Network Security

AERAsec
Network Security
Current Security Messages


Most of the links lead to the corresponding files at CERT or other organisations. So changes take place immediately, especially which patches should be installed or which changes in the configuration should be made to avoid this vulnerability. Some of the files are transferred by FTP.

By the way: If we're not publishing well-known risks inheritant in any widely used platform or program that doesn't mean this particular platform or program is safe to use!

Here you find our network security search engine!


This is some information you send:

Your Browser

CCBot/2.0

Your IP address

ec2-184-72-91-94.compute-1.amazonaws.com [184.72.91.94]

Your referer

(filtered or not existing)

Current month, Last month, Last 10 messages, Last 20 messages (index only)

Chosen month 07 / 2012

System: Red Hat Enterprise Linux
Topic: Vulnerability in bind, bind97
Links: RHSA-2012-1122, RHSA-2012-1123, CVE-2012-3817, ESB-2012.0717
ID: ae-201207-082

An uninitialized data structure use flaw was found in BIND when DNSSEC validation was enabled. A remote attacker able to send a large number of queries to a DNSSEC validating BIND resolver could use this flaw to cause it to exit unexpectedly with an assertion failure. It is recommend to upgrade BIND packages.

System: Debian GNU/Linux 6
Topic: Vulnerability in bind9
Links: dsa-2517, CVE-2012-3817, ESB-2012.0715
ID: ae-201207-081

It was discovered that under certain conditions bind9, a DNS server, may use cached data before initialization. As a result, an attacker can trigger and assertion failure on servers under high query load that do DNSSEC validation. It is recommend to upgrade bind9 packages.

System: Linux Variants
Topic: Vulnerability in Scale Out Network Attached Storage
Links: swg1IC84088, CVE-2012-2110, ESB-2012.0713
ID: ae-201207-080

An error in the Remote Procedure Call (RPC) code in Samba results in a security vulnerability that could be leveraged by a remote attacker to take ownership of files or directories he does not own. SONAS included a vulnerable version of Samba and may be susceptible to an attack that takes advantage of this vulnerability. A new update is available.

System: Network Appliance
Topic: Vulnerability in WebSphere DataPower SOA Appliances
Links: swg1IC84088, CVE-2012-2110, ESB-2012.0713
ID: ae-201207-079

An appliance restart or other unpredictable behavior can be triggered by malicious ASN.1 content coming into the DataPower appliance from a variety of entry points. A new update is available.

System: Many
Topic: Vulnerabilities in Bugzilla
Links: CVE-2012-1969, CVE-2012-1968, ESB-2012.0712
ID: ae-201207-078

Two vulnerabilities have been identified in bugzilla, a web based bug tracking system. These vulnerabilities may allow remote attackers to gain access to confidential data. A new update is available to address this issue.

System: IBM AIX
Topic: Vulnerability in Kernel
Links: IBM syscall advisory, ESB-2012.0711
ID: ae-201207-077

A kernel extension call is exported to user space without proper sanity checks causing a system crash. This Denial-of-Service (DoS) can be avoided by installing a fix.

System: Several
Topic: Vulnerability in IBM Websphere MQ
Links: IBM swg21595523, ESB-2012.0708
ID: ae-201207-076

There is the potential for client applications to bypass security configuration setup on an MQ 7.1 SVRCONN channel, allowing access to the queue manager to unathourised user IDs. Updated packages are available now.

System: Several
Topic: Vulnerability in IBM Eclipse Help System
Links: IBM swg21605703, ESB-2012.0706
ID: ae-201207-075

There is a vulnerability in the IBM Eclipse Help System (IEHS), used in locally installed IBM product information centers, that can permit a local user to exploit and gain escalated privilege. To improve security, updated IEHS and IEHS WAR files are provided.

System: Apple OS X
Topic: Vulnerabilities in Safari and Xcode
Links: APPLE-SA-2012-07-25-1, ESB-2012.0705,
APPLE-SA-2012-07-25-2, CVE-2011-3389, CVE-2012-3698, ESB-2012.0707
ID: ae-201207-074

Safari is a web browser by Apple. Safari 6.0 is now available and addresses 121 (!) vulnerabilities. So this update ist strongly recommended.
Xcode is an integrated framework for software development. Vulnerabilities may allow attackers to decrypt data protected by SSL. Helper tools built with Xcode allow any App Store application to read their keychain entries. Due to this, also this update is recommended.

System: Several
Topic: Vulnerability in perl-DBD-Pg
Links: CVE-2012-1151,
RHSA-2012-1116, ESB-2012.0703, MDVSA-2012:112
ID: ae-201207-073

Perl DBI is a database access Application Programming Interface (API) for the Perl language. perl-DBD-Pg allows Perl applications to access PostgreSQL database servers. Two format string flaws were found in perl-DBD-Pg. A specially-crafted database warning or error message from a server could cause an application using perl-DBD-Pg to crash or, potentially, execute arbitrary code with the privileges of the user running the application. Updated packages are available now.

System: Microsoft Windows
Topic: Several vulnerabilities in Microsoft Exchange Server and FAST Search Server 2010 for Sharepoint
Links: Microsoft #2737111, ESB-2012.0702
ID: ae-201207-072

No further comment due to legal reasons

System: Many
Topic: Vulnerabilities in ISC BIND
Links: ISC AA-00729, CVE-2012-3817, CVE-2012-3868, ESB-2012.0701,
NetBSD-SA2012-004, MDVSA-2012:119, ESB-2012.0704
ID: ae-201207-071

The Berkeley Internet Name Daemon, BIND, is a very often used DNS server. High numbers of queries with DNSSEC validation enabled can cause an assertion failure in named, caused by using a "bad cache" data structure before it has been initialized.
Updated packages are available now.

System: Many
Topic: Vulnerabilities in ISC DHCP
Links: ISC AA-00712, ISC AA-00714, ISC AA-00737, CVE-2012-3570, CVE-2012-3571, CVE-2012-3954, ESB-2012.0700
DSA-2516, ESB-2012.0709
ID: ae-201207-070

An error in the handling of malformed client identifiers can cause a DHCP server running affected versions to enter a state where further client requests are not processed and the server process loops endlessly, consuming all available CPU cycles. An unexpected client identifier parameter can cause the ISC DHCP daemon to segmentation fault when running in DHCPv6 mode, resulting also in a Denial-of-Service (DoS). Two memory leaks have been found in ISC DHCP. Both are reproducible when running in DHCPv6 mode (with the -6 command-line argument).
Updated packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in Kernel
Links: RHSA-2012-1114, CVE-2012-2744, ESB-2012.0698
ID: ae-201207-069

The kernel packages contain the Linux kernel, the core of any Linux operating system. A NULL pointer dereference flaw was found in the Linux kernel's netfilter IPv6 connection tracking implementation. A remote attacker could use this flaw to send specially-crafted packets to a target system that is using IPv6 and also has the nf_conntrack_ipv6 kernel module loaded, causing it to crash.
Updated packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Ipswitch WhatsUp Gold
Links: Securityfocus #54626, CVE-2012-2601, Exploit-DB #20035, X-Force #77152
ID: ae-201207-068

Ipswitch WhatsUp Gold is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the WrVMwareHostList.asp script using the sGroupList parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. Until now, no patch is available.

System: Microsoft Windows
Topic: Vulnerability in Dell SonicWALL Scrutinizer
Links: Securityfocus #54625, CVE-2012-2962, Exploit-DB #20033, X-Force #77148, VU #404051, ESB-2012.0716
ID: ae-201207-067

TeamviewDell SonicWALL Scrutinizer is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements to the statusFilter.php script using the q parameter, which could allow the attacker to view, add, modify or delete information in the back-end database. A new patch is available for download.

System: Microsoft Windows
Topic: Vulnerability in Teamviewer
Links: Teamviewer, Securityfocus #54632, Secunina #50015, X-Force #77108, ASB-2012.0107
ID: ae-201207-066

Teamviewer has been published in Version 7.0.13989. As stated, this version is a security update fixing a vulnerability that isn't described further.

System: Several
Topic: Vulnerabilities in Symantec Web Gateway
Links: SYM12-011, CVE-2012-2574, CVE-2012-2953, CVE-2012-2957, CVE-2012-2961, CVE-2012-2976, CVE-2012-2977, ESB-2012.0697, VU #108471
ID: ae-201207-065

Symantec's Web Gateway management console is susceptible to multiple security issues that include remote command execution, local file inclusion, arbitrary password change and SQL injection security issues. Successful exploitation could result in unauthorized command execution on or access to the management console and backend database. Symantec engineers verified these issues and have released an update to address them.

System: Red Hat Enterprise Linux
Topic: Vulnerability in BIND
Links: RHSA-2012-1110, CVE-2012-1667, ESB-2012.0696
ID: ae-201207-064

A potential security vulnerability has been identified with Red Hat Enterprise Linux running the famous NDS Server BIND. This vulnerability could be exploited remotely to create a Denial-of-Service (DoS). An update is available for download.

System: Red Hat Enterprise Linux
Topic: Vulnerability in JBoss Application Server
Links: RHSA-2012-1109, CVE-2012-4605, ESB-2012.0695, X-Force #77164
ID: ae-201207-063

JBoss Application Server is the base package for JBoss Enterprise Portal Platform, providing the core server components. The Java Naming and Directory Interface (JNDI) Java API allows Java software clients to locate objects or services in an application server. It has been detected that the JBoss JNDI service allows unauthenticated, remote write access by default. The JNDI and HA-JNDI services, and the HAJNDIFactory invoker servlet were all affected. A remote attacker able to access the JNDI service (port 1099), HA-JNDI service (port 1100), or the HAJNDIFactory invoker servlet on a JBoss server could use this flaw to add, delete, and modify items in the JNDI tree. This could have various, application-specific impacts. Updated packages are available now.

System: Mandriva Linux
Topic: Vulnerability in libxslt
Links: MDVSA-2012:109, CVE-2012-2825
ID: ae-201207-062

The XSL implementation in libxslt allows remote attackers to cause a Denial-of-Service (DoS) due to an incorrect read operation via unspecified vectors. Updated packages are available now.

System: Many
Topic: Vulnerabilities in PHP
Links: ASB-2012.0105, CVE-2012-2688, CVE-2012-3365, X-Force #77135,
MDVSA-2012:108
ID: ae-201207-061

Multiple vulnerabilities has been discovered in PHP. An unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.x before 5.4.5 has unknown impact and remote attack vectors, related to an overflow. Besides this, the SQLite functionality in PHP before 5.3.15 allows remote attackers to bypass the open_basedir protection mechanism via unspecified vectors. Please check if updates are available for your system.

System: Debian GNU/Linux
Topic: Vulnerability in kfreebsd-8
Links: DSA-2508, CVE-2012-0217, ESB-2012.0694
ID: ae-201207-060

It has been discovered that FreeBSD isn't handling correctly uncanonical return addresses on Intel amd64 CPUs, allowing privilege escalation to kernel for local users. Updated packages are available now.

System: Microsoft Windows
Topic: Vulnerability in Symantec System Recovery
Links: SYM12-012, X-Force #77107, Securityfocus #54594, CVE-2012-0305, ESB-2012.0699
ID: ae-201207-059

Symantec System Recovery (formerly Backup Exec System Recovery) doesn't directly specify the fully qualified path to a dynamic-linked library when running on Microsoft Windows. By persuading a victim to open a specially-crafted file from a WebDAV or SMB share using a vulnerable application, a remote attacker could exploit this vulnerability via a specially-crafted library to execute arbitrary code on the system. An official fix is available now.

System: Several
Topic: Vulnerabilities in WebSphere Operational Decision Management
Links: IBM swg21600616, CVE-2012-2159, CVE-2012-2161, ESB-2012.0693
ID: ae-201207-058

Security vulnerabilities have been found in IBM WebSphere Operational Decision Management and IBM WebSphere ILOG JRules Flash. Exploiting them might lead to Cross-Site Scripting (XSS) and provisioning of misleading information. Fixes are available now.

System: Linux
Topic: Vulnerabilities in Lotus Protector for Mail Security
Links: IBM swg21605199, CVE-2012-2202, CVE-2012-2955, ESB-2012.0692, VU #659791
ID: ae-201207-057

Two vulnerabilities have been detected in the management interface of Lotus Protector for Mail Security. Both possible attacks are post-authentication and require the attacker to have valid login credentials for the admin UI. The end user interface is not affected by these vulnerabilities. An update has been created by IBM Security Systems that addresses the vulnerabilities.

System: Microsoft Windows
Topic: Vulnerabilities in HP StorageWorks File Migration Agent
Links: ZDI-12-126, X-Force #77089, ZDI-12-127, X-Force #77090, ESB-2012.0691
ID: ae-201207-056

The HsmCfgSvc.exe service of HP StorageWorks File Migration Agent listens by default on TCP port 9111. When processing CIFS archives or FTP archives the process doesn't properly validate the size of the root path specified and proceeds to copy the string into a fixed-length buffer on the stack. This can be exploited to execute arbitrary remote code under the context of the running service. Using a firewall can protect vulnerable servers.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in pidgin and PKI
Links: RHSA-2012-1102, CVE-2012-1178, CVE-2012-2318, CVE-2012-3374, ESB-2012.0688,
RHSA-2012-1103, CVE-2012-2262, CVE-2012-3367, ESB-2012.0689
ID: ae-201207-055

Pidgin is an instant messaging program which can log in to multiple accounts on multiple instant messaging networks simultaneously. A flaw was found in the way the Pidgin MSN protocol plug-in processes text that was not encoded in UTF-8 and MSN notification messages. A malicious server or a remote attacker could use these flaws to crash Pidgin by sending specially-crafted MSN notification messages. Besides this, a buffer overflow flaw was found in the Pidgin MXit protocol plug-in. Also this vulnerability can lead to a Denial-of-Service (DoS).
Red Hat Certificate System is an enterprise software system designed to manage enterprise Public Key Infrastructure (PKI) deployments. Multiple Cross-Site scripting (XSS) flaws were discovered in the Red Hat Certificate System Agent and End Entity pages. It was also discovered that Red Hat Certificate System's Certificate Manager doesn't properly check certificate revocation requests performed via its web interface. So the CA's certifcate can be revoked by a bad entity.
Updated packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in nsd3
Links: DSA-2515, CVE-2012-2978, ESB-2012.0690
ID: ae-201207-054

It has been discovered that NSD, an authoritative domain name server, isn't properly handling non-standard DNS packets. This can result in a NULL pointer dereference and crash the handling process. A remote attacker can abuse this flaw to perform Denial-of-Service (DoS) attacks. Updated packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in Kernel, nss/nspr and glibc
Links: RHSA-2012-1087, CVE-2012-2136, ESB-2012.0683,
RHSA-2012-1090, RHSA-2012-1091, CVE-2012-0441, ESB-2012.0685,
RHSA-2012-1097, RHSA-2012-1098, CVE-2012-3404, CVE-2012-3405, CVE-2012-3406, ESB-2012.0687,
ID: ae-201207-053

The kernel packages contain the Linux kernel, the core of any Linux operating system. It was found that an error in the Linux kernel's networking implementation might allow local users to crash the system or, potentially, escalate their privileges.
Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client and server applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities. A flaw has been found in the way the ASN.1 (Abstract Syntax Notation One) decoder in NSS handles zero length items. A Certificate Authority (CA) issued a subordinate CA certificate to its customer can be used to issue certificates for any name. Exploiting these vulnerabilities might allow to spread misleading information.
The glibc packages provide the standard C and standard math libraries used by multiple programs on the system. It was discovered that the formatted printing functionality in glibc doesn't properly restrict the use of alloca(). This could allow a local attacker to bypass protections and execute arbitrary code using a format string flaw in an application.
Updated packages are available now.

System: Many
Topic: Multiple Vulnerabilities in Firefox/Thunderbird and Iceweasel/Iceape
Links: ASB-2012.0104,
RHSA-2012-1088, RHSA-2012-1089, ESB-2012.0684, DSA-2513, DSA-2514, ESB-2012.0686, MDVSA-2012:110
ID: ae-201207-052

Updates address many vulnerabilities in the Mozilla Software. Since some of the vulnerabilities are rated as critical, these updates are recommended.

System: Many
Topic: Multiple Vulnerabilities in HP Network Node Manager i
Links: HPSBMU02799 SSRT100867, HPSBMU02797 SSRT100867, ESB-2012.0682
ID: ae-201207-051

Many potential security vulnerabilities have been identified with HP Network Node Manager I (NNMi) running JDK for HP-UX, Linux, Solaris, and Windows. The vulnerabilities could be remotely exploited resulting in unauthorized information disclosure, modification, and Denial-of-Service (DoS). HP has made hotfixes available to resolve these vulnerabilities for NNMi.

System: IBM AIX
Topic: Several vulnerabilities in Oracle products
Links: Oracle, VU #118913, ASB-2012.0103
ID: ae-201207-050

Oracle has published their critical patch update for July. This update affects many products like e.g. Oracle Fusion Middleware, Oracle Database but also Oracle Identity Management, Oracle Application Server and others. Since there are 87 vulnerabilities addressed with this update, it's strongly recommended.

System: IBM AIX
Topic: Vulnerability in BIND
Links: IBM, CVE-2012-1667, ESB-2012.0681
ID: ae-201207-049

A potential security vulnerability has been identified with IBM AIX running the famous NDS Server BIND. This vulnerability could be exploited remotely to create a Denial-of-Service (DoS). An update is available for download.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in java-1.4.2-ibm-sap and sudo
Links: RHSA-2012-1080, CVE-2011-3563, CVE-2012-0499, CVE-2009-0502, CVE-2012-0503, CVE-2009-0505, CVE-2012-0506, ESB-2012.0679,
RHSA-2012-1081, CVE-2012-2337, ESB-2012.0680
ID: ae-201207-048

An update fixes several vulnerabilities in the IBM Java 1.4.2 Runtime Environment and the IBM Java 1.4.2 Software Development Kit. Exploiting the vulnerabilities might lead to e.g. Denial-of-Service (DoS), unauthorized access or modification of arbitrary files. User interaction is necessary to exploit them.
The sudo (superuser do) utility allows system administrators to give certain users the ability to run commands as root. A flaw was found in the way the network matching code in sudo handles multiple IP networks listed in user specification configuration directives. A user who is authorized to run commands with sudo on specific hosts could use this flaw to bypass intended restrictions and run those commands on hosts not matched by any of the network specifications. An updated package addresses this issue.

System: Many
Topic: Vulnerabilities in IBM DB2
Links: IBM swg21600837, CVE-2012-0711, CVE-2012-2194, CVE-2012-2196, CVE-2012-2197, ESB-2012.0678
ID: ae-201207-047

Fix Pack 12 for DB2 V9.1 is now available which includes fixes for some security vulnerabilities. These fixes, where applicable, are also available in a Fix Pack for DB2 Version 9.5, a Fix Pack for DB2 Version 9.7, a Fix Pack for DB2 Version 9.8 and a Fix Pack for DB2 Version 10.1. IBM recommends to review the APAR descriptions and deploy one of the fix packs to correct them on affected DB2 installations.

System: Many
Topic: Vulnerabilities in libexif
Links: sourceforge #29534027, CVE-2012-2812, CVE-2012-2813, CVE-2012-2814, CVE-2012-2836, CVE-2012-2837, CVE-2012-2840, CVE-2012-2841, ASB-2012.0102,
MDVSA-2012:106
ID: ae-201207-046

A number of remotely exploitable issues were discovered in libexif and exif, with effects ranging from information leakage to potential remote code execution. Please check if version 0.6.21 is available for your system.

System: Mandriva Linux
Topic: Vulnerability in exif
Links: MDVSA-2012:107, CVE-2012-2845
ID: ae-201207-045

A vulnerability has been discovered and corrected in exif. An integer overflow in the function jpeg_data_load_data in the exif program could cause a data read beyond the end of a buffer, causing an application crash or leakage of potentially sensitive information when parsing a crafted JPEG file. Updated packages are available now.

System: VMware ESX
Topic: Multiple Vulnerabilities in Vmware ESXi
Links: VMSA-2012-0012, CVE-2010-4008, CVE-2010-4494, CVE-2011-0216, CVE-2011-1944, CVE-2011-2821, CVE-2011-2834, CVE-2011-3905, CVE-2011-3919, CVE-2012-0841, ESB-2012.0677
ID: ae-201207-044

A VMware ESXi update addresses several security issues. The libxml2 third party library has been updated which addresses multiple security issues. Exploiting them might lead to e.g. remote Denial-of-Service (DoS) or command execution. So this update is recommended.

System: Mandriva Linux
Topic: Vulnerability in Pidgin
Links: MDVSA-2012:105, CVE-2012-3374
ID: ae-201207-043

Pidgin is a multi protocol instant messaging client. A vulnerability might lead to a buffer oferflow. This can be exploited by an incoming message in the MXit protocol plugin. A remote attacker may cause a crash, and in some circumstances can lead to remote code execution. Updated packages are available now.

System: Several
Topic: Vulnerability in HP AssetManager
Links: HPSBGN02787 SSRT100876, CVE-2012-2021, ESB-2012.0676
ID: ae-201207-042

A potential security vulnerability has been identified with HP AssetManager. The vulnerabilities could be exploited remotely resulting in Cross-Site Scripting (XSS) or unauthorized data modification. HP has provided patch kits to solve this problem.

System: Debian GNU/Linux
Topic: Vulnerabilities in puppet and mono
Links: DSA-2511, CVE-2012-3864, CVE-2012-3865, CVE-2012-3866, CVE-2012-3867, ESB-2012.0673,
DSA-2512, CVE-2012-3882, ESB-2012.0674
ID: ae-201207-041

Several security vulnerabilities have been found in Puppet, a centralized configuration management. Authenticated clients could read or delete arbitrary files on the puppet master. Reports can be read and agent hostnames are insufficiently validated.
The web server included in Mono performs insufficient sanitising of requests, resulting in Cross-Site Scripting (XSS).
Updated packages are available now.

System: Several
Topic: Vulnerabilities in RSA Authentication Manager
Links: ESA-2012-023, CVE-2012-2278, CVE-2012-2279, CVE-2012-2280, ESB-2012.0675
ID: ae-201207-040

Patch 14 (P14) for RSA Authentication Manager 7.1 Service Pack 4 (SP4) and Appliance 3.0 SP4 contains fixes for multiple security vulnerabilities. Exploiting them might allow Cross-Site Scripting (XSS) attacks and could provide misleading information. So this patch is recommended.

System: Debian GNU/Linux
Topic: Vulnerability in eXtplorer
Links: DSA-2510, CVE-2012-3362, ESB-2012.0672
ID: ae-201207-039

A vulnerability in eXtplorer, a very feature rich web server file manager, can be exploited by malicious people to conduct cross-site request forgery (XSRF) attacks. Updated packages are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerability in JBoss Cache
Links: RHSA-2012-1072, CVE-2012-0034, ESB-2012.0671
ID: ae-201207-038

JBoss Cache is the clustering backbone for data distribution in JBoss Enterprise Web Platform. It was been detected that NonManagedConnectionFactory would log the username and password in plain text when an exception was thrown. This could lead to the exposure of authentication credentials if local users had permissions to read the log file. Updated packages are available now.

System: Appliance
Topic: Vulnerability in SMC Switches
Links: VU #377915, CVE-2012-2974
ID: ae-201207-037

The SMC8024L2 switch does not require authentication for the web interface configuration pages if they are visited with a direct URL. An unauthenticated attacker can retrieve all configuration pages from the web management GUI. So remote management of the switch is possible. The vendor has stated this product is end-of-life and not supported. So please protect these switches by appropriate rules in surrounding firewalls.

System: Mandriva Linux
Topic: Vulnerability in automake
Links: MDVSA-2012:103, CVE-2012-3386
ID: ae-201207-036

A race condition in automake could allow a local attacker to run arbitrary code with the privileges of the user running make distcheck. Updated packages are available now.

System: Cisco
Topic: Several vulnerabilities in Cisco Telepresence
Links: cisco-sa-20120711-ctsman, cisco-sa-20120711-ctms, cisco-sa-20120711-cts, cisco-sa-20120711-ctrs, CVE-2012-2486, CVE-2012-3073, CVE-2012-3074, CVE-2012-3075, CVE-2012-3076, ESB-2012.0670
ID: ae-201207-035

Several vulnerabilities have been found in Cisco TelePresence Manager, Cisco TelePresence Multipoint Switch, Cisco TelePresence Endpoint devices, and Cisco TelePresence Recording Server. Exploiting them might lead to remote Denial-of-Service (DoS) and remote code execution. Updates are available now.

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in OpenJPEG
Links: RHSA-2012-1068, CVE-2009-5030, CVE-2012-3358, ESB-2012.0669
ID: ae-201207-034

OpenJPEG is an open source library for reading and writing image files in JPEG 2000 format. An input validation flaw, leading to a heap-based buffer overflow, was found in the way OpenJPEG handles the tile number and size in an image tile header. OpenJPEG allocates also insufficient memory when encoding JPEG 2000 files from input images that have certain color depths. Both vulnerabilities might allow a remote attacker to execute arbitrary code on a vulnerable system if a user opens a crafted file. Updated packages are available now.

System: Several
Topic: Vulnerability in EMC Celerra/VNX/VNXe
Links: ESA-2012-027, CVE-2012-2282, ESB-2012.0668
ID: ae-201207-033

A vulnerability exists in EMC Celerra/VNX/VNXe systems. Under certain circumstances, NFS v2/3/4 clients with network access to exported file systems may be able to gain unauthorized access to files or directories in that file system due to access control issues. Updates address this issue.

System: Microsoft Windows
Topic: Vulnerabilities in Gadgets
Links: Microsoft #2719662, ESB-2012.0665
ID: ae-201207-032

No further comment due to legal reasons

System: Microsoft Windows
Topic: Problems with Digital Certificates
Links: Microsoft #2728973, ESB-2012.0664
ID: ae-201207-031

No further comment due to legal reasons

System: OSX
Topic: Vulnerability in Microsoft Office for Mac
Links: MS12-051, CVE-2012-1894, ESB-2012.0663
ID: ae-201207-030

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft SharePoint and Windows SharePoint Services
Links: MS12-050, CVE-2012-1858, CVE-2012-1859, CVE-2012-1860, CVE-2012-1861, CVE-2012-1862, CVE-2012-1863, ESB-2012.0662
ID: ae-201207-029

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in TLS
Links: MS12-049, CVE-2012-1870, ESB-2012.0661
ID: ae-201207-028

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Windows Shell
Links: MS12-048, CVE-2012-0175, ESB-2012.0660
ID: ae-201207-027

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Windows Kernel-Mode Drivers
Links: MS12-047, CVE-2012-1890, CVE-2012-1893, ESB-2012.0659
ID: ae-201207-026

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in MS Visual Basic for Applications
Links: MS12-046, CVE-2012-1854, ESB-2012.0658
ID: ae-201207-025

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft Data Access Components
Links: MS12-045, CVE-2012-1891, ESB-2012.0657
ID: ae-201207-024

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerabilities in Microsoft Internet Explorer 9
Links: MS12-044, CVE-2012-1522, CVE-2012-1524, ESB-2012.0656
ID: ae-201207-023

No further comment due to legal reasons

System: Microsoft Windows
Topic: Vulnerability in Microsoft XML Core Services
Links: MS12-043, CVE-2012-1889, ESB-2012.0655, X-Force Alert #451
ID: ae-201207-022

No further comment due to legal reasons

System: Red Hat Enterprise Linux
Topic: Vulnerabilities in kernel
Links: RHSA-2012-1061, RHSA-2012-1064, CVE-2012-2744, CVE-2012-2745, CVE-2012-3375, ESB-2012.0666, ESB-2012.0667
ID: ae-201207-021

The kernel packages contain the Linux kernel, the core of any Linux operating system. A NULL pointer dereference flaw has been found in working with netfilter IPv6 connection tracking. Besides this, a flaw in the kernel's key management and in the Event Poll Subsystem have been detected. All vulnerabilities can be exploited by local users to trigger a Denial-of-Service (DoS). Updated kernel packages are available now.

System: Appliance
Topic: Vulnerabilities in Avaya products
Links: Avaya 100164390, CVE-2012-2143, CVE-2012-2655, ESB-2012.0654
ID: ae-201207-020

Vulnerabilities have been found in PostgreSQL which is used in Avaya products. They affect DES and extended DES based cryptography and plugins. Updates are currently not available by Avaya. Please refer to the advisory to get further information about workarounds.

System: Several
Topic: Vulnerability in IBM WebSphere Portal
Links: X-Force #75584, CVE-2012-2181, ESB-2012.0653
ID: ae-201207-019

WebSphere Portal could allow a remote attacker to traverse directories on the system, caused by improper validation of user supplied input. By sending a specially-crafted URL request to the Dojo module an attacker could exploit this vulnerability to view arbitrary files on the system. A patch is available now.

System: Several
Topic: Vulnerabilities in HP Operations Agent
Links: HPSBMU02796 SSRT100594, CVE-2012-2019, CVE-2012-2020, ESB-2012.0652
ID: ae-201207-018

Potential security vulnerabilities have been identified with HP Operations Agent for AIX, HP-UX, Linux, Solaris, and Windows. The vulnerabilities could be remotely exploited resulting in the execution of arbitrary code. HP has made patches available to resolve these vulnerabilities.

System: Red Hat Enterprise Linux Server
Topic: Vulnerability in cobbler
Links: RHSA-2012-1060, CVE-2012-2395, ESB-2012.0651
ID: ae-201207-017

Cobbler is a network install server. A command injection flaw was found in Cobbler's power management XML-RPC method. A remote, authenticated user who is permitted to perform Cobbler configuration changes via the Cobbler XML-RPC API, could use this flaw to execute arbitrary code with root privileges on the Red Hat Network Satellite server. Updated packages are available now.

System: Debian GNU/Linux
Topic: Vulnerability in Pidgin
Links: DSA-2509, CVE-2012-3374, ESB-2012.0649
ID: ae-201207-016

Pidgin is a multi protocol instant messaging client. A vulnerability might lead to a buffer oferflow. This can be exploited by an incoming message in the MXit protocol plugin. A remote attacker may cause a crash, and in some circumstances can lead to remote code execution. Updated packages are available now.

System: Many
Topic: Vulnerabilities in Asterisk
Links: AST-2012-010, AST-2012-011, CVE-2012-3863, CVE-2012-3812, ESB-2012.0650, ESB-2012.0648
ID: ae-201207-015

Asterisk is a free PBX Software. If Asterisk sends a re-invite and an endpoint responds to the re-invite with a provisional response but never sends a final response, then the SIP dialog structure is never freed and the RTP ports for the call are never released. If an attacker has the ability to place a call, they could create a Denial-of-Service (DoS) by using all available RTP ports. Besides this, if a single voicemail account is manipulated by two parties simultaneously, a condition can occur where memory is freed twice causing a crash.
Upgrades solve these issues.

System: Red Hat Enterprise Linux
Topic: Vulnerability in resteasy
Links: RHSA-2012-1056, RHSA-2012-1057, RHSA-2012-1058, RHSA-2012-1059, CVE-2012-0818, ESB-2012.0645
ID: ae-201207-014

RESTEasy provides various frameworks to help you build RESTful web services and RESTful Java applications. It was found that RESTEasy is vulnerable to XML External Entity (XXE) attacks. An update for JBoss Enterprise Application Platform 5.1.2 fixes this security issue.

System: Microsoft Windows
Topic: Vulnerability in HP ProtectTools Enterprise Device Access Manager
Links: HPSBGN02750 SSRT100795, CVE-2011-4162, ESB-2012.0646
ID: ae-201207-013

A potential security vulnerability has been identified with HP ProtectTools Enterprise Device Access Manager (EDAM) running on Windows. The vulnerability can be remotely exploited to cause execution of arbitrary code or Denial-of-Service (DoS). HP has updated HP ProtectTools Enterprise Device Access Manager (EDAM) running on Windows to resolve the vulnerability.

System: Microsoft Windows
Topic: Vulnerabilities in Invensys Wonderware SuiteLink
Links: ICSA-12-171-01, CVE-2012-3007, CVE-2012-3847, ESB-2012.0644
ID: ae-201207-012

The Invensys Wonderware SuiteLink service (slssvc.exe) shows a vulnerability that causes a stack-based buffer overflow due to a maliciously crafted Unicode string. This can be exploited remotely. The consequence is a Denial-of-Service (DoS). Please check if the version used is vulnerable, information can be found in the advisory.

System: Several
Topic: Vulnerability in TYPO3
Links: TYPO3-CORE-SA-2012-003, ESB-2012.0643
ID: ae-201207-011

TYPO3 bundles and uses an external JavaScript and Flash Upload Library called swfupload. It can be configured to use this Flash uploader. Input passed via the "movieName" parameter to swfupload.swf isn't properly sanitised before being used. This can be exploited to execute arbitrary script code in a user's browser session in context of an affected site. This Cross-Site Scripting (XSS) vulnerability can be fixed by an upgrade.

System: Debian GNU/Linux
Topic: Vulnerabilities in openjdk-6
Links: DSA-2507, CVE-2012-1711, CVE-2012-1713, CVE-2012-1716, CVE-2012-1717, CVE-2012-1718, CVE-2012-1719, CVE-2012-1723, CVE-2012-1724, CVE-2012-1725, ESB-2012.0642
ID: ae-201207-010

Multiple vulnerabilities exist in Java for Debian Linux. They allow remote attackers unautorised access as well as remote code execution and to initiate a Denial-of-Service (DoS). Updated packages address these issues.

System: Red Hat Enterprise Linux
Topic: Vulnerability in JBoss Enterprise Platform
Links: RHSA-2012-1052, RHSA-2012-1053, CVE-2012-1154, ESB-2012.0640
ID: ae-201207-009

Updated mod_cluster packages that fix one security issue are now available for JBoss Enterprise Application Platform 5.1.2 for Red Hat Enterprise Linux 4, 5, and 6.

System: Many
Topic: Vulnerabilities in libtiff
Links: RHSA-2012-1054, MDVSA-2012:101, CVE-2012-2088, CVE-2012-2113
ID: ae-201207-008

Updated libtiff packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5 and 6 and Mandriva Enterprise Server.

System: HP-UX
Topic: Vulnerability in BIND
Links: emr_na-c03388901, CVE-2012-1667, ESB-2012.0639
ID: ae-201207-007

A potential security vulnerability has been identified with HP-UX running BIND. This vulnerability could be exploited remotely to create a Denial of Service (DoS). New update is available for download.

System: AIX
Topic: Vulnerability in IBM DB2
Links: swg21600160, ESB-2012.0637
ID: ae-201207-006

When using DB2 Version 9.7 Fix Pack 6, Memory is consumed quickly in the DB2 private memory when an application uses the db2readlog API to extract log records (common in replication solutions). This leads to a severe memory leak. New update is available for download.

System: Many
Topic: Vulnerabilities in HP Network Node Manager i
Links: emr_na-c03333585, emr_na-c03343724, CVE-2010-4015, CVE-2010-3433, CVE-2010-1975, CVE-2010-1170, CVE-2010-1169, CVE-2009-4136, CVE-2009-4034, CVE-2009-3231, CVE-2009-3230, CVE-2009-3229, CVE-2009-0922, CVE-2012-2018, ESB-2012.0636, ESB-2012.0638
ID: ae-201207-005

Potential security vulnerabilities have been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows running PostgreSQL. The vulnerabilities could be remotely exploited resulting in execution of arbitrary code and Denial of Service (DoS) and Cross-Site-Scripting (XSS). New update is available for download.

System: Many
Topic: Vulnerability in libapache-mod-security
Links: dsa-2506, CVE-2012-2751, ESB-2012.0635
ID: ae-201207-004

A vulnerability in ModSecurity, a security module for the Apache webserver, was discovered. In situations where both 'Content:Disposition: attachment' and 'Content-Type: multipart' were present in HTTP headers, the vulernability could allow an attacker to bypass policy and execute cross-site script (XSS) attacks through properly crafted HTML documents New packets are available for download.

System: Mandriva Enterprise Server
Topic: Vulnerabilities in python
Links: MDVSA-2012:096-1, CVE-2011-3389, CVE-2011-4940, CVE-2011-4944, CVE-2012-0845, CVE-2012-0876, CVE-2012-1150
ID: ae-201207-003

Multiple vulnerabilities have been discovered and corrected in python. These vulnerabilities may lead to Denial of Service (DoS), Cross-Site-Scripting (XSS) or may allow access of privileged data. New packets are available for download.

System: Microsoft Windows/Linux
Topic: Vulnerabilities in IBM Support Assistant
Links: swg21599620, CVE-2012-0191, CVE-2012-0187, CVE-2012-0186, CVE-2010-4647, CVE-2008-7271, ESB-2012.0634
ID: ae-201207-002

IBM has identified a total of four vulnerabilities in IBM Support Assistant. All four vulnerabilities are resolved by the IBM Support Assistant 4.1.3 fixpack.

System: Many
Topic: Vulnerability in zendframework
Links: dsa-2505, CVE-2012-3363, ESB-2012.0633
ID: ae-201207-001

A file disclosure flaw was found in the way SimpleXMLElement class of Zend Framework, a PHP framework, processed XML data provided within certain XML-RPC requests. A remote attacker could use this flaw to obtain sensitive information by issuing a specially-crafted XML-RPC request to the Zend Framework based PHP application. New packets are available for update purposes.



(c) 2000-2013 AERAsec Network Services and Security GmbH