| |
 |
 |
 |
 |
 |
 |
AusCERT Security Bulletins are security bulletins written by AusCERT using information gathered by our own research or by research done by other computer security incident response teams, vendors, and other groups concerned about security.
AusCERT Security Bulletins are released when a single quotable source of information is not available.
AusCERT includes a summary of key information at the front of the document and cross-references it to relevant bulletins. A section at the end of the bulletin lists all references use to create the bulletin.
ASB-2009.1059 - [Win][UNIX/Linux] Thunderbird: Access privileged data - Remote/unauthenticated
- Mozilla have released a new version of Thunderbrid, correcting one
critical security vulnerability.
(24/08/2009)
ASB-2009.1040.5 - UPDATE [Win][UNIX/Linux] Firefox 3.5.1: Multiple vulnerabilities
- Mozilla has released four advisories relating to Firefox.
(24/08/2009)
ASB-2009.1058 - [Win][UNIX/Linux] WordPress: Multiple vulnerabilities
- WordPress has released an update to correct multiple vulnerabilities.
(20/08/2009)
ASB-2009.1057 - [Win][Linux][Solaris][AIX] DB2 Version 8: Multiple vulnerabilities
- IBM has corrected multiple vulnerabilities in DB2 Version 8.
(20/08/2009)
ASB-2009.1056 - [FreeBSD] Multiple packages: Multiple vulnerabilities
-
(19/08/2009)
ASB-2009.1055 - [Linux][Solaris][AIX] IBM Network Authentication Service (NAS) for DB2 Version 8.2: Multiple vulnerabilities
-
(19/08/2009)
ASB-2009.1054 - [Win][UNIX/Linux] Python 3.1 : Denial of service - Remote/unauthenticated
-
(18/08/2009)
ASB-2009.1053 - [Win][UNIX/Linux] New patches from Adobe fix multiple vulnerabilities in ColdFusion and JRun
-
(18/08/2009)
ASB-2009.1052 - [Win][Linux][HP-UX][Solaris][AIX] IBM WebSphere Application Server SCA 1.0 : Increased privileges - Remote/unauthenticated
-
(18/08/2009)
ASB-2009.1051 - [Appliance] Avaya CMS and IR: Denial of service - Remote/unauthenticated
-
(18/08/2009)
ASB-2009.1025.2 - UPDATE [Appliance] DD-WRT: Root compromise - Remote/unauthenticated
- A vulnerability has been reported in the httpd server for the
DD-WRT management GUI.
(18/08/2009)
ASB-2009.1049.2 - UPDATE [Win][UNIX/Linux] WordPress prior to 2.8.4: Denial of service - Remote/unauthenticated
- WordPress 2.8.4 has been released fixing a vulnerability.
(14/08/2009)
ASB-2009.1048 - [Win][UNIX/Linux] GnuTLS prior to 2.8.2: Provide misleading information - Remote with user interaction
- A vulnerability has been identified in GnuTLS prior to version 2.8.2.
(13/08/2009)
ASB-2009.1047 - [UNIX/Linux] Asterisk Open Source, Asterisk Business Edition & s800i Asterisk Appliance: Denial of service - Remote/unauthenticated
- A vulnerability has been identified in Asterisk's SIP channel driver.
(11/08/2009)
ASB-2009.1046 - [Netware] Novell NetWare DNS Server: Read-only data access - Remote/unauthenticated
- A vulnerability has been identified in Novell NetWare DNS Server as
used by Novell NetWare version 6.5.
(11/08/2009)
ASB-2009.1045 - [Win][UNIX/Linux] Apache 2.2.12 and prior: Denial of service - Remote/unauthenticated
- Apache HTTP Server 2.2.13 has been released correcting a number of bugs
and a security vulnerability.
(10/08/2009)
ASB-2009.1044 - [Win][UNIX/Linux] PHP prior to version 5.2.10: Denial of service - Remote with user interaction
-
(10/08/2009)
ASB-2009.1043.3 - UPDATE [Appliance] BIG-IP: Denial of service - Remote/unauthenticated
-
(07/08/2009)
ASB-2009.1042 - [Linux] strongSwan 2.8.10 and prior: Denial of service - Remote/unauthenticated
-
(05/08/2009)
ASB-2009.1041 - [Win][UNIX/Linux] Wordpress 2.8.1 and prior: Multiple vulnerabilities
- A number of vulnerabilities have been identified in Wordpress 2.8.1 and prior.
(04/08/2009)
ASB-2009.1039 - [Win][UNIX/Linux] MySQL: Denial of service - Existing account
-
(03/08/2009)
ASB-2009.1038 - ALERT [Win][UNIX/Linux] SquirrelMail plugins: Access confidential data - Remote/unauthenticated
- A number of SquirrelMail plugins have been confirmed to have been compromised as a result of the SquirrelMail Webserver compromise that took place on June 16th 2009.
(03/08/2009)
ASB-2009.1037 - [Win][UNIX/Linux] Joomla!: Reduced security - Existing account
- A vulnerability has been identified in Joomla! prior to version 1.5.14.
(03/08/2009)
ASB-2009.1026.4 - UPDATED ALERT [Win][UNIX/Linux] Adobe Flash, Adobe Acrobat and Adobe Reader: Multiple vulnerabilities
-
(03/08/2009)
ASB-2009.1036 - [Win][UNIX/Linux] VLC prior to 1.0.1: Execute arbitrary code/commands - Remote with user interaction
-
(31/07/2009)
ASB-2009.1035 - [OpenBSD] BIND: Denial of service - Remote/unauthenticated
-
(31/07/2009)
ASB-2009.1034.2 - UPDATE [UNIX/Linux] Asterisk: Denial of service - Remote/unauthenticated
- A vulnerability has been identified in Asterisk prior to version 1.6.1.2.
(31/07/2009)
ASB-2009.1033 - ALERT [Win][UNIX/Linux][Appliance] BIND 9: Denial of service - Remote/unauthenticated
- ISC has released updated versions of BIND 9 to solve a remotely
exploitable Denial of Service vulnerability.
(29/07/2009)
ASB-2009.1032 - [Win][Linux][AIX] Hitachi Business Logic - Container: Cross-site scripting - Remote/unauthenticated
- A vulnerability has been identified in Hitachi Business Logic - Container and Hitachi Business Logic - Container 2, component products of Electronic Form Workflow.
(28/07/2009)
ASB-2009.1031 - [Win] Kaspersky Anti-Virus & Kaspersky Internet Security 2010: Reduced security - Remote/unauthenticated
-
(27/07/2009)
ASB-2009.1030 - ALERT [Win] Microsoft Bulletin Notification - July Out-of-Band Pre-release Announcement
- Microsoft will be releasing two out-of-band security patches on Wednesday 29 July 2009.
(27/07/2009)
ASB-2009.1029.2 - UPDATE [Win][Linux][HP-UX][Solaris][AIX] IBM Tivoli Identity Manager: Unauthorised access - Remote/unauthenticated
- IBM have released an Interim Fix for Tivoli Identity Manager
correcting a security vulnerability.
(24/07/2009)
ASB-2009.1028 - [Win][UNIX/Linux] Joomla!: Multiple vulnerabilities
- Joomla! 1.5.13 has been released correcting two (2) security
vulnerabilities.
(24/07/2009)
ASB-2009.1027 - [UNIX/Linux] ZNC: Multiple vulnerabilities
- A vulnerability has been reported in ZNC that can allow an attacker
to conduct directory traversal attacks with write capabilities.
(23/07/2009)
ASB-2009.1024 - [Win][UNIX/Linux] WordPress: Cross-site scripting - Remote/unauthenticated
- WordPress 2.8.2 has been released and fixes a cross site scripting
vulnerability.
(22/07/2009)
Previous 1, 2, 3 ... , 21, 22, 23 Next
denotes AusCERT member only content.
|
|
 |
 |
 |
 |
 |
 |
|