Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesCentOS : RHSA-2008-0288- (Found June 29, 2008 ) Critical Risk -- The remote CentOS system is missing a security update which has been documented in Red Hat advisory RHSA-2008-0288. yum updatehttp://www.edgeos.com/threats/32456 SuSE Security Update: opensuse-updater: Fix for memory and symlink problem(s) (opensuse-updater-5262)- (Found June 29, 2008 ) Critical Risk -- This update fixes a symlink problem and two off-by-onevulnerabilities. The overflows can be considered nosecurity problem but the symlink flaw could be used bylocal users to gain unauthorized access to information(like passwords).http://www.edgeos.com/threats/32454 HP-UX Security patch : PHCO_37291- (Found June 29, 2008 ) Critical Risk -- The remote host is missing HP-UX Security Patch number PHCO_37291 .(ugm cumulative patch)http://www.edgeos.com/threats/32453 HP-UX Security patch : PHCO_37290- (Found June 29, 2008 ) Critical Risk -- The remote host is missing HP-UX Security Patch number PHCO_37290 .(ugm cumulative patch)http://www.edgeos.com/threats/32452 HP-UX Security patch : PHCO_36953- (Found June 29, 2008 ) Critical Risk -- The remote host is missing HP-UX Security Patch number PHCO_36953 .(11.31 ugm cumulative patch)http://www.edgeos.com/threats/32451 FreeBSD : spamdyke -- open relay (1125)- (Found June 29, 2008 ) Medium Risk -- The remote host is missing an update to the systemThe following package is affected: spamdykehttp://www.edgeos.com/threats/32449 ThinkVantage System Update < 3.14 SSL Certificate Issuer Spoofing Vulnerability- (Found June 29, 2008 ) Critical Risk -- The remote host is running ThinkVantage System Update, a softwaredistribution tool for Lenovo computers. The version of System Update installed on the remote host reportedlydoes not perform certificate chain verification when initiating an SSLconnection with an update server. An attacker who could redirectconnections to a malicious server could leverage this issue to sendspecially-crafted XML and EXE files in response to requests fromSystem Update, which would then lead to...http://www.edgeos.com/threats/32443 Fedora Core 9 2008-4501: cbrpager- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4501 (cbrpager).A no-nonsense, simple to use, small viewer for cbr and cbz(comic book archive) files. As it is written in C,the executable is small and fast. It views jpg (or jpeg),gif and png images, and you can zoom in and out.-Update Information:New version 0.9.17 is released:9http:sourceforge.netforumforum.phpforum_id=827120http://www.edgeos.com/threats/32463 Fedora Core 8 2008-4528: cbrpager- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4528 (cbrpager).A no-nonsense, simple to use, small viewer for cbr and cbz(comic book archive) files. As it is written in C,the executable is small and fast. It views jpg (or jpeg),gif and png images, and you can zoom in and out.-Update Information:New version 0.9.17 is released:9http:sourceforge.netforumforum.phpforum_id=827120http://www.edgeos.com/threats/32464 Fedora Core 9 2008-4531: stunnel- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4531 (stunnel).Stunnel is a socket wrapper which can provide SSL (Secure SocketsLayer) support to ordinary applications. For example, it can be usedin conjunction with imapd to create an SSL secure IMAP server.-Update Information:New upstream release 4.24 fixing security issue in certificate verification viaOCSP protocol: 9http:stunnel.mirt.netpipermailstunnel-announce2008-May000035.htmlhttp://www.edgeos.com/threats/32465 |