Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesAltiris Notification Server Agent GUI Local Privilege Escalation Vulnerability (KB 39159)- (Found June 29, 2008 ) Critical Risk -- Altiris Notification Server Agent, also known as Altiris Agent, isinstalled on the remote host, allowing it to be managed by an AltirisNotification Server. The installed version of the Altiris Agent is reportedly vulnerable toan as-yet unspecified shatter attack involving its GUI that can allowlocal users to escalate their privileges.http://www.edgeos.com/threats/33225 Vulnerability in Active Directory Could Allow Denial of Service (953235)- (Found June 29, 2008 ) High Risk -- The remote version of Active Directory contains a denial of servicevulnerability when processing LDAP requests.An attacker may exploit this flaw to crash the remote Active Directory server.http:www.microsoft.comtechnetsecuritybulletinms08-035.mspxhttp://www.edgeos.com/threats/33138 RHSA-2008-0512: XFree- (Found June 29, 2008 ) Critical Risk -- Updated XFree86 packages that fix several security issues are now available for Red Hat Enterprise Linux 2.1. This update has been rated as having important security impact by the Red Hat Security Response Team. XFree86 is an implementation of the X Window System, which provides the core functionality for the Linux graphical desktop. An input validation flaw was discovered in X.org's Security and Record extensions. A malicious authorized client could exploit this issue...http://www.edgeos.com/threats/33154 SuSE Security Update: Multiple Xorg vulnerabilities reported by iDefense (xorg-x11-Xvnc-5317)- (Found June 29, 2008 ) Critical Risk -- This update fixes multiple vulnerabilities reported byiDefense:- CVE-2008-2360 - RENDER Extension heap buffer overflow- CVE-2008-2361 - RENDER Extension crash- CVE-2008-2362 - RENDER Extension memory corruption - CVE-2008-1379 - MIT-SHM arbitrary memory read- CVE-2008-1377 - RECORD and Security extensions memory corruption Additionally fixes for:- XvReputImage crashes due to Nulled PortPriv->pDraw- gnome-screensaver loses keyboard focus lock under compiz (CVE-2007-3920)http://www.edgeos.com/threats/33165 SuSE Security Update: Multiple Xorg vulnerabilities reported by iDefense (xorg-x11-server-5316)- (Found June 29, 2008 ) Critical Risk -- This update fixes multiple vulnerabilities reported byiDefense:- CVE-2008-2360 - RENDER Extension heap buffer overflow- CVE-2008-2361 - RENDER Extension crash- CVE-2008-2362 - RENDER Extension memory corruption - CVE-2008-1379 - MIT-SHM arbitrary memory read- CVE-2008-1377 - RECORD and Security extensions memory corruption Additionally fixes for:- gnome-screensaver loses keyboard focus lock under compiz (CVE-2007-3920)http://www.edgeos.com/threats/33166 Xerox XRX08-006- (Found June 29, 2008 ) Urgent Risk -- According to its model number and software versions, the remote hostis a Xerox WorkCentre device that reportedly contains a unspecifiedvulnerability affecting the Extensible Interface Platform feature inthe products Web Services. A remote attacker may be able to leveragethis issue to make changes to the system configuration.http://www.edgeos.com/threats/33167 Opera < 9.50 Multiple Vulnerabilities- (Found June 29, 2008 ) High Risk -- The version of Opera installed on the remote host reportedly isaffected by several issues : - Improper handling of special characters in page addresses can make addresses look like other ones, aiding in phishing attacks. - Specially-crafted HTML canvas elements could violate the same-origin image policy. - Framed sources contained on the same parent page can modify each other's location.http://www.edgeos.com/threats/33168 CentOS : RHSA-2008-0502- (Found June 29, 2008 ) Critical Risk -- The remote CentOS system is missing a security update which has been documented in Red Hat advisory RHSA-2008-0502. yum updatehttp://www.edgeos.com/threats/33170 CentOS : RHSA-2008-0522- (Found June 29, 2008 ) Critical Risk -- The remote CentOS system is missing a security update which has been documented in Red Hat advisory RHSA-2008-0522. yum updatehttp://www.edgeos.com/threats/33171 CentOS : RHSA-2008-0538- (Found June 29, 2008 ) Critical Risk -- The remote CentOS system is missing a security update which has been documented in Red Hat advisory RHSA-2008-0538. yum updatehttp://www.edgeos.com/threats/33172 |