Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-23-22-76-170.compute-1.amazonaws.com [23.22.76.170]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 04 / 2011

System: Microsoft Windows
Topic: Vulnerabilities in HP OpenView Storage Data Protector
Links: HPSBMA02668 SSRT100474, CVE-2011-1736, CVE-2011-1735, CVE-2011-1734, CVE-2011-1733, CVE-2011-1732, CVE-2011-1731, CVE-2011-1729, CVE-2011-1728, ESB-2011.0486, X-Force #67207
ID: ae-201104-115

Potential security vulnerabilities have been discovered in HP OpenView Storage Data Protector on Windows. These vulnerabilities can be exploited to execute arbitrary code. HP has made software upgrades available to fix these vulnerabilities.

System: SuSE Linux
Topic: Multiple vulnerabilities in kernel
Links: SUSE-SA:2011:019, ESB-2011.0487
ID: ae-201104-114

In the kernel of SUSE Linux Enterprise 11 Service Pack 1 several vulnerabilities have been found. Exploiting them might allow local attackers to gain increased privileges. Additionally, attackers might be able to initialize a Denial-of-Service (DoS). Updated kernel packages (2.6.32.36) are available now.

System: VMware ESX Server
Topic: Vulnerabilities in VMware ESX, VMware ESXi and VMware ESX Server
Links: VMSA-2011-0007, ESB-2010.1105.4, ESB-2011.0010.3, ESB-2011.0270.2, ESB-2011.0485, X-Force #67195
ID: ae-201104-113

For VMware ESX, VMware ESXi and VMware ESX Server different security updates are available. Some vulnerabilities, of which the most serious may lead to denial of service and the possibility of execution of arbitrary code via network are fixed. This affects the versions of VMware ESX 4.1, VMware ESX 4.0, VMware ESX 3.5, VMware ESX 3.0.3 and VMware ESXi 4.1 such as VMware ESXi 4.0.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in nss
Links: RHSA-2011-0471
ID: ae-201104-112

Network Security Services (NSS) is a collection of libraries that support the development of safety-critical client and server applications. Updated nss packages that fix several vulnerabilities are now available for Red Hat Enterprise Linux 4, 5 and 6.

System: Many
Topic: Many vulnerabilities in firefox, thunderbird, seamonkey, iceweasel, icedove, and iceape
Links: CVE-2011-1202, CVE-2011-0081, CVE-2011-0080, CVE-2011-0078, CVE-2011-0077, CVE-2011-0075, CVE-2011-0074, CVE-2011-0073, CVE-2011-0072, CVE-2011-0071, CVE-2011-0069, CVE-2011-0067, CVE-2011-0066, CVE-2011-0065,
RHSA-2011-0471, RHSA-2011-0472, RHSA-2011-0473, RHSA-2011-0474, RHSA-2011-0475, ESB-2011.0488, MDVSA-2011:079, DSA-2227, DSA-2228, SUSE-SA:2011:022, DSA-2235
ID: ae-201104-111

Updated firefox, thunderbird, seamonkey, iceweasel, icedove and iceape packages that fix several security issues are now available for several systems. Please update your software.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2011-017, ESB-2011.0483,
DRUPAL-SA-CONTRIB-2011-018, ESB-2011.0484
ID: ae-201104-110

Several vulnerabilities have been found in the Drupal third-party modules Node Reference URL and Save Draft, allowing remote administrative access by deploying a Cross-Site Scripting (XSS) vulnerability. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Cisco
Topic: Vulnerability in Cisco Unified Communications Manager and Cisco Wireless LAN Controllers
Links: Cisco #112878, CVE-2011-1610, CVE-2011-1609, CVE-2011-1607, CVE-2011-1606, CVE-2011-1605, CVE-2011-1604, ESB-2011.0481, ISS #67122
Cisco #112916, CVE-2011-1613, ESB-2011.0482
ID: ae-201104-109

The Cisco Unified Communications Manager contains the following vulnerabilities: Three Denial of Service vulnerabilities affect the Session Initiation Protocol (SIP) services. A directory transversal vulnerability and two SQL injection vulnerabilities. Cisco has released free software updates for affected versions of Cisco Unified Communications Manager to eliminate the vulnerabilities.
The Cisco Wireless LAN Controller product family is prone to a Denial of Service (DoS) vulnerability, which allows an unauthenticated attacker to restart a device by loading a series of ICMP packets. Cisco has released free software updates for this vulnerability.

System: various
Topic: Vulnerabilities in CA Arcot WebFort Versatile Authentication Server
Links: CVE-2011-1826, CVE-2011-1825, ESB-2011.0480
ID: ae-201104-108

There are vulnerabilities in CA Arcot WebFort Versatile Authentication Server. The vulnerabilities are caused by a lack of protection of request parameters to the Arcot management console. An attacker who can convince a user to follow a URL can perform cross-site scripting attacks. These vulnerabilities only affect the administrative console. Administrators should access the administrative console using a bookmark and not via external links.

System: Many
Topic: Vulnerability in Adobe Reader and Acrobat
Links: APSB11-08, CVE-2011-0611, CVE-2011-0610, ESB-2011.0479
ID: ae-201104-107

A vulnerability in numerous versions of the Adobe Acrobat and Reader has been found. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page, or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an E-Mail attachment, targeting the Windows platform. Opening this file with a vulnerable version leads to a crash of the application and potentially allows an attacker to take control of the affected system. Adobe recommends to install an updated version that is available now.

System: Microsoft Windows
Topic: Vulnerability in CA Output Management Web Viewer
Links: CVE-2011-1719, ESB-2011.0478
ID: ae-201104-106

Potential security vulnerabilities have been discovered in Ca Output Management Web Viewer. Two vulnerabilities exist that can allow a remote attacker to execute arbitrary code. CA Technologies has issued patches to address the vulnerabilities.

System: various
Topic: Vulnerability in CA SiteMinder
Links: CVE-2011-1718, ESB-2011.0477
ID: ae-201104-105

The CA Support Technologies has informed customers about a security risk in the CA SiteMinder. There is a vulnerability that may allow a malicious user to impersonate another user. CA Technologies has released patches for the vulnerability.

System: NetBSD
Topic: Vulnerability in dhclient
Links: NetBSD-SA2011-005, CVE-2011-0997, ESB-2011.0476
ID: ae-201104-104

ISC Dhclient does not escape certain shell metacharacters from DHCP responses (such as hostname) before passing it to the dhclient-script. This can enable to run malicious code on the client. Updated packages or workarounds are available.

System: various
Topic: Vulnerabilities in HP SiteScope
Links: HPSBMA02667, SSRT100464, CVE-2011-1727, CVE-2011-1726, ESB-2011.0475
ID: ae-201104-103

Vulnerabilities were found in HP SiteScope. These vulnerabilities can be exploited via Cross Site Scripting (XSS) and HTML-injection. The vulnerability can be solved by installing the hotfix SS1110110412 in HP SiteScope v11.1.

System: various
Topic: Vulnerabilities in HP Network Automation
Links: HPSBMA02666, SSRT100434, CVE-2011-1725, ESB-2011.0474
ID: ae-201104-102

A potential vulnerability has been identified in HP Network Automation for Linux, Solaris and Windows. This vulnerability can be exploited to expose information. HP has released a hotfix to close this gap.

System: Microsoft Windows
Topic: Vulnerabilities in HP Virtual Server Environment
Links: HPSBMA02665, SSRT100185, CVE-2011-1724, ESB-2011.0473
ID: ae-201104-101

A potential security vulnerability has been discovered in HP Virtual Server Environment for Windows. The vulnerability could be exploited over the network to extend privileges of users. HP has released HP Virtual Server Environment v6.3 to fix the vulnerability.

System: Microsoft Windows
Topic: Several Vulnerabilities in HP Insight Control Performance Management
Links: HPSBMA02664, SSRT100417, CVE-2011-1545, CVE-2011-1544, ESB-2011.0472
ID: ae-201104-100

Several potential security vulnerabilities have been identified in the HP Insight Control performance management for Windows. The vulnerabilities could be exploited remotely resulting in Cross-Site Request Forgery (CSRF).
HP has provided HP Insight Control performance management v6.3 to resolve these vulnerabilities.

System: Some
Topic: Vulnerabilities in HP OpenView Storage Data Protector
Links: HPSBMA02654, SSRT100441, CVE-2011-0924, CVE-2011-0923, CVE-2011-0922, CVE-2011-0921, ESB-2011.0471
ID: ae-201104-099

Potential security vulnerabilities have been discovered in HP OpenView Storage Data Protector. These vulnerabilities can be exploited to execute arbitrary code. HP has made software upgrades available to fix these vulnerabilities.

System: Red Hat Enterprise Linux 6
Topic: Vulnerabilities in kdelibs and kdenetwork
Links: RHSA-2011-0464, CVE-2011-1168, CVE-2011-1094, ESB-2011.0469,
RHSA-2011-0465, CVE-2011-1586, CVE-2010-1000, ESB-2011.0470
ID: ae-201104-098

The kdelibs packages provide libraries for the K Desktop Environment (KDE). An error was found in the manner kdelibs reviewd the specified host name against the hostname in the server SSL certificate. A man-in-the-middle attacker could exploit this flaw to move an application that uses kdlibs to the acceptance of a false certificate. Moreover, there is a cross-site scripting (XSS) vulnerability.
The kdenetwork packages contain networking applications for the K Desktop Environment (KDE). A directory traversal vulnerability was found in KGet, a download manager. An attacker could exploit this flaw to create a specially crafted file that, when they open, it allows all the files of the running user to overwrite.
Users should upgrade this updated packages. The desktop must be restarted in both cases, so that the fix is active.

System: Debian GNU/Linux
Topic: Vulnerabilities in asterisk and libmodplug
Links: DSA-2225, CVE-2011-1599, CVE-2011-1507, CVE-2011-1175, CVE-2011-1174, CVE-2011-1147, ESB-2011.0467,
DSA-2226, CVE-2011-1574, ESB-2011.0468
ID: ae-201104-097

Asterisk is a free software implementation of a telephone private branch exchange (PBX). Several vulnerabilities have been discovered in Asterisk, which can lead to serious denial-of-service and execution of arbitrary code. We recommend that you upgrade your asterisk packages. Libmodplug renders mod music files into raw audio data in order to play or convert. It was discovered a buffer overflow in the code to handle Tracker S3M files in the Modplug tracker music library, which can lead to the execution of arbitrary code. Updated libmodplug packages are available.

System: Mandriva Linux
Topic: Vulnerability in xorg-x11
Links: MDVSA-2011:076, CVE-2011-0465
ID: ae-201104-096

X.Org is an open source implementation of the X Window System. Certain variables are not properly filtered by the xrdb helper program of the xorg-x11 package. So remote attackers might be able to to execute arbitrary code with root privileges. Updated xorg-x11 packages are available now.

System: Many
Topic: Vulnerability in Adobe Reader and Acrobat
Links: APSB11-08, CVE-2011-0611, ISS #66978
ID: ae-201104-095

A vulnerability in numerous versions of the Adobe Acrobat and Reader has been found. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page, or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an E-Mail attachment, targeting the Windows platform. Opening this file with a vulnerable version leads to a crash of the application and potentially allows an attacker to take control of the affected system. Adobe recommends to install an updated version that is available now.

System: Some
Topic: Several Vulnerabilities in HP Systems Insight Manager
Links: HPSBMA02663, SSRT100428, ESB-2011.0466
ID: ae-201104-094

Several potential security vulnerabilities have been identified in the HP Systems Insight Manager (SIM) for HP-UX, Linux and Windows. The vulnerabilities could be exploited remotely resulting in Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), execution of arbitrary code, or a Denial-of-Service (DoS). Most of them are reasoned by the integrated Flash Player.
HP has provided HP SIM v6.3 to resolve these vulnerabilities.

System: Some
Topic: Vulnerabilities in HP System Management Homepage
Links: HPSBMA02662, SSRT100409, CVE-2010-1917, CVE-2010-2531, CVE-2010-2939, CVE-2010-2950, CVE-2010-3709, CVE-2010-4008, CVE-2010-4156, CVE-2011-1540, CVE-2011-1541, ESB-2011.0465
ID: ae-201104-093

Several potential security vulnerabilities have been identified with HP System Management Homepage (SMH) for Linux and Windows. The vulnerabilities could be exploited remotely resulting in unauthorized access, execution of arbitrary code, and Denial-of-Service (DoS).
HP has provided HP System Management Homepage v6.3 to resolve the vulnerabilities.

System: Some
Topic: Vulnerabilities in HP Proliant Support Pack
Links: HPSBMA02661, SSRT100408, CVE-2011-1537, CVE-2011-1538, CVE-2011-1539, ESB-2011.0464
ID: ae-201104-092

Potential security vulnerabilities have been identified with HP Proliant Support Pack running on Linux and Windows. They could be exploited remotely resulting in cross site scripting (XSS), URL redirection, and information disclosure.
HP has provided HP Proliant Support Pack 8.7 to resolve the vulnerabilities.

System: Some
Topic: Vulnerability in HP Performance Insight
Links: HPSBMA02660, SSRT100433, CVE-2011-1536, ESB-2011.0463
ID: ae-201104-091

A potential vulnerability has been identified with HP Performance Insight running on HP-UX, Linux, Solaris, and Windows. The vulnerability could be exploited remotely to access sensitive information.
HP has made a hotfix available to resolve the vulnerability.

System: Linux
Topic: Vulnerabilities in HP Insight Control for Linux
Links: HPSBMA02658, SSRT100413, CVE-2010-3864, CVE-2010-4180, CVE-2011-0014, CVE-2011-0539, CVE-2011-1535, ISS #66867, ESB-2011.0462
ID: ae-201104-090

Potential security vulnerabilities have been identified with Insight Control for Linux (IC-Linux). They could be exploited remotely to allow unauthorized elevation of privilege, execution of arbitrary code, encryption downgrade, information disclosure, and Denial-of-Service (DoS).
HP has made Insight Control for Linux (IC-Linux) v6.3 or subsequent available to resolve the vulnerabilities.

System: Some
Topic: Vulnerability in JBoss Enterprise Application Platform / JBoss Enterprise SOA Platform
Links: CVE-2011-1484, ISS #66982, RHSA-2011-0460, RHSA-2011-0461, RHSA-2011-0462, RHSA-2011-0463, ESB-2011.0458, ESB-2011.0459, ESB-2011.0460, ESB-2011.0461, ISS #66982
ID: ae-201104-089

The JBoss Seam 2 framework is an application framework for building web applications in Java. JBoss Enterprise SOA Platform is the next-generation ESB and business process automation infrastructure. It has been found that JBoss Seam 2 doesn't properly block access to JBoss Expression Language (EL) constructs in page exception handling, allowing arbitrary Java methods to be executed. A remote attacker could use this flaw to execute arbitrary code via a specially-crafted URL provided to certain applications based on the JBoss Seam 2 framework.
An updated version is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in tinyproxy, doctrine, and openjdk-6
Links: DSA-2222, CVE-2011-1499, ESB-2011.0455,
DSA-2223, CVE-2011-1522, ESB-2011.0456,
DSA-2224, CVE-2011-0025, CVE-2011-0706, CVE-2010-4472, CVE-2010-4471, CVE-2010-4470, CVE-2010-4469, CVE-2010-4465, CVE-2010-4450, CVE-2010-4448, CVE-2010-4351, ESB-2011.0457
ID: ae-201104-088

It has been discovered that incorrect ACL processing in TinyProxy, a lightweight, non-caching, optionally anonymizing http proxy could lead to unintended network access rights. Doctrine is a PHP library for implementing object persistence. It contains SQL injection vulnerabilities. The exact impact depends on the application which uses the Doctrine library. Further on, several security vulnerabilities were discovered in OpenJDK, an implementation of the Java platform.
Updated packages address these issues.

System: FreeBSD
Topic: Vulnerability in mountd
Links: FreeBSD-SA-11:01, CVE-2011-1739, ESB-2011.04504
ID: ae-201104-087

The mountd(8) daemon services NFS mount requests from other client machines. While parsing the exports(5) table, a network mask in the form of "-network=netname/prefixlength" results in an incorrect network mask being computed if the prefix length is not a multiple of 8. When using a prefix length which is not multiple of 8, access would be granted to the wrong client systems. An upgrade remedies this problem.

System: Various
Topic: Vulnerability in RSA Adaptive Authentication
Links: ESA-2011-014, CVE-2011-1422, ESB-2011.0453
ID: ae-201104-086

A potential cross-site scripting vulnerability has been identified in RSA Adaptive Authentication (On-Premise) that could be exploited in certain circumstances. This is due to an input validation error in a Flash Shockwave file provided by the Adaptive Authentication system.
EMC has made hot fixes available to resolve this vulnerability.

System: Various
Topic: Vulnerability in EMC NetWorker
Links: ESA-2011-013, SecurityFocus #47410, CVE-2011-1421, SA44237, VUPEN/ADV-2011-1025, ESB-2011.0452
ID: ae-201104-085

EMC NetWorker contains a potential security vulnerability that can be exploited to execute malicious code with elevated privileges on the affected system. This is due to an unspecified file in EMC NetWorker contains incorrect permissions.
EMC has made patches available to resolve this vulnerability.

System: SuSE Linux
Topic: Multiple vulnerabilities in kernel
Links: SUSE-SA:2011:017
ID: ae-201104-084

In the kernel of openSUSE 11.2 several vulnerabilities have been found. Exploiting them might allow local attackers to gain increased privileges. Additionally, attackers might be able to initialize a Denial-of-Service (DoS). Updated kernel packages are available now.

System: Various
Topic: Vulnerability in HP Network Node Manager i
Links: HPSBMA02659, SSRT100440, CVE-2011-1534, ESB-2011.0451
ID: ae-201104-083

A potential vulnerability has been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in unauthorized access to NNMi processes.
HP has made patches available to resolve this vulnerability.

System: Red Hat Enterprise Linux 6
Topic: Vulnerability in polkit
Links: RHSA-2011-0455, CVE-2011-1485, ESB-2011.0450
ID: ae-201104-082

PolicyKit is a toolkit for defining and handling authorizations. A race condition flaw was found in the PolicyKit pkexec utility and polkitd daemon. A local user could use this flaw to appear as a privileged user to pkexec, allowing them to execute arbitrary commands as root by running those commands with pkexec. Updated packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in request-tracker and libmojolicious-perl
Links: DSA-2220, CVE-2011-1685, CVE-2011-1686, CVE-2011-1687, CVE-2011-1688, CVE-2011-1689, CVE-2011-1690, ESB-2011.0449,
DSA-2221, CVE-2011-1589
ID: ae-201104-081

Request Tracker is an issue tracking system. Several vulnerabilities have been found. If they are exploited, remote code execution is possible as well as a read-only access to data. A local user might be able to access confidential data.
Mojolicious is a Perl Web Application Framework. Here, a directory traversal vulnerability has been found.
Updated packages address these issues.

System: SuSE Linux
Topic: Vulnerabilities in NetworkManager, OpenOffice_org, apache2-slms, dbus-1-glib, dhcp/dhcpcd/dhcp6, freetype2, kbd, krb5, libcgroup, libmodplug, libvirt, mailman, moonlight-plugin, nbd, openldap2, pure-ftpd, python-feedparser, rsyslog, telepathy-gabble, and wireshark
Links: SUSE-SR:2011:007, ESB-2011.0448
ID: ae-201104-080

A new SUSE Security Summary reports about vulnerabilities in the packages NetworkManager, OpenOffice_org, apache2-slms, dbus-1-glib, dhcp/dhcpcd/dhcp6, freetype2, kbd, krb5, libcgroup, libmodplug, libvirt, mailman, moonlight-plugin, nbd, openldap2, pure-ftpd, python-feedparser, rsyslog, telepathy-gabble, and wireshark. Updated packages are available now and should be installed on vulnerable systems.

System: Many
Topic: Vulnerabilities in Oracle products
Links: Oracle, VU# 520721, ASB-2011.0031
ID: ae-201104-079

Oracle has published a Critical Patch Update, fixing multiple security vulnerabilities in Oracle products. Affected are Oracle Database, Oracle Fusion Middleware, Oracle Enterprise Manager and further Oracle Applications as well as the Oracle Sun Products Suite. It's strongly recommended to update affected systems.

System: Debian GNU/Linux
Topic: Vulnerability in xmlsec1
Links: DSA-2219, CVE-2011-1425, ESB-2011.0444
ID: ae-201104-078

The XML Security Library xmlsec allows remote attackers to create or overwrite arbitrary files through specially crafted XML files using the libxslt output extension and a ds:Transform element during signature verification. Updated packages address this problem.

System: Red Hat Enterprise Linux 6
Topic: Vulnerability in libtiff
Links: RHSA-2011-0452, CVE-2009-5022, ESB-2011.0446
ID: ae-201104-077

The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. A heap-based buffer overflow flaw has been found in the way libtiff processes certain TIFF image files that are compressed with the JPEG compression algorithm. An attacker could use this flaw to create a specially-crafted TIFF file that, when opened, would cause an application linked against libtiff to crash or, possibly, execute arbitrary code. Updated packages are available now.

System: Windows, Mac OS X
Topic: Vulnerabilities in Apple iTunes
Links: APPLE-SA-2011-04-18-1, CVE-2011-1290, CVE-2011-1344, ESB-2011.0443
ID: ae-201104-076

Apple iTunes is a program for the administration of multimedia data. A man-in-the-middle attack may lead to an unexpected application termination or arbitrary code execution while browsing the iTunes Store via iTunes. iTunes 10.2.2 is now available and addresses this security problem.

System: Many
Topic: Vulnerabilities in wireshark
Links: Wireshark, VU #243670, ASB-2011.0029, MDVSA-2011:083
ID: ae-201104-075

Wireshark is a mighty tool for analyzing network traffic and troubleshooting. Wireshark has been published in version 1.4.5. This release fixes some vulnerabilities. The NFS dissector on Windows as well as the X.509if dissector might crash when analyzing data. Further on, a buffer overflow in the DECT dissector might lead to remote code execution. So an upgrade to version 1.4.5 is recommended.

System: Many
Topic: Vulnerability in Adobe Flash Player
Links: APSB11-07, CVE-2011-0611, ISS Alert #425, ESB-2011.0442, Symantec #44504,
SUSE-SA:2011:018, ESB-2011.0447, RHSA-2011-0451, ESB-2011.0445
ID: ae-201104-074

A vulnerability in numerous versions of the Adobe Flash Player has been found. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a malicious Web page, or a Flash (.swf) file embedded in a Microsoft Word (.doc) or Microsoft Excel (.xls) file delivered as an E-Mail attachment, targeting the Windows platform. Opening this file with a vulnerable version leads to a crash of the application and potentially allows an attacker to take control of the affected system. Adobe recommends to install an updated version, being available now.

System: Apple Mac OS X
Topic: Problem with SSL certificates
Links: APPLE-SA-2011-04-14-4, ESB-2011.0441
ID: ae-201104-073

As reported for other systems before, several fraudulent SSL certificates were issued by a Comodo affiliate registration authority. This may allow a man-in-the-middle attacker to redirect connections and intercept user credentials or other sensitive information. This issue is now addressed by blacklisting the fraudulent certificates.

System: Various
Topic: Vulnerabilities in Apple Safari 5.0.4 and prior
Links: APPLE-SA-2011-04-14-3, CVE-2011-1290, CVE-2011-1344, ESB-2011.0440
ID: ae-201104-072

Using the web browser Apple Safari 5.0.4 and earlier might result in security risks. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This is due to an integer overflow in the handling of nodesets and a use after free issue in the handling of text nodes, respectively. Version 5.0.5 is available now, solving these issues.

System: Apple iOS
Topic: Software update for Apple iOS available
Links: APPLE-SA-2011-04-14-1, APPLE-SA-2011-04-14-2, ESB-2011.0439
ID: ae-201104-071

From now on, the Apple iOS 4.3.2 Software Update as well as the Apple iOS 4.2.7 Software Update is available. Please use this latest version to be protected against many security related problems.

System: Microsoft Windows
Topic: Several vulnerabilities in CA Total Defense Suite
Links: CA, ZDI-11-126, ZDI-11-127, ZDI-11-128, ZDI-11-130, ZDI-11-131, ZDI-11-132, ZDI-11-133, ZDI-11-134, CVE-2011-1653, CVE-2011-1654, CVE-2011-1655, ESB-2011.0437
ID: ae-201104-070

Several vulnerabilities have been found in CA Total Defense Suite. Exploiting them might lead to unauthorized access as well as remote and unauthenticated execution of arbitrary code on a vulnerable system running Windows 7, Windows Server 2003 or 2008. A patch is available now.

System: Various
Topic: Vulnerabilities in HP Network Node Manager i
Links: HPSBUX02642, SSRT100415, CVE-2010-4476, ESB-2011.0435,
HPSBMA02643, SSRT100416, CVE-2011-0897, CVE-2011-0898, ESB-2011.0436
ID: ae-201104-069

A potential vulnerability has been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows running Java. The vulnerability could be remotely exploited to create a Denial-of-Service (DoS).
Further potential security vulnerabilities have been identified with HP Network Node Manager i (NNMi). One vulnerability could be exploited by a local user to gain unauthorized access to files. The other vulnerability could result in remote cross site scripting (XSS).
HP has made patches available to resolve the vulnerabilities.

System: Unix / Linux
Topic: Vulnerability in MIT krb5 kadmind
Links: MITKRB5-SA-2011-004, CVE-2011-0285, ESB-2011.0434,
RHSA-2011-0447, ESB-2011.0438, MDVSA-2011:077
ID: ae-201104-068

The password-changing capability of the MIT krb5 administration daemon (kadmind) has a bug that can cause it to attempt to free() an invalid pointer under certain error conditions. This can cause the daemon to crash (Denial-of-Service) or induce the execution of arbitrary code. kadmind in MIT releases krb5-1.7 and later is vulnerable. A workaround as well as a patch have been published.

System: Red Hat Enterprise Linux 5
Topic: Vulnerabilities in rhev-hypervisor
Links: RHSA-2011-0439, CVE-2010-4346, CVE-2010-4352, CVE-2011-0521, CVE-2011-0710, CVE-2011-1010, CVE-2011-1024, CVE-2011-1090, CVE-2011-1146, ESB-2011.0433
ID: ae-201104-067

The rhev-hypervisor package provides a Red Hat Enterprise Virtualization Hypervisor ISO disk image. The Red Hat Enterprise Virtualization Hypervisor is a dedicated Kernel-based Virtual Machine (KVM) hypervisor. Various vulnerabilities have been found in this package. Exploiting them might lead to a Denial-of-Service (DoS). It's recommended to install updated packages, that are available now.

System: SuSE Linux
Topic: Vulnerability in xorg-x11
Links: SUSE-SA:2011:016, CVE-2011-0465, ESB-2011.0432
ID: ae-201104-066

X.Org is an open source implementation of the X Window System. Certain variables are not properly filtered by the xrdb helper program of the xorg-x11 package. So remote attackers might be able to to execute arbitrary code with root privileges. Updated xorg-x11 packages are available now.

System: Various
Topic: Vulnerabilities in BlackBerry Enterprise Server
Links: BB-KB25966, BB-KB26296, CVE-2010-2227, CVE-2009-3555, CVE-2008-5515, CVE-2008-1678, CVE-2007-5333, CVE-2007-3385, CVE-2007-1858, CVE-2011-0286, ESB-2011.0430, ESB-2011.0431
ID: ae-201104-065

There are vulnerabilities in the versions of the Apache Tomcat Web server, which some BlackBerry Enterprise Server components use to manage administration pages. These problems may cause Denial of Service (DoS) and influence the functioning of the affected components. There is also the possibility of disclosure of information or cross-site scripting (XSS) on the affected components. These gaps have no effect on BlackBerry messaging services. RIM has released updates that address these vulnerabilities in the affected versions of the BlackBerry Enterprise Server.

System: HP-UX
Topic: Vulnerability in BIND
Links: HPSBUX02655, SSRT100353, CVE-2010-3613, ASB-2010.0244, ESB-2011.0429
ID: ae-201104-064

BIND is an open-source software package to implement a domain name system server. There was a potential security issue on HP-UX found in Bind. This vulnerability could be exploited to cause a Denial of Service (DoS) attack. HP has made upgrades to correct this vulnerability.

System: HP-UX
Topic: Vulnerability in NFS/ONCplus
Links: HPSBUX02653, SSRT100310, CVE-2011-0896, ESB-2011.0428
ID: ae-201104-063

A potential security vulnerability has been found in NFS/ONCplus on HP-UX. The vulnerability can lead to Denial of Service (DoS). HP has released an upgrade to resolve this vulnerability.

System: Various
Topic: Vulnerability in RealPlayer
Links: RealNetworks, ZDI-11-122, CVE-2011-1426, ESB-2011.0426
ID: ae-201104-062

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of RealNetworks RealPlayer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. RealNetworks has issued an update to correct this vulnerability.

System: Red Hat Enterprise Linux 5
Topic: Vulnerabilities in kernel and avahi
Links: RHSA-2011-0429, CVE-2010-4346, CVE-2011-0521, CVE-2011-0710, CVE-2011-1010, CVE-2011-1090, CVE-2011-1478, ESB-2011.0425,
RHSA-2011-0436, CVE-2010-2244, CVE-2011-1002, ESB-2011.0427
ID: ae-201104-061

In the kernel of Red Hat Enterprise Linux 5 several vulnerabilities have been found. Exploiting them might allow local attackers to gain increased privileges. Additionally, attackers might be able to initialize a Denial-of-Service (DoS) or to gain unauthorized access.
Avahi is an implementation of the DNS Service Discovery and Multicast DNS specifications for Zero Configuration Networking. A flaw was found in the way the Avahi daemon (avahi-daemon) processes Multicast DNS (mDNS) packets with an empty payload. An attacker on the local network could use this flaw to cause avahi-daemon on a target system to enter an infinite loop via an empty mDNS UDP packet (DoS).
Updated packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in vlc
Links: DSA-2218, ESB-2011.0424
ID: ae-201104-060

It has been discovered that the MP4 decoder plugin of vlc, a multimedia player and streamer, is vulnerable to a heap-based buffer overflow. This has been introduced by a wrong data type being used for a size calculation. An attacker could use this flaw to trick a victim into opening a specially crafted MP4 file and possibly execute arbitrary code or crash the media player.
Updated packages are available now.

System: Microsoft Windows
Topic: Several vulnerabilities in Microsoft Windows Kernel-Mode Drivers
Links: MS11-034, ESB-2011.0423
ID: ae-201104-059

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows WordPad Text Converters
Links: MS11-033, CVE-2011-0028, ESB-2011.0422
ID: ae-201104-058

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows OpenType Compact Font Format (CFF) Driver
Links: MS11-032, CVE-2011-0034, ESB-2011.0421
ID: ae-201104-057

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft JScript and VBScript Scripting Engines
Links: MS11-031, CVE-2011-0663, ESB-2011.0420
ID: ae-201104-056

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft JScript and VBScript Scripting Engines
Links: MS11-031, CVE-2011-0663, ESB-2011.0420
ID: ae-201104-055

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows DNS Resolution
Links: MS11-030, CVE-2011-0657, ESB-2011.0419
ID: ae-201104-054

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft GDI+
Links: MS11-029, CVE-2011-0041, ESB-2011.0418
ID: ae-201104-053

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft .NET Framework
Links: MS11-028, CVE-2010-3958, ESB-2011.0417
ID: ae-201104-052

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows ActiveX Kill Bits
Links: MS11-027, CVE-2010-0811, CVE-2010-3973, CVE-2011-1243, ESB-2011.0416
ID: ae-201104-051

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows MHTML
Links: MS11-026, CVE-2011-0096, ESB-2011.0415
ID: ae-201104-050

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Foundation Class (MFC) Library
Links: MS11-025, CVE-2010-3190, ESB-2011.0414
ID: ae-201104-049

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Fax Cover Page Editor
Links: MS11-024, CVE-2010-3974, ESB-2011.0413
ID: ae-201104-048

No further comment due to legal reasons

System: Microsoft Windows, Mac OS X
Topic: Vulnerabilities in Microsoft Office
Links: MS11-023, CVE-2011-0107, CVE-2011-0977, ESB-2011.0412
ID: ae-201104-047

No further comment due to legal reasons

System: Microsoft Windows, Mac OS X
Topic: Vulnerabilities in Microsoft Office PowerPoint
Links: MS11-022, CVE-2011-0655, CVE-2011-0656, CVE-2011-0976, ESB-2011.0411
ID: ae-201104-046

No further comment due to legal reasons

System: Microsoft Windows, Mac OS X
Topic: Vulnerabilities in Microsoft Office Excel
Links: MS11-021, CVE-2011-0097, CVE-2011-0098, CVE-2011-0101, CVE-2011-0103, CVE-2011-0104, CVE-2011-0105, CVE-2011-0978, CVE-2011-0979, CVE-2011-0980, ESB-2011.0410
ID: ae-201104-045

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows SMB Server
Links: MS11-020, CVE-2011-0661, ESB-2011.0409
ID: ae-201104-044

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows SMB Client
Links: MS11-019, CVE-2011-0654, CVE-2011-0660, ESB-2011.0408
ID: ae-201104-043

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer 6, 7, and 8
Links: MS11-018, CVE-2011-0094, CVE-2011-0346, CVE-2011-1244, CVE-2011-1245, CVE-2011-1345, ESB-2011.0407
ID: ae-201104-042

No further comment due to legal reasons

System: HP
Topic: Multiple vulnerabilities in Hewlett-Packard Photosmart Printers
Links: HPSBPI02656, SSRT090262, CVE-2011-1533, CVE-2011-1532, CVE-2011-1531, CVE-2010-1533, CVE-2010-1532, CVE-2010-1531, ESB-2011.0406
ID: ae-201104-041

On some HP Photosmart printers potential security vulnerabilities have been discovered. These vulnerabilities can be exploited to carry out cross-site scripting (XSS) or gain unauthorized access to data or printer configuration information. In the CVEs a workaround to the particular vulnerability is described.

System: Various
Topic: Vulnerability in Novell Zenworks
Links: ZDI-11-118, CVE-2010-4229, ESB-2011.0404, ISS #66656
ID: ae-201104-040

There exists a vulnerability within a servlet of Novell Zenworks, which provides functions for uploading files. This vulnerability allows attackers to execute arbitrary code on vulnerable installations of Novell Zenworks Asset Management. Authentication is not required to exploit this vulnerability. Novell has released an update to correct this vulnerability.

System: Red Hat Enterprise Linux
Topic: Security updates for xorg-x11, xorg-x11-server-utils and Red Hat Network Satellite
Links: RHSA-2011-0432, RHSA-2011-0433, CVE-2011-0465, ESB-2011.0401,
RHSA-2011-0432, CVE-2010-1171, CVE-2009-0788, ESB-2011.0402
ID: ae-201104-039

X. Org is an open source implementation of the X Window System. The xorg-x11-server-utils package contains a collection of tools to modify and query the runtime configuration of X.Org server. Certain variables are not properly filtered when you start a graphical session, which could allow an attacker to execute arbitrary code with root privileges. Updated xorg-x11 and xorg-x11-server-utils packages are now available and resolve several vulnerabilities in Red Hat Enterprise Linux. Red Hat Network Satellite (RHN Satellite) is a management tool for Linux-based IT infrastructures. It enables the deployment, management and monitoring of multiple Linux systems with a single tool. Updated packages fix several security vulnerabilities and are now available for Red Hat Network Satellite 5.3 and 5.4 available.

System: Many
Topic: Vulnerability in Adobe Flash Player, Adobe Reader and Acrobat
Links: APSA11-02, CVE-2011-0611, ESB-2011.0405, VU #230057
ID: ae-201104-038

A critical vulnerability exists in Flash Player 10.2.153.1 and earlier versions, Adobe Flash Player 10.2.156.12 and earlier versions, and the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.2) and earlier 10.x and 9.x. This vulnerability could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Word (.doc) file delivered as an E-Mail attachment, targeting the Windows platform. Currently an update is planned, at least at the next quarterly update this problem will be solved.

System: Microsoft Windows
Topic: Vulnerability in McAfee Firewall Reporter
Links: McAfee SB10015, ZDI-11-117, ESB-2011.0403
ID: ae-201104-037

A vulnerability allows unauthenticated remote attackers to execute arbitrary code on vulnerable installations of McAfee Firewall Reporter. This is due to a flaw within the code responsible for authenticating users. The GernalUtilities.pm file contains code to validate sessions by parsing cookie values without sanitization. The faulty logic simply checks for the existence of a particular file, without verifying its contents. By using a directory traversal technique an attacker can point the cgisess cookie value to an arbitrary file that exists on the server and thus bypass authentication. This problem is solved in McAfee Firewall Reporter version 5.1.0.13.

System: Debian GNU/Linux
Topic: Vulnerability in gitolite
Links: DSA-2215, ESB-2011.0398
ID: ae-201104-036

Gitolite, an SSH-based gatekeeper for Git repositories, is vulnerable to directory traversal attacks, when admin defined commands (ADC) will be processed. This allows an attacker to execute arbitrary commands with the privileges of the gitolite-server. Please note that this only affects systems where ADC is enabled (not default on Debian). We recommend that you update your gitolite packages.

System: Linux
Topic: Vulnerability in dhclient
Links: ISC, RHSA-2011-0428, CVE-2011-0997, ESB-2011.0395, DSA-2216, ESB-2011.0399, DSA-2217, ESB-2011.0400, MDVSA-2011:073
ID: ae-201104-035

As reported before (ae-201104-022), it was found out, that the DHCP client daemon dhclient is not sufficiently filtering certain options in the responses of the DHCP server. A malicious DHCP server could send such a package with a specially crafted value to a DHCP client, which can then lead to arbitrary code execution with the privileges of the process. All users of dhclient should upgrade the packages.

System: Debian GNU/Linux
Topic: Vulnerability in ikiwiki
Links: DSA-2214, CVE-2011-1401, ESB-2011.397
ID: ae-201104-034

Ikiwiki, a wiki compiler, does not validate input data when the htmlscrubber plugin is enabled or alternative style sheets are added. This allows an attacker who is able to upload custom stylesheets, to thereby perform cross-site scripting attacks. We recommend that you upgrade your ikiwiki package.

System: Debian GNU/Linux
Topic: Vulnerability in xserver-utils
Links: DSA-2213, CVE-2011-0465, ESB-2011.0392, ESB-2011.0396
ID: ae-201104-033

It was found that in the x11-xserver-utils, a collection of utilities to optimize and configure the X server, host names are not filtered properly. This allows an attacker to execute arbitrary code with root privileges. We recommend that you update your x11-xserver-utils packages.

System: Red Hat Enterprise Linux 6
Topic: Multiple vulnerabilities in kernel
Links: RHSA-2011-0421, ESB-2011.0394
ID: ae-201104-032

In the kernel of Red Hat Enterprise Linux 6 several vulnerabilities have been found. Exploiting them might allow local attackers to gain increased privileges. Additionally, attackers might be able to initialize a Denial-of-Service (DoS) or to gain unauthorized access. Updated kernel packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in spice-xpi
Links: RHSA-2011-0426, RHSA-2011-0427, CVE-2011-0012, CVE-2011-1179, ESB-2011.0393
ID: ae-201104-031

The Simple Protocol for Independent Computing Environments (SPICE) is a remote display protocol used in Red Hat Enterprise Linux for viewing virtualized guests running on the Kernel-based Virtual Machine (KVM) hypervisor, or on Red Hat Enterprise Virtualization Hypervisor. The spice-xpi package provides a plug-in that allows the SPICE client to run from within Mozilla Firefox. An uninitialized pointer use flaw was found in the SPICE Firefox plug-in. If a user were tricked into visiting a malicious web page with Firefox while the SPICE plug-in was enabled, it could cause Firefox to crash or, possibly, execute arbitrary code with the privileges of the user running Firefox. Further on, it was found that the SPICE Firefox plug-in uses a predictable name for one of its log files. A local attacker could use this flaw to conduct a symbolic link attack, allowing them to overwrite arbitrary files accessible to the user running Firefox.
Updated packages are available now.

System: NetBSD
Topic: Vulnerability in the Kernel
Links: NetBSD-SA2011-004, CVE-2011-1547, ESB-2011.0390
ID: ae-201104-030

A malicious packet containing nested RFC 3173 - IP Payload Compression Protocol (IPComp) headers can cause a panic due to kernel stack exhaustion in a kernel with option IPSEC enabled. Under certain conditions, kernel memory may get overwritten. In kernels with option FAST_IPSEC a sufficient quantity of such packets may cause a Denial-of-Service.
Updated packages are available now.

System: Various
Topic: Vulnerability in Drupal 3rd party module
Links: DRUPAL-SA-CONTRIB-2011-016, ESB-2011.0387
ID: ae-201104-029

A vulnerability was found in the Drupal third-party module Node Quick Find, allowing unauthorized access for unauthenticated users. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in postfix
Links: RHSA-2011-0422, RHSA-2011-0423, CVE-2008-2937, CVE-2011-0411, ESB-2011.0386
ID: ae-201104-028

Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL), and TLS.
It was discovered that Postfix doesn't flush the received SMTP commands buffer after switching to TLS encryption for an SMTP session. A man-in-the-middle attacker could use this flaw to inject SMTP commands into a victim's session during the plain text phase. This would lead to those commands being processed by Postfix after TLS encryption is enabled, possibly allowing the attacker to steal the victim's mail or authentication credentials. Further on, it was discovered that Postfix doesn't properly check the permissions of users' mailbox files. A local attacker able to create files in the mail spool directory could use this flaw to create mailbox files for other local users, and be able to read mail delivered to those users.
Updated packages are available now.

System: Various
Topic: Vulnerabilities in Tomcat
Links: Apache Tomcat, Apache Tomcat 7, CVE-2011-1088, CVE-2011-1183, CVE-2011-1475, ESB-2011.0385
ID: ae-201104-027

A regression in the fix for CVE-2011-1088 meant that security constraints were ignored when no login configuration was present in the web.xml and the web application was marked as meta-data complete. Changes introduced to the HTTP BIO connector to support Servlet 3.0 asynchronous requests did not fully account for HTTP pipelining. As a result, when using HTTP pipelining a range of unexpected behaviours occurrs including the mixing up of responses between requests.
It's expected that vendors who support Apache Tomcat will be providing updates soon.

System: Debian GNU/Linux
Topic: Vulnerabilities in vlc and tmux
Links: DSA-2211, CVE-2010-0552, CVE-2010-1441, CVE-2010-1442, CVE-2010-3275, CVE-2010-3276, CVE-2011-0531, ESB-2011.0384,
DSA-2212, CVE-2011-1496, ESB-2011.0389
ID: ae-201104-026

VLC is a multimedia player and streamer. Due to missing input santising the execution of arbitrary code is possible if a user is tricked into opening a malformed media file.
tmux is a terminal multiplexer. It's not properly dropping group privileges, so a user with an existing account may gain increased privileges.
Updated packages are available now.

System: Mandriva Linux
Topic: Vulnerability in subversion
Links: MDVSA-2011:067, CVE-2011-0715
ID: ae-201104-025

Subversion (SVN) is a concurrent version control system which enables one or more users to collaborate in developing and maintaining a hierarchy of files and directories while keeping a history of all changes. It has been found out that HTTP-based Subversion servers crash when processing lock requests on repositories which support unauthenticated read access. This Denial-of-Service (DoS) can be avoided by updating the affected packages.

System: IBM AIX
Topic: Vulnerability caused by LDAP
Links: IBM, CVE-2011-1561, ESB-2011.0382
ID: ae-201104-024

After installing bos.rte.security 6.1.6.4 fileset, an LDAP user will be able to log in with an incorrect password. This occurs only when authtype is set to ldap_auth. Under specific conditions, non-LDAP users can also log in with incorrect passwords. IBM has assigned an APAR to solve this problem.

System: SuSE Linux
Topic: Vulnerabilities in apache2-mod_php5/php5, cobbker, envince, gdm, kdelibs4, orts, and quagga
Links: SUSE-SR:2011:006, ESB-2011.0381
ID: ae-201104-023

A new SUSE Security Summary reports about vulnerabilities in the packages apache2-mod_php5/php5, cobbker, envince, gdm, kdelibs4, orts, and quagga. Updated packages are available now and should be installed on vulnerable systems.

System: Various
Topic: Vulnerability in dhclient
Links: ISC, CVE-2011-0997, VU #107886, ESB-2011.0383, X-Force #66580
ID: ae-201104-022

dhclient doesn't strip or escape certain shell meta-characters in dhcpd responses, allowing a rogue server or party with with escalated privileges on the server to cause remote code execution on the client. Updated software is available now.

System: Oracle Solaris 10
Topic: Vulnerability caused by back-out patch files
Links: CVE-2011-0412, VU #648244, ESB-2011.0388, X-Force #66579
ID: ae-201104-021

The root password hash along with other users' password hashes may be contained in the back-out patch files. In some instances, these files may be readable by unprivileged users. An unprivileged user can extract the password hashes from the file and perform a brute force attack on the password hashes in an attempt to recover the password. It's recommended to install the concerning patch.

System: HP-UX, Linux, Solaris, Windows
Topic: Vulnerability in HP Network Node Manager i
Links: HP, HPSBMA02652, SSRT100432, CVE-2011-0895, ESB-2011.0380
ID: ae-201104-020

A potential vulnerability has been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerability could be remotely exploited resulting in information disclosure. HP has made a hotfix available to resolve this vulnerability.

System: Various
Topic: Vulnerability in Novell File Reporter
Links: ZDI-11-116, CVE-2011-0994, ESB-2011.0379, ISS #66548
ID: ae-201104-019

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Novell File Reporter Agent. Authentication is not required to exploit this vulnerability. The flaw exists within the NFRAgent.exe component which listens by default on TCP port 3037. When handling the content of an XML tag the process blindly copies user supplied data into a fixed-length buffer on the stack. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the SYSTEM user. Updated software is available now.

System: Red Hat Enterprise Linux 6
Topic: Vulnerability in policycoreutils
Links: RHSA-2011-0414, CVE-2011-1011, ESB-2011.0377
ID: ae-201104-018

The policycoreutils packages contain the core utilities that are required for the basic operation of a Security-Enhanced Linux (SELinux) system and its policies.
It has been discovered that the seunshare utility doesn't enforce proper file permissions on the directory used as an alternate temporary directory mounted as /tmp/. A local user could use this flaw to overwrite files or, possibly, execute arbitrary code with the privileges of a setuid or setgid application that relies on proper /tmp/ permissions, by running that application via seunshare.
Updated packages are available now.

System: Mandriva Linux
Topic: Vulnerabilities in xmlsec1, libtiff, logrotate, and rsync
Links: MDVSA-2011:063, CVE-2011-1425, MDVSA-2011:064, CVE-2011-0191, CVE-2011-1167, MDVSA-2011:065, CVE-2011-1098, CVE-2011-1154, CVE-2011-1155, MDVSA-2011:066, CVE-2011-1097
ID: ae-201104-017

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to create or overwrite arbitrary files via vectors involving the libxslt output extension and a ds:Transform element during signature verification. A buffer overflow in LibTIFF allows remote attackers to execute arbitrary code or cause a Denial-of-Service via a crafted TIFF image with JPEG encoding. Further on, a heap-based buffer overflow in the thunder (aka ThunderScan) decoder in tif_thunder.c in LibTIFF 3.9.4 and earlier allows remote attackers to execute arbitrary code via crafted THUNDER_2BITDELTAS data in a .tiff file that has an unexpected BitsPerSample value.
A race condition in the createOutputFile function in logrotate.c in logrotate 3.7.9 and earlier allows local users to read log data by opening a file before the intended permissions are in place. The shred_file function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to execute arbitrary commands via shell metacharacters in a log filename, as demonstrated by a filename that is automatically constructed on the basis of a hostname or virtual machine name. Finally, the writeState function in logrotate.c in logrotate 3.7.9 and earlier might allow context-dependent attackers to cause a Denial-of-Service (DoS) via special characters in a log filename.
rsync 3.x before 3.0.8, when certain recursion, deletion, and ownership options are used, allows remote rsync servers to cause a Denial-of-Service (DoS) or possibly execute arbitrary code via malformed data.
Updated packages are available now.

System: Linux
Topic: Vulnerability in pWhois Layer Four Traceroute
Links: LFT, CVE-2011-0765, VU #946652
ID: ae-201104-016

Layer Four Traceroute (LFT) is an alternative traceroute command. Given a specific set of command line arguments, Layer Four Traceroute (lft) will produce a segmentation fault leading to a possible privilege escalation vulnerability. An upgrade to Layer Four Traceroute 3.3 or later is recommended.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in glibc
Links: RHSA-2011-0412, RHSA-2011-0413, CVE-2010-0296, CVE-2010-3847, CVE-2011-0536, CVE-2011-1071, CVE-2011-1095, ESB-2011.0376
ID: ae-201104-015

The glibc packages contain the standard C libraries used by multiple programs on the system. These packages contain the standard C and the standard math libraries. Without these two libraries, a Linux system cannot function properly.
Some vulnerabilities have been found in glibc. Exploiting them might lead to the execution of arbitrary code or commands, increased privileges, also to modify arbitrary files and finally a Denial-of-Service (DoS). Updated packages are available now.

System: Various
Topic: Vulnerability in IBM solidDB
Links: ZDI-11-115, ESB-2011.0375
ID: ae-201104-014

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM solidDB. The reason is the solid.exe process which listens by default on TCP ports 1315, 1964 and 2315. The authentication protocol allows a remote attacker to specify the length of a password hash. By specifying a minimum length the attacker can force the process to validate only the first several bytes of the password hash. This can be abused to bypass authentication to the database. IBM has issued an update to correct this vulnerability.

System: Debian GNU/Linux
Topic: Vulnerabilities in tiff
Links: DSA-2210, CVE-2011-0191, CVE-2011-0192, CVE-2011-1167, ESB-2011.0373
ID: ae-201104-013

TIFF is the widely used Tag Image File Format. The library being responsible for TIFF manipulation and conversion shows some vulnerabilities. Exploiting them might lead to a Denial-of-Service (DoS) or the execution of arbitrary code. This can be done by a crafted TIFF image with JPEG encoding, a crafted TIFF Internet Fax Image or a TIFF file that has an unexpected BitsPerSample value. Updated packages address these issues.

System: HP-UX
Topic: Vulnerabilities in Apache
Links: HPSBUX02645, SSRT100387, CVE-2009-3560, CVE-2009-3720, CVE-2010-1623, CVE-2010-2718, CVE-2010-4476, CVE-2011-0013, ESB-2011.0370
ID: ae-201104-012

Apache is a famous and widely use web server. Potential security vulnerabilities have been identified with HP-UX Apache Web Server. These vulnerabilities could be exploited remotely to disclose information, allow Cross-Site Scripting (XSS), or create a Denial-of-Service (DoS). The Tomcat-based Servlet Engine is contained in the HP-UX Apache Web Server Suite. Updated packages are available now, it's recommended to install them.

System: HP-UX
Topic: Vulnerability in HP-UX
Links: HPSBUX02646, SSRT100396, CVE-2011-0891, ESB-2011.0371
ID: ae-201104-011

A potential security vulnerability have been identified with HP-UX B.11.23 and B.11.31. The vulnerability could be exploited locally to create a Denial-of-Service (DoS). It's recommended to install a patch which is available now.

System: HP-UX
Topic: Vulnerability in XNTP
Links: HPSBUX02639, SSRT100293, CVE-2009-3563, ESB-2011.0369
ID: ae-201104-010

A potential and longer known security vulnerability has been identified with HP-UX running XNTP. The vulnerability might be exploited remotely create a Denial-of-Service (DoS). Updated packages are available now.

System: Various
Topic: Vulnerabilities in HP Operations for UNIX
Links: HPSBMA02650, SSRT100429, CVE-2011-0893, CVE-2011-0894, ESB-2011.0368
ID: ae-201104-009

Potential security vulnerabilities have been identified in HP Operations for UNIX. The vulnerabilities could be exploited remotely resulting in Cross-Site Scripting (XSS) or unauthorized access. HP has provided a hotfix to resolve the vulnerabilities.

System: SuSE Linux
Topic: Vulnerabilities in hplip, perl, subversion, t1lib, bind, tomcat 5/6, avahi, gimp, aaa_base, build, libtiff, krb5, nbd, clamav, flash-player, pango, openssl, postgresql, logwatch, libxml2, quagga, and fuse / util-linux
Links: SUSE-SR:2011:005, ESB-2011.0374
ID: ae-201104-008

A new SUSE Security Summary reports about vulnerabilities in the packages hplip, perl, subversion, t1lib, bind, tomcat 5/6, avahi, gimp, aaa_base, build, libtiff, krb5, nbd, clamav, flash-player, pango, openssl, postgresql, logwatch, libxml2, quagga, and fuse / util-linux. Updated packages are available now and should be installed on vulnerable systems.

System: Debian GNU/Linux
Topic: Vulnerability in tgt
Links: DSA-2209, CVE-2011-0001, ESB-2011.0372
ID: ae-201104-007

A double free in tgt, the Linux SCSI target user-space tools, might lead to a Denial-of-Service. Updated packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Juniper Networks Secure Access
Links: Secunia #43983, ISS #66512
ID: ae-201104-006

Juniper Networks Secure Access could allow a remote attacker to bypass security restrictions, caused by an error in the Network Connect Credential Provider. An attacker could exploit this vulnerability to bypass the authentication process on Microsoft Windows. It's recommended to upgrade to the latest version of Networks Secure Access (6.5R9, 7.0R4, or 7.1R1 or later), available from the Juniper Networks Web site.

System: Many
Topic: Vulnerability in RealPlayer
Links: SecurityFocus #47114, ISS #66513
ID: ae-201104-005

RealPlayer 14.0.2.633 is vulnerable to a buffer overflow, caused by improper bounds checking when processing malicious files. By persuading a victim to open a specially-crafted .avi file, a remote attacker could overflow a buffer and execute arbitrary code on the system. A patch is not yet available.

System: Mandriva Linux
Topic: Vulnerabilities in ffmpeg
Links: MDVSA-2011:060, CVE-2009-4632, CVE-2009-4633, CVE-2009-4634, CVE-2009-4635, CVE-2009-4639, CVE-2009-4640, CVE-2010-3429, CVE-2010-4704
ID: ae-201104-004

FFmpeg offers a collection of free programs and libraries to record, send and convert video and audio files. Several well known vulnerabilities can be fixed now by installing the latest packages.

System: Various
Topic: Vulnerability in IPComp
Links: FullDisclosure, CVE-2011-1547, VU #668220
ID: ae-201104-003

The IP Payload Compression Protocol (IPComp) is a protocol intended to provide compression of ip datagrams, and is commonly used alongside IPSec. For compression, mostly the DEFLATE algorithm is used. Some network stack implementations, particularly those incorporating the KAME project or NetBSD project IPComp and IPsec implementations, may fail to check for stack overflow in their recursive handling of nested IPComp-encapsulated payloads. Exploitation of this vulnerability could allow a remote attacker to cause kernel memory corruption. Please check the advisory to find out if your system is affected, and also please check if an update is available.

System: IBM z/OS
Topic: Vulnerability in IBM WebSphere Application Server
Links: IBM, CVE-2010-4476, ESB-2011.0367
ID: ae-201104-002

A potential security exposure with IBM WebSphere Application Server on z/OS has been found. Unauthorized users might be granted unintended access to WebSphere applications. This only occurs when WebSphere is configured with a Local OS user registry or a Federated Repository configured with RACF (Resource Access Control Facility) adapter. Both the Local OS user registry and the Federated Repository configuration with RACF adapter use SAF (System Authorization Facility) implementation which means both RACF usage and equivalent product usage are affected. Patches are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in quagga
Links: RHSA-2011-0406, CVE-2010-1674, CVE-2010-1675, ESB-2011.0364
ID: ae-201104-001

It has been discovered that the Quagga routing daemon contains two Denial-of-Service vulnerabilities in its BGP implementation. A crafted Extended Communities attribute triggers a NULL pointer dereference which causes the BGP daemon to crash. The crafted attributes are not propagated by the Internet core, so only explicitly configured direct peers are able to exploit this vulnerability in typical configurations. Further on, the BGP daemon resets BGP sessions when it encounters malformed AS_PATHLIMIT attributes, introducing a distributed BGP session reset vulnerability which disrupts packet forwarding. Such malformed attributes are propagated by the Internet core, and exploitation of this vulnerability is not restricted to directly configured BGP peers. Updated packages are available now.



(c) 2000-2013 AERAsec Network Services and Security GmbH