Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesSuSE Security Update: gnome-screensaver security update (gnome-screensaver-5175)- (Found June 29, 2008 ) Critical Risk -- An attacker could log in without a valid password if theNIS server is down. (CVE-2008-0887)http://www.edgeos.com/threats/33215 SuSE Security Update: sudo: clearing stin buffer on timeout (sudo-5349)- (Found June 29, 2008 ) Critical Risk -- This update of sudo flushs the stdin buffer on passwordtimeout. Unflushed buffers can lead to leaking thepassword via a parent process reading stdin after sudoexits.http://www.edgeos.com/threats/33216 USN617-1 : Samba vulnerabilities- (Found June 29, 2008 ) Critical Risk -- Samba developers discovered that nmbd could be made to overruna buffer during the processing of GETDC logon server requests.When samba is configured as a Primary or Backup Domain Controller,a remote attacker could send malicious logon requests and possiblycause a denial of service. (CVE-2007-4572)Alin Rad Pop of Secunia Research discovered that Samba did notproperly perform bounds checking when parsing SMB replies. A remoteattacker could send crafted SMB packets and execute...http://www.edgeos.com/threats/33217 Owner Free File System Client Detection- (Found June 29, 2008 ) Low Risk -- The remote web server is an OFFSystem client. OFFSystem (Owner-FreeFilesystem) is a distributed filesystem for peer-to-peer file sharingin which files are stored as randomized data blockshttp://www.edgeos.com/threats/33228 DSA1598 DSA-1598-1 libtk-img- (Found June 29, 2008 ) Critical Risk -- It was discovered that a buffer overflow in the GIF image parsing codeof Tk, a cross-platform graphical toolkit, could lead to denial ofservice and potentially the execution of arbitrary code.For the stable distribution (etch), this problem has been fixed in version1:1.3-15etch2.http://www.edgeos.com/threats/33230 GLSA-200806-07 X.Org X server: Multiple vulnerabilities- (Found June 29, 2008 ) Critical Risk -- The remote host is affected by the vulnerability described in GLSA-200806-07(X.Org X server: Multiple vulnerabilities) Regenrecht reported multiple vulnerabilities in various X server extensions via iDefense: The SProcSecurityGenerateAuthorization() and SProcRecordCreateContext() functions of the RECORD and Security extensions are lacking proper parameter validation (CVE-2008-1377). An integer overflow is possible in the function ShmPutImage() of the...http://www.edgeos.com/threats/33243 GLSA-200806-08 OpenSSL: Denial of Service- (Found June 29, 2008 ) High Risk -- The remote host is affected by the vulnerability described in GLSA-200806-08(OpenSSL: Denial of Service) Ossi Herrala and Jukka Taimisto of Codenomicon discovered two vulnerabilities: A double free() call in the TLS server name extension (CVE-2008-0891). The OpenSSL client code does not properly handle servers that omit the Server Key Exchange message in the TLS handshake (CVE-2008-1672). Impact A remote attacker could connect to a vulnerable server, or entice a .http://www.edgeos.com/threats/33244 GLSA-200806-09 libvorbis: Multiple vulnerabilities- (Found June 29, 2008 ) High Risk -- The remote host is affected by the vulnerability described in GLSA-200806-09(libvorbis: Multiple vulnerabilities) Will Drewry of the Google Security Team reported multiple vulnerabilities in libvorbis: A zero value for "codebook.dim" is not properly handled, leading to a crash, infinite loop or triggering an integer overflow (CVE-2008-1419). An integer overflow in "residue partition value" evaluation might lead to a heap-based buffer...http://www.edgeos.com/threats/33245 GLSA-200806-10 FreeType: User-assisted execution of arbitrary code- (Found June 29, 2008 ) High Risk -- The remote host is affected by the vulnerability described in GLSA-200806-10(FreeType: User-assisted execution of arbitrary code) Regenrecht reported multiple vulnerabilities in FreeType via iDefense: An integer overflow when parsing values in the Private dictionary table in a PFB file, leading to a heap-based buffer overflow (CVE-2008-1806). An invalid free() call related to parsing an invalid "number of axes" field in a PFB file (CVE-2008-1807). ...http://www.edgeos.com/threats/33246 USN612-11 : openssl-blacklist update- (Found June 29, 2008 ) Critical Risk -- USN-612-3 addressed a weakness in OpenSSL certificate and keygeneration and introduced openssl-blacklist to aid in detectingvulnerable certificates and keys. This update adds RSA-4096blacklists to the openssl-blacklist-extra package and adjustsopenssl-vulnkey to properly handle RSA-4096 and higher moduli.Original advisory details: A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain...http://www.edgeos.com/threats/33254 |