Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesSuSE Security Update: pan security update (pan-5325)- (Found June 29, 2008 ) Critical Risk -- Specially crafted nzb files could trigger a heap basedbuffer overflow that could potentially be exploited toexecute arbitrary code (CVE-2008-2363).http://www.edgeos.com/threats/33162 DSA1593 DSA-1593-1 tomcat5.5- (Found June 29, 2008 ) Critical Risk -- It was discovered that the Host Manager web application performedinsufficient input sanitising, which could lead to cross-site scripting.For the stable distribution (etch), this problem has been fixed inversion 5.5.20-2etch3.http://www.edgeos.com/threats/33174 DSA1594 DSA-1594-1 imlib2- (Found June 29, 2008 ) Critical Risk -- Stefan Cornelius discovered two buffer overflows in Imlib's - a powerfulimage loading and rendering library - image loaders for PNM and XPMimages, which may result in the execution of arbitrary code.For the stable distribution (etch), this problem has been fixed inversion 1.3.0.0debian1-4+etch1.http://www.edgeos.com/threats/33175 FreeBSD : Courier Authentication Library -- SQL Injection (1130)- (Found June 29, 2008 ) Medium Risk -- The remote host is missing an update to the systemThe following package is affected: courier-authlibhttp://www.edgeos.com/threats/33186 FreeBSD : xorg -- multiple vulnerabilities (1132)- (Found June 29, 2008 ) Medium Risk -- The remote host is missing an update to the systemThe following package is affected: xorg-serverhttp://www.edgeos.com/threats/33187 FreeBSD : moinmoin -- superuser privilege escalation (1131)- (Found June 29, 2008 ) Medium Risk -- The remote host is missing an update to the systemThe following package is affected: moinmoinhttp://www.edgeos.com/threats/33188 GLSA-200806-04 rdesktop: Multiple vulnerabilities- (Found June 29, 2008 ) High Risk -- The remote host is affected by the vulnerability described in GLSA-200806-04(rdesktop: Multiple vulnerabilities) An anonymous researcher reported multiple vulnerabilities in rdesktop via iDefense Labs: An integer underflow error exists in the function iso_recv_msg() in the file iso.c which can be triggered via a specially crafted RDP request, causing a heap-based buffer overflow (CVE-2008-1801). An input validation error exists in the function...http://www.edgeos.com/threats/33189 HP-UX Security patch : PHSS_38009- (Found June 29, 2008 ) Critical Risk -- The remote host is missing HP-UX Security Patch number PHSS_38009 .(X OV NNM8.01 NNM 8.0x Patch 8.02.001)http://www.edgeos.com/threats/33190 RHSA-2008-0537: openoffice.org- (Found June 29, 2008 ) Critical Risk -- Updated openoffice.org packages to correct a security issue are now available for Red Hat Enterprise Linux 4 and Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team. OpenOffice.org is an office productivity suite that includes desktop applications such as a word processor, spreadsheet, presentation manager, formula editor, and drawing program. Sean Larsson found a heap overflow flaw in the...http://www.edgeos.com/threats/33191 RHSA-2008-0538: openoffice.org- (Found June 29, 2008 ) Critical Risk -- Updated openoffice.org packages to correct two security issues are now available for Red Hat Enterprise Linux 3 and 4. This update has been rated as having important security impact by the Red Hat Security Response Team. OpenOffice.org is an office productivity suite that includes desktop applications such as a word processor, spreadsheet, presentation manager, formula editor, and drawing program. Sean Larsson found a heap overflow flaw in the OpenOffice memory...http://www.edgeos.com/threats/33192 |