Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-72-44-48-122.compute-1.amazonaws.com [72.44.48.122]

Your referer

(filtered or not existing)

Last change 3 hours ago

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen the last 10 messages

System: Red Hat Enterprise Linux 5
Topic: Vulnerability in kernel
Links: RHSA-2013-0847, CVE-2013-0153, ESB-2013.0719
ID: ae-201305-096

The kernel packages contain the Linux kernel, the core of any Linux operating system. A flaw was found in the way the Xen hypervisor AMD IOMMU driver handles interrupt remapping entries. Due to this, a local user can conduct a Denial-of-Service (DoS) under certain conditions.
Updated packages are available now.

System: Mandriva Linux
Topic: Vulnerability in krb5
Links: MDVSA-2013:166, CVE-2012-2443, Red Hat
ID: ae-201305-095

The kpasswd service provided by kadmind is vulnerable to a UDP ping-pong attack. Updated packages are available now.

System: Several
Topic: Vulnerabilities in JBoss Enterprise Application Platform
Links: RHSA-2013-0833, RHSA-2013-0834, RHSA-2013-0839, ESB-2013.0716
ID: ae-201305-094

JBoss Enterprise Application Platform 6.1.0 fixes multiple (also serious) security issues, various bugs, and adds enhancements. It's now available from the Red Hat Customer Portal.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in kernel-rt
Links: RHSA-2013-0829, ESB-2013.0715
ID: ae-201305-093

Updated kernel-rt packages that fix several security issues and multiple bugs are now available for Red Hat Enterprise MRG 2.3. Exploiting them by local users, some attack vectors like Denial-of-Service (DoS) or Root Compromise are possible.

System: Many
Topic: Vulnerabilities in Wireshark
Links: Wireshark_00, Wireshark_01, CVE-2013-2486, CVE-2013-2487, ESB-2013.0714
ID: ae-201305-092

Wireshark is a popular network protocol analyzer. When analysing data, the RELOAD dissector could go into an infinite loop, meaning a Denial-of-Service (DoS). Wireshark 1.6.15 adresses these issues and delivers further bug fixes.

System: VMware ESX Server
Topic: Vulnerabilities in IBM Security Virtual Server Protection
Links: IBM swg21636105, CVE-2011-4354, CVE-2013-0166, CVE-2013-0169, X-Force #81902, ESB-2013.0712
ID: ae-201305-091

IBM Security Virtual Server Protection for VMware System can be affected by several vulnerabilities in OpenSSL. These vulnerabilities include obtaining sensitive information and denial of service vulnerabilities that could be exploited remotely by an attacker. Fixes are available now.

System: IBM AIX
Topic: Vulnerability in IBM Sterling Connect
Links: X-Force #84016, CVE-2013-2989, ESB-2013.0711
ID: ae-201305-090

A user who has been successfully authenticated by Connect:Direct for UNIX executes Connect:Directls file copying functionality with elevated file system privileges. So file system permissions can be bypassed. A fix addresses this issue.

System: VMware ESX Server, Appliance
Topic: Vulnerability in EMC VNX and Celerra Control Station
Links: ESA-2013-041, CVE-2013-3270, ESB-2013.0710
ID: ae-201305-089

A vulnerability exists in EMC VNX and EMC Celerra Control Station that could result in elevation of privileges by a lower level administrator with access to the system. Updates are available now.

System: Several
Topic: Vulnerability in RSA SecurID
Links: ESA-2013-029, CVE-2013-0941, ESB-2013.0709
ID: ae-201305-088

The node secret is a symmetric encryption key that RSA Authentication Manager and RSA Authentication Agents use to protect network communications. In affected products, the node secret is encrypted and stored on the agent host using a dated encryption algorithm and weak key. All agent software which leverages the RSA SecurID Authentication API should be updated to use stronger encryption and stronger keys.

System: VMware ESX Server, Cisco
Topic: Vulnerability in Cisco Unified Communications Manager
Links: Cisco, CVE-2013-1227, ESB-2013.0654
ID: ae-201305-087

A vulnerability in device authentication of Cisco Unified Communications Manager (CUCM) could allow an unauthenticated, remote attacker to impact application response. The vulnerability is due to incomplete throttling of authentication requests. An attacker could exploit this vulnerability by sending multiple authentication requests in a short period of time. An update is available via the common support channels.



(c) 2000-2013 AERAsec Network Services and Security GmbH