Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/1.0 (+http://www.commoncrawl.org/bot.html)

Your IP address

(no reverse DNS resolution) [38.107.191.86]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 12 / 2009

System: Debian GNU/Linux
Topic: Vulnerabilities in PostgreSQL
Links: DSA-1964, CVE-2009-4034, CVE-2009-4136, ESB-2010.0001
ID: ae-200912-068

Multiple security vulnerabilities have been identified in the PostgreSQL software shipped with Debian Linux. These vulnerabilities may allow a remote authenticated user with certain privileges to gain extra privileges via a table with a crafted index function. Further vulnerabilities may allow man-in-the-middle attacks on SSL based PostgreSQL servers by substituting malicious SSL certificates for trusted ones. New releases are available now.

System: Unix, Linux, OS X
Topic: Vulnerability in MIT Kerberos 5
Links: MITKRB5-SA-2009-003, CVE-2009-3295, ESB-2009.1685
ID: ae-200912-067

An unauthenticated remote attacker could cause the KDC to crash due to a null pointer dereference. Legitimate requests can also cause this crash to occur, meaning a Denial-of-Service. A workaround is described in the advisory. The upcoming krb5-1.7.1 release will contain a fix for this vulnerability.

System: Many
Topic: Vulnerabilities in Directory Proxy Server
Links: Sun Alert #270789, CVE-2009-4440, CVE-2009-4441, CVE-2009-4442, CVE-2009-4443, ESB-2009.1684
ID: ae-200912-066

The Sun Microsystems Directory Proxy Server provided with Directory Server Enterprise Edition 6 is subject to Denial-of-Service (DoS) and may allow unauthorized access to certain data. Patches address this issue.

System: Debian GNU/Linux
Topic: Vulnerability in aria2
Links: DSA-1957, CVE-2009-3575, ESB-2009.1682
ID: ae-200912-065

Aria2 is a high speed download utility, which is prone to a buffer overflow in the DHT routing code, which might lead to the execution of arbitrary code. Updated software is available now.

System: Sun Solaris
Topic: Vulnerabilities in PostgreSQL
Links: Sun Alert #274870, CVE-2009-4034, CVE-2009-4136, ESB-2009.1683
ID: ae-200912-064

Multiple security vulnerabilities have been identified in the PostgreSQL software shipped with Solaris. These vulnerabilities may allow a remote authenticated user with certain privileges to gain extra privileges via a table with a crafted index function. Further vulnerabilities may allow man-in-the-middle attacks on SSL based PostgreSQL servers by substituting malicious SSL certificates for trusted ones. New releases are available now.

System: Various
Topic: Vulnerabilities in two Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2009-113, DRUPAL-SA-CONTRIB-2009-114, ESB-2009.1680, ESB-2009.1681
ID: ae-200912-063

Several vulnerabilities were found in the Drupal third-party modules Frequently Asked Questions (faq) and Automated Logout. Updated software is available now. Please be aware that Drupal core is not affected.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-ibm
Links: RHSA-2009-1694, RHSA-2010-0043, CVE-2009-0217, CVE-2009-3865, CVE-2009-3866, CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877, ESB-2009.1679, ESB-2010.0045
ID: ae-200912-062

Several vulnerabilities were found in the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in BIND 9, kvm, and unbound
Links: DSA-1961, CVE-2009-4022, VU#418861, ESB-2009.1675,
DSA-1962, CVE-2009-3638, CVE-2009-3722, CVE-2009-4031, ESB-2009.1676,
DSA-1962, CVE-2009-3602, ESB-2009.1677
ID: ae-200912-061

The DNS resolver component in BIND doesn't properly check DNS records contained in additional sections of DNS responses, leading to a cache poisoning vulnerability. This vulnerability is only present in resolvers which have been configured with DNSSEC trust anchors.
Several vulnerabilities have been discovered in kvm, a full virtualization system. They might lead to Denial-of-Service (DoS) and maybe further consequences.
Unbound is a DNS resolver. It doesn't properly check cryptographic signatures on NSEC3 records. As a result, zones signed with the NSEC3 variant of DNSSEC lose their cryptographic protection.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerability in proftpd
Links: MDVSA-2009:337, CVE-2009-3555, ESB-2009.1674
ID: ae-200912-060

A potential security vulnerability has been identified in proftpd, a common FTP server included in Mandriva Linux. This vulnerability is the well known in SSL and TLS leading to attackers remotely injecting unauthorized data or creating a Denial-of-Service (DoS). A software update addresses this issue.

System: SuSE Linux
Topic: Vulnerabilities in kernel
Links: SUSE-SA:2009:064, ESB-2009.1673
ID: ae-200912-059

An update fixes several security issues and various bugs in the SuSE Linux Enterprise 10 SP 2 kernel. Exploiting these vulnerablities might lead to the execution of arbitrary code or commands, increased privileges or Denial-of-Service (DoS).

System: Many
Topic: Vulnerabilities in Firefox and Seamonkey
Links: MFSA 2009-65, MFSA 2009-66, MFSA 2009-67, MFSA 2009-68, MFSA 2009-69, MFSA 2009-70, SUSE-SA:2009:063, ESB-2009.1671, MDVSA-2009:339, TLSA-2009-35
ID: ae-200912-058

Several vulnerabilities have been found in Firefox, the well known web browser. Versions before 3.0.16 and 3.5.6 might allow remote execution of code or give attackers the ability to crash the browser. Please use the latest versions only.

System: Many
Topic: Vulnerabilities in flash-player
Links: SUSE-SA:2009:062, CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800, CVE-2009-3951, ESB-2009.1672, TLSA-2009-34
ID: ae-200912-057

A security update was released for the Adobe Flash Player 10. Specially crafted Flash (SWF) files can cause overflows in flash-player. Attackers could potentially exploit that to execute arbitrary code. Fixed packages for Adobe Flash Player 9 will hopefully be released in the new year.

System: Many
Topic: Vulnerability in Apache
Links: HPSBUX02498, SSRT090264, CVE-2009-3555, ESB-2009.1670
ID: ae-200912-056

A potential security vulnerability has been identified with HP-UX running Apache v2.0.59.12 and earlier. Exploiting this ssl based vulnerability might allow attackers to remotely to inject unauthorized data or to create a Denial-of-Service (DoS). Temporary software updates are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in condor
Links: RHSA-2009-1688, RHSA-2009-1689, CVE-2009-4133, ESB-2009.1669
ID: ae-200912-055

Condor is a specialized workload management system for compute-intensive jobs. A flaw has been found in the way Condor manages jobs. This could allow a user that is authorized to submit jobs into Condor to queue a job as if it were submitted by a different local user, potentially leading to unauthorized access to that user's account. An updated package is available now.

System: Mandriva Linux
Topic: Vulnerabilities in koffice
Links: MDVSA-2009:336, CVE-2009-3606, CVE-2009-3609, ESB-2009.1668
ID: ae-200912-054

Security vulnerabilities have been discovered and fixed in pdf processing code embedded in koffice package. So it's recommended to update to the latest patchlevel.

System: Many
Topic: Vulnerability in IBM SDK for Java
Links: IBM, CVE-2009-3555, ESB-2009.1667
ID: ae-200912-053

A TLS/SSL weakness exists in multiple implementations of the Transport Layer Security (TLS) protocol, including SSLv3. SSLv2 is not affected. The vulnerability is possible when the rarely used TLS handshake recognition is configured. It allows a man-in-the-middle attack by injecting HTTP requests in a HTTPS session without being noticed. An update addresses this issue by disabling the TLS handshake recognition.

System: Various
Topic: Vulnerabilities in gtk2
Links: Fedora, ESB-2009.1666
ID: ae-200912-052

GTK+ is a multi-platform toolkit for creating graphical user interfaces. An update fixes a crasher issue in gtk2 involving out of process windows. Side effects of the bug are sporadic panel crashes, and occasional crashes in gnome-screensaver when typing an invalid password. It's recommended to use this latest version only.

System: Debian GNU/Linux
Topic: Vulnerabilities in ganeti and acpid
Links: DSA-1959, CVE-2009-4261, ESB-2009.1663,
DSA-1960, CVE-2009-4235, ESB-2009.1664
ID: ae-200912-051

It was discovered that ganeti, a virtual server cluster manager, doesn't validate the path of scripts passed as arguments to certain commands, which allows local or remote users to execute arbitrary commands on a host acting as a cluster master.
Further on, it has been found out that acpid, the Advanced Configuration and Power Interface event daemon, creates its log file with weak permissions. Due to this, sensitive information might be exposed or abused by a local user to consume all free disk space on the same partition of the file.
Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Adobe Flash Media Server
Links: APSB09-18, CVE-2009-3791, CVE-2009-3792, ESB-2009.1665
ID: ae-200912-050

Critical vulnerabilities have been identified in Adobe Flash Media Server (FMS) 3.5.2 and earlier versions. The vulnerabilities might allow an attacker, who successfully exploits the vulnerabilities, to run malicious code on the affected system. Adobe has provided a solution for the reported vulnerabilities.

System: Microsoft Windows
Topic: Vulnerability in Citrix NetScaler and Citrix Access Gateway
Links: CTX123649, CVE-2008-4609, ESB-2009.1662
ID: ae-200912-049

A vulnerability has been identified in the NetScaler and Access Gateway Enterprise Edition appliance firmware that could result in a limited denial of service. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in ffmpeg
Links: MDVSA-2009:335, CVE-2007-6718, CVE-2008-4610, ESB-2009.1661
ID: ae-200912-048

MPlayer allows remote attackers to cause a denial of service via a malformed AAC file or a malformed Ogg Media (OGM) file. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Cisco WebEx WRF Player
Links: Cisco, CVE-2009-2875, CVE-2009-2876, CVE-2009-2877, CVE-2009-2878, CVE-2009-2879, CVE-2009-2880, ESB-2009.1655
ID: ae-200912-047

Multiple buffer overflow vulnerabilities exist in the Cisco WebEx Recording Format (WRF) Player. In some cases, exploitation of the vulnerabilities could allow a remote attacker to execute arbitrary code on the system of a targeted user. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in xpdf, gpdf, and kdegraphics
Links: RHSA-2009-1680, RHSA-2009-1681, RHSA-2009-1682, CVE-2009-4035, ESB-2009.1648
ID: ae-200912-046

A buffer overflow flaw was discovered in Xpdf's Type 1 font parser. A specially-crafted PDF file with an embedded Type 1 font could cause Xpdf to crash or, possibly, execute arbitrary code when opened. Also affected are the gpdf and kdegraphics packages. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in cacti and network-manager
Links: DSA-1954, CVE-2007-3112, CVE-2007-3113, CVE-2009-4032, CVE-2009-4112, ESB-2009.1649,
DSA-1955, CVE-2009-0365, ESB-2009.1650
ID: ae-200912-045

Several vulnerabilities have been found in cacti, a frontend to rrdtool for monitoring systems and services.
It was discovered that network-manager-applet, a network management framework, lacks some dbus restriction rules, which allows local users to obtain sensitive information.
Fixed packages are available now.

System: Various
Topic: Vulnerability in Adobe Reader and Adobe Acrobat
Links: APSA09-07, APSB10-02, CVE-2009-4324, VU#508357
ID: ae-200912-044

A critical vulnerability was discovered in Adobe Reader and Acrobat that could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild. Fixed software is not available yet. Workarounds are discribed in the advisory.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in Kernel
Links: RHSA-2009-1670, RHSA-2009-1671, CVE-2009-2910, CVE-2009-3612, CVE-2009-3613, CVE-2009-3620, CVE-2009-3621, CVE-2009-3726, ESB-2009.1643
ID: ae-200912-043

Several vulnerabilities have been discovered in the Linux kernels of Red Hat Enterprise Linux. Updated kernel packages are available now.

System: Various
Topic: Vulnerabilities in Mozilla Firefox, Thunderbird, and Seamonkey
Links: Mozilla, RHSA-2009-1673, RHSA-2009-1674, ESB-2009.1646, DSA-1956, ESB-2009.1646
ID: ae-200912-042

Several vulnerabilities were found in the Mozilla Firefox browser, Thuderbird and Seamonkey. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in firefox-sage, asterisk, and expat
Links: DSA-1951, CVE-2009-4102, ESB-2009.1640,
DSA-1952, CVE-2007-2383, CVE-2008-3903, CVE-2008-7220, CVE-2009-0041, CVE-2009-3727, CVE-2009-4055, ESB-2009.1641,
DSA-1953, CVE-2009-3560, ESB-2009.1642
ID: ae-200912-041

It was discovered that firefox-sage, a lightweight RSS and Atom feed reader for Firefox, does not sanitise the RSS feed information correctly, which makes it prone to a cross-site scripting and a cross-domain scripting attack.
Several vulnerabilities have been discovered in asterisk, an Open Source PBX and telephony toolkit.
An error was discovered in expat, an XML parsing C library, when parsing certain UTF-8 sequences, which can be exploited to crash an application using the library.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerability in gimp
Links: MDVSA-2009:332, CVE-2009-3909, ESB-2009.1637
ID: ae-200912-040

An integer overflow in the read_channel_data function in plug-ins/file-psd/psd-load.c in GIMP might allow remote attackers to execute arbitrary code via a crafted PSD file that triggers a heap-based buffer overflow. Fixed packages are available now.

System: SuSE Enterprise Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2009:061, CVE-2005-4881, CVE-2009-2903, CVE-2009-3080, CVE-2009-3612, CVE-2009-3620, CVE-2009-3621, CVE-2009-3726, CVE-2009-3889, CVE-2009-3939, CVE-2009-4005, CVE-2009-4021, ESB-2009.1645
ID: ae-200912-039

Several vulnerabilities were found in the kernel of SuSE Linux and OpenSUSE Linux. Exploiting these vulnerabilities might have security impact, e.g. local users getting privileged access to the system. Fixed kernel packages are available now.

System: Various
Topic: Vulnerabilities in Sun Ray Server Software
Links: Sun Alert, ESB-2009.1632,
Sun Alert, ESB-2009.1639
ID: ae-200912-038

When a local user logs out of a Sun Ray desktop session, the session may log the user back in again.
A security vulnerability in the generation of encryption keys for Sun Ray firmware may allow a remote unprivileged user, who is able to intercept network traffic, to predict the private key and decrypt the mouse, keyboard, and display traffic between the Sun Ray DTU and the Sun Ray Server.
Patches are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in php-net-ping and webkit
Links: DSA-1949, CVE-2009-4024, ESB-2009.1635,
DSA-1950, CVE-2009-0945, CVE-2009-1681, CVE-2009-1684, CVE-2009-1687, CVE-2009-1690, CVE-2009-1692, CVE-2009-1693, CVE-2009-1694, CVE-2009-1695, CVE-2009-1697, CVE-2009-1698, CVE-2009-1710, CVE-2009-1711, CVE-2009-1712, CVE-2009-1714, CVE-2009-1725, ESB-2009.1636
ID: ae-200912-037

It was discovered that php-net-ping, a PHP PEAR module to execute ping independently of the Operating System, performs insufficient input sanitising, which might be used to inject arguments or execute arbitrary commands on a system that uses php-net-ping.
Several vulnerabilities have been discovered in WebKit, a Web content engine library for Gtk+.
Updated software is available now.

System: Various
Topic: Vulnerability in CA Service Desk
Links: CA20091208-01, CVE-2009-4149, ESB-2009.1629
ID: ae-200912-036

A cross-site scripting vulnerability exists with CA Service Desk, that can allow a remote attacker to potentially gain sensitive information. Patches are available now.

System: Various
Topic: Vulnerabilities in Sun Ray Server Software
Links: Sun Alert, ESB-2009.1630,
Sun Alert, ESB-2009.1631
ID: ae-200912-035

A security vulnerability in the Sun Ray Server Software Authentication Manager may allow a remote unprivileged user to cause a Denial of Service (DoS) to Sun Ray services or to run arbitrary code with root privileges.
A security vulnerability in the generation of encryption keys for Sun Ray firmware may allow a remote unprivileged user, who is able to intercept network traffic, to predict the private key and decrypt the mouse, keyboard, and display traffic between the Sun Ray DTU and the Sun Ray Server.
Patches are available now.

System: Various
Topic: Vulnerabilities in HP OpenView Network Node Manager
Links: CVE-2009-3845, CVE-2009-3848, CVE-2009-3849, ESB-2009.1627
ID: ae-200912-034

Several security vulnerabilities have been identified with the HP OpenView Network Node Manager. Patches are available now.

System: Various
Topic: Vulnerability in HP Application Recovery Manager
Links: CVE-2009-3844, ESB-2009.1626
ID: ae-200912-033

A security vulnerability has been identified with the Hewlett-Packard Application Recovery Manager. Patches are available now.

System: HP-UX
Topic: Vulnerability in VRTSweb
Links: HPSBUX02480 SSRT090253, CVE-2009-3027, ESB-2009.1624
ID: ae-200912-032

A security vulnerability has been identified with HP-UX running VRTSweb version 5.0. The vulnerability could be exploited remotely to execute arbitrary code or increase privilege. Patches are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in flash-plugin, kvm, and JBoss Enterprise Application Platform
Links: RHSA-2009-1658, RHSA-2009-1659, CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800, ESB-2009.1620,
RHSA-2009-1659, CVE-2009-4031, ESB-2009.1621,
RHSA-2009-1636, RHSA-2009-1637, RHSA-2009-1649, RHSA-2009-1650, CVE-2009-0217, CVE-2009-1380, CVE-2009-2405, CVE-2009-2625, CVE-2009-3554, ESB-2009.1622
ID: ae-200912-031

Several vulnerabilities were found in the Adobe Flash Player.
Users in guest operating systems could leverage a flaw in 'kvm' to cause large latencies on SMP hosts that could lead to a local denial of service on the host operating system.
Several vulnerabilities were found in the JBoss Enterprise Application Platform (JBEAP).
Fixed packages are available now.

System: HP-UX
Topic: Vulnerability in sendmail
Links: HPSBUX02495, SSRT090151, CVE-2009-2261, ESB-2009.1619
ID: ae-200912-030

A potential security vulnerability has been identified with HP-UX running sendmail. This vulnerability could allow a remote user to cause a Denial-of-Service (DoS). An upgrade to sendmail 8.13.3 should be done.

System: Microsoft Windows
Topic: Vulnerability in Indeo Codec
Links: MS #954157, iDefense, VU#228561, CVE-2009-4210, ESB-2009.1617
ID: ae-200912-029

No further comment due to legal reasons

System: Many
Topic: Vulnerabilities in java-1.5.0-ibm
Links: CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877, RHSA-2009-1647, ESB-2009.1616, SUSE-SA:2010:002
ID: ae-200912-028

Several vulnerabilities were found in the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. Fixed packages are available now.

System: Linux
Topic: Vulnerabilities in libtool
Links: CVE-2009-3736, RHSA-2009-1646, ESB-2009.1618, DSA-1958, ESB-2009.1686,
ID: ae-200912-027

A flaw has been found in the way GNU Libtool's libltdl library looks for modules to load. It's possible for libltdl to load and run modules from an arbitrary library in the current working directory. If a local attacker could trick a local user into running an application (which uses libltdl) from an attacker-controlled directory containing a malicious Libtool control file (.la), the attacker could possibly execute arbitrary code with the privileges of the user running the application. Updated software is available now.

System: Various
Topic: Vulnerability in NTP
Links: NTP #1331, CVE-2009-3563, VU #568372, RHSA-1648, RHSA-1651, ESB-2009.1614, DSA-1948, ESB-2009.1613
ID: ae-200912-026

A flaw in NTP allows to build an effective and easy exploitable Denial-of-Service (DoS) attack. The reson is that unexpected mode 7 responses are not dropped as they should. Further on, mode 7 packets originated from port 123/udp are not dropped. An update is available now.

System: Microsoft Windows
Topic: Vulnerability in Microsoft Office Project
Links: MS09-074, CVE-2009-0102, ESB-2009.1615
ID: ae-200912-025

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in WordPad and Office Text Converters
Links: MS09-073, iDefense, CVE-2009-2506, ESB-2009.1612
ID: ae-200912-024

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer
Links: MS09-072, iDefense, CVE-2009-2493, CVE-2009-3671, CVE-2009-3672, CVE-2009-3673, CVE-2009-3674, ESB-2009.1611
ID: ae-200912-023

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Internet Authentication Service
Links: MS09-071, CVE-2009-2505, CVE-2009-3677, ESB-2009.1610
ID: ae-200912-022

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Active Directory Federation Services
Links: MS09-070, CVE-2009-2508, CVE-2009-2509, ESB-2009.1609
ID: ae-200912-021

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Local Security Authority Subsystem Service
Links: MS09-069, CVE-2009-3675, ESB-2009.1608
ID: ae-200912-020

No further comment due to legal reasons

System: Various
Topic: Vulnerability in HP OpenView Data Protector Application Recovery Manager
Links: HPSBMA02481 SSRT090113, CVE-2009-3844, ESB-2009.1607
ID: ae-200912-019

A security vulnerability has been identified with HP OpenView Data Protector Application Recovery Manager version 5.5 and 6.0. The vulnerability could be exploited remotely to create a denial of service (DoS). A software update is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.4.2-ibm
Links: RHSA-2009-1643, CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877, ESB-2009.1605
ID: ae-200912-018

Several vulnerabilities were found in the IBM Java 2 Runtime Environment and the IBM Java 2 Software Development Kit. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in expat and acpid
Links: RHSA-2009-1625, CVE-2009-3560, CVE-2009-3720, ESB-2009.1604,
RHSA-2009-1642, CVE-2009-4033, ESB-2009.1603
ID: ae-200912-017

Two buffer over-read flaws were found in the way Expat handled malformed UTF-8 sequences when processing XML files. A specially-crafted XML file could cause applications using Expat to crash while parsing the file.
It was discovered that acpid could create its log file ("/var/log/acpid") with random permissions on some systems. A local attacker could use this flaw to escalate their privileges if the log file was created as world-writable and with the setuid or setgid bit set.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in shibboleth
Links: DSA-1947, CVE-2009-3300, ESB-2009.1606
ID: ae-200912-016

It was discovered that Shibboleth, a federated web single sign-on system is vulnerable to script injection through redirection URLs. Fixed packages are available now.

System: Sun Solaris, OpenSolaris
Topic: Vulnerabilities in gtar and wget
Links: Sun Alert #273551, CVE-2007-4131, CVE-2009-4476, ESB-2009.1595,
Sun Alert #273590, CVE-2009-3490, ESB-2009.1596
ID: ae-200912-015

Two security vulnerabilities have been found in the GNU tar gtar(1) archiving program bundled with Solaris 9, Solaris 10 and OpenSolaris. The first issue is a directory traversal vulnerability that may allow a local or remote unprivileged user who provides a specially crafted archive to overwrite arbitrary files which the user executing gtar(1) has permission to modify. The second issue is a buffer overflow which may allow a local or remote unprivileged user who provides a specially crafted tar archive to execute arbitrary commands with the privileges of the user executing gtar(1) or to cause gtar(1) to crash. The ability to cause a program crash is a type of Denial-of-Service (DoS).
A security vulnerability in the wget(1) command shipped with Solaris may allow a local or remote unprivileged user who provides a specially crafted certificate signed by a legitimate Certification Authority to intercept encrypted HTTP (HTTPS) communication between the wget(1) client and a web server using a man-in-the-middle (MITM) attack.
Updated packages address these issues.

System: Sun Solaris
Topic: Vulnerabilities in libxml2 and libexpat
Links: Sun Alert #266428, CVE-2008-3529, CVE-2008-4225, CVE-2008-4226, ESB-2009.1594,
Sun Alert #273630, CVE-2009-3560, CVE-2009-3720, ESB-2009.1597
ID: ae-200912-014

Multiple security vulnerabilities in the XML library bundled with Sun Management Center 3.6.1 and 4.0 may allow a local or remote unprivileged user to execute arbitrary code with the privileges of the SunMC application or crash the SunMC application causing a Denial-of-Service (DoS) by providing a specially crafted XML file. The SunMC application runs with root privileges.
Multiple security vulnerabilities have been identified in Sun Solaris 10 libexpat, a library for parsing XML files. These vulnerabilities may allow a local or remote unprivileged user to create a crafted XML file that may cause an application linked with libexpat to crash, resulting in a Denial-of-Service (DoS) condition.
Updated packages are available now.

System: FreeBSD
Topic: Vulnerabilities in ssl, rtld, and freebsd-update
Links: FreeBSD-SA-09:15, CVE-2009-3555, ESB-2009.1591,
FreeBSD-SA-09:16, CVE-2009-4146, CVE-2009-4147, ESB-2009.1592,
FreeBSD-SA-09:17, ESB-2009.1593
ID: ae-200912-013

The SSL version 3 and TLS protocols support session renegotiation without cryptographically tying the new session parameters to the old parameters. So an attacker who can intercept a TCP connection being used for SSL or TLS can cause the initial session negotiation to take the place of a session renegotiation leading to a man-in-the-middle attack.
The run-time link-editor, rtld, links dynamic executable with their needed libraries at run-time. When running setuid programs rtld will normally remove potentially dangerous environment variables. Due to recent changes in FreeBSD environment variable handling code, a corrupt environment may result in attempts to unset environment variables failing. An unprivileged user who can execute programs on a system can gain the privileges of any setuid program which he can run, mostly root.
When downloading updates to FreeBSD via 'freebsd-update fetch' or 'freebsd-update upgrade', the freebsd-update(8) utility copies currently installed files into its working directory. A local user can read files which have been updated by freebsd-update(8), even if those files have permissions which would normally not allow users to read them.
Patches address these issues.

System: Debian GNU/Linux
Topic: Vulnerabilities in request-tracker, gforge, and belpic
Links: DSA-1944, CVE-2009-3585, ESB-2009.1589,
DSA-1945, CVE-2009-3304, ESB-2009.1590,
DSA-1946, CVE-2009-0049, ESB-2009.1600
ID: ae-200912-012

Request-tracker is a trouble-ticket system. It's prone to an attack where an attacker with access to the same domain can hijack a user's RT session.
Gforge is a collaborative development tool. Local users are able to perform a Denial-of-Service (DoS) by overwriting aritrary files via a symlink attack.
Belpic is the belgian eID PKCS11 library. Due to a not sufficient checking of the result of an OpenSSL function for verifying cryptographic signatures, the certification verification can be bypassed.
Updated software is available now.

System: Red Hat Enterprise Linux Server 5
Topic: Vulnerabilities in kernel-rt
Links: RHSA-2009-1635, CVE-2009-3726, CVE-2009-3889, CVE-2009-3939, ESB-2009.1588
ID: ae-200912-011

For MRG Realtime for RHEL 5 Server updated kernel-rt packages are available now. They are fixing security issues as well as some bugs. It's recommended to install this update.

System: Mac OS X
Topic: Many vulnerabilities in Java
Links: Apple #3969, Apple #3970, ESB-1587
ID: ae-200912-010

Java for Mac OS X 10.6 Update 1 and 10.5 Update 6 has been published now. Many vulnerabilities regarding Java are fixed in these updates. Exploiting them could lead to Denial-of-Service, the execution of arbitrary code as well as further effects leading to reduced security.

System: Turbolinux
Topic: Vulnerability in OpenLDAP
Links: Mozilla Foundation, TLSA-2009-31, CVE-2009-2408, CVE-2009-2409
ID: ae-200912-009

Mozilla Firefox (webnavi) is an open-source web browser. A new version of the Turbolinux Client solves many of security problems with this software.

System: Debian GNU/Linux
Topic: Vulnerability in OpenLDAP
Links: DSA-1943, CVE-2009-3767, ESB-2009.1585
ID: ae-200912-008

It has been discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, when OpenSSL is used, does not properly handle a special character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. Updated software is available now.

System: HP-UX
Topic: Vulnerability in OpenSSL
Links: Sun Alert #273350, CVE-2009-3555, ESB-2009.1584
ID: ae-200912-007

The TLS/SSLv3 protocol as implemented in openssl isn't able to associate already sent data to a renegotiated connection. This allows a man-in-the-middle attack by injecting HTTP requests in a HTTPS session without being noticed. An update of Sun Java Enterprise System and sun-nss addresses this issue which affects not only Sun Solaris, but also RHEL, HP-UX and Microsoft Windows.

System: Various
Topic: Vulnerabilities in Sun Java System Portal Server
Links: Sun Alert #269368, ESB-2009.1583
ID: ae-200912-006

Multiple Cross-Site Scripting (XSS) security vulnerabilities exist in Sun Java System Portal Server's Gateway that may allow remote users to execute arbitrary JavaScript code in a user's web browser. A patch remedies this issue.

System: HP NonStop Servers
Topic: Vulnerabilities in Kernel
Links: HPSBNS02475, SSRT090068, CVE-2009-2686, ESB-2009.1582
ID: ae-200912-005

A potential vulnerability has been identified with the HP NonStop Servers. The vulnerability could be exploited locally resulting in an unauthorized access to data, Denial-of-Service (DoS), or execution of arbitrary code. A software update is available now.

System: SuSE Enterprise Linux
Topic: Vulnerabilities in Kernel
Links: SUSE-SA:2009:060, CVE-2005-4881, CVE-2009-2903, CVE-2009-2910, CVE-2009-3286, CVE-2009-3547, CVE-2009-3612, CVE-2009-3620, CVE-2009-3621, CVE-2009-3726, ESB-2009.1581
ID: ae-200912-004

Several vulnerabilities were found in the kernel of SuSE Linux and OpenSUSE Linux. Exploiting these vulnerabilities might have security impact, e.g. local users getting privileged access to the system. Fixed kernel packages are available now.

System: SuSE Linux
Topic: Vulnerability in BIND
Links: SUSE-SA:2009:059, CVE-2009-4022, ESB-2009.1580
ID: ae-200912-003

The BIND DNS server was updated to close a possible cache poisoning vulnerability which allowed to bypass DNSSEC. This problem can only happen after the other spoofing/poisoning mechanisms have been bypassed already (the port and transaction id randomization). Also this can only happen if the server is setup for DNSSEC. An update addresses this issue.

System: Unix / Linux
Topic: Vulnerability in Asterisk
Links: AST-2009-010, CVE-2009-4055, ESB-2009.1579
ID: ae-200912-002

Asterisk is a free software for telephones. An attacker sending a valid RTP comfort noise payload containing a data length of 24 bytes or greater can remotely crash Asterisk. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in xerces-j2 and dstat
Links: RHSA-2009-1615, CVE-2009-2625, ESB-2009.1573,
RHSA-2009-1619, CVE-2009-3894, ESB-2009.1576
ID: ae-200912-001

A flaw was found in the way the Apache Xerces2 Java Parser processed the SYSTEM identifier in DTDs. A remote attacker could provide a specially-crafted XML file, which once parsed by an application using the Apache Xerces2 Java Parser, would lead to a denial of service.
A flaw was found in the Python module search path used in dstat. If a local attacker could trick a local user into running dstat from a directory containing a Python script that is named like an importable module, they could execute arbitrary code with the privileges of the user running dstat.
Fixed packages are available now.



(c) 2000-2010 AERAsec Network Services and Security GmbH