Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-54-234-42-16.compute-1.amazonaws.com [54.234.42.16]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 06 / 2010

System: Microsoft Windows
Topic: Vulnerability in Citrix XenServer
Links: CTX125319, ESB-2010.0584
ID: ae-201006-063

A vulnerability has been identified in Citrix XenServer that, when triggered, could result in a Denial-of-Service (DoS) to the host. This vulnerability can be triggered when a guest using a pvops kernel makes specific calls to the host, causing XenServer to incorrectly set flags. A hotfix has been released to address this issue.

System: Various
Topic: Vulnerability in Snare Agents
Links: HIO-2010-0426, Secunia #39562, VU #173009
ID: ae-201006-062

SNARE (System iNtrusion Analysis and Reporting Environment) is a series of log collection agents that facilitate centralised analysis of audit log data. The web interface allows the administrator to manage several agent settings, including changing the listening port and password. These HTTP requests don't perform proper validity checks and are susceptible to a cross-site request forgery attack (CSRF). Due to this, an attacker can change several agent settings, such as the password or listening port, if able to trick an administrator into visiting a specially crafted link. Updated software is available now.

System: Various
Topic: Important Patch available for Adobe Flash Player, Adobe Reader and Adobe Acrobat
Links: APSA10-01, APSB10-15, ESB-2010.0583, RHSA-2010-0503, ESB-2010.0585, SUSE-SA:2010:029, ESB-2010.0603
ID: ae-201006-061

As reported in AE-201006-008, critical vulnerabilities exist in Adobe Flash Player, Adobe Reader, and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. A fix is available now, so an upgrade is strongly recommended.

System: Various
Topic: Vulnerability in IBM FileNet P8
Links: IBM, ESB-2010.0581
ID: ae-201006-060

A security vulnerability with the IBM FileNet P8 Content Engine and Content Search Engine has been discovered. An attacker who successfully exploits this vulnerability could gain the same user rights as the user credentials used to install and configure the CSE or the user credentials used to bootstrap the CE. Fixes are available now.

System: Cisco
Topic: Vulnerability in Cisco Adaptive Security Appliance (ASA)
Links: AV10-018, CVE-2008-7257, ESB-2010.0580
ID: ae-201006-059

Cisco Adaptive Security Appliance (ASA) is vulnerable to HTTP response splitting caused by improper validation of user supplied input. A remote user can exploit this to spoof content on the target ASA appliance, attempt to poison any intermediate web caches or conduct cross-site scripting attacks. Cisco has released free software updates that address this vulnerability.

System: Linux, Microsoft Windows
Topic: Vulnerability in F-Secure Policy Manager Server
Links: FSC-2010-2, CVE-2006-3918, ESB-2010.0582
ID: ae-201006-058

F-Secure Policy Manager Server does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests. Fixed software is available now.

System: Various
Topic: Vulnerability in libTIFF
Links: iDEFENSE #874, CVE-2010-2067 , ESB-2010.0579
ID: ae-201006-057

Remote exploitation of a stack buffer overflow vulnerability in LibTIFF could allow an attacker to execute arbitrary code with the privileges of the current user. Fixed software is available now.

System: Various
Topic: Vulnerability in Bugzilla
Links: Bugzilla, CVE-2010-0180 , CVE-2010-1204 , ESB-2010.0576
ID: ae-201006-056

Bugzilla is a Web-based bug-tracking system used by a large number of software projects. Two vulnerabilities were found that allow an attacker to access privileged data. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in kvirc
Links: DSA-2065, CVE-2010-2451, CVE-2010-2452, ESB-2010.0573
ID: ae-201006-055

Two security issues have been discovered in the DCC protocol support code of kvirc, a KDE-based next generation IRC client, which allow the overwriting of local files through directory traversal and the execution of arbitrary code through a format string attack. Fixed packages are available now.

System: Various
Topic: Vulnerability in splunk
Links: SP-CAAAFHY, ISS #59517, CVE-2010-2429, Secunia #40187, ESB-2010.0570
ID: ae-201006-054

Splunk helps admininstrators to keep the overview in their IT infrastructure. A vulnerability has been discovered in Splunk. Input passed via the "Referer" header is not properly sanitised before being returned to the user within a HTTP 404 error message. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site which is a Cross-Site Scripting (XSS) attack. Successful exploitation requires the victim to use Internet Explorer. An update to version 4.1.3 remedies this problem.

System: Various
Topic: Vulnerability in PHP
Links: IBM, CVE-2010-2225, ESB-2010.0569
ID: ae-201006-053

Fllow a remote attacker to execute arbitrary code on the system, caused by an error in the SplObjectStorage class unserialize() function. An attacker could exploit this vulnerability to execute arbitrary code. ixed software is not available yet.

System: Various
Topic: Vulnerabilities in IBM WebSphere Application Server
Links: IBM #59646, IBM #59647, CVE-2010-0778, CVE-2010-0779, ESB-2010.0568
ID: ae-201006-052

Two cross-site scripting vulnerabilities were found in the IBM WebSphere Application Server. Fixed software is available now.

System: Various
Topic: Vulnerabilities in Novell iManager
Links: CORE-2010-0316, CVE-2010-1929, CVE-2010-1930, ESB-2010.0567
ID: ae-201006-051

Novell iManager is prone to a stack-based buffer overflow vulnerability that can be exploited by authenticated users to execute arbitrary code, and to an off-by-one error that can be abused by remote, unauthenticated attackers to cause a Denial of Service to the application. Fixed software is not available yet.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2010-068, DRUPAL-SA-CONTRIB-2010-069, DRUPAL-SA-CONTRIB-2010-070, ESB-2010.0565
ID: ae-201006-050

Some vulnerabilities regarding Cross-Site Scripting (XSS) were found in the Drupal third-party modules Masquerade, Case Tracker, Easy Translator, Block Queue, and Multiple Image Upload. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Mandriva Linux
Topic: Vulnerability in pulseaudio
Links: MDVSA-2010:124, CVE-2009-1299
ID: ae-201006-049

It was discovered that 'pulseaudio' creates temporary files in an insecure way. Fixed packages are available now.

System: Red Hat Enterprise Virtualization
Topic: Vulnerabilities in Red Hat Enterprise Virtualization Manager, vdsm, and rhev-hypervisor
Links: RHSA-2010-0478, ESB-2010.0561,
RHSA-2010-0473, CVE-2010-2223, ESB-2010.0562,
RHSA-2010-0476, ESB-2010.0563
ID: ae-201006-048

Several vulnerabilities were found in the 'Red Hat Enterprise Virtualization Manager', 'vdsm', and 'rhev-hypervisor'. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Mozilla Firefox, Thunderbird, and Seamonkey
Links: Mozilla, RHSA-2010-0499, RHSA-2010-0500, RHSA-2010-0501, ESB-2010.0560, ESB-2010.0564, MDVSA-2010:125, DSA-2064, ESB-2010.0572, SUSE-SA:2010:030, ESB-2010.0605
ID: ae-201006-047

Several vulnerabilities were found in the Mozilla Firefox browser, Thuderbird and Seamonkey. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in squirrelmail
Links: MDVSA-2010:120, CVE-2010-1637, ESB-2010.0556
ID: ae-201006-046

A vulnerability was reported in the SquirrelMail Mail Fetch plugin, wherein a user is allowed to specify (without restriction) any port number for their external POP account settings. Fixed packages are available now.

System: Various
Topic: Vulnerability in IBM WebSphere Application Serve
Links: IBM, CVE-2010-1632, ESB-2010.0553
ID: ae-201006-045

The web services run-time might allow an attacker to cause a denial of service or remotely read arbitrary files on the file system where the run-time is installed. This vulnerability might potentially be exploited on any installation that receives XML messages from untrusted sources. Fixed software is available now.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2010-066, DRUPAL-SA-CONTRIB-2010-067, ESB-2010.0551
ID: ae-201006-044

A vulnerability regarding Cross-Site Scripting (XSS) has been found in the Drupal third-party module FileField. The module Views shows is vulnerable to a Cross Site Request Forgery (CSRF). Fixed software is available now. Please be aware that Drupal core is not affected.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in CUPS
Links: RHSA-2010-0490, CVE-2010-0540, CVE-2010-0542, CVE-2010-1748, ESB-2010.0550
ID: ae-201006-043

Some vulnerabilities have been found in CUPS, the Common UNIX Printing System (CUPS). Exploiting them might lead to a NULL pointer dereference, a Cross-Site Request Forgery (CSRF) issue in the web interface. Further on, an uninitialized memory read issue was found in the CUPS web interface. Updated packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.5.0-ibm
Links: RHSA-2010-0489, CVE-2010-0839, CVE-2010-0840, CVE-2010-0841, CVE-2010-0842, CVE-2010-0843, CVE-2010-0844, CVE-2010-0846, CVE-2010-0847, CVE-2010-0848, CVE-2010-0849, ESB-2010.0549
ID: ae-201006-042

Several vulnerabilities were found in the java-1.5.0-ibm packages for Red Hat Enterprise Linux 4 Extras and 5 Supplementary. Fixed packages are available now.

System: HP-UX
Topic: Vulnerabilities in PHP
Links: HPSBUX02543, SSRT100152, CVE-2009-2687, CVE-2009-3291, CVE-2009-3292, CVE-2009-3293, CVE-2009-3557, CVE-2009-4017, CVE-2009-4018, CVE-2009-4142, CVE-2009-4143, ESB-2010.0548
ID: ae-201006-041

Potential security vulnerabilities have been identified with HP-UX running Apache with PHP. These vulnerabilities could be exploited remotely to create a Denial-of-Service (DoS) gain unauthorized access, and perform cross site scripting (XSS). Updates are available now.

System: HP-UX
Topic: Vulnerabilities in Tomcat Servlet Engine
Links: HPSBUX02541, SSRT100145, CVE-2009-2693, CVE-2009-2693, CVE-2009-3548, ESB-2010.0547
ID: ae-201006-040

Potential security vulnerabilities have been identified with HP-UX running Tomcat-based Servlet Engine. The vulnerabilities could be exploited remotely to increase privilege or arbitrarily modify files. Tomcat-based Servlet Engine is contained in the Apache Web Server Suite. An upgrade is available now.

System: Debian GNU/Linux
Topic: Vulnerability in pmount
Links: DSA-2063, CVE-2010-2192, ESB-2010.0546
ID: ae-201006-039

It was discovered that pmount, a wrapper around the standard mount program which permits normal users to mount removable devices without a matching /etc/fstab entry, creates files in /var/lock insecurely. A local attacker could overwrite arbitrary files utilising a symlink attack. Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerability in cacti
Links: MDVSA-2010:117, CVE-2010-2092
ID: ae-201006-038

It was discovered that cacti, a front-end to rrdtool for monitoring systems and services, is not properly validating input passed to the rra_id parameter of the graph.php script. Fixed packages are available now.

System: Various
Topic: Vulnerability in Samba
Links: CVE-2010-2063, DSA-2061, ESB-2010.0540, RHSA-2010-0488, ESB-2010.0541, MDVSA-2010:119
ID: ae-201006-037

It was discovered that Samba, an implementation of the SMB/CIFS protocol for Unix systems, is not properly handling certain offset values when processing chained SMB1 packets. This enables an unauthenticated attacker to write to an arbitrary memory location resulting in the possibility to execute arbitrary code with root privileges. Fixed software is available now.

System: SuSE Linux
Topic: Vulnerabilities in SUSE Linux
Links: SUSE-SR:2010:012, ESB-2010.0476
ID: ae-201006-036

A new SUSE Security Summary reports about vulnerabilities in the packages apache2-mod_php5/php5, bytefx-data-mysql/mono, flash-player, fuse, java-1_4_2-ibm, krb5, libcmpiutil/libvirt, libmozhelper-1_0-0/mozilla-xulrunner190, libopenssl-devel, libpng12-0, libpython2_6-1_0, libtheora, memcached, ncpfs, pango, puppet, python, seamonkey, te_ams, and texlive. Updated packages are available now and should be installed on vulnerable systems.

System: Various
Topic: Vulnerability in sudo
Links: CVE-2010-1646, RHSA-2010-0475, ESB-2010.0538, DSA-2062, ESB-2010.0545, MDVSA-2010:118
ID: ae-201006-035

A flaw was found in the way sudo handled the presence of duplicated environment variables. A local user authorized to run commands using sudo could use this flaw to set additional values for the environment variables set by sudo, which could result in those values being used by the executed command instead of the values set by sudo. Fixed packages are available now.

System: Red Hat Enterprise Linux 4
Topic: Vulnerabilities in kernel
Links: RHSA-2010-0474, CVE-2009-3726, CVE-2010-1173, CVE-2010-1437, ESB-2010.0537
ID: ae-201006-034

Updated kernel packages that fix one security issue and add one enhancement are now available for Red Hat Enterprise Linux 4.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-ibm
Links: RHSA-2010-0471, CVE-2010-0084, CVE-2010-0085, CVE-2010-0087, CVE-2010-0088, CVE-2010-0089, CVE-2010-0090, CVE-2010-0091, CVE-2010-0092, CVE-2010-0094, CVE-2010-0095, CVE-2010-0837, CVE-2010-0838, CVE-2010-0839, CVE-2010-0840, CVE-2010-0841, CVE-2010-0842, CVE-2010-0843, CVE-2010-0844, CVE-2010-0846, CVE-2010-0848, CVE-2010-0849, ESB-2010.0535
ID: ae-201006-033

Several vulnerabilities were found in the Java 2 Runtime Environment. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in cacti
Links: DSA-2060, CVE-2010-2092, ESB-2010.0530
ID: ae-201006-032

It was discovered that cacti, a front-end to rrdtool for monitoring systems and services, is not properly validating input passed to the rra_id parameter of the graph.php script. Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in perl
Links: MDVSA-2010:115, CVE-2010-1168, CVE-2010-1447
ID: ae-201006-031

Multiple vulnerabilities has been discovered and corrected in Safe.pm which could lead to escalated privileges. Updated packages have been patched to correct these issues.

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Help and Support Center
Links: Microsoft Security Advisory (2219475), VU#12909, CVE-2009-0217, ESB-2010.0525
ID: ae-201006-030

No further comment due to legal reasons

System: Various
Topic: Vulnerabilities in Adobe Flash Player
Links: APSB10-14, VU#486225, iDefense, iDefense, ESB-2010.0524, RHSA-2010-0464, RHSA-2010-0470, ESB-2010.0529, ESB-2010.0534, SUSE-SA:2010:024, ESB-2010.0533
ID: ae-201006-029

Several critical vulnerabilities have been identified in Adobe Flash Player These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in glibc and pcsc-lite
Links: DSA-2058, CVE-2008-1391, CVE-2009-4880, CVE-2009-4881, CVE-2010-0296, CVE-2010-0830, ESB-2010.0526,
DSA-2059, CVE-2010-0407, ESB-2010.0527
ID: ae-201006-028

Several vulnerabilities have been discovered in the GNU C Library (aka glibc).
It was discovered that PCSCD, a daemon to access smart cards, was vulnerable to a buffer overflow allowing a local attacker to elevate his privileges to root.
Fixed packages are available now.

System: Cisco
Topic: Vulnerabilities in Cisco Unified Contact Center Express
Links: Cisco, CVE-2010-1570, CVE-2010-1571, ESB-2010.0522
ID: ae-201006-027

Cisco Unified Contact Center Express (UCCX or Unified CCX) contains a denial of service (DoS) vulnerability and a directory traversal vulnerability. Cisco has released free software updates that address these vulnerabilities.

System: Cisco
Topic: Vulnerability in Cisco Application Extension Platform
Links: Cisco, CVE-2010-1572, ESB-2010.0521
ID: ae-201006-026

The Cisco Application Extension Platform contains a privilege escalation vulnerability in the tech support diagnostic shell that may allow an authenticated user to obtain administrative access to a vulnerable Cisco Application Extension Platform module. Cisco has released free software updates that address this vulnerability.

System: Various
Topic: Vulnerabilities in HP OpenView Network Node Manager
Links: HPSBMA02537 SSRT010027, CVE-2010-1960, CVE-2010-1961, CVE-2010-1962, ESB-2010.0520
ID: ae-201006-025

Several security vulnerabilities have been identified with the HP OpenView Network Node Manager (OV NNM). These vulnerabilities could be exploited remotely to execute arbitrary code under the context of the user running the web server. Patches are available now.

System: Microsoft Windows
Topic: Vulnerability in Microsoft .NET Framework
Links: MS10-041, CVE-2009-0217, ESB-2010.0519
ID: ae-201006-024

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Internet Information Services
Links: MS10-040, CVE-2010-1256, ESB-2010.0518
ID: ae-201006-023

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft SharePoint
Links: MS10-039, CVE-2010-0817, CVE-2010-1257, CVE-2010-1264, ESB-2010.0517
ID: ae-201006-022

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Office Excel
Links: MS10-038, CVE-2010-0821, CVE-2010-0822, CVE-2010-0823, CVE-2010-0824, CVE-2010-1245, CVE-2010-1246, CVE-2010-1247, CVE-2010-1248, CVE-2010-1249, CVE-2010-1250, CVE-2010-1251, CVE-2010-1252, CVE-2010-1253, CVE-2010-1254, ESB-2010.0516
ID: ae-201006-021

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Windows OpenType Compact Font Format Driver
Links: MS10-037, CVE-2010-0819, ESB-2010.0515
ID: ae-201006-020

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Office
Links: MS10-036, CVE-2010-1263, ESB-2010.0514
ID: ae-201006-019

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer
Links: MS10-035, CVE-2010-0255, CVE-2010-1257, CVE-2010-1259, CVE-2010-1260, CVE-2010-1261, ESB-2010.0513
ID: ae-201006-018

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in ActiveX Controls
Links: MS10-034, CVE-2010-0252, CVE-2010-0811, ESB-2010.0512
ID: ae-201006-017

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Windows Media Decompression
Links: MS10-033, CVE-2010-1879, CVE-2010-1880, ESB-2010.0511
ID: ae-201006-016

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows Kernel-Mode Drivers
Links: MS10-032, CVE-2010-0484, CVE-2010-0485, CVE-2010-1255, ESB-2010.0510
ID: ae-201006-015

No further comment due to legal reasons

System: Mandriva Linux
Topic: Vulnerabilities in glibc
Links: MDVSA-2010:111, CVE-2009-4880, CVE-2009-4881, CVE-2010-0015, CVE-2010-0296, CVE-2010-0830
ID: ae-201006-014

Multiple vulnerabilities were discovered in glibc. Fixed packages are available now.

System: Various
Topic: Vulnerability in Safari
Links: APPLE-SA-2010-06-07-1, ESB-2010.0509
ID: ae-201006-013

Several vulnerabilities were found in the Apple Safari web browser. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in perl and openoffice.org
Links: RHSA-2010-0457, RHSA-2010-0458, CVE-2008-5302, CVE-2008-5303, CVE-2010-1168, CVE-2010-1447, ESB-2010.0506,
RHSA-2010-0459, CVE-2010-0395, ESB-2010.0507
ID: ae-201006-012

Several vulnerabilities were found in the 'perl' Safe module and the File::Path module.
A flaw was found in the way OpenOffice.org enforced a macro security setting for macros, written in the Python scripting language, that were embedded in OpenOffice.org documents. If a user were tricked into opening a specially-crafted OpenOffice.org document and previewed the macro directory structure, it could lead to Python macro execution even if macro execution was disabled.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in mysql-dfsg-5.0
Links: DSA-2057, CVE-2010-1626, CVE-2010-1848, CVE-2010-1849, CVE-2010-1850, ESB-2010.0508
ID: ae-201006-011

Several vulnerabilities have been discovered in the MySQL database server. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerabilitiy in CA ARCserve Backup
Links: CA20100603-01, CVE-2010-2157, ESB-2010.0505
ID: ae-201006-010

A vulnerability exists in CA ARCserve Backup that can potentially allow a local attacker to gain sensitive information. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in bind9, openoffice.org, and zonecheck
Links: DSA-2054, CVE-2010-0097, CVE-2010-0290, CVE-2010-0382, ESB-2010.0502,
DSA-2055, CVE-2010-0395, ESB-2010.0503,
DSA-2056, CVE-2009-4882, CVE-2010-2052, CVE-2010-2155, ESB-2010.0504
ID: ae-201006-009

Several cache-poisoning vulnerabilities have been discovered in BIND. These vulnerabilities are apply only if DNSSEC validation is enabled and trust anchors have been installed.
It was discovered that OpenOffice.org suite is not properly handling python macros embedded in an office document. This allows an attacker to perform user-assisted execution of arbitrary code in certain use cases of the python macro viewer component.
It was discovered that in zonecheck, a tool to check DNS configurations, the CGI does not perform sufficient sanitation of user input; an attacker can take advantage of this and pass script code in order to perform cross-site scripting attacks.
Fixed packages are available now.

System: Various
Topic: Critical vulnerability in Adobe Flash Player, Adobe Reader and Adobe Acrobat
Links: APSA10-01, APSB10-15, CVE-2010-1297, VU#486225
ID: ae-201006-008

A critical vulnerability exists in Adobe Flash Player 10.0.45.2 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems, and the authplay.dll component that ships with Adobe Reader and Acrobat 9.x for Windows, Macintosh and UNIX operating systems. This vulnerability could cause a crash (DoS) and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being actively exploited in the wild against both Adobe Flash Player, and Adobe Reader and Acrobat.
A fix is going to be published as soon as possible.

System: Various
Topic: Vulnerability in HP ServiceCenter
Links: HPSBMA02538, SSRT100136, CVE-2010-1963, ESB-2010.0501
ID: ae-201006-007

A potential security vulnerability has been identified with HP ServiceCenter running on AIX, HP-UX, Linux, Solaris, and Windows. The vulnerability could be exploited remotely to allow Cross-Site scripting (XSS). A patch is available now.

System: Various
Topic: Vulnerability in HP StorageWorks Storage Mirroring
Links: HPSBST02536, SSRT100057, CVE-2010-1962, ESB-2010.0498
ID: ae-201006-006

A potential security vulnerability has been identified with HP StorageWorks Storage Mirroring. This vulnerability could be exploited remotely to gain unauthorized access. A patch is available now.

System: HP-UX
Topic: Vulnerabilities in Java and Apache
Links: HPSBUX02524, SSRT100089, ESB-2010.0496,
HPSBUX02531, SSRT100108, ESB-2010.0497
ID: ae-201006-005

Potential security vulnerabilities have been identified in Java Runtime Environment (JRE) and Java Developer Kit (JDK) running on HP-UX. These vulnerabilities could allow remote execution of arbitrary code, disclosure of information, and other vulnerabilities. Further on, many security vulnerabilities have been identified with HP-UX running Apache-based Web Server. The vulnerabilities could be exploited remotely to cause a Denial-of-Service (DoS) or unauthorized access. Updated software is available now.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2010-054, ESB-2010.0494,
DRUPAL-SA-CONTRIB-2010-057, ESB-2010.0495
ID: ae-201006-004

Some vulnerabilities regarding Cross-Site Scripting (XSS) were found in the Drupal third-party modules Storm and Rotor Banner. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Various
Topic: Vulnerability in Novell ZENworks Configuration Management Preboot Service
Links: Novell, ZDI-10-090, ESB-2010.0491
ID: ae-201006-003

A vulnerability in Novell ZENworks allows remote attackers to execute arbitrary code on vulnerable installations of Novell ZENworks. Authentication is not required to exploit this vulnerability. Novell has issued an update to correct this vulnerability.

System: Sun Solaris / OpenSolaris
Topic: Multiple vulnerabilities in Accoria Rock Web Server
Links: IOActive, VU #245081
ID: ae-201006-002

The Accoria web server is also known as Rock Web Server. Accoria Web Server 1.4.7 for x86 Solaris and on OpenSolaris 2008.11 in VMWare contains several Cross-Site scripting (XSS) and Cross-Site request forgery (XSRF) vulnerabilities. Directory traversal and format string vulnerabilities exist as well. The getenv sample code contains a XSS vulnerability when viewed by Internet Explorer 6 or other web browsers that don't follow RFC 2616 Section 7.2.1. Generated cookies appear to be weak and predictable which may allow an attacker to bypass authentication. An update isn't available yet.

System: Red Hat Enterprise Linux
Topic: Vulnerability in rhn-client-tools
Links: RHSA-2010-0449, CVE-2010-1439, ESB-2010.0493
ID: ae-201006-001

It was discovered that rhn-client-tools set insecure permissions on the loginAuth.pkl file, used to store session credentials for authenticating connections to Red Hat Network servers. A local, unprivileged user could use these credentials to download packages from the Red Hat Network. They could also manipulate package or action lists associated with the system's profile. Fixed packages are available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH