Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesFreeBSD : ikiwiki -- cleartext passwords (1129)- (Found June 29, 2008 ) Medium Risk -- The remote host is missing an update to the systemThe following package is affected: ikiwikihttp://www.edgeos.com/threats/32489 FreeBSD : ikiwiki -- empty password security hole (1128)- (Found June 29, 2008 ) Medium Risk -- The remote host is missing an update to the systemThe following package is affected: ikiwikihttp://www.edgeos.com/threats/32488 FreeBSD : linux-flashplugin -- unspecified remote code execution vulnerability (1127)- (Found June 29, 2008 ) Medium Risk -- The remote host is missing an update to the systemThe following package is affected: linux-flashpluginhttp://www.edgeos.com/threats/32487 Fedora Core 7 2008-4797: samba- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4797 (samba).Samba is the suite of programs by which a lot of PC-related machinesshare files, printers, and other information (such as lists ofavailable files and printers). The Windows NT, OS2, and Linuxoperating systems support this natively, and add-on packages canenable the same thing for DOS, Windows, VMS, UNIX of all kinds, MVS,and more. This package provides an SMBCIFS server that can be used toprovide...http://www.edgeos.com/threats/32486 Fedora Core 9 2008-4723: openssl- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4723 (openssl).The OpenSSL toolkit provides support for secure communications betweenmachines. OpenSSL includes a certificate management tool and sharedlibraries which provide various cryptographic algorithms andprotocols.-Update Information:Fixes moderate impact security issue CVE-2008-0891 and low impact security issueCVE-2008-1672. See also 9http:www.openssl.orgnewssecadv_20080528.txtAll applications and...http://www.edgeos.com/threats/32484 Fedora Core 8 2008-4679: samba- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4679 (samba).Samba is the suite of programs by which a lot of PC-related machinesshare files, printers, and other information (such as lists ofavailable files and printers). The Windows NT, OS2, and Linuxoperating systems support this natively, and add-on packages canenable the same thing for DOS, Windows, VMS, UNIX of all kinds, MVS,and more. This package provides an SMBCIFS server that can be used toprovide...http://www.edgeos.com/threats/32483 DSA1590 DSA-1590-1 samba- (Found June 29, 2008 ) Critical Risk -- Alin Rad Pop discovered that Samba contained a buffer overflow conditionwhen processing certain responses received while acting as a client,leading to arbitrary code execution (CVE-2008-1105).For the stable distribution (etch), this problem has been fixed in version 3.0.24-6etch10.http://www.edgeos.com/threats/32482 Now SMSMMS Gateway < 2008.02.22 Buffer Overflow Vulnerabilities- (Found June 29, 2008 ) Urgent Risk -- The remote host is running Now SMSMMS Gateway, a tool for connectingto SMS andor MMS messaging providers and managing GSM modems. The web interface component of the version of Now SMSMMS Gatewayinstalled on the remote host contains a stack-based buffer overflowthat can be triggered using a specially-crafted HTTP Authorizationrequest header. An unauthenticated remote attacker can leverage thisissue to crash the affected service or to execute arbitrary code onthe affected host...http://www.edgeos.com/threats/32481 Solaris 10 (sparc) : 136839-01- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 136839-01(Service Tags).Date this patch was last updated by Sun : Tue May 20 08:22:54 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/32494 Solaris 10 (sparc) : 137017-02- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 137017-02(SunOS 5.10: crontab patch).Date this patch was last updated by Sun : Fri May 30 08:34:31 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/32495 |