Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesSuSE Security Update: evolution: fixed CVE-2008-1108 and CVE-2008-1109 (evolution-5326)- (Found June 29, 2008 ) Critical Risk -- Multiple buffer overflows have been fixed in evolution.CVE-2008-1108 and CVE-2008-1109 have been assigned to thisissue.http://www.edgeos.com/threats/33193 SuSE Security Update: Security update for evolution (evolution-5327)- (Found June 29, 2008 ) Critical Risk -- Multiple buffer overflows have been fixed in evolution.CVE-2008-1108 and CVE-2008-1109 have been assigned to thisissue.http://www.edgeos.com/threats/33194 Fedora Core 8 2008-5342: roundcubemail- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5342 (roundcubemail).RoundCube Webmail is a browser-based multilingual IMAP clientwith an application-like user interface. It provides fullfunctionality you expect from an e-mail client, including MIMEsupport, address book, folder manipulation, message searchingand spell checking. RoundCube Webmail is written in PHP andrequires the MySQL database or the PostgreSQL database. The userinterface is fully skinnable...http://www.edgeos.com/threats/33185 Fedora Core 9 2008-5333: roundcubemail- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5333 (roundcubemail).RoundCube Webmail is a browser-based multilingual IMAP clientwith an application-like user interface. It provides fullfunctionality you expect from an e-mail client, including MIMEsupport, address book, folder manipulation, message searchingand spell checking. RoundCube Webmail is written in PHP andrequires the MySQL database or the PostgreSQL database. The userinterface is fully skinnable...http://www.edgeos.com/threats/33184 DSA1595 DSA-1595-1 xorg-server- (Found June 29, 2008 ) Critical Risk -- Several local vulnerabilities have been discovered in the X Window system.The Common Vulnerabilities and Exposures project identifies the followingproblems: Lack of validation of the parameters of the SProcSecurityGenerateAuthorization and SProcRecordCreateContext functions makes it possible for a specially crafted request to trigger the swapping of bytes outside the parameter of these requests, causing memory corruption. An integer overflow in the validation..http://www.edgeos.com/threats/33176 DSA1596 DSA-1596-1 typo3- (Found June 29, 2008 ) Critical Risk -- Several remote vulnerabilities have been discovered in the TYPO3 contentmanagement framework.Because of a not sufficiently secure default value of the TYPO3configuration variable fileDenyPattern, authenticated backend userscould upload files that allowed to execute arbitrary code as thewebserver user.User input processed by fe_adminlib.inc is not being properly filteredto prevent Cross Site Scripting (XSS) attacks, which is exposed whenspecific plugins are in use.For the stable.http://www.edgeos.com/threats/33177 DSA1597 DSA-1597-1 mt-daapd- (Found June 29, 2008 ) Critical Risk -- Three vulnerabilities have been discovered in the mt-daapd DAAP audioserver (also known as the Firefly Media Server). The CommonVulnerabilities and Exposures project identifies the following threeproblems: Insufficient validation and bounds checking of the Authorization: HTTP header enables a heap buffer overflow, potentially enabling the execution of arbitrary code. Format string vulnerabilities in debug logging within the authentication of XML-RPC requests...http://www.edgeos.com/threats/33178 Fedora Core 9 2008-5254: xorg-x11-server- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5254 (xorg-x11-server).X.Org X11 X server-Update Information:For further details, see X.org security advisory:9http:lists.freedesktop.orgarchivesxorg2008-June036026.htmlhttp://www.edgeos.com/threats/33179 Fedora Core 8 2008-5279: xorg-x11-server- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5279 (xorg-x11-server).X.Org X11 X server-Update Information:For further details, see X.org security advisory:9http:lists.freedesktop.orgarchivesxorg2008-June036026.htmlhttp://www.edgeos.com/threats/33180 Fedora Core 7 2008-5285: xorg-x11-server- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5285 (xorg-x11-server).X.Org X11 X server-Update Information:For further details, see X.org security advisory:9http:lists.freedesktop.orgarchivesxorg2008-June036026.htmlhttp://www.edgeos.com/threats/33181 |