Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/1.0 (+http://www.commoncrawl.org/bot.html)

Your IP address

(no reverse DNS resolution) [38.107.191.87]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 07 / 2010

System: Mandriva Linux
Topic: Vulnerability in gnupg2
Links: MDVSA-2010:143, CVE-2010-2547
ID: ae-201007-054

Importing a certificate with more than 98 Subject Alternate Names via GPGSM's import command or implicitly while verifying a signature causes GPGSM to reallocate an array with the names. The bug is that the reallocation code misses assigning the reallocated array to the old array variable and thus the old and freed array will be used. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in freetype
Links: RHSA-2010-0577, RHSA-2010-0578, CVE-2010-2498, CVE-2010-2499, CVE-2010-2500, CVE-2010-2519, CVE-2010-2520, CVE-2010-2527, CVE-2010-2541, ESB-2010.0662
ID: ae-201007-053

Several vulnerabilities were discovered in the FreeType font library, which could lead to the execution of arbitrary code if a malformed font file is processed.Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in openldap
Links: DSA-2077, CVE-2010-0211, CVE-2010-0212, ESB-2010.0661
ID: ae-201007-052

Multiple flaws have been discovered in the way the slapd daemon handles relative distinguished name (modrdn) requests. An authenticated user with privileges to perform modrdn operations could use these flaws to crash the slapd daemon via specially-crafted modrdn requests. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.4.2-ibm
Links: RHSA-2010-0574, ESB-2010.0660
ID: ae-201007-051

Updated java-1.4.2-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 3 Extras, Red Hat Enterprise Linux 4 Extras, and Red Hat Enterprise Linux 5 Supplementary.

System: Cisco Content Delivery System
Topic: Vulnerability in Cisco Internet Streamer application
Links: Cisco, CVE-2010-1577, ESB-2010.0642
ID: ae-201007-050

The Cisco Internet Streamer application, part of the Cisco Content Delivery System, contains a directory traversal vulnerability on its web server component that allows access to arbitrary files. By exploiting this vulnerability, an attacker may be able to read arbitrary files on the device, outside of the web server document directory, by using a specially crafted URL. Cisco has released free software updates that address this vulnerability.

System: Various
Topic: Vulnerability in RSA Federated Identity Manager
Links: ISS #60654, ESB-2010.0659
ID: ae-201007-049

RSA Federated Identity Manager 4.0 and 4.1 might provide weaker than expected security, caused by the redirection of users. A remote attacker could exploit this vulnerability using an unknown attack vector to construct a malicious URL which would redirect a victim to an arbitrary Web site, once the site is visited, and launch further attacks on the vulnerable system. This problem can be solved by insatalling Hotfix 4.0.25 and Hotfix 4.1.26, respectively.

System: Mandriva Linux
Topic: Vulnerabilities in openldap
Links: MDVSA-2010:142, CVE-2010-0211, CVE-2010-0212
ID: ae-201007-048

Multiple flaws have been discovered in the way the slapd daemon handles relative distinguished name (modrdn) requests. An authenticated user with privileges to perform modrdn operations could use these flaws to crash the slapd daemon via specially-crafted modrdn requests. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in several Symantec products
Links: SYM10-009, CVE-2010-0126, CVE-2010-0131, CVE-2010-0133, CVE-2010-0134, CVE-2010-0135, CVE-2010-1524, CVE-2010-1525, ESB-2010.0658
ID: ae-201007-047

Vulnerabilities have been found in Symantec Mail Security, Symantec Brightmail Gateway, Symantec Data Loss Prevention Servers and Endpoint Agents as well as Symantec IM Manager 2007. These products ship with the Verity KeyView Filter which has been updated to address multiple security issues being reported in the content filter processing of specifically crafted document formats. So this update is recommended.

System: Unix, Linux, OSX
Topic: New versions of Safari available
Links: APPLE-SA-2010-07-28-1, ESB-2010.0657
ID: ae-201007-046

Multiple vulnerabilities have been fixed with the latest versions of Safari 5.0.1 and Safari 4.1.1. It's recommended to upgrade to these latest versions.

System: IBM AIX
Topic: Vulnerability in BIND
Links: IBM, CVE-2009-4022, VU #418861, ESB-2010.0656
ID: ae-201007-045

Since some time a vulnerability in the popular DNS Server BIND regarding DNSSEC validations and caching is known. Now, a patch is available for IBM AIX 6.1, too.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2010-076, DRUPAL-SA-CONTRIB-2010-077, DRUPAL-SA-CONTRIB-2010-078, ESB-2010.0655
ID: ae-201007-044

Several vulnerabilities were found in the Drupal third-party modules Dashboard, Sage Pay (former Protx) Direct Payment Gateway for Ubercart, and Kaltura show vulnerabilities in Cross-Site Scripting and Information Disclosure. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Red Hat Enterprise Linux 4/5
Topic: Vulnerability in lvm2-cluster
Links: RHSA-2010-0567, RHSA-2010-0568, CVE-2010-2526, ESB-2010.0654
ID: ae-201007-043

The lvm2-cluster package contains support for Logical Volume Management (LVM) in a clustered environment. It was discovered that the cluster logical volume manager daemon (clvmd) did not verify the credentials of clients connecting to its control UNIX abstract socket, allowing local, unprivileged users to send control commands that were intended to only be available to the privileged root user. This could allow a local, unprivileged user to cause clvmd to exit, or request clvmd to activate, deactivate, or reload any logical volume on the local system or another system in the cluster. Updated packages are available now.

System: Microsoft Windows
Topic: Vulnerability in HP Insight Control
Links: HPSBMA02549, SSRT090158, CVE-2010-1966, ESB-2010.0653
ID: ae-201007-042

A potential security vulnerability has been identified with HP Insight Control power management for Windows. The vulnerability could be exploited locally to allow unauthorized read access to data. HP has made an update available to resolve the vulnerability.

System: Mandriva Linux
Topic: Vulnerabilities in freetype2, iputils, and php
Links: MDVSA-2010:137, CVE-2010-2497, CVE-2010-2498, CVE-2010-2499, CVE-2010-2500, CVE-2010-2519, CVE-2010-2520,
MDVSA-2010:138, CVE-2010-2529,
MDVSA-2010:139, CVE-2010-0397, CVE-2010-2225, CVE-2010-2484, CVE-2010-2531
ID: ae-201007-041

In freetype2, multiple integer underflows/overflows and heap buffer overflows have been found. Further on, a heap buffer overflow has been detected in the bytecode support. Ping.c as part of iputils hangs when a special echo request answer is received. PHP 5.2.14 is available now. This version offers many security enhancements. For the other two problems fixes are available now.

System: Some
Topic: Vulnerability in IBM FileNet P8 Content Manager
Links: IBM, CVE-2010-2896, ESB-2010.0647
ID: ae-201007-040

A potential authorization vulnerability in P8 has been found. It occurs when security inheritance was disabled on one or more folders and an upgrade from 3.x to 4.x was performed. A fix is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in jboss-seam2
Links: RHSA-2010-0564, CVE-2010-1871, ESB-2010.0648
ID: ae-201007-039

An input sanitization flaw was found in the way JBoss Seam processed certain parametrized JBoss Expression Language (EL) expressions. If a remote attacker could trick an authenticated JBoss Seam user into visiting a specially-crafted web page, it could lead to arbitrary code execution. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in gnupg2
Links: DSA-2076, CVE-2010-2547, ESB-2010.0651
ID: ae-201007-038

It was discovered that GnuPG 2 uses a freed pointer when verify a signature or importing a certificate with many Subject Alternate Names, potentially leading to arbitrary code execution. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in w3m
Links: RHSA-2010-0565, CVE-2010-2074, ESB-2010.0649
ID: ae-201007-037

It was discovered that w3m is affected by the previously published "null prefix attack", caused by incorrect handling of NULL characters in X.509 certificates. If an attacker is able to get a carefully-crafted certificate signed by a trusted Certificate Authority, the attacker could use the certificate during a man-in-the-middle attack and potentially confuse w3m into accepting it by mistake. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in ncompress
Links: DSA-2074, CVE-2010-0001, ESB-2010.0641
ID: ae-201007-036

An integer underflow was discovered in ncompress, the original Lempel-Ziv compress/uncompress programs. This could lead to the execution of arbitrary code when trying to decompress a crafted LZW compressed gzip archive. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in HP OpenView Network Node Manager
Links: HPSBMA02557 SSRT100025, HPSBMA02558 SSRT010158, CVE-2010-2703, CVE-2010-2704, ESB-2010.0635
ID: ae-201007-035

Several security vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). The vulnerability could be exploited remotely to execute arbitrary code under the context of the user running the web server. Patches are available now.

System: SuSE Linux
Topic: Vulnerabilities in kernel
Links: SUSE-SA:2010:031, ESB-2010.0636
ID: ae-201007-034

The SUSE Linux Enterprise Server/Desktop 11 kernel was updated to fix various bugs and some security issues.

System: Debian GNU/Linux
Topic: Vulnerability in mlmmj
Links: DSA-2073, CVE-2009-4896, ESB-2010.0637
ID: ae-201007-033

A directory traversal flaw was discoverd in the way the Mailing List Managing Made Joyful mailing list manager processed users' requests originating from the administrator web interface without enough input validation. A remote, authenticated attacker could use these flaws to write and / or delete arbitrary files. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in openldap
Links: RHSA-2010-0542, RHSA-2010-0543, CVE-2009-3767, CVE-2010-0211, CVE-2010-0212, ESB-2010.0634
ID: ae-201007-032

Multiple flaws were discovered in the way the slapd daemon handled modify relative distinguished name (modrdn) requests. An authenticated user with privileges to perform modrdn operations could use these flaws to crash the slapd daemon via specially-crafted modrdn requests. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Mozilla Firefox, Thunderbird, and Seamonkey
Links: Mozilla, RHSA-2010-0545, RHSA-2010-0546, RHSA-2010-0547, RHSA-2010-0556, RHSA-2010-0557, RHSA-2010-0558, ESB-2010.0638, ESB-2010.0639, ESB-2010.0645, ESB-2010.0646, DSA-2075, ESB-2010.0650, SUSE-SA:2010:032, ESB-2010.0663
ID: ae-201007-031

Several vulnerabilities were found in the Mozilla Firefox browser, Thuderbird and Seamonkey. Fixed software is available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in libpng
Links: DSA-2072, CVE-2010-1205, CVE-2010-2249, ESB-2010.0631
ID: ae-201007-030

Several vulnerabilities have been discovered in libpng, a library for reading and writing PNG files. Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerabilities in Ipswitch Imail Server
Links: ESB-2010.0627
ID: ae-201007-029

Several vulnerabilities allow remote attackers to execute arbitrary code on vulnerable installations of IPSwitch IMail and IPSwitch IMail List Mailer. Authentication is not required to exploit these vulnerabilities. Patches are available now.

System: Mandriva Linux
Topic: Vulnerabilities in libpng and ghostscript
Links: MDVSA-2010:133, CVE-2008-6218, CVE-2010-1205, CVE-2010-2249,
MDVSA-2010:134, CVE-2009-4270, CVE-2010-1628 CVE-2010-1628, ESB-2010.0629
ID: ae-201007-028

Multiple vulnerabilities has been found in libpng.
Multiple vulnerabilities has been found in ghostscript.
Fixed packages are available now.

System: HP-UX
Topic: Vulnerability in rpc.ttdbserver
Links: HPSBUX02556 SSRT100014, CVE-2010-0083, ESB-2010.0619
ID: ae-201007-027

A security vulnerability has been identified with HP-UX running rpc.ttdbserver. The vulnerability could be exploited remotely to execute arbitrary code. Patches are available now.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2010-073, DRUPAL-SA-CONTRIB-2010-074, ESB-2010.0624
ID: ae-201007-026

Several vulnerabilities were found in the Drupal third-party modules Simple Gallery, OG Menu, Tell a Friend Node, JsMath For Displaying Mathematics With TeX, and Drupad. Fixed software is available now. Please be aware that Drupal core is not affected.

System: Mandriva Linux
Topic: Vulnerabilities in python
Links: MDVSA-2010:132, CVE-2010-1634, CVE-2010-2089, ESB-2010.0625
ID: ae-201007-025

Multiple vulnerabilities has been found in python. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in pcsc-lite and libpng
Links: RHSA-2010-0533, CVE-2009-4901, CVE-2010-0407, ESB-2010.0620
RHSA-2010-0534, CVE-2009-2042, CVE-2010-0205, CVE-2010-1205, CVE-2010-2249, ESB-2010.0621
ID: ae-201007-024

Multiple buffer overflow flaws were discovered in the way the pcscd daemon, a resource manager that coordinates communications with smart card readers and smart cards connected to the system, handled client requests. A local user could create a specially-crafted request that would cause the pcscd daemon to crash or, possibly, execute arbitrary code.
Several vulnerabilities were found in libpng.
Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in freetype and libmikmod
Links: DSA-2070, CVE-2010-2497, CVE-2010-2498, CVE-2010-2499, CVE-2010-2500, CVE-2010-2519, CVE-2010-2520, CVE-2010-2527, ESB-2010.0622,
DSA-2071, CVE-2009-3995, CVE-2009-3996, ESB-2010.0623
ID: ae-201007-023

Several vulnerabilities were discovered in the FreeType font library, which could lead to the execution of arbitrary code if a malformed font file is processed.
Several buffer overflows were discovered in the MikMod sound library, which could lead to the execution of arbitrary code if a user is tricked into opening malformed Impulse Tracker or Ultratracker sound files.
Fixed packages are available now.

System: Microsoft Windows
Topic: Vulnerability in SolidDB
Links: ZDI-10-125, ESB-2010.0617
ID: ae-201007-022

A vulnerability in IBM solidDB allows remote attackers to execute arbitrary code on vulnerable installations. Authentication is not required to exploit this vulnerability. Patches are available now.

System: Various
Topic: Vulnerabilities in HP Management Agents
Links: ESB-2010.0616, ESB-2010.0618
ID: ae-201007-021

Several security vulnerabilities have been identified in HP Systems Insight Manager (SIM) for HP-UX, Linux, and Windows. The vulnerabilities could be exploited remotely to execute arbitrary code and other exploits. Patches are available now.

System: HP OpenVMS
Topic: Vulnerability in HP OpenVMS Auditing
Links: HPSBOV02539 SSRT090267, CVE-2010-1973, ESB-2010.0615
ID: ae-201007-020

A security vulnerability has been identified with HP OpenVMS Auditing. The vulnerability could result in a local disclosure of information or elevation of privilege. Patches are available now.

System: VMware
Topic: Vulnerabilities in VMware Studio
Links: RHSA-2010-0528, CVE-2009-0758, CVE-2010-2244, ESB-2010.0614
ID: ae-201007-019

A vulnerability in the Virtual Appliance Management Infrastructure (VAMI) allows for remote command execution in Studio 2.0 or in virtual appliances created with Studio 2.0. Exploitation of the issue requires authentication to Studio or to the virtual appliance. Fixed software is available now.

System: Microsoft Windows
Topic: Vulnerability in Microsoft Outlook
Links: MS10-045, CVE-2010-0266, ESB-2010.0612
ID: ae-201007-018

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Office Access
Links: MS10-044, CVE-2010-0814, CVE-2010-1881, ESB-2010.0611
ID: ae-201007-017

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Canonical Display Driver
Links: MS10-043, CVE-2009-3678, ESB-2010.0610
ID: ae-201007-016

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Help and Support Center
Links: MS10-042, CVE-2010-1885, ESB-2010.0609
ID: ae-201007-015

No further comment due to legal reasons

System: Debian GNU/Linux
Topic: Vulnerability in python-cjson
Links: DSA-2068, CVE-2010-1666, ESB-2010.0607
ID: ae-201007-014

A buffer overflow was discovered in python-cjson, a fast JSON encoder/decoder for Python. This allows a remote attacker to cause a denial of service (application crash) through a specially-crafted Python script. Fixed packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in avahi
Links: RHSA-2010-0528, CVE-2009-0758, CVE-2010-2244, ESB-2010.0614
ID: ae-201007-013

Two vulnerabilities were found in avahi-daemon regarding the handling of mDNS messages. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in znc
Links: DSA-2069, CVE-2010-2448, ESB-2010.0606
ID: ae-201007-012

It was discovered that znc, an IRC bouncer, is vulnerable to denial of service attacks via a NULL pointer dereference when traffic statistics are requested while there is an unauthenticated connection. Fixed packages are available now.

System: Various
Topic: Vulnerabilities in Drupal 3rd party modules
Links: DRUPAL-SA-CONTRIB-2010-071, DRUPAL-SA-CONTRIB-2010-072, ESB-2010.0594
ID: ae-201007-011

Some vulnerabilities regarding Cross-Site Scripting (XSS) were found in the Drupal third-party modules MultiSafepay Integration and Hierarchical Select. Fixed software is available now. Please be aware that Drupal core is not affected.

System: SuSE Linux
Topic: Vulnerabilities in kernel
Links: SUSE-SA:2010:027
ID: ae-201007-010

The SUSE Linux Enterprise Server/Desktop 11 kernel was updated to fix various bugs and some security issues.

System: Cisco Industrial Ethernet 3000 Series Switches
Topic: Vulnerability in Cisco IOS
Links: Cisco, CVE-2010-1574, VU#732671, ESB-2010.0595
ID: ae-201007-009

Cisco Industrial Ethernet 3000 (IE 3000) Series switches running Cisco IOS Software contain a vulnerability where well known SNMP community names are hard-coded for both read and write access. The hard-coded community names are "public" and "private." Cisco has released free software updates that address this vulnerability.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in scsi-target-utils, libtiff, and gfs-kmod
Links: RHSA-2010-0518, CVE-2010-2221, ESB-2010.0599
RHSA-2010-0519, RHSA-2010-0520, CVE-2010-1411, CVE-2010-2481, CVE-2010-2483, CVE-2010-2595, CVE-2010-2597, CVE-2010-2598, ESB-2010.0600,
RHSA-2010-0521, CVE-2010-0727, ESB-2010.0601
ID: ae-201007-008

Multiple buffer overflow flaws were found in scsi-target-utils' tgtd daemon. A remote attacker could trigger these flaws by sending a carefully-crafted Internet Storage Name Service (iSNS) request, causing the tgtd daemon to crash.
Multiple input validation flaws were discovered in libtiff.
A flaw was found in the gfs_lock() implementation. The GFS locking code could skip the lock operation for files that have the S_ISGID bit (set-group-ID on execution) in their mode set. A local, unprivileged user on a system that has a GFS file system mounted could use this flaw to cause a kernel panic.
Fixed packages are available now.

System: Mandriva Linux
Topic: Vulnerability in heimdal
Links: MDVSA-2010:130, CVE-2010-1321
ID: ae-201007-007

A vulnerability has been found and corrected in heimdal. Certain invalid GSS-API tokens can cause a GSS-API acceptor (server) to crash due to a null pointer dereference in the GSS-API library. Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in java-1_5_0-ibm and java-1_6_0-ibm
Links: SUSE-SA:2010:026, SUSE-SA:2010:028, ESB-2010.0589, ESB-2010.0593
ID: ae-201007-006

Several vulnerabilities were found in IBM Java 1.5.0 and IBM Java 1.6.0. Fixed packages are available now.

System: Debian GNU/Linux
Topic: Vulnerabilities in mahara
Links: DSA-2067, CVE-2010-1667, CVE-2010-1668, CVE-2010-1670, CVE-2010-2479, ESB-2010.0591
ID: ae-201007-005

Several vulnerabilities were discovered in mahara, an electronic portfolio, weblog, and resume builder. Fixed packages are available now.

System: SuSE Linux
Topic: Vulnerabilities in samba
Links: SUSE-SA:2010:025, CVE-2010-0787, CVE-2010-2063
ID: ae-201007-004

The samba server shows some vulnerabilities. First of all, it should be assured that a mount point of mount.cifs isn't changed during mount. Further on, a buffer overrun in chain_reply code in samba 3.3x and earlier might lead to a server crash or even the execution of code. An update is available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in perl-Archive-Tar
Links: RHSA-2010-0505, CVE-2007-4829, ESB-2010.0587
ID: ae-201007-003

Multiple directory traversal flaws were discovered in the Archive::Tar module. A specially-crafted tar file could cause a Perl script, using the Archive::Tar module to extract the archive, to overwrite an arbitrary file writable by the user running the script. Fixed packages are available now.

System: Red Hat Enterprise Linux 5
Topic: Vulnerabilities in kernel
Links: RHSA-2010-0504, CVE-2010-0291, CVE-2010-0622, CVE-2010-1087, CVE-2010-1088, CVE-2010-1173, CVE-2010-1187, CVE-2010-1436, CVE-2010-1437, CVE-2010-1641, ESB-2010.0586
ID: ae-201007-002

Updated kernel packages that fix one security issue and add one enhancement are now available for Red Hat Enterprise Linux 5.

System: Debian GNU/Linux
Topic: Vulnerabilities in wireshark
Links: DSA-2066, CVE-2010-2283, CVE-2010-2284, CVE-2010-2285, CVE-2010-2286, CVE-2010-2287, ESB-2010.0588
ID: ae-201007-001

Several remote vulnerabilities have been discovered in the Wireshark network traffic analyzer. It was discovered that null pointer dereferences, buffer overflows and infinite loops in the SMB, SMB PIPE, ASN1.1 and SigComp dissectors could lead to denial of service or the execution of arbitrary code. Fixed packages are available now.



(c) 2000-2010 AERAsec Network Services and Security GmbH