| |
 |
 |
 |
 |
 |
 |
AusCERT Security Bulletins are security bulletins written by AusCERT using information gathered by our own research or by research done by other computer security incident response teams, vendors, and other groups concerned about security.
AusCERT Security Bulletins are released when a single quotable source of information is not available.
AusCERT includes a summary of key information at the front of the document and cross-references it to relevant bulletins. A section at the end of the bulletin lists all references use to create the bulletin.
ASB-2012.0137 - [Win][UNIX/Linux][Mobile] Mozilla Firefox, Thunderbird & SeaMonkey: Multiple vulnerabilities
- New versions of Mozilla Firefox, Thunderbird, and SeaMonkey fix multiple vulnerabilities.
(11/10/2012)
ASB-2012.0136 - [Win][UNIX/Linux] Google Chrome: Denial of service - Remote with user interaction
- A number of vulnerabilities have been identified in Google Chrome
(10/10/2012)
ASB-2012.0135 - [Solaris] Perl: Execute arbitrary code/commands - Remote with user interaction
- Oracle have addressed a vulnerability with Perl
(04/10/2012)
ASB-2012.0134 - [Win][UNIX/Linux] Wireshark: Denial of service - Remote with user interaction
- Wireshark 1.8.3 has been released
(04/10/2012)
ASB-2012.0133 - [Win][Netware] Novell GroupWise 8: Multiple vulnerabilities
- Multiple vulnerabilities have been fixed in GroupWise 8.0 SP3
(03/10/2012)
ASB-2012.0132 - [Win][UNIX/Linux] Google Chrome: Multiple vulnerabilities
- A number of vulnerabilities have been identified in Google Chrome prior to version 22.0.1229.79.
(27/09/2012)
ASB-2012.0129.2 - UPDATE [Appliance] Siemens SIMATIC S7-1200 PLC: Provide misleading information - Remote with user interaction
-
(27/09/2012)
ASB-2012.0131 - [Win][UNIX/Linux] Moodle: Multiple vulnerabilities
- A number of vulnerabilities have been identified in Moodle prior to version 2.3.2.
(20/09/2012)
ASB-2012.0130 - [Win] Sophos Anti-Virus: Reduced security
- An issue has been identified in Sophos Anti-Virus which is causing false positives to be detected.
(20/09/2012)
ASB-2012.0128.2 - UPDATED ALERT [Win] Internet Explorer: Execute arbitrary code/commands - Remote with user interaction
-
(19/09/2012)
ASB-2012.0127 - [Appliance] McAfee Firewall Enterprise: Denial of service - Remote/unauthenticated
- A number of vulnerabilities have been identified in Quagga as used by McAfee Firewall Enterprise 8.x and 7.x.
(13/09/2012)
ASB-2012.0126 - ALERT [Win] Siemens SIMATIC WinCC: Multiple vulnerabilities
- A patch which addresses multiple vulnerabilities has been released by Siemens for the WinCC WebNavigator software. The WinCC product is used in SCADA system control.
(12/09/2012)
ASB-2012.0125 - [Win][VMware ESX][Linux][HP-UX][Solaris][AIX] IBM Asset and Service Management products: Multiple vulnerabilities
- A number of vulnerabilities have been identified in Maximo Asset Management, Maximo Asset Management Essentials, SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk and Change and Configuration Management Database.
(07/09/2012)
ASB-2012.0124 - [Appliance] BIG-IP ASM: Cross-site scripting - Remote with user interaction
- A vulnerability has been identified in BIG-IP ASM versions 10.0.0 through 10.2.4-HF3, 11.0.0 through 11.0.0-HF3, 11.1.0 through 11.1.0-HF4, and 11.2.0 through 11.2.0-HF1.
(07/09/2012)
ASB-2012.0123 - [Win][UNIX/Linux] WordPress: Increased privileges - Unknown/unspecified
- A number of vulnerabilities have been identified in WordPress prior to version 3.4.2.
(07/09/2012)
ASB-2012.0049.2 - UPDATE [Win][UNIX/Linux] Joomla!: Multiple vulnerabilities
-
(07/09/2012)
ASB-2012.0012.2 - UPDATE [Win][UNIX/Linux] Joomla!: Multiple vulnerabilities
-
(07/09/2012)
ASB-2012.0122 - [Win][Mac][OSX] Adobe Photoshop CS6: Execute arbitrary code/commands - Remote with user interaction
- Security update available for Adobe Photoshop CS6
(05/09/2012)
ASB-2012.0121 - [Win][Linux][OSX] Google Chrome: Multiple vulnerabilities
- A number of vulnerabilities have been identified in Google Chrome.
(03/09/2012)
ASB-2012.0120 - ALERT [Win][UNIX/Linux][Mobile] Oracle JDK and JRE 6 and 7: Execute arbitrary code/commands - Remote with user interaction
- Oracle has released an update for Java SE to mitigate vulnerability CVE-2012-4681 from being actively exploited.
(31/08/2012)
ASB-2012.0119 - [Win][UNIX/Linux][Mobile] Mozilla Firefox, Thunderbird & SeaMonkey: Multiple vulnerabilities
- Bugs fixed in new versions of Mozilla Firefox, Thunderbird, and SeaMonkey
(29/08/2012)
ASB-2012.0118 - [Win][Linux][HP-UX][Solaris][AIX] IBM Rational ClearQuest: Multiple vulnerabilities
- A number of vulnerabilities have been identified in IBM Rational ClearQuest prior to versions 7.1.2.7 and 8.0.0.3.
(20/08/2012)
ASB-2012.0115.2 - UPDATE [Win] Siemens COMOS: Increased privileges - Existing account
-
(17/08/2012)
ASB-2012.0117 - [Win][UNIX/Linux] Wireshark: Multiple vulnerabilities
- A number of vulnerabilities have been identified in Wireshark prior to versions 1.4.15, 1.6.10 and 1.8.2.
(16/08/2012)
ASB-2012.0116 - ALERT [Win][Linux][Mac][OSX] Google Chrome: Execute arbitrary code/commands - Remote with user interaction
- A remote code execution vulnerability with Adobe Flash Player has been fixed in Google Chrome.
(15/08/2012)
ASB-2012.0114 - ALERT [Win][UNIX/Linux] Oracle Database Server: Increased privileges - Existing account
- A privilege escalation vulnerability has been fixed in Oracle Database Server.
(13/08/2012)
ASB-2012.0113 - [Win][UNIX/Linux] Ruby on Rails: Multiple vulnerabilities
- Multiple cross site scripting vulnerabilities have been fixed in Ruby on Rails 3.2.8
(13/08/2012)
ASB-2012.0112 - [Win][UNIX/Linux] Google Chrome: Denial of service - Remote/unauthenticated
- Two denial of service vulnerabilities have been fixed in Google Chrome.
(10/08/2012)
ASB-2012.0111 - [Win][UNIX/Linux] Ruby on Rails: Denial of service - Remote/unauthenticated
- A denial of service vulnerability in the Action Pack digest authentication has been fixed in Ruby on Rails 3.2.7
(09/08/2012)
ASB-2012.0110 - [Win] JP1/Integrated Management - Service Support: Cross-site scripting - Remote with user interaction
- A cross site scripting vulnerability has been fixed in JP1/Integrated Management - Service Support 09-50-04
(09/08/2012)
ASB-2012.0109 - [Win][UNIX/Linux] Google Chrome: Multiple vulnerabilities
- A number of vulnerabilities have been identified in Chrome prior to 21.0.1180.57 for Mac and Linux and 21.0.1180.60 for Windows
and Chrome Frame.
(02/08/2012)
ASB-2012.0108 - [Win] Siemens SIMATIC STEP7 and PCS7: Execute arbitrary code/commands - Existing account
- A vulnerability has been identified in Siemens SIMATIC STEP7 prior to version 5.5 SP1, and Siemens SIMATIC PCS7 prior to version 7.1 SP3.
(26/07/2012)
ASB-2012.0107 - [Win][Linux][OSX] TeamViewer: Reduced security - Unknown/unspecified
- Vulnerabilities have been identified in TeamViewer prior to versions 7.0.13989, 6.0.13992 and 5.1.13999
(26/07/2012)
ASB-2012.0106 - [Win][UNIX/Linux] Wireshark: Denial of service - Remote with user interaction
- A number of vulnerabilities have been identified in Wireshark prior to versions 1.8.1, 1.6.9 and 1.4.14.
(25/07/2012)
ASB-2012.0105 - [Win][UNIX/Linux] PHP: Multiple vulnerabilities
- A number of vulnerabilities have been identified in PHP prior to versions 5.4.5 and 5.3.15.
(23/07/2012)
Previous 1, 2, 3, 4, 5 ... 21, 22, 23 Next
denotes AusCERT member only content.
|
|
 |
 |
 |
 |
 |
 |
|