Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesSuSE Security Update: mozilla-xulrunner181: Update to 1.8.1.14 (epiphany-5293)- (Found June 29, 2008 ) Critical Risk -- mozilla-xulrunner181 was updated to version 1.8.1.14,fixing various bugs including 1 security bug:+ MFSA 2008-20CVE-2008-1380: Crash in JavaScript garbage collectorhttp://www.edgeos.com/threats/33121 Fedora Core 9 2008-4990: evolution- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-4990 (evolution).Evolution is the GNOME mailer, calendar, contact manager andcommunications tool. The components which make up Evolutionare tightly integrated with one another and act as a seamlesspersonal information-management tool.-Update Information:Fix two buffer overflows in iCalendar .ics file fromat support discovered andreported by Alin Rad Pop of the Secunia Research: CVE-2008-1108,...http://www.edgeos.com/threats/33113 Fedora Core 8 2008-5001: snort- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5001 (snort).Snort is a libpcap-based packet snifferlogger whichcan be used as a lightweight network intrusion detection system.It features rules based logging and can perform protocol analysis,content searchingmatching and can be used to detect a variety ofattacks and probes, such as buffer overflows, stealth port scans,CGI attacks, SMB probes, OS fingerprinting attempts, and much more.Snort has a real-time...http://www.edgeos.com/threats/33114 Fedora Core 8 2008-5016: evolution- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5016 (evolution).Evolution is the GNOME mailer, calendar, contact manager andcommunications tool. The tools which make up Evolution willbe tightly integrated with one another and act as a seamlesspersonal information-management tool.-Update Information:Fix two buffer overflows in iCalendar .ics file fromat support discovered andreported by Alin Rad Pop of the Secunia Research: CVE-2008-1108,...http://www.edgeos.com/threats/33115 Fedora Core 7 2008-5018: evolution- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5018 (evolution).Evolution is the GNOME mailer, calendar, contact manager andcommunications tool. The tools which make up Evolution willbe tightly integrated with one another and act as a seamlesspersonal information-management tool.-Update Information:Fix two buffer overflows in iCalendar .ics file fromat support discovered andreported by Alin Rad Pop of the Secunia Research: CVE-2008-1108,...http://www.edgeos.com/threats/33116 Fedora Core 7 2008-5045: snort- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5045 (snort).Snort is a libpcap-based packet snifferlogger whichcan be used as a lightweight network intrusion detection system.It features rules based logging and can perform protocol analysis,content searchingmatching and can be used to detect a variety ofattacks and probes, such as buffer overflows, stealth port scans,CGI attacks, SMB probes, OS fingerprinting attempts, and much more.Snort has a real-time...http://www.edgeos.com/threats/33117 GLSA-200806-03 Imlib 2: User-assisted execution of arbitrary code- (Found June 29, 2008 ) High Risk -- The remote host is affected by the vulnerability described in GLSA-200806-03(Imlib 2: User-assisted execution of arbitrary code) Stefan Cornelius (Secunia Research) reported two boundary errors in Imlib2: One of them within the load() function in the file srcmodulesloadersloader_pnm.c when processing the header of a PNM image file, possibly leading to a stack-based buffer overflow. The second one within the load() function in the file srcmodulesloader_xpm.c...http://www.edgeos.com/threats/33118 SuSE Security Update: MozillaThunderbird: Update to 2.0.0.14 (MozillaThunderbird-5280)- (Found June 29, 2008 ) Critical Risk -- MozillaThunderbird was updated to version 2.0.0.14, fixingvarious bugs including 1 security bug:+ MFSA 2008-20CVE-2008-1380: Crash in JavaScript garbage collectorJavascript is not default enabled in our Thunderbird buildsthough.http://www.edgeos.com/threats/33119 SuSE Security Update: MozillaThunderbird: Security fixes (MozillaThunderbird-5329)- (Found June 29, 2008 ) Critical Risk -- Various MozillaThunderbird fixes were backported to the10.2 version (1.5.0.x).+ MFSA 2008-15CVE-2008-1236 and CVE-2008-1237: Crashes with evidence of memory corruption (rv:1.8.1.13)+ MFSA 2008-14CVE-2008-1233, CVE-2008-1234, and CVE-2008-1235: JavaScript privilege escalation and arbitrary code execution.Javascript is not default enabled in our Thunderbird buildsthough.http://www.edgeos.com/threats/33120 Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (951376)- (Found June 29, 2008 ) Critical Risk -- The remote host contains a version of the Windows Bluetooth stack which is vulnerable to a security flaw in the service description request handle which may allow a remote attacker to execute code with SYSTEM privileges.http:www.microsoft.comtechnetsecuritybulletinms08-030.mspxhttp://www.edgeos.com/threats/33132 |