Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesSolaris 10 (sparc) : 137111-01- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 137111-01(SunOS 5.10: kernel patch).Date this patch was last updated by Sun : Mon Jun 23 10:39:27 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/33206 Solaris 10 (sparc) : 136892-01- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 136892-01(SunOS 5.10: libc.so.1.9 patch).Date this patch was last updated by Sun : Fri Jun 06 08:56:23 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/33205 SuSE Security Update: Security update for libxslt (libxslt-5343)- (Found June 29, 2008 ) Critical Risk -- A libxslt XSL-match processing overflow has been fixed.CVE-2008-1767 has been assigned to this issue.http://www.edgeos.com/threats/33196 USN612-10 : OpenVPN regression- (Found June 29, 2008 ) Critical Risk -- USN-612-3 addressed a weakness in OpenSSL certificate and keygeneration in OpenVPN by adding checks for vulnerable certificatesand keys to OpenVPN. A regression was introduced in OpenVPN whenusing TLS with password protected certificates which caused OpenVPNto not start when used with applications such as NetworkManager.Original advisory details: A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this...http://www.edgeos.com/threats/33197 USN612-9 : openssl-blacklist update- (Found June 29, 2008 ) Critical Risk -- USN-612-3 addressed a weakness in OpenSSL certificate and keygeneration in OpenVPN by introducing openssl-blacklist to aid indetecting vulnerable private keys. This update enhances theopenssl-vulnkey tool to check Certificate Signing Requests, acceptinput from STDIN, and check moduli without a certificate.It was also discovered that additional moduli are vulnerable ifgenerated with OpenSSL 0.9.8g or higher. While it is believed thatthere are few of these vulnerable moduli in...http://www.edgeos.com/threats/33198 USN616-1 : X.org vulnerabilities- (Found June 29, 2008 ) Critical Risk -- Multiple flaws were found in the RENDER, RECORD, and Securityextensions of X.org which did not correctly validate function arguments.An authenticated attacker could send specially crafted requests and gainroot privileges or crash X. (CVE-2008-1377, CVE-2008-2360, CVE-2008-2361,CVE-2008-2362)It was discovered that the MIT-SHM extension of X.org did not correctlyvalidate the location of memory during an image copy. An authenticatedattacker could exploit this to read arbitrary...http://www.edgeos.com/threats/33199 LISa Detection- (Found June 29, 2008 ) Low Risk -- The remote service is a LISa server (LAN Information Server), whichprovides a list of nearby hosts, like a 'network neighborhood', butbased solely on TCPIP.http://www.edgeos.com/threats/33200 GLSA-200806-05 cbrPager: User-assisted execution of arbitrary code- (Found June 29, 2008 ) High Risk -- The remote host is affected by the vulnerability described in GLSA-200806-05(cbrPager: User-assisted execution of arbitrary code) Mamoru Tasaka discovered that filenames of the image archives are not properly sanitized before being passed to decompression utilities like unrar and unzip, which use the system() libc library call. Impact A remote attacker could entice a user to open an archive with a specially crafted filename, resulting in arbitrary code execution...http://www.edgeos.com/threats/33202 GLSA-200806-06 Evolution: User-assisted execution of arbitrary code- (Found June 29, 2008 ) High Risk -- The remote host is affected by the vulnerability described in GLSA-200806-06(Evolution: User-assisted execution of arbitrary code) Alin Rad Pop (Secunia Research) reported two vulnerabilities in Evolution: A boundary error exists when parsing overly long timezone strings contained within iCalendar attachments and when the ITip formatter is disabled (CVE-2008-1108). A boundary error exists when replying to an iCalendar request with an overly long...http://www.edgeos.com/threats/33203 Solaris 10 (sparc) : 121657-28- (Found June 29, 2008 ) Critical Risk -- The remote host is missing Sun Security Patch number 121657-28(Calendar Server SunOS 5.9 5.10: Core patch).Date this patch was last updated by Sun : Mon Jun 09 08:50:17 MDT 2008You should install this patch for your system to be up-to-date.http://www.edgeos.com/threats/33204 |