copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2010.0187 - [RedHat] JBoss Enterprise Web Server: Multiple vulnerabilities

Date: 24 February 2010
References: ASB-2009.1125.2  ESB-2010.0005  ESB-2010.0077  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2010.0187
               Low: JBoss Enterprise Web Server 1.0.1 update
                             24 February 2010

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           JBoss Enterprise Web Server
Publisher:         Red Hat
Operating System:  Red Hat Enterprise Linux AS/ES/WS 4
                   Red Hat Enterprise Linux Server 5
Impact/Access:     Modify Arbitrary Files -- Remote with User Interaction
                   Delete Arbitrary Files -- Remote with User Interaction
                   Unauthorised Access    -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2009-3555 CVE-2009-2902 CVE-2009-2693

Reference:         ESB-2010.0077
                   ESB-2010.0005
                   ASB-2009.1125.2

Original Bulletin: 
   https://rhn.redhat.com/errata/RHSA-2010-0119.html

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

=====================================================================
                   Red Hat Security Advisory

Synopsis:          Low: JBoss Enterprise Web Server 1.0.1 update
Advisory ID:       RHSA-2010:0119-01
Product:           JBoss Enterprise Web Server
Advisory URL:      https://rhn.redhat.com/errata/RHSA-2010-0119.html
Issue date:        2010-02-23
CVE Names:         CVE-2009-2693 CVE-2009-2902 CVE-2009-3555 
=====================================================================

1. Summary:

JBoss Enterprise Web Server 1.0.1 is now available for Red Hat Enterprise
Linux 4 and 5.

This update has been rated as having low security impact by the Red Hat
Security Response Team.

2. Relevant releases/architectures:

JBoss Enterprise Web Server 1.0.0 for RHEL 4 AS - i386, noarch, x86_64
JBoss Enterprise Web Server 1.0.0 for RHEL 4 ES - i386, noarch, x86_64
JBoss Enterprise Web Server 1.0.0 for RHEL 5 Server - i386, noarch, x86_64

3. Description:

JBoss Enterprise Web Server is a fully integrated and certified set
of components for hosting Java web applications. It is comprised of the
industry's leading web server (Apache HTTP Server), the popular Apache
Tomcat servlet container, as well as the mod_jk connector and the Tomcat
Native library.

This 1.0.1 release of JBoss Enterprise Web Server serves as a replacement
to JBoss Enterprise Web Server 1.0.0 GA. These updated packages include
a number of bug fixes. For detailed component, installation, and bug fix
information, refer to the JBoss Enterprise Web Server 1.0.1 Release Notes,
available shortly from the link in the References section of this erratum.

The following security issues are also fixed with this release:

A directory traversal flaw was found in the Tomcat deployment process. An
attacker could create a specially-crafted WAR file, which once deployed
by a local, unsuspecting user, would lead to attacker-controlled content
being deployed outside of the web root, into directories accessible to the
Tomcat process. (CVE-2009-2693)

A second directory traversal flaw was found in the Tomcat deployment
process. WAR file names were not sanitized, which could allow an attacker
to create a specially-crafted WAR file that could delete files in the
Tomcat host's work directory. (CVE-2009-2902)

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. (CVE-2009-3555)

This update provides a mitigation for this flaw in the following
components:

tomcat5 and tomcat6: A new attribute, allowUnsafeLegacyRenegotiation, is
available for the blocking IO (BIO) connector using JSSE, to enable or
disable TLS session renegotiation. The default value is "false", meaning
session renegotiation, both client- and server-initiated, is disabled by
default.

tomcat-native: Client-initiated renegotiation is now rejected by the native
connector. Server-initiated renegotiation is still allowed.

Refer to the following Knowledgebase article for additional details about
the CVE-2009-3555 flaw: http://kbase.redhat.com/faq/docs/DOC-20491

All users of JBoss Enterprise Web Server 1.0.0 on Red Hat Enterprise Linux
4 and 5 are advised to upgrade to these updated packages.

4. Solution:

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied.

This update is available via Red Hat Network.  Details on how to use
the Red Hat Network to apply this update are available at
http://kbase.redhat.com/faq/docs/DOC-11259

5. Bugs fixed (http://bugzilla.redhat.com/):

533125 - CVE-2009-3555 TLS: MITM attacks via session renegotiation
558872 - JBEWS 1.0.1 release tracker bug for RHEL 4
558873 - JBEWS 1.0.1 release tracker bug for RHEL-5
559738 - CVE-2009-2693 tomcat: unexpected file deletion and/or alteration
559761 - CVE-2009-2902 tomcat: unexpected file deletion in work directory

6. Package List:

JBoss Enterprise Web Server 1.0.0 for RHEL 4 AS:

Source:
glassfish-jsf-1.2_13-2.ep5.el4.src.rpm
httpd22-2.2.14-4.ep5.el4.src.rpm
jakarta-commons-chain-1.2-2.1.ep5.el4.src.rpm
jakarta-commons-digester-1.8.1-7.ep5.el4.src.rpm
jakarta-commons-io-1.4-1.ep5.el4.src.rpm
jakarta-commons-modeler-2.0-3.3.ep5.el4.src.rpm
jakarta-commons-validator-1.3.1-7.4.ep5.el4.src.rpm
jakarta-oro-2.0.8-3jpp.ep1.3.ep5.el4.src.rpm
jboss-javaee-5.0.1-2.3.ep5.el4.src.rpm
mod_jk-1.2.28-4.ep5.el4.src.rpm
struts12-1.2.9-2.ep5.el4.src.rpm
tomcat-native-1.1.19-2.0.ep5.el4.src.rpm
tomcat5-5.5.28-7.ep5.el4.src.rpm
tomcat6-6.0.24-2.ep5.el4.src.rpm
xerces-j2-2.9.1-2.2_patch_01.ep5.el4.src.rpm
xml-commons-resolver12-1.2-1.1.ep5.el4.src.rpm

i386:
httpd22-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-devel-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-util-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-util-devel-2.2.14-4.ep5.el4.i386.rpm
httpd22-debuginfo-2.2.14-4.ep5.el4.i386.rpm
httpd22-devel-2.2.14-4.ep5.el4.i386.rpm
httpd22-manual-2.2.14-4.ep5.el4.i386.rpm
mod_jk-ap20-1.2.28-4.ep5.el4.i386.rpm
mod_jk-debuginfo-1.2.28-4.ep5.el4.i386.rpm
mod_jk-manual-1.2.28-4.ep5.el4.i386.rpm
mod_ssl22-2.2.14-4.ep5.el4.i386.rpm
tomcat-native-1.1.19-2.0.ep5.el4.i386.rpm
tomcat-native-debuginfo-1.1.19-2.0.ep5.el4.i386.rpm

noarch:
glassfish-jsf-1.2_13-2.ep5.el4.noarch.rpm
jakarta-commons-chain-1.2-2.1.ep5.el4.noarch.rpm
jakarta-commons-digester-1.8.1-7.ep5.el4.noarch.rpm
jakarta-commons-io-1.4-1.ep5.el4.noarch.rpm
jakarta-commons-modeler-2.0-3.3.ep5.el4.noarch.rpm
jakarta-commons-validator-1.3.1-7.4.ep5.el4.noarch.rpm
jakarta-oro-2.0.8-3jpp.ep1.3.ep5.el4.noarch.rpm
jboss-javaee-poms-5.0.1-2.3.ep5.el4.noarch.rpm
jboss-transaction-1.0.1-api-5.0.1-2.3.ep5.el4.noarch.rpm
struts12-1.2.9-2.ep5.el4.noarch.rpm
tomcat5-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-admin-webapps-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-common-lib-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jasper-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jasper-eclipse-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jasper-javadoc-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jsp-2.0-api-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jsp-2.0-api-javadoc-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-parent-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-server-lib-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-servlet-2.4-api-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-servlet-2.4-api-javadoc-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-webapps-5.5.28-7.ep5.el4.noarch.rpm
tomcat6-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-admin-webapps-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-docs-webapp-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-el-1.0-api-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-javadoc-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-lib-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-log4j-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-webapps-6.0.24-2.ep5.el4.noarch.rpm
xerces-j2-2.9.1-2.2_patch_01.ep5.el4.noarch.rpm
xml-commons-resolver12-1.2-1.1.ep5.el4.noarch.rpm

x86_64:
httpd22-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-devel-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-util-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-util-devel-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-debuginfo-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-devel-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-manual-2.2.14-4.ep5.el4.x86_64.rpm
mod_jk-ap20-1.2.28-4.ep5.el4.x86_64.rpm
mod_jk-debuginfo-1.2.28-4.ep5.el4.x86_64.rpm
mod_jk-manual-1.2.28-4.ep5.el4.x86_64.rpm
mod_ssl22-2.2.14-4.ep5.el4.x86_64.rpm
tomcat-native-1.1.19-2.0.ep5.el4.x86_64.rpm
tomcat-native-debuginfo-1.1.19-2.0.ep5.el4.x86_64.rpm

JBoss Enterprise Web Server 1.0.0 for RHEL 4 ES:

Source:
glassfish-jsf-1.2_13-2.ep5.el4.src.rpm
httpd22-2.2.14-4.ep5.el4.src.rpm
jakarta-commons-chain-1.2-2.1.ep5.el4.src.rpm
jakarta-commons-digester-1.8.1-7.ep5.el4.src.rpm
jakarta-commons-io-1.4-1.ep5.el4.src.rpm
jakarta-commons-modeler-2.0-3.3.ep5.el4.src.rpm
jakarta-commons-validator-1.3.1-7.4.ep5.el4.src.rpm
jakarta-oro-2.0.8-3jpp.ep1.3.ep5.el4.src.rpm
jboss-javaee-5.0.1-2.3.ep5.el4.src.rpm
mod_jk-1.2.28-4.ep5.el4.src.rpm
struts12-1.2.9-2.ep5.el4.src.rpm
tomcat-native-1.1.19-2.0.ep5.el4.src.rpm
tomcat5-5.5.28-7.ep5.el4.src.rpm
tomcat6-6.0.24-2.ep5.el4.src.rpm
xerces-j2-2.9.1-2.2_patch_01.ep5.el4.src.rpm
xml-commons-resolver12-1.2-1.1.ep5.el4.src.rpm

i386:
httpd22-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-devel-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-util-2.2.14-4.ep5.el4.i386.rpm
httpd22-apr-util-devel-2.2.14-4.ep5.el4.i386.rpm
httpd22-debuginfo-2.2.14-4.ep5.el4.i386.rpm
httpd22-devel-2.2.14-4.ep5.el4.i386.rpm
httpd22-manual-2.2.14-4.ep5.el4.i386.rpm
mod_jk-ap20-1.2.28-4.ep5.el4.i386.rpm
mod_jk-debuginfo-1.2.28-4.ep5.el4.i386.rpm
mod_jk-manual-1.2.28-4.ep5.el4.i386.rpm
mod_ssl22-2.2.14-4.ep5.el4.i386.rpm
tomcat-native-1.1.19-2.0.ep5.el4.i386.rpm
tomcat-native-debuginfo-1.1.19-2.0.ep5.el4.i386.rpm

noarch:
glassfish-jsf-1.2_13-2.ep5.el4.noarch.rpm
jakarta-commons-chain-1.2-2.1.ep5.el4.noarch.rpm
jakarta-commons-digester-1.8.1-7.ep5.el4.noarch.rpm
jakarta-commons-io-1.4-1.ep5.el4.noarch.rpm
jakarta-commons-modeler-2.0-3.3.ep5.el4.noarch.rpm
jakarta-commons-validator-1.3.1-7.4.ep5.el4.noarch.rpm
jakarta-oro-2.0.8-3jpp.ep1.3.ep5.el4.noarch.rpm
jboss-javaee-poms-5.0.1-2.3.ep5.el4.noarch.rpm
jboss-transaction-1.0.1-api-5.0.1-2.3.ep5.el4.noarch.rpm
struts12-1.2.9-2.ep5.el4.noarch.rpm
tomcat5-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-admin-webapps-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-common-lib-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jasper-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jasper-eclipse-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jasper-javadoc-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jsp-2.0-api-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-jsp-2.0-api-javadoc-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-parent-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-server-lib-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-servlet-2.4-api-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-servlet-2.4-api-javadoc-5.5.28-7.ep5.el4.noarch.rpm
tomcat5-webapps-5.5.28-7.ep5.el4.noarch.rpm
tomcat6-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-admin-webapps-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-docs-webapp-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-el-1.0-api-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-javadoc-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-lib-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-log4j-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-2.ep5.el4.noarch.rpm
tomcat6-webapps-6.0.24-2.ep5.el4.noarch.rpm
xerces-j2-2.9.1-2.2_patch_01.ep5.el4.noarch.rpm
xml-commons-resolver12-1.2-1.1.ep5.el4.noarch.rpm

x86_64:
httpd22-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-devel-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-util-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-apr-util-devel-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-debuginfo-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-devel-2.2.14-4.ep5.el4.x86_64.rpm
httpd22-manual-2.2.14-4.ep5.el4.x86_64.rpm
mod_jk-ap20-1.2.28-4.ep5.el4.x86_64.rpm
mod_jk-debuginfo-1.2.28-4.ep5.el4.x86_64.rpm
mod_jk-manual-1.2.28-4.ep5.el4.x86_64.rpm
mod_ssl22-2.2.14-4.ep5.el4.x86_64.rpm
tomcat-native-1.1.19-2.0.ep5.el4.x86_64.rpm
tomcat-native-debuginfo-1.1.19-2.0.ep5.el4.x86_64.rpm

JBoss Enterprise Web Server 1.0.0 for RHEL 5 Server:

Source:
glassfish-jsf-1.2_13-3.ep5.el5.src.rpm
httpd-2.2.14-1.2.1.ep5.el5.src.rpm
jakarta-commons-chain-1.2-2.1.1.ep5.el5.src.rpm
jakarta-commons-io-1.4-1.1.ep5.el5.src.rpm
jakarta-oro-2.0.8-3.1.ep5.el5.src.rpm
mod_jk-1.2.28-4.1.ep5.el5.src.rpm
struts12-1.2.9-2.ep5.el5.src.rpm
tomcat-native-1.1.19-2.0.1.ep5.el5.src.rpm
tomcat5-5.5.28-7.1.ep5.el5.src.rpm
tomcat6-6.0.24-2.1.ep5.el5.src.rpm

i386:
httpd-2.2.14-1.2.1.ep5.el5.i386.rpm
httpd-debuginfo-2.2.14-1.2.1.ep5.el5.i386.rpm
httpd-devel-2.2.14-1.2.1.ep5.el5.i386.rpm
httpd-manual-2.2.14-1.2.1.ep5.el5.i386.rpm
mod_jk-ap20-1.2.28-4.1.ep5.el5.i386.rpm
mod_jk-debuginfo-1.2.28-4.1.ep5.el5.i386.rpm
mod_jk-manual-1.2.28-4.1.ep5.el5.i386.rpm
mod_ssl-2.2.14-1.2.1.ep5.el5.i386.rpm
tomcat-native-1.1.19-2.0.1.ep5.el5.i386.rpm
tomcat-native-debuginfo-1.1.19-2.0.1.ep5.el5.i386.rpm

noarch:
glassfish-jsf-1.2_13-3.ep5.el5.noarch.rpm
jakarta-commons-chain-1.2-2.1.1.ep5.el5.noarch.rpm
jakarta-commons-io-1.4-1.1.ep5.el5.noarch.rpm
jakarta-oro-2.0.8-3.1.ep5.el5.noarch.rpm
struts12-1.2.9-2.ep5.el5.noarch.rpm
tomcat5-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-admin-webapps-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-common-lib-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-jasper-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-jasper-eclipse-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-jasper-javadoc-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-jsp-2.0-api-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-jsp-2.0-api-javadoc-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-parent-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-server-lib-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-servlet-2.4-api-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-servlet-2.4-api-javadoc-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat5-webapps-5.5.28-7.1.ep5.el5.noarch.rpm
tomcat6-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-admin-webapps-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-docs-webapp-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-el-1.0-api-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-javadoc-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-jsp-2.1-api-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-lib-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-log4j-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-servlet-2.5-api-6.0.24-2.1.ep5.el5.noarch.rpm
tomcat6-webapps-6.0.24-2.1.ep5.el5.noarch.rpm

x86_64:
httpd-2.2.14-1.2.1.ep5.el5.x86_64.rpm
httpd-debuginfo-2.2.14-1.2.1.ep5.el5.x86_64.rpm
httpd-devel-2.2.14-1.2.1.ep5.el5.x86_64.rpm
httpd-manual-2.2.14-1.2.1.ep5.el5.x86_64.rpm
mod_jk-ap20-1.2.28-4.1.ep5.el5.x86_64.rpm
mod_jk-debuginfo-1.2.28-4.1.ep5.el5.x86_64.rpm
mod_jk-manual-1.2.28-4.1.ep5.el5.x86_64.rpm
mod_ssl-2.2.14-1.2.1.ep5.el5.x86_64.rpm
tomcat-native-1.1.19-2.0.1.ep5.el5.x86_64.rpm
tomcat-native-debuginfo-1.1.19-2.0.1.ep5.el5.x86_64.rpm

These packages are GPG signed by Red Hat for security.  Our key and 
details on how to verify the signature are available from
https://www.redhat.com/security/team/key/#package

7. References:

https://www.redhat.com/security/data/cve/CVE-2009-2693.html
https://www.redhat.com/security/data/cve/CVE-2009-2902.html
https://www.redhat.com/security/data/cve/CVE-2009-3555.html
http://www.redhat.com/security/updates/classification/#low
http://kbase.redhat.com/faq/docs/DOC-20491
http://www.redhat.com/docs/en-US/JBoss_Enterprise_Web_Server/1.0.1/html-single/Release_Notes/index.html

8. Contact:

The Red Hat security contact is <secalert@redhat.com>.  More contact
details at https://www.redhat.com/security/team/contact/

Copyright 2010 Red Hat, Inc.
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)

iD8DBQFLhDm1XlSAg2UNWIIRAr7CAJ4syLe9gdEVccyHPvFBl/LMvzG9LQCfTawT
OnSBEYLrz9TFZdMuNLXkWj0=
=R6Ya
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iD8DBQFLhF+n/iFOrG6YcBERAlGeAJ4iWAa6Yh7N+pNkcGVsxrBxyRA7uwCgrmGY
hd/0psfZxis4hrZuouB0fiI=
=Z5+E
-----END PGP SIGNATURE-----