Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-184-73-74-47.compute-1.amazonaws.com [184.73.74.47]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 10 / 2010

System: Mandriva Linux
Topic: Vulnerabilities in python and php
Links: MDVSA-2010:215, CVE-2009-4134, CVE-2010-1449, CVE-2010-1450, CVE-2010-3492, CVE-2010-3493, ESB-2010.0997,
MDVSA-2010:218, CVE-2010-3436, CVE-2010-3709, CVE-2010-3710, ESB-2010.0998
ID: ae-201010-079

Multiple vulnerabilities was discovered in python. Exploiting them might lead to a Denial-of-Service (DoS) or other unspecified impacts.
Further on, several vulnerabilities have been found in php. They also might lead to a Denial-of-Service (DoS), e.g. by providing a very long e-mail address.
Updated packages are available now.

System: Various
Topic: Vulnerability in Drupal 3rd party module
Links: DRUPAL-SA-CONTRIB-2010-101, ESB-2010.0986
ID: ae-201010-078

A vulnerability regarding XSS and CSRF was found in the Drupal third-party module Watcher. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Red Hat Enterprise Linux 5
Topic: Vulnerabilities in CUPS
Links: RHSA-2010-0811, CVE-2010-2431, CVE-2010-2941, ESB-2010.0983
ID: ae-201010-077

The Common UNIX Printing System (CUPS) provides a portable printing layer for UNIX operating systems. Updated cups packages that fix two security issues are now available for Red Hat Enterprise Linux 5.

System: Windows and Macintosh
Topic: Vulnerabilities in Adobe Shockwave Player
Links: APSB10-25, CVE-2010-2581, CVE-2010-2582, CVE-2010-3653, CVE-2010-3655, CVE-2010-4084, CVE-2010-4085, CVE-2010-4086, CVE-2010-4087, CVE-2010-4088, CVE-2010-4089, CVE-2010-4090, ESB-2010.0987
ID: ae-201010-076

Critical vulnerabilities have been identified in Adobe Shockwave Player 11.5.8.612 and earlier versions on the Windows and Macintosh operating systems. These vulnerabilities might allow an attacker to run malicious code on the affected system. Adobe recommends to update to Adobe Shockwave Player 11.5.9.615.

System: Many
Topic: Vulnerability in Adobe Flash Player, Adobe Reader and Acrobat
Links: APSA10-05, CVE-2010-3654, VU #298081, ESB-2010.0982
ID: ae-201010-075

A critical vulnerability exists in Adobe Flash Player 10.1.85.3 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems; Adobe Flash Player 10.1.95.2 and earlier versions for Android; and the authplay.dll component that ships with Adobe Reader 9.4 and earlier 9.x versions for Windows, Macintosh and UNIX operating systems, and Adobe Acrobat 9.4 and earlier 9.x versions for Windows and Macintosh operating systems. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. A patch is under development.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.5.0-ibm
Links: RHSA-2010-0807, CVE-2009-3555, CVE-2010-1321, CVE-2010-3541, CVE-2010-3548, CVE-2010-3549, CVE-2010-3550, CVE-2010-3551, CVE-2010-3556, CVE-2010-3559, CVE-2010-3562, CVE-2010-3565, CVE-2010-3566, CVE-2010-3568, CVE-2010-3569, CVE-2010-3572, CVE-2010-3573, CVE-2010-3574, ESB-2010.0980
ID: ae-201010-074

Several vulnerabilities were discovered in the java-1.5.0-ibm packages. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in HP LoadRunner Web Tours 9.10
Links: HPSBMA02597, SSRT100198, CVE-2010-3994, ESB-2010.0970
ID: ae-201010-073

A potential vulnerability has been identified with HP LoadRunner Web Tours 9.10. The vulnerability could be remotely exploited to cause a Denial-of-Service. An update is available now.

System: Several
Topic: Vulnerability in HP Storage Essentials
Links: HPSBST02595, SSRT1000303, CVE-2010-4029, ESB-2010.0975
ID: ae-201010-072

A potential security vulnerability has been identified with HP Storage Essentials using LDAP authentication. This vulnerability could be exploited to allow remote unauthenticated access. Updated software is available now.

System: Microsoft Windows
Topic: Vulnerabilities in Symantec IM Manager
Links: SYM10-010, CVE-2010-0112, ESB-2010.0979
ID: ae-201010-071

Symantecs IM Manager administration console is susceptible to multiple SQL injection issues which could result in a compromise of the Symantec IM Manager database by an authorized but unprivileged network user. An update to Symantec IM Manager 8.4.16 remedies these problems.

System: Several
Topic: Vulnerability in CiscoWorks
Links: Cisco #112118, CVE-2010-3036, ESB-2010.0978
ID: ae-201010-070

CiscoWorks Common Services for both Oracle Solaris and Microsoft Windows contains a vulnerability that could allow a remote unauthenticated attacker to execute arbitrary code on a host device with privileges of a system administrator. Cisco has released free software updates that address this vulnerability.

System: NetBSD
Topic: Vulnerability in OpenSSL
Links: NetBSD-SA2010-011, CVE-2010-2939, ESB-2010.0977
ID: ae-201010-069

Client programs using the openssl library to open and process SSLv3 and TLSv1 connections may crash or execute arbitrary code if the server provides a specially crafted SSL key that can inject arbitrary code. A patch is available now.

System: Palm webOS
Topic: Multiple vulnerabilities in Palm webOS and its applications
Links: HPSBMI02573, SSRT100227, HPSBMI02580, SSRT100254, HPSBMI02582, SSRT10026, CVE-2010-4025, CVE-2010-4026, CVE-2010-4027, ESB-2010.0972, ESB-2010.0973, ESB-2010.0974
ID: ae-201010-068

A potential security vulnerability has been identified with Palm webOS Doc Viewer. This vulnerability could be exploited to execute arbitrary code. Another vulnerability has been identified with a Palm webOS service API. This vulnerability could be exploited by a local user on the device, who already has gained the ability to issue privileged webOS service calls, to execute arbitrary code. Further on, a vulnerability has been identified with the webOS camera application. This vulnerability could be exploited by a local user on the device to overwrite arbitrary files on the filesystem. Upgrading to webOS version 1.4.5 solves these problems.

System: Microsoft Windows
Topic: Vulnerability in HP Operations Orchestration
Links: HPSBMA02588, SSRT100001, ISS #62727, CVE-2010-3985, ESB-2010.0971
ID: ae-201010-067

HP Operations Orchestration is vulnerable to Cross-Site scripting, caused by improper validation of user-supplied input. A fix is available now.

System: Microsoft Windows
Topic: Vulnerability in HP Version Control Repository Manager (VCRM)
Links: HPSBMA02597, SSRT100198, CVE-2010-3994, ESB-2010.0970
ID: ae-201010-066

A potential security vulnerability has been identified in HP Version Control Repository Manager (VCRM) for Windows. The vulnerability could be exploited remotely resulting in Cross-Site scripting (XSS). An update is available now.

System: Microsoft Windows
Topic: Vulnerabilities in HP Insight Control Virtual Machine Management
Links: HPSBMA02598, SSRT100314, CVE-2010-3987, CVE-2010-3988, CVE-2010-3989, ESB-2010.0969
ID: ae-201010-065

Potential security vulnerabilities have been identified in HP Insight Control virtual machine management for Windows. The vulnerabilities could be exploited remotely resulting in Cross-Site scripting (XSS), privilege escalation, or Cross-Site request forgery (CSRF). HP has provided HP Insight Control virtual machine management v6.2 to resolve the vulnerabilities.

System: Microsoft Windows
Topic: Vulnerability in HP Virtual Server Environment
Links: HPSBMA02599, SSRT100235, CVE-2010-3990, ESB-2010.0968
ID: ae-201010-064

A potential security vulnerability has been identified in HP Virtual Server Environment for Windows. The vulnerability could be exploited remotely to download arbitrary files. A patch is available now.

System: Microsoft Windows
Topic: Vulnerabilities in HP Insight Control Power Management
Links: HPSBMA02603, SSRT100319, CVE-2010-4023, CVE-2010-4024, ESB-2010.0966
ID: ae-201010-063

Potential security vulnerabilities have been identified in HP Insight Control Power Management for Windows. The vulnerabilities could be exploited remotely resulting in Cross-Site Scripting (XSS) or Cross-Site request forgery (CSRF). HP has provided HP Insight Control Power Management v6.2 or subsequent to resolve the vulnerabilities.

System: Microsoft Windows
Topic: Vulnerabilities in HP Insight Control Server Migration
Links: HPSBMA02601, SSRT100316, CVE-2010-3991, CVE-2010-3992, CVE-2010-3993, ESB-2010.0967
ID: ae-201010-062

Potential security vulnerabilities have been identified in HP Insight Control Server Migration for Windows. The vulnerabilities could be exploited remotely resulting in Cross-Site scripting (XSS), privilege escalation, or unauthorized access. HP has provided HP Insight Control Server Migration v6.2 or subsequent to resolve the vulnerabilities.

System: Various
Topic: Vulnerabilities in IBM WebSphere Application Server
Links: AV10-044, VUPEN ADV-2010-2775, IBM, ESB-2010.0965
ID: ae-201010-061

Multiple vulnerabilities have been reported in IBM WebSphere Application Server. Exploitation of these vulnerabilities could result in Cross-Site Scripting attacks, cross-site request forgery attacks or URL injection attacks. A patch is available now.

System: Various
Topic: Vulnerability in Mozilla Firefox, Thunderbird, and Seamonkey
Links: Mozilla, CVE-2010-3765, RHSA-2010-0808, RHSA-2010-0809, RHSA-2010-0810, RHSA-2010-0812, RHSA-2010-0896, ESB-2010.0981, ESB-2010.0984, ESB-2010.1058, MDVSA-2010:213, DSA-2123, ESB-2010.0993, DSA-2124, ESB-2010.0994, SUSE-SA:2010:056, ESB-2010.1014
ID: ae-201010-060

A critical vulnerabilitys was found in the Mozilla Firefox browser, Thuderbird and Seamonkey. Fixed software is available now.

System: SuSE Linux
Topic: Vulnerabilities in OpenOffice_org, acroread/acroread_ja, cifs-mount/samba, dbus-1-glib, festival, freetype2, java-1_6_0-sun, krb5, libHX13/libHX18/libHX22, mipv6d, mysql, postgresql, and squid3
Links: SUSE-SR:2010:019, ESB-2010.0964
ID: ae-201010-059

A new SUSE Security Summary reports about vulnerabilities in the packages OpenOffice_org, acroread/acroread_ja, cifs-mount/samba, dbus-1-glib, festival, freetype2, java-1_6_0-sun, krb5, libHX13/libHX18/libHX22, mipv6d, mysql, postgresql, and squid3. Updated packages are available now and should be installed on vulnerable systems.

System: Linux
Topic: Vulnerability in Linux kernel
Links: CVE-2010-3904, VU#362983, RHSA-2010-0792, ESB-2010.0962
ID: ae-201010-058

The rds_page_copy_user() function in the Linux kernel Reliable Datagram Sockets (RDS) protocol implementation was missing sanity checks. A local, unprivileged user could use this flaw to escalate their privileges. Fixed software is available now.

System: Various
Topic: Vulnerabilities in IBM solidDB
Links: CVE-2010-4055, CVE-2010-4056, CVE-2010-4057, IBM X-Force, ESB-2010.0961
ID: ae-201010-057

IBM solidDB is vulnerable to a denial of service, caused by an error in the solid.exe database server. A remote attacker could exploit this vulnerability to reference an unallocated memory region and cause the service to crash. Fixed software is not available yet.

System: Microsoft Windows
Topic: Vulnerability in HP Virtual Connect Enterprise Manager
Links: HPSBMA02593 SSRT100237, CVE-2010-3986, ESB-2010.0959
ID: ae-201010-056

A security vulnerability has been identified in HP Virtual Connect Enterprise Manager (VCEM) for Windows. The vulnerability could be exploited remotely to download arbitrary files. Fixed software is available now.

System: Mandriva Linux
Topic: Vulnerability in libsmi
Links: MDVSA-2010:209, CVE-2010-2891
ID: ae-201010-055

A buffer overflow was discovered in libsmi when long OID was given in numerical form. This could lead to arbitraty code execution. Updated software is available now.

System: Various
Topic: Vulnerability in Adobe Shockwave Player
Links: APSA10-04, CVE-2010-3653, VU#402231
ID: ae-201010-054

A critical vulnerability exists in Adobe Shockwave Player on the Windows and Macintosh operating systems. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. Fixed software is not available yet.

System: Various
Topic: Vulnerabilities in HP Systems Insight Manager
Links: HPSBMA02591 SSRT100299, HPSBMA02592 SSRT100300, CVE-2010-0209, CVE-2010-2213, CVE-2010-2214, CVE-2010-2215, CVE-2010-2216, CVE-2010-3288, CVE-2010-3289, CVE-2010-3290, ESB-2010.0954, ESB-2010.0955
ID: ae-201010-053

Several security vulnerabilities have been identified in HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows. Fixed software is available now.

System: Various
Topic: Vulnerability in HP AssetCenter and HP AssetManager
Links: HPSBMA02596 SSRT100271, CVE-2010-3291, ESB-2010.0953
ID: ae-201010-052

A security vulnerability has been identified in HP AssetCenter and HP AssetManager for AIX, HP-UX, Linux, Solaris and Windows. The vulnerability could be exploited remotely resulting in cross site scripting (XSS). Fixed software is available now.

System: NetBSD
Topic: Vulnerabilities in larn and netsmb
Links: NetBSD-SA2010-009, ESB-2010.0956,
NetBSD-SA2010-010, ESB-2010.0957
ID: ae-201010-051

'larn' uses the setgid privileges in an inproper way.
The netsmb filesystem kernel module was incorrectly checking buffer limits, thus enabling a regular user to cause the kernel to allocate large internal buffers to handle the request, which leads to memory exhaustion.
Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in pidgin
Links: RHSA-2010-0788, CVE-2010-1624, CVE-2010-3711, ESB-2010.0952
ID: ae-201010-050

Several Multiple NULL pointer dereference flaws were found in the way Pidgin handled Base64 decoding and the Pidgin MSN protocol plug-in. Fixed packages are available now.

System: Apple Mac OS X
Topic: Vulnerabilities in Java
Links: APPLE-SA-2010-10-20-1, APPLE-SA-2010-10-20-2, CVE-2009-3555, CVE-2010-1321, CVE-2010-1826, CVE-2010-1827, ESB-2010.0949
ID: ae-201010-049

Several vulnerabilities were discovered in Java for Mac OS X. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in quagga
Links: RHSA-2010-0785, CVE-2007-4826, CVE-2010-2948, ESB-2010.0946
ID: ae-201010-048

A stack-based buffer overflow flaw and multiple NULL pointer dereference flaws were found in the Quagga bgpd daemon. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.4.2-ibm
Links: RHSA-2010-0786, CVE-2009-3555, CVE-2010-3541, CVE-2010-3548, CVE-2010-3549, CVE-2010-3551, CVE-2010-3553, CVE-2010-3556, CVE-2010-3557, CVE-2010-3562, CVE-2010-3565, CVE-2010-3568, CVE-2010-3569, CVE-2010-3571, CVE-2010-3572, CVE-2010-3573, ESB-2010.0947
ID: ae-201010-047

Several vulnerabilities were discovered in the java-1.4.2-ibm packages. Fixed packages are available now.

System: Various
Topic: Vulnerability in glibc
Links: CVE-2010-3847, CVE-2010-3856, VU#537223, RHSA-2010-0787, ESB-2010.0948, RHSA-2010-0793, ESB-2010.0963, MDVSA-2010:207, DSA-2122, ESB-2010.0958, SUSE-SA:2010:052, ESB-2010.0985
ID: ae-201010-046

It was discovered that the glibc dynamic linker/loader did not handle the $ORIGIN dynamic string token set in the LD_AUDIT environment variable securely. A local attacker with write access to a file system containing setuid or setgid binaries could use this flaw to escalate their privileges. Fixed software is available now.

System: Various
Topic: Vulnerability in IBM DB2 Universal Database
Links: IBM IZ22143, CVE-2008-2154, ZDI-10-218, ESB-2010.0944
ID: ae-201010-045

A vulnerability within the install_jar procedure allows remote attackers to execute arbitrary code on vulnerable installations of IBM DB2. Authentication is required in that a user must have the ability to connect to the database. Fixed software is available now.

System: Red Hat Enterprise Linux 4
Topic: Vulnerabilities in kernel
Links: RHSA-2010-0779, CVE-2010-2942, CVE-2010-3067, CVE-2010-3477, ESB-2010.0942
ID: ae-201010-044

Updated kernel packages that fix multiple security issues and add one enhancement are now available for Red Hat Enterprise Linux 4.

System: Various
Topic: Vulnerabilities in Mozilla Firefox, Thunderbird, and Seamonkey
Links: Mozilla, RHSA-2010-0780, RHSA-2010-0781, RHSA-2010-0782, ESB-2010.0943, ESB-2010.0945, MDVSA-2010:210
ID: ae-201010-043

Several vulnerabilities were found in the Mozilla Firefox browser, Thuderbird and Seamonkey. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in typo3-src
Links: DSA-2121, CVE-2010-3714, CVE-2010-3715, CVE-2010-3716, CVE-2010-3717, ESB-2010.0941
ID: ae-201010-042

Several remote vulnerabilities have been discovered in TYPO3. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in IBM Informix Dynamic Server
Links: ZDI-10-215, ZDI-10-216, ZDI-10-217, ESB-2010.0939
ID: ae-201010-041

Several buffer overflow vulnerabilities were found in IBM Informix Dynamic Server. Fixed software is available now.

System: Various
Topic: Vulnerability in IBM Rational Quality Manager
Links: ZDI-10-214, ESB-2010.0938
ID: ae-201010-040

A vulnerability was found in Rational Quality Manager and Rational Test Lab Manager, that allows remote attackers to execute code. Fixed software is available now.

System: Various
Topic: Vulnerability in TWiki
Links: IBM Xforce, CVE-2010-3841, ESB-2010.0940
ID: ae-201010-039

TWiki is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the view and login scripts. A remote attacker could exploit this vulnerability using the rev or origurl parameter in a specially- crafted URL to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials. Fixed software is available now.

System: SuSE Linux
Topic: Vulnerabilities in kernel
Links: SUSE-SA:2010:051
ID: ae-201010-038

The openSUSE 11.3 kernel was updated to fix various bugs and some security issues.

System: Red Hat Enterprise Linux
Topic: Vulnerability in cobbler
Links: RHSA-2010-0775, CVE-2010-2235, ESB-2010.0937
ID: ae-201010-037

A code injection flaw was found in the way Cobbler processed templates for kickstart files. A remote, authenticated user, that has the Configuration Administrator role privilege, could use this flaw to create a specially-crafted kickstart template file containing embedded Python code that could, when processed by Cheetah, execute arbitrary code with root privileges on the Red Hat Network Satellite Server. Fixed packages are available now.

System: Various
Topic: Vulnerability in Drupal 3rd party module
Links: DRUPAL-SA-CONTRIB-2010-099, ESB-2010.0936
ID: ae-201010-036

A vulnerability was found in the Drupal third-party module Views. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Various
Topic: Vulnerability in HP Systems Insight Manager
Links: HPSBMA02590 SSRT100182, CVE-2010-3286, ESB-2010.0932
ID: ae-201010-035

A security vulnerability has been identified in HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows. The vulnerability could be exploited remotely to download arbitrary files. Fixed software is available now.

System: HP ProCurve
Topic: Vulnerabilities in HP ProCurve Access Points, Access Controllers, and Mobility Controllers
Links: HPSBGN02589 SSRT100296, CVE-2010-3287, ESB-2010.0931
ID: ae-201010-034

A security vulnerability has been identified in HP ProCurve Access Points, Access Controllers, and Mobility Controllers. The vulnerability could be remotely exploited resulting in a privilege escalation. Fixed software is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in Red Hat Enterprise MRG Messaging and Grid
Links: RHSA-2010-0773, RHSA-2010-0774, CVE-2009-5005, CVE-2009-5006, ESB-2010.0935
ID: ae-201010-033

A flaw was found in the way Apache Qpid handled the receipt of invalid AMQP data. A remote user could send invalid AMQP data to the server, causing it to crash, resulting in the cluster shutting down. A flaw was found in the way Apache Qpid handled a request to redeclare an existing exchange while adding a new alternate exchange. If a remote, authenticated user issued such a request, the server would crash, resulting in the cluster shutting down. Fixed packages are available now.

System: Red Hat Enterprise MRG for RHEL 5
Topic: Vulnerabilities in kernel-rt
Links: RHSA-2010-0771, CVE-2010-0307, CVE-2010-2942, CVE-2010-2955, CVE-2010-3297, ESB-2010.0934
ID: ae-201010-032

Updated kernel-rt packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise MRG 1.3. This update has been rated as having moderate security impact by the Red Hat Security Response Team.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-sun
Links: RHSA-2010-0770, CVE-2009-3555, CVE-2010-1321, CVE-2010-3541, CVE-2010-3548, CVE-2010-3549, CVE-2010-3550, CVE-2010-3551, CVE-2010-3552, CVE-2010-3553, CVE-2010-3554, CVE-2010-3555, CVE-2010-3556, CVE-2010-3557, CVE-2010-3558, CVE-2010-3559, CVE-2010-3560, CVE-2010-3561, CVE-2010-3562, CVE-2010-3563, CVE-2010-3565, CVE-2010-3566, CVE-2010-3567, CVE-2010-3568, CVE-2010-3569, CVE-2010-3570, CVE-2010-3571, CVE-2010-3572, CVE-2010-3573, CVE-2010-3574, ESB-2010.0933
ID: ae-201010-031

Several vulnerabilities were discovered in the java-1.6.0-sun packages. Fixed packages are available now.

System: Various
Topic: Vulnerability in IBM Tivoli Storage Manager
Links: IBM, ESB-2010.0930
ID: ae-201010-030

Security vulnerabilities exist in the specified versions of IBM Tivoli Storage Manager FastBack, which has the potential to crash the IBM Tivoli Storage Manager FastBack Mount process or to allow malicious code injection. Fixed software is available now.

System: SuSE Linux
Topic: Vulnerabilities in kernel
Links: SUSE-SA:2010:050, ESB-2010.0929
ID: ae-201010-029

The SUSE Linux Enterprise Server/Desktop 11 SP1 kernel was updated to fix various bugs and some security issues.

System: SuSE Linux
Topic: Vulnerabilities in samba, libgdiplus0, libwebkit, bzip2, php5, and okular
Links: SUSE-SR:2010:018
ID: ae-201010-028

A new SUSE Security Summary reports about vulnerabilities in the packages samba, libgdiplus0, libwebkit, bzip2, php5, and okular. Updated packages are available now and should be installed on vulnerable systems.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.6.0-openjdk
Links: RHSA-2010-0768, CVE-2009-3555, CVE-2010-3541, CVE-2010-3548, CVE-2010-3549, CVE-2010-3551, CVE-2010-3553, CVE-2010-3554, CVE-2010-3557, CVE-2010-3561, CVE-2010-3562, CVE-2010-3564, CVE-2010-3565, CVE-2010-3566, CVE-2010-3567, CVE-2010-3568, CVE-2010-3569, CVE-2010-3573, CVE-2010-3574, ESB-2010.0928
ID: ae-201010-027

Several vulnerabilities were discovered in the java-1.6.0-openjdk packages. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Windows Shared Cluster Disks
Links: MS10-086, CVE-2010-3223, ESB-2010.0922
ID: ae-201010-026

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Internet Information Services
Links: MS10-085, CVE-2010-3229, ESB-2010.0921
ID: ae-201010-025

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Windows Local Procedure Call
Links: MS10-084, CVE-2010-3222, ESB-2010.0920
ID: ae-201010-024

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows
Links: MS10-083, CVE-2010-1263, ESB-2010.0919
ID: ae-201010-023

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Media Player
Links: MS10-082, CVE-2010-2745, ESB-2010.0918
ID: ae-201010-022

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Common Control Library
Links: MS10-081, CVE-2010-2746, ESB-2010.0917
ID: ae-201010-021

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Excel
Links: MS10-080, CVE-2010-3230, CVE-2010-3231, CVE-2010-3232, CVE-2010-3233, CVE-2010-3234, CVE-2010-3235, CVE-2010-3236, CVE-2010-3237, CVE-2010-3238, CVE-2010-3239, CVE-2010-3241, CVE-2010-3242, ESB-2010.0916
ID: ae-201010-020

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Word
Links: MS10-079, CVE-2010-2747, CVE-2010-2748, CVE-2010-2750, CVE-2010-3214, CVE-2010-3215, CVE-2010-3216, CVE-2010-3217, CVE-2010-3218, CVE-2010-3219, CVE-2010-3220, CVE-2010-3221, ESB-2010.0915
ID: ae-201010-019

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Windows OpenType Font format driver
Links: MS10-078, CVE-2010-2740, CVE-2010-2741, ESB-2010.0914
ID: ae-201010-018

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in .NET Framework
Links: MS10-077, CVE-2010-3228, ESB-2010.0913
ID: ae-201010-017

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Embedded OpenType Font Engine
Links: MS10-076, CVE-2010-1883, ESB-2010.0912
ID: ae-201010-016

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Media Player
Links: MS10-075, CVE-2010-3225, ESB-2010.0911
ID: ae-201010-015

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Foundation Classes
Links: MS10-074, CVE-2010-3227, ESB-2010.0910
ID: ae-201010-014

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Windows kernel-mode drivers
Links: MS10-073, CVE-2010-2549, CVE-2010-2743, CVE-2010-2744, ESB-2010.0909
ID: ae-201010-013

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft SharePoint
Links: MS10-072, CVE-2010-3323, CVE-2010-3324, ESB-2010.0908
ID: ae-201010-012

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer
Links: MS10-071, CVE-2010-0808, CVE-2010-3243, CVE-2010-3324, CVE-2010-3325, CVE-2010-3326, CVE-2010-3327, CVE-2010-3328, CVE-2010-3329, CVE-2010-3330, CVE-2010-3331, ESB-2010.0907
ID: ae-201010-011

No further comment due to legal reasons

System: NetBSD
Topic: Vulnerabilities in sftp, ftp, and glob
Links: NetBSD-SA2010-008, ESB-2010.0905
ID: ae-201010-010

The glob(3) function allows denial of service attacks. Affected are sftp(1) and ftp(1). Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in poppler and postgresql
Links: DSA-2119, CVE-2010-3702, CVE-2010-3704, ESB-2010.0923
DSA-2120, CVE-2010-3433, ESB-2010.0924
ID: ae-201010-009

Two vulnerabilities were discovered in the Poppler PDF rendering library, which may lead to the execution of arbitrary code if a malformed PDF file is opened.
It was discovered that PostgreSQL, a database server software, does not properly separate interpreters for server-side stored procedures which run in different security contexts. As a result, non-privileged authenticated database users might gain additional privileges.
Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Adobe Reader and Acrobat
Links: APSB10-21, ESB-2010.0890, RHSA-2010-0743, ESB-2010.0892, SUSE-SA:2010:048, ESB-2010.0906
ID: ae-201010-008

Several critical vulnerabilities have been identified in Adobe Reader and Adobe Acrobat.These vulnerabilities could cause the application to crash and could potentially allow an attacker to take control of the affected system. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerability in subversion
Links: DSA-2118, CVE-2010-3315, ESB-2010.0904
ID: ae-201010-007

It was discovered that the mod_dav_svn module of subversion, a version control system, is not properly enforcing access rules which are scope-limited to named repositories. If the SVNPathAuthz option is set to "short_circuit" set this may enable an unprivileged attacker to bypass intended access restrictions and disclose or modify repository content. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in xpdf, gpdf, kdegraphics, cups, and poppler
Links: RHSA-2010-0751, RHSA-2010-0752, RHSA-2010-0753, RHSA-2010-0754, RHSA-2010-0749, CVE-2010-3702, CVE-2010-3704, ESB-2010.0897, ESB-2010.0898, ESB-2010.0899, ESB-2010.0900, ESB-2010.0901
ID: ae-201010-006

Several vulnerabilities were found in 'xpdf'. Also affected are 'gpdf', 'kdegraphics', 'cups', and 'poppler'. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in apr-util
Links: DSA-2117, CVE-2010-1623, ESB-2010.0887
ID: ae-201010-005

A flaw was discovered in the apr_brigade_split_line() function in apr-util. A remote attacker could send crafted http requests to cause a greatly increased memory consumption in Apache httpd, resulting in a denial of service. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in FreeType
Links: CVE-2010-2806, CVE-2010-2808, CVE-2010-3054, CVE-2010-3311, DSA-2116, ESB-2010.0886, RHSA-2010-0736, RHSA-2010-0737, ESB-2010.0888
ID: ae-201010-004

Several vulnerabilities were found in 'FreeType'. Fixed software is available now.

System: Various
Topic: Vulnerability in Novell eDirectory Server
Links: ESB-2010.0885
ID: ae-201010-003

The flaw exists within Novell's eDirectory Server's NCP implementation. This vulnerability allows attackers to deny services on vulnerable installations of Novell eDirectory. Authentication is not required in order to trigger this vulnerability. Fixed software is available now.

System: VMware ESX
Topic: Vulnerabilities in VMware ESX 4.0
Links: CVE-2009-2409, CVE-2009-3245, CVE-2009-3555, CVE-2010-0433, CVE-2010-0734, CVE-2010-0826, CVE-2010-1646, ESB-2010.0883
ID: ae-201010-002

Several vulnerabilities were found in the VMware ESX Service Console. Fixed software is available now.

System: Various
Topic: Vulnerability in ISC BIND
Links: VU#784855
ID: ae-201010-001

There is a flaw in BIND where the wrong ACL is applied. This flaw could allow access to a cache via recursion even though the ACL disallowed it. This bug is primarily a risk to operators running both authoritative and recursive DNS on the same BIND server in the same view. Fixed software is available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH