that contains publicly known vulnerabilities. An attacker could exploit these vulnerabilities to potentially execute arbitrary code on the system running WSI and TFTPD32. It's recommended to upgrade TFTPD32 to the latest version.

System: Various
Topic: Vulnerabilities in some Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2009-102, DRUPAL-SA-CONTRIB-2009-103, DRUPAL-SA-CONTRIB-2009-104, DRUPAL-SA-CONTRIB-2009-105, DRUPAL-SA-CONTRIB-2009-106, DRUPAL-SA-CONTRIB-2009-107, DRUPAL-SA-CONTRIB-2009-108, DRUPAL-SA-CONTRIB-2009-109, ESB-2009.1548
ID: ae-200911-068

Several vulnerabilities were found in the Drupal third-party modules PHPList Integration, Strongarm, Feed Element Mapper, Subgroups for Organic Groups, PHPList Integration, Ubercart, Gallery Assist, and Printfriendly. Please be aware that Drupal core is not affected.

System: Various
Topic: Vulnerabilities in IBM SolidDB Server
Links: CORE-2009-1027, IBM, CVE-2009-3840, CVE-2009-3977, ESB-2009.1547
ID: ae-200911-067

SolidDB is an in-memory relational database from IBM. A remotely exploitable vulnerability was found in the database server core component. Exploitation of this bug does not require authentication and will lead to a remotely triggered Denial-of-Service of the database service. IBM has issued the SolidDB and SolidDB Universal Cache 6.3 Fix Pack 3 which addresses this problem.

System: Cisco
Topic: Vulnerability in Cisco Catalyst Blade Switch 3020/3120
Links: HPSBMI02473, SSRT080138, CVE-2009-4609, ESB-2009.1545
ID: ae-200911-066

A potential vulnerability has been identified with the Cisco Catalyst Blade Switch 3020/3021. It might be exploited remotely to create a Denial-of-Service (DoS) or even execute arbitrary code. A firmware update is available now.

System: Various
Topic: Vulnerability in HP Openview NNM
Links: HPSBMA02477 SSRT090177, core security, HP, CVE-2009-3840, ESB-2009.1546, ESB-2010.0084
ID: ae-200911-065

HP Openview Network Node Manager (NNM) is a widely used tool for network monitoring. A remotely exploitable vulnerability has been found in the database server core component used by NNM 7.53. Exploitation of the bug does not require authentication and will lead to a remotely triggered Denial-of-Service (DoS) of the internal database service. Fixes are available now.

System: Sun Solaris, OpenSolaris
Topic: Vulnerabilities in Samba
Links: Sun Alert #271069, CVE-2009-2813, CVE-2009-2906, ESB-2009.1546
ID: ae-200911-064

Two security vulnerabilities in SAMBA(7) have been found. A remote unprivileged user with a valid SAMBA account may gain unauthorized access to the remote root file system. Further on, a remote unprivileged user on an authenticated SAMBA connection may cause a Denial-of-Service (DoS) condition via specially crafted SMB requests. Updates are available now.

System: SuSE Linux
Topic: Vulnerability in OpenSSL
Links: SUSE-SA:2009:057, CVE-2009-3555, ESB-2009.1544
ID: ae-200911-063

The TLS/SSLv3 protocol as implemented in openssl isn't able to associate already sent data to a renegotiated connection. This allows a man-in-the-middle attack by injecting HTTP requests in a HTTPS session without being noticed. An update addresses this issue.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in cups
Links: RHSA-2009-1595, CVE-2009-2820, CVE-2009-3553, ESB-2009.1543
ID: ae-200911-062

Several vulnerabilities were found in the Common UNIX Printing System (CUPS). Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in Kernel
Links: RHSA-2009-1587, RHSA-2009-1588, ESB-2009.1542
ID: ae-200911-061

Several vulnerabilities have been discovered in the Linux kernels of Red Hat Enterprise Linux. Updated kernel packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in apache2, gnutls13, gnutls26, and libgd2
Links: DSA-1934, CVE-2009-3094, CVE-2009-3095, CVE-2009-3555, ESB-2009.1539,
DSA-1935, CVE-2009-2409, CVE-2009-2730, ESB-2009.1540,
DSA-1936, CVE-2007-0455, CVE-2009-3546, ESB-2009.1541
ID: ae-200911-060

Several vulnerabilities were found in the Apache HTTP server. A design flaw has been found in the TLS and SSL protocol that allows an attacker to inject arbitrary content at the beginning of a TLS/SSL connection. Insufficient input validation in the mod_proxy_ftp module allowed remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command. Insufficient input validation in the mod_proxy_ftp module allowed remote authenticated attackers to bypass intended access restrictions and send arbitrary FTP commands to an FTP server.
It was discovered that gnutls, an implementation of the TLS/SSL protocol, does not properly handle a '\0' character in a domain name in the subject's Common Name or Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.
Several vulnerabilities have been discovered in libgd2, a library for programmatic graphics creation and manipulation.
Fixed packages are available now.

System: Various
Topic: Vulnerability in IBM WebSphere Application Server
Links: ISS #54227, ESB-2009.1538
ID: ae-200911-059

IBM WebSphere Application Server is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input by the Administration Console. By persuading an authenticated user to visit a malicious Web site, a remote attacker could exploit this vulnerability to perform cross-site scripting attacks, Web cache poisoning, and other malicious activities. A Fix Pack solves this problem.

System: Mandriva Linux
Topic: Vulnerability in apache-conf
Links: MDVSA-2009:300, CVE-2009-2823, ESB-2009.1536
ID: ae-200911-058

The Apache HTTP Server enables the HTTP TRACE method per default which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified web client software. Fixed packages are available now.

System: SuSE Enterprise Linux 9
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2009:055, CVE-2009-1192, CVE-2009-1633, CVE-2009-2848, CVE-2009-2909, CVE-2009-2910, CVE-2009-3002, CVE-2009-3547, CVE-2009-3547, ESB-2009.1535
ID: ae-200911-057

Several vulnerabilities were found in the kernel of SUSE SLES 9 and Novell Linux Desktop 9. Fixed kernel packages are available now.

System: Red Hat Enterprise Linux 5
Topic: Vulnerabilities in samba3x
Links: RHSA-2009-1585, CVE-2009-1888, CVE-2009-2813, CVE-2009-2906, CVE-2009-2948, ESB-2009.1532
ID: ae-200911-056

Several vulnerabilities were found in the 'samba3x' packages of Red Hat Enterprise Linux 5 Supplementary. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-openjdk
Links: RHSA-2009-1584, CVE-2009-2409, CVE-2009-3728, CVE-2009-3869, CVE-2009-3871, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877, CVE-2009-3879, CVE-2009-3880, CVE-2009-3881, CVE-2009-3882, CVE-2009-3883, CVE-2009-3884, ESB-2009.1533
ID: ae-200911-055

Several vulnerabilities were found in the OpenJDK 6 Java Runtime Environment and the OpenJDK 6 Software Development Kit. Fixed packages are available now.

System: Various
Topic: Vulnerability in IBM WebSphere Application Server
Links: ISS #54229, ESB-2009.1531
ID: ae-200911-054

IBM WebSphere Application Server is vulnerable to cross-site scripting, caused by improper validation of user-supplied input in the Administration Console. A remote attacker could exploit this vulnerability to inject malicious script into a Web page which would be executed in a victim's Web browser within the security context of the hosting Web site, once the page is viewed. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. A Fix Pack solves this problem.

System: Unix, Linux, OSX
Topic: Vulnerability in poppler
Links: ISS #54215, CVE-2009-3938, ESB-2009.1530
ID: ae-200911-053

Poppler is vulnerable to a buffer overflow, caused by improper bounds checking. By persuading a victim to open a specially-crafted PDF file, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the affected application to crash. Please check if there is an update for your system available.

System: Mandriva Linux
Topic: Vulnerability in gimp
Links: MDVSA-2009:296, CVE-2009-1570, ESB-2009.1529
ID: ae-200911-052

An Integer Overflow in the ReadImage function may allow remote attackers to execute arbitrary code via a BMP file with crafted width and height values that trigger a heap-based buffer overflow. An updated package is available now.

System: Various
Topic: Vulnerability in Sun xVM VirtualBox
Links: Sun Alert #271149, ESB-2009.1528
ID: ae-200911-051

A security vulnerability in the optional Sun VirtualBox Guest Additions may allow local unprivileged users to exhaust the kernel memory of the guest operating system, leading to a Denial-of-Service (DoS) against the guest operating system running in a virtual machine. Since the Guest Additions are installed in the guest operating system only, this vulnerability is limited to local users of the guest operating system running in a virtual machine where the Guest Additions have been installed. The host operating system is not affected. A new release remedies this problem.

System: Microsoft Windows
Topic: Vulnerability in SMB
Links: MS-977544, CVE-2009-3676, ESB-2009.1527
ID: ae-200911-050

No further comment due to legal reasons

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-ibm
Links: RHSA-2009-1582, CVE-2009-2625, CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, ESB-2009.1523
ID: ae-200911-049

Several vulnerabilities were found in the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. Fixed packages are available now.

System: SuSE Enterprise Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2009:055, CVE-2009-1192, CVE-2009-2909, CVE-2009-2910, CVE-2009-3238, CVE-2009-3547, ESB-2009.1526
ID: ae-200911-048

Several vulnerabilities were found in the kernel of SuSE Linux. Exploiting these vulnerabilities might have security impact, e.g. local users getting privileged access to the system. Fixed kernel packages are available now.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2009-099, DRUPAL-SA-CONTRIB-2009-100, DRUPAL-SA-CONTRIB-2009-101, ESB-2009.1522
ID: ae-200911-047

Several vulnerabilities were found in the Drupal third-party modules RootCandy, AddToAny, and Web Services. Please be aware that Drupal core is not affected.

System: Sun Solaris, OpenSolaris
Topic: Vulnerabilities in kernel, cups, and pidgin
Links: Sun Alert #266488, ESB-2009.1519,
Sun Alert #271169, CVE-2009-2820, ESB-2009.1520,
Sun Alert #272489, CVE-2009-3615, ESB-2009.1521
ID: ae-200911-046

A security vulnerability in Solaris TCP sockets may allow local unprivileged users to leak kernel memory, thereby causing a Denial of Service (DoS) condition.
The web interface of the Common Unix Printing System (CUPS) in versions 1.4.1 and earlier is impacted by multiple security vulnerabilities which may lead to Cross-Site Scripting (XSS) and HTTP Response Splitting Attacks.
A security vulnerability in the the OSCAR protocol plugin library, the shared library that adds support for various instant messaging networks to the pidgin(1) Instant Messaging client (previously known as Gaim), may allow remote unprivileged users to cause a Denial of Service (DoS) through an application crash via crafted contact-list data for ICQ and possibly AIM.
Patches are available now.

System: SUSE Linux Enterprise
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2009:054, CVE-2009-1192, CVE-2009-1633, CVE-2009-2848, CVE-2009-2909, CVE-2009-2910, CVE-2009-3002, CVE-2009-3238, CVE-2009-3547, ESB-2009.1518
ID: ae-200911-045

Several vulnerabilities were found in the kernel of SuSE Linux. Exploiting these vulnerabilities might have security impact, e.g. local users getting privileged access to the system. Fixed kernel packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in httpd
Links: RHSA-2009-1579, RHSA-2009-1580, 2009-1891, 2009-3094, 2009-3095, 2009-3555, ESB-2009.1515
ID: ae-200911-044

Several vulnerabilities were found in the Apache Webserver 'httpd'. Fixed packages are available now.

System: Red Hat Enterprise Linux 3 / 4
Topic: Vulnerability in 4Suite
Links: RHSA-2009-1572, CVE-2009-3720, ESB-2009.1512
ID: ae-200911-043

The 4Suite package contains XML-related tools and libraries for Python. A buffer over-read flaw has been found in the way 4Suite's XML parser handles malformed UTF-8 sequences when processing XML files. A specially-crafted XML file could cause applications using the 4Suite library to crash while parsing the file. Updated packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.5.0-sun
Links: RHSA-2009-1571, ESB-2009.1511
ID: ae-200911-042

An update fixes several vulnerabilities in the Sun Java 5 Runtime Environment and the Sun Java 5 Software Development Kit. It should be installed immediately.

System: Microsoft Windows / OSX
Topic: Vulnerabilities in Microsoft Office Word
Links: MS09-068, CVE-2009-3135, iDEFENSE #831, ESB-2009.1510
ID: ae-200911-041

No further comment due to legal reasons

System: Microsoft Windows / OSX
Topic: Vulnerabilities in Microsoft Office Excel
Links: MS09-067, CVE-2009-3127, CVE-2009-3128, CVE-2009-3129, CVE-2009-3130, CVE-2009-3131, CVE-2009-3132, CVE-2009-3133, CVE-2009-3134, iDEFENSE #832, ESB-2009.1509
ID: ae-200911-040

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Windows Active Directory
Links: MS09-066, CVE-2009-1928, ESB-2009.1508
ID: ae-200911-039

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Windows Kernel-Mode Drivers
Links: MS09-065, CVE-2009-1127, CVE-2009-2513, CVE-2009-2514, ESB-2009.1507
ID: ae-200911-038

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Windows License Logging Server
Links: MS09-064, CVE-2009-2523, ESB-2009.1506
ID: ae-200911-037

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Web Services on Devices API
Links: MS09-063, CVE-2009-2512, ESB-2009.1505
ID: ae-200911-036

No further comment due to legal reasons

System: Various
Topic: Vulnerability in Adobe Photoshop Elements
Links: RHSA-2009-1561, CVE-2009-3379, ESB-2009.1498
ID: ae-200911-035

A vulnerability has been identified in Adobe Photoshop Elements versions 8.0 and 7.0. It might allow a user with valid login credentials and/or physical access to execute arbitrary commands with elevated privileges. A workaround is described in the advisory.

System: SuSE Linux
Topic: Vulnerabilities in cyrus-imapd, neon/libneon, freeradius, strongswan, openldap2, apache2-mod_jk, expat, xpdf, and mozilla-nspr
Links: SUSE-SR:2009:018, ESB-2009.1513
ID: ae-200911-034

A new SUSE Security Summary reports about vulnerabilities in the packages cyrus-imapd, neon/libneon, freeradius, strongswan, openldap2, apache2-mod_jk, expat, xpdf, and mozilla-nspr. Updated packages are available now and should be installed on vulnerable systems.

System: Microsoft Windows
Topic: Vulnerability in Apache Tomcat Windows Installer
Links: Apache, CVE-2009-3548, ESB-2009.1504
ID: ae-200911-033

The Windows installer defaults to a blank password for the administrative user. If this is not changed during the install process, then by default a user is created with the name admin, roles admin and manager and a blank password. It's recommended to set a strong password correctly.

System: HP-UX
Topic: Vulnerabilities in Java
Links: HPSBUX02476, SSRT090250, CVE-2009-0217, CVE-2009-2625, CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, ESB-2009.1503
ID: ae-200911-032

Potential security vulnerabilities have been identified in Java Runtime Environment (JRE) and Java Developer Kit (JDK) running on HP-UX. These vulnerabilities could allow remote unauthorized access, privilege escalation, and Denial-of-Service (DoS). It's recommended to install updates now.

System: Debian GNU/Linux
Topic: Vulnerability in CUPS
Links: DSA-1933, CVE-2009-2820, ESB-2009.1502
ID: ae-200911-031

CUPS is the Common Unix Printing System. It shows a possibility to initiate a Cross-Site Scripting (XSS) attack successfully. Fixed packages are available now.

System: Cisco
Topic: Vulnerability in Transport Layer Security
Links: Cisco, CVE-2009-3555, ESB-2009.1501
ID: ae-200911-030

An industry-wide vulnerability exists in the Transport Layer Security (TLS) protocol that could impact any Cisco product that uses any version of TLS and SSL. The vulnerability exists in how the protocol handles session renegotiation and exposes users to a potential man-in-the-middle attack. Cisco currently investigates and will provide updates when finished and necessary.

System: Apple Mac OS X
Topic: Many vulnerabilities in Mac OS X fixed
Links: APPLE-SA-2009-11-09-1, ESB-2009.1500
ID: ae-200911-029

Security Update 2009-006 / Mac OS X v10.6.2 is now available and addresses many vulnerabilities, which could be exploited locally or remote. It's strongly recommended to install this update.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in tomcat
Links: RHSA-2009-1562, RHSA-2009-1563, CVE-2007-5333, CVE-2008-5515, CVE-2009-0033, CVE-2009-0580, CVE-2009-0781, CVE-2009-0783, ESB-2009.1499
ID: ae-200911-028

Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies. Several vulnerabilities might lead to Cross-Site Scripting (XSS), information leaks, Denial-of-Service (DoS) or other impacts. Due to this, updated packages have been published.

System: Various
Topic: Vulnerabilities in libvorbis
Links: RHSA-2009-1561, CVE-2009-3379, ESB-2009.1498
ID: ae-200911-027

The libvorbis packages contain runtime libraries for use in programs that support Ogg Vorbis audio format. Multiple flaws were found in the libvorbis library. A specially-crafted Ogg Vorbis media format file (Ogg) could cause an application using libvorbis to crash or, possibly, execute arbitrary code when opened. Updated packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-sun
Links: RHSA-2009-1560, ESB-2009.1497
ID: ae-200911-026

An update fixes several vulnerabilities in the Sun Java 6 Runtime Environment and the Sun Java 6 Software Development Kit. It should be installed immediately.

System: Sun Solaris, OpenSolaris
Topic: Vulnerabilities in mod_perl2
Links: Sun Alert #272230, CVE-2009-0796, CVE-2009-1349, ESB-2009.1495, ESB-2009.1586
ID: ae-200911-025

Two security vulnerabilities exist in the Apache 2 mod_perl2(3) module components. A Denial of Service (DoS) vulnerability in the "RunPerl.pm" component may allow a remote unprivileged user to cause a Denial-of-Service (DoS) to the Apache 2 "httpd" process. Further on, a Cross-Site Scripting (XSS) vulnerability in the "Status.pm" component may allow a remote unprivileged user to inject arbitrary web script or HTML. This may allow the unprivileged user to bypass access control and gain access to unauthorized data. Updates are available now.

System: Sun Solaris
Topic: Vulnerability in Sun Solaris SCTP
Links: Sun Alert #266388, CVE-2009-3899, ESB-2009.1489
ID: ae-200911-024

A security vulnerability in SCTP (Stream Control Transmission Protocol) and SDP (Sockets Direct Protocol) driver sockets has been found. It may allow local unprivileged users to leak kernel memory, thereby causing a Denial-of-Service (DoS) condition. Updates address this issue.

System: Unix / Linux
Topic: Vulnerabilities in Asterisk
Links: AST-2009-008, AST-2009-009, CVE-2008-7220, ESB-2009.1487
ID: ae-200911-023

Asterisk is a free software for telephones. Asterisk includes a demonstration AJAX based manager interface which uses the prototype.js framework. An issue has been found in this framework which could allow someone to execute a cross-site AJAX request exploit. Further on, it's possible to determine if a peer with a specific name is configured in Asterisk by sending a specially crafted REGISTER message twice. Upgrading to the latest version remedies these issues.

System: Many
Topic: Vulnerability in Blender
Links: CORE, CVE-2009-3850, ESB-2009.1486
ID: ae-200911-022

Blender is a 3D graphics application released as free software. Blender .blend project files can be modified to execute arbitrary commands without user intervention by design. An attacker can take full control of the machine where Blender is installed sending a specially crafted .blend file and enticing the user to open it. Until now, a patch isn't available.

System: Various
Topic: Vulnerability in HP Power Manager
Links: HPSBMA02474, SSRT090107, HP_c01905743, CVE-2009-2685, ESB-2009.1485
ID: ae-200911-021

A potential security vulnerability has been identified with HP Power Manager. The vulnerability could be exploited remotely to execute arbitrary code. To avoid this vulnerability network access to the HP Power Manager should be limited to trusted users.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.4.2-ibm
Links: RHSA-2009-1551, CVE-2008-5349, CVE-2009-2625, ESB-2009.1483
ID: ae-200911-020

Two vulnerabilities have been found in the IBM Java 4 JRE/SDK used in Red Hat Enterprise Linux for SAP. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2009-090, DRUPAL-SA-CONTRIB-2009-091, DRUPAL-SA-CONTRIB-2009-092, DRUPAL-SA-CONTRIB-2009-093, DRUPAL-SA-CONTRIB-2009-094, DRUPAL-SA-CONTRIB-2009-095, DRUPAL-SA-CONTRIB-2009-096, DRUPAL-SA-CONTRIB-2009-097, DRUPAL-SA-CONTRIB-2009-098, ESB-2009.1482
ID: ae-200911-019

Several vulnerabilities were found in the Drupal third-party modules User Protect, Node Hierarchy , Presentation Player, Temporary Invitation, NGP COO/CWP Integration, Smartqueues for Organic Groups, Link, Organic Groups Vocabulary, and Zoomify.
Updated software is available now and should be installed immediately when using these modules. Please be aware that Drupal core is not affected.

System: IBM AIX
Topic: Vulnerability in PowerHA Cluster Management
Links: IBM, CVE-2009-3900, ESB-2009.1481
ID: ae-200911-018

PowerHA Cluster Management monitoring of port 6177 allows a remote attacker to make arbitrary changes to the local AIX configuration. Fixes are now available.

System: Many
Topic: Vulnerability in Shibboleth
Links: Shibboleth Security Advisory, CVE-2009-3300, ESB-2009.1480
ID: ae-200911-017

The Shibboleth System is a standards based, open source software package for web single sign-on. The Shibboleth software includes code to perform arbitrary redirections and generates forms containing arbitrary destinations in certain cases. The URLs used were not properly checked for certain kinds of cross-site scripting (XSS) attacks and are vulnerable to script injection and some related vulnerabilities. Updated versions of the Shibboleth 1.3.x and 2.x Identity Provider and Service Provider software are available now.

System: Sun Solaris 10
Topic: Problem with Sun Solaris Kernel patches
Links: Sun Alert #264730, ESB-2009.1471
ID: ae-200911-016

Sun Solaris 10 Kernel Patches 141444-09 and 141445-09 may cause Interface failure in IP Multipathing (IPMP) when configured for probe based failure detection. This issue doesn't occur with a IPMP link based failure detection configuration. A workaround is described in the advisory.

System: Sun Solaris
Topic: Vulnerability in Sun Virtual Desktop Infrastructure
Links: Sun Alert #268328, CVE-2009-3923, ESB-2009.1478
ID: ae-200911-015

A security vulnerability in the Sun Virtual Infrastructure (VDI) 3.0 authentication mechanism may allow remote unprivileged users to gain unauthorized access to the VirtualBox web service. A patch for Sun Solaris 10 is available now.

System: SuSE Linux
Topic: Vulnerability in the kernel
Links: SUSE, CVE-2009-3547, ESB-2009.1477
ID: ae-200911-014

A bug in the Linux kernels "pipe" system call implementation was found which can be used by local attackers to gain root privileges. Hints for increasing security have been published. They should be implemented until a patch is available.

System: Microsoft Windows
Topic: Vulnerability in Symantec Altiris
Links: Symantec, CVE-2009-3031, ESB-2009.1473
ID: ae-200911-013

Symantecs Altiris Deployment Solution and Notification Server web consoles install a vulnerable ActiveX control. While the control is not intended to be called externally, it fails to properly validate/filter user input which could potentially allow unauthorized execution of arbitrary code on the targeted system in the context of the users browser. An update resolves this issue.

System: Sun Solaris 10
Topic: Vulnerability in Solaris Sockets Direct Protocol
Links: Sun Alert #264730, ESB-2009.1471
ID: ae-200911-012

A security vulnerability in Solaris Sockets Direct Protocol (SDP) driver (sdp(7D)) may allow a local or remote unprivileged user to exhaust all kernel memory. This is a type of Denial-of-Service (DoS). A patch remedies this problem.

System: Various
Topic: Vulnerability in Novell eDirectory
Links: ZDI-09-075, CVE-2009-3862, ESB-2009.1469
ID: ae-200911-011

A vulnerability in Novell's eDirectory Server has been found. Due to a flaw in the LDAP implementation, attackers are able to initiate a remote Denial-of-Service (DoS) attack. Novell has issued an update to correct this vulnerability.

System: Debian GNU/Linux
Topic: Vulnerabilities in drupal6, nspr, and pidgin
Links: DSA-1930, CVE-2009-2372, CVE-2009-2373, CVE-2009-2374, ESB-2009.1492,
DSA-1931, CVE-2009-1563, CVE-2009-2463, ESB-2009.1493,
DSA-1932, CVE-2009-3615, ESB-2009.1494
ID: ae-200911-010

Several vulnerabilities have been found in drupal6, a fully-featured content management framework.
Several vulnerabilities have been discovered in the NetScape Portable Runtime Library, which may lead to the execution of arbitrary code.
It was discovered that incorrect pointer handling in the purple library, an internal component of the multi-protocol instant messaging client Pidgin, could lead to denial of service or the execution of arbitrary code through malformed contact requests.
Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in java-1_6_0-ibm
Links: SUSE-SA:2009:053, CVE-2009-0217, CVE-2009-2493, CVE-2009-2625, CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, CVE-2009-2676, ESB-2009.1476
ID: ae-200911-009

Several vulnerabilities were found in the IBM Java 6 JRE/SDK. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in typo3
Links: DSA-1926, CVE-2009-3628, CVE-2009-3629, CVE-2009-3630, CVE-2009-3631, CVE-2009-3632, CVE-2009-3633, CVE-2009-3634, CVE-2009-3635, CVE-2009-3636, ESB-2009.1474
ID: ae-200911-008

Several remote vulnerabilities have been discovered in the TYPO3 web content management framework. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in kernel 2.6
Links: DSA-1927, DSA-1928, DSA-1929, CVE-2009-3228, CVE-2009-3547, CVE-2009-3612, CVE-2009-3620, CVE-2009-3621, CVE-2009-3638, ESB-2009.1484, ESB-2009.1488, ESB-2009.1491
ID: ae-200911-007

Several vulnerabilities have been found in linux 2.6, the kernel which is the base of the system. These vulnerabilities might lead to privilege escalation, Denial-of-Service (DoS) or leaking sensitive information. An update addresses this issue.

System: Microsoft Windows, Apple Mac OS
Topic: Vulnerabilities in Adobe Shockwave Player
Links: APSB09-16, CVE-2009-3244, CVE-2009-3463, CVE-2009-3464, CVE-2009-3465, CVE-2009-3466, ESB-2009.1472
ID: ae-200911-006

Critical vulnerabilities have been identified in Adobe Shockwave Player. The vulnerabilities could allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in wget
Links: RHSA-2009-1549, CVE-2009-3490, ESB-2009.1468
ID: ae-200911-005

It was discovered that Wget is affected by the previously published "null prefix attack", caused by incorrect handling of NULL characters in X.509 certificates. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in Kernel
Links: RHSA-2009-1541, RHSA-2009-1548, RHSA-2009-1550, ESB-2009.1467
ID: ae-200911-004

Several vulnerabilities have been discovered in the Linux kernels of Red Hat Enterprise Linux. Updated kernel packages are available now.

System: SUSE Linux Enterprise, openSuSE
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2009:051, CVE-2009-2909, CVE-2009-2910, CVE-2009-3002, ESB-2009.1466
ID: ae-200911-003

Several vulnerabilities were found in the kernel of SuSE Linux. Exploiting these vulnerabilities might have security impact, e.g. local users getting privileged access to the system. Fixed kernel packages are available now.

System: Various
Topic: Vulnerability in Sun GlassFish Enterprise Server
Links: Sun Alert #269208, CVE-2009-0217, ESB-2009.1464
ID: ae-200911-002

A security vulnerability with verifying HMAC-based XML digital signatures in the XML digital signature implementation included with the Sun GlassFish Enterprise Server may allow authentication to be bypassed. Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in mahara and proftpd-dfsg
Links: DSA-1924, CVE-2009-3298, CVE-2009-3299, ESB-2009.1462,
DSA-1925, CVE-2009-3639, ESB-2009.1463
ID: ae-200911-001

Two vulnerabilities have been discovered in mahara, an electronic portfolio, weblog, and resume builder.
It has been discovered that proftpd-dfsg, a virtual-hosting FTP daemon, does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 client certificate, when the dNSNameRequired TLS option is enabled.
Fixed packages are available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH