Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesFedora Core 8 2008-4604: kvm- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4604 (kvm).KVM (for Kernel-based Virtual Machine) is a full virtualization solutionfor Linux on x86 hardware.Using KVM, one can run multiple virtual machines running unmodified Linuxor Windows images. Each virtual machine has private virtualized hardware:a network card, disk, graphics adapter, etc.-ChangeLog:Update information : Tue May 27 2008 Glauber Costa <gcosta redhat com> - 60-6.fc8- Fix Cirrus heap...http://www.edgeos.com/threats/32467 Fedora Core 8 2008-4579: stunnel- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4579 (stunnel).Stunnel is a socket wrapper which can provide SSL (Secure SocketsLayer) support to ordinary applications. For example, it can be usedin conjunction with imapd to create an SSL secure IMAP server.-Update Information:New upstream release 4.24 fixing security issue in certificate verification viaOCSP protocol: 9http:stunnel.mirt.netpipermailstunnel-announce2008-May000035.htmlhttp://www.edgeos.com/threats/32466 AIX 610000 : U812695- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U812695 which is relatedto the security of the package bos.diag.rteYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32548 Creative Software AutoUpdate Engine ActiveX Control Buffer Overflow Vulnerability- (Found June 29, 2008 ) Critical Risk -- The remote host contains the Creative Software AutoUpdate EngineActiveX control, which is used to automatically update Creative Labssoftware. The version of this control installed on the remote host reportedlycontains an unspecified stack buffer overflow. If an attacker cantrick a user on the affected host into viewing a specially-craftedHTML document, he may be able to use this method to execute arbitrarycode on the affected system subject to the user's privileges.http://www.edgeos.com/threats/32442 AIX 610000 : U813258- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U813258 which is relatedto the security of the package bos.net.tcp.serverYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32552 AIX 610000 : U813257- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U813257 which is relatedto the security of the package bos.net.tcp.smitYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32551 AIX 610000 : U813256- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U813256 which is relatedto the security of the package bos.diag.comYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32550 AIX 610000 : U813255- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U813255 which is relatedto the security of the package bos.64bitYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32549 AIX 610000 : U812694- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U812694 which is relatedto the security of the package bos.rte.shellYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32547 AIX 610000 : U812693- (Found June 29, 2008 ) Critical Risk -- The remote host is missing AIX PTF U812693 which is relatedto the security of the package bos.adt.sccsYou should install this PTF for your system to be up-to-date.http://www.edgeos.com/threats/32546 |