Edgeos - New VulnerabilitiesEdgeos - Private-Labeled Vulnerability Assessment ServicesUSN618-1 : Linux kernel vulnerabilities- (Found June 29, 2008 ) Critical Risk -- It was discovered that the ALSA proc interface did not write thecorrect number of bytes when reporting memory allocations. A localattacker might be able to access sensitive kernel memory, leading toa loss of privacy. (CVE-2007-4571)Multiple buffer overflows were discovered in the handling of CIFSfilesystems. A malicious CIFS server could cause a client system crashor possibly execute arbitrary code with kernel privileges. (CVE-2007-5904)It was discovered that PowerPC kernels..http://www.edgeos.com/threats/33255 Novell iPrint Client Unspecified Vulnerability- (Found June 29, 2008 ) Critical Risk -- The remote host has Novell iPrint Client installed.The installed version of Novell iPrint is affected by an unspecifiedvulnerability.http://www.edgeos.com/threats/33227 Safari < 3.1.2 Multiple Vulnerabilities- (Found June 29, 2008 ) Critical Risk -- The version of Safari installed on the remote host reportedly isaffected by several issues : - An out-of-bounds memory read while handling BMP and GIF images may lead to information disclosure (CVE-2008-1573). - Safari will automatically launch executable files downloaded from a site if that site is in an IE7 zone with 'Launching applications and unsafe files' set to 'Enable' or an IE6 'Local intranet ' ' Trusted sites' zone (CVE-2008-2306). - There is a..http://www.edgeos.com/threats/33226 3D-FTP Multiple Directory Traversal Vulnerabilities- (Found June 29, 2008 ) Critical Risk -- The remote host has the 3D-FTP FTP client installed. The installed version of 3D-FTP is affected by multiple directorytraversal vulnerabilities. By prefixing '..' to filenames inresponse to 'LIST' and 'MLSD' commands, it may be possible for anattacker to write arbitrary files outside the client's directory,subject to the privileges of the user. An attacker can leverage thisissue to write arbitrary files (potentially containing malicious code)to client startup directory which..http://www.edgeos.com/threats/33218 ListManager words Parameter Cross-Site Scripting Vulnerability- (Found June 29, 2008 ) High Risk -- The remote host is running ListManager, a web-based commercial mailinglist management application from Lyris. The version of ListManager installed on the remote host fails tosanitize user input to the 'words' parameter of the'readsearchresults' script before including it in dynamic HTMLoutput. An attacker may be able to leverage this issue to injectarbitrary HTML and script code into a user's browser to be executedwithin the security context of the affected site.http://www.edgeos.com/threats/33219 Adobe Flex History Management Cross-Site Scripting Vulnerability- (Found June 29, 2008 ) High Risk -- The remote host contains one or more HTML documents associated withAdobe Flex 3's History Management Feature and affected by a DOM-basedcross-site scripting vulnerability. Due to its failure to sanitizeuser input, an attacker may be able to leverage this issue to injectarbitrary HTML and script code into a user's browser to be executedwithin the security context of the affected site, possibly by usingJavaScript code flow manipulation techniques.http://www.edgeos.com/threats/33220 Fedora Core 9 2008-5425: freetype- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5425 (freetype).The FreeType engine is a free and portable font renderingengine, developed to provide advanced font support for a variety ofplatforms and environments. FreeType is a library which can open andmanages font files as well as efficiently load, hint and renderindividual glyphs. FreeType is not a font server or a completetext-rendering library.-Update Information:This update backports security fixes...http://www.edgeos.com/threats/33221 Fedora Core 8 2008-5430: freetype- (Found June 29, 2008 ) Critical Risk -- The remote host is missing the patch for the advisory FEDORA-2008-5430 (freetype).The FreeType engine is a free and portable font renderingengine, developed to provide advanced font support for a variety ofplatforms and environments. FreeType is a library which can open andmanages font files as well as efficiently load, hint and renderindividual glyphs. FreeType is not a font server or a completetext-rendering library.-Update Information:This update backports security fixes...http://www.edgeos.com/threats/33222 SuSE Security Update: courier-authlib: SQL injection (courier-authlib-5352)- (Found June 29, 2008 ) Critical Risk -- This update of courier-authlib fixes a bug that allowedSQL injections. (CVE-2008-2667)http://www.edgeos.com/threats/33223 SuSE Security Update: Opera: Security upgrade to version 9.50 (opera-5354)- (Found June 29, 2008 ) Critical Risk -- This patch brings Opera to security update level 9.50Following security problems were fixed: CVE-2008-2714:Opera before 9.26 allows remote attackers to misrepresentweb page addresses using 'certain characters' that 'causethe page address text to be misplaced.'CVE-2008-2715: Unspecified vulnerability in Opera before9.5 allows remote attackers to read cross-domain images viaHTML CANVAS elements that use the images as patterns.CVE-2008-2716: Unspecified vulnerability in Opera...http://www.edgeos.com/threats/33224 |