<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.nessus.org/">
<title>Nessus.org Plugins</title>
<link>http://www.nessus.org/scripts.php</link>
<description>All the newest security checks for the Nessus scanner</description>

<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33396" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33395" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33394" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33393" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33392" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33391" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33390" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33389" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33388" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33387" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33386" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33385" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33384" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33383" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33382" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33381" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33380" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33379" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33378" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=33377" />
</rdf:Seq>
</items>
</channel>

<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus Plugins</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>

<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33396">
<title>Opera &lt; 9.51 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote host contains a web browser that is affected by several<br />
issues. <br />
<br />
Description :<br />
<br />
The version of Opera installed on the remote host reportedly is<br />
affected by several issues :<br />
<br />
  - Specially-crafted HTML canvas elements could reveal data from<br />
    random areas of memory.<br />
	<br />
  - An unspecified arbitrary code execution vulnerability.<br />
  <br />
  - Improperly set security status when navigating from HTTP to<br />
	HTTPS.<br />
<br />
See also :<br />
<br />
<a href="http://www.opera.com/support/search/view/887/" target="_blank">http://www.opera.com/support/search/view/887/</a><br />
<a href="http://www.opera.com/docs/changelogs/windows/951/" target="_blank">http://www.opera.com/docs/changelogs/windows/951/</a><br />
<br />
Solution :<br />
<br />
Upgrade to Opera version 9.51 or later. <br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 9.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33396</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33395">
<title>Microsoft Dynamics GP &lt; 10.0 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote host contains an application that is affected by multiple<br />
vulnerabilities.<br />
<br />
Description :<br />
<br />
Microsoft Dynamics GP (formerly known as Great Plains), is installed on<br />
remote host.<br />
<br />
The installed version of Microsoft Dynamics GP is affected by multiple<br />
vulnerabilities.<br />
<br />
- By sending a specially crafted DPS message with a very long IP address<br />
  or a string, to Distributed Process Server (DPS) or Distributed <br />
  Process Manager (DPM), it may be possible to overflow a buffer or <br />
  execute arbitrary code on the remote system.<br />
<br />
- By sending a specially crafted DPS message, containing an invalid magic<br />
  number, it may be possible to cause a denial of service condition and <br />
  crash the remote system.<br />
 <br />
- By sending a specially crafted DPM message, it may be possible to<br />
  execute arbitrary code on the remote system.<br />
<br />
It should be noted that code execution will generally result in system wide<br />
compromise.<br />
<br />
See also :<br />
<br />
<a href="http://xforce.iss.net/xforce/xfdb/25840" target="_blank">http://xforce.iss.net/xforce/xfdb/25840</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/25841" target="_blank">http://xforce.iss.net/xforce/xfdb/25841</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/25842" target="_blank">http://xforce.iss.net/xforce/xfdb/25842</a><br />
<a href="http://xforce.iss.net/xforce/xfdb/25844" target="_blank">http://xforce.iss.net/xforce/xfdb/25844</a><br />
<br />
Solution :<br />
<br />
Upgrade to Microsoft Dynamics GP 10.0 or later.<br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33395</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33394">
<title>SeaMonkey &lt; 1.1.10</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
A web browser on the remote host is affected by multiple<br />
vulnerabilities. <br />
<br />
Description :<br />
<br />
The installed version of SeaMonkey is affected by various security<br />
issues :<br />
<br />
  - A stability problem that could result in a crash during<br />
    JavaScript garbage collection (MFSA 2008-20).<br />
<br />
  - Several stability bugs leading to crashes which, in<br />
    some cases, show traces of memory corruption<br />
    (MFSA 2008-21).<br />
<br />
  - A vulnerability involving violation of the same-origin <br />
    policy could allow for cross-site scripting attacks<br />
    (MFSA 2008-22).<br />
<br />
  - JavaScript can be injected into the context of signed <br />
    JARs and executed under the context of the JAR's signer<br />
    (MFSA 2008-23).<br />
<br />
  - By taking advantage of the privilege level stored in <br />
    the pre-compiled 'fastload' file. an attacker may be<br />
    able to run arbitrary JavaScript code with chrome <br />
    privileges (MFSA 2008-24).<br />
<br />
  - Arbitrary code execution is possible in <br />
    'mozIJSSubScriptLoader.loadSubScript()' (MFSA 2008-25).<br />
<br />
  - An attacker can steal files from known locations on a <br />
    victim's computer via originalTarget and DOM Range<br />
    (MFSA 2008-27).<br />
<br />
  - It is possible for a malicious Java applet to bypass <br />
    the same-origin policy and create arbitrary socket <br />
    connections to other domains (MFSA 2008-28).<br />
<br />
  - An improperly encoded '.properties' file in an add-on <br />
    can result in uninitialized memory being used, which<br />
    could lead to data formerly used by other programs<br />
    being exposed to the add-on code (MFSA 2008-29).<br />
<br />
  - File URLs in directory listings are not properly HTML-<br />
    escaped when the filenames contained particular <br />
    characters (MFSA 2008-30).<br />
<br />
  - A weakness in the trust model regarding alt names on <br />
    peer-trusted certs could lead to spoofing secure <br />
    connections to any other site (MFSA 2008-31).<br />
<br />
  - URL shortcut files on Windows (for example, saved IE <br />
    favorites) could be interpreted as if they were in the <br />
    local file context when opened by SeaMonkey, although <br />
    the referenced remote content would be downloaded and <br />
    displayed (MFSA 2008-32).<br />
<br />
  - A crash in Mozilla's block reflow code could be used <br />
    by an attacker to crash the browser and run arbitrary <br />
    code on the victim's computer (MFSA 2008-33).<br />
<br />
See also :<br />
<br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-20.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-20.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-21.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-21.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-22.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-22.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-23.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-23.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-24.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-24.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-25.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-25.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-27.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-27.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-28.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-28.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-29.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-29.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-30.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-30.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-31.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-31.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-32.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-32.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-33.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-33.html</a><br />
<br />
Solution : <br />
<br />
Upgrade to SeaMonkey 1.1.10 or later. <br />
<br />
Risk factor : <br />
<br />
High / CVSS Base Score : 9.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33394</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33393">
<title>Firefox &lt; 2.0.0.15</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Windows host contains a web browser that is affected by<br />
multiple vulnerabilities. <br />
<br />
Description :<br />
<br />
The installed version of Firefox is affected by various security<br />
issues :<br />
<br />
  - Several stability bugs leading to crashes which, in<br />
    some cases, show traces of memory corruption<br />
    (MFSA 2008-21).<br />
<br />
  - A vulnerability involving violation of the same-origin <br />
    policy could allow for cross-site scripting attacks<br />
    (MFSA 2008-22).<br />
<br />
  - JavaScript can be injected into the context of signed <br />
    JARs and executed under the context of the JAR's signer<br />
    (MFSA 2008-23).<br />
<br />
  - By taking advantage of the privilege level stored in <br />
    the pre-compiled 'fastload' file. an attacker may be<br />
    able to run arbitrary JavaScript code with chrome <br />
    privileges (MFSA 2008-24).<br />
<br />
  - Arbitrary code execution is possible in <br />
    'mozIJSSubScriptLoader.loadSubScript()' (MFSA 2008-25).<br />
<br />
  - An attacker can steal files from known locations on a <br />
    victim's computer via originalTarget and DOM Range<br />
    (MFSA 2008-27).<br />
<br />
  - It is possible for a malicious Java applet to bypass <br />
    the same-origin policy and create arbitrary socket <br />
    connections to other domains (MFSA 2008-28).<br />
<br />
  - An improperly encoded '.properties' file in an add-on <br />
    can result in uninitialized memory being used, which<br />
    could lead to data formerly used by other programs<br />
    being exposed to the add-on code (MFSA 2008-29).<br />
<br />
  - File URLs in directory listings are not properly HTML-<br />
    escaped when the filenames contained particular <br />
    characters (MFSA 2008-30).<br />
<br />
  - A weakness in the trust model regarding alt names on <br />
    peer-trusted certs could lead to spoofing secure <br />
    connections to any other site (MFSA 2008-31).<br />
<br />
  - URL shortcut files on Windows (for example, saved IE <br />
    favorites) could be interpreted as if they were in the <br />
    local file context when opened by Firefox, although <br />
    the referenced remote content would be downloaded and <br />
    displayed (MFSA 2008-32).<br />
<br />
  - A crash in Mozilla's block reflow code could be used <br />
    by an attacker to crash the browser and run arbitrary <br />
    code on the victim's computer (MFSA 2008-33).<br />
<br />
See also :<br />
<br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-21.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-21.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-22.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-22.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-23.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-23.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-24.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-24.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-25.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-25.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-27.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-27.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-28.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-28.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-29.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-29.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-30.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-30.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-31.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-31.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-32.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-32.html</a><br />
<a href="http://www.mozilla.org/security/announce/2008/mfsa2008-33.html" target="_blank">http://www.mozilla.org/security/announce/2008/mfsa2008-33.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to Firefox 2.0.0.15 or later. <br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 9.3<br />
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33393</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33392">
<title>Microsoft Dynamics GP Distributed Process Manager Detection</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
There is a business accounting software installed on the remote host. <br />
<br />
Description :<br />
<br />
The remote host is running Microsoft Dynamics GP Distributed Process<br />
Manager. Dynamics GP is a business accounting and management software<br />
solution from Microsoft.<br />
<br />
<br />
See also :<br />
<br />
<a href="http://www.microsoft.com/dynamics/gp/default.mspx" target="_blank">http://www.microsoft.com/dynamics/gp/default.mspx</a><br />
<br />
Risk factor :<br />
<br />
None]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33392</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33391">
<title>Wordtrans-web advanced Parameter Command Execution Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote web server contains a PHP script that allows arbitrary<br />
command execution. <br />
<br />
Description :<br />
<br />
The remote host is running wordtrans-web, a web-based front-end for<br />
wordtrans, for translating words. <br />
<br />
The version of wordtrans-web installed on the remote host fails to<br />
sanitize input to the 'advanced' parameter of the 'wordtrans.php'<br />
script before using it in an 'passthru()' statement to execute PHP<br />
code.  Provided PHP's 'magic_quotes_gpc' setting is disabled, an<br />
unauthenticated attacker can leverage this issue to execute arbitrary<br />
code on the remote host subject to the privileges of the web server<br />
user id. <br />
<br />
See also :<br />
<br />
<a href="http://www.scanit.net/rd/advisories/adv02" target="_blank">http://www.scanit.net/rd/advisories/adv02</a><br />
<a href="http://www.scanit.net/rd/advisories/adv02_2" target="_blank">http://www.scanit.net/rd/advisories/adv02_2</a><br />
<a href="http://archives.neohapsis.com/archives/bugtraq/2008-07/0004.html" target="_blank">http://archives.neohapsis.com/archives/bugtraq/2008-07/0004.html</a><br />
<a href="http://archives.neohapsis.com/archives/bugtraq/2008-07/0005.html" target="_blank">http://archives.neohapsis.com/archives/bugtraq/2008-07/0005.html</a><br />
<br />
Solution :<br />
<br />
Unknown at this time. <br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.5<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33391</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33390">
<title>USN621-1 : Ruby vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
These remote packages are missing security patches :<br />
- irb1.8 <br />
- libdbm-ruby1.8 <br />
- libgdbm-ruby1.8 <br />
- libopenssl-ruby1.8 <br />
- libreadline-ruby1.8 <br />
- libruby1.8 <br />
- libruby1.8-dbg <br />
- libtcltk-ruby1.8 <br />
- rdoc1.8 <br />
- ri1.8 <br />
- ruby1.8 <br />
- ruby1.8-dev <br />
- ruby1.8-elisp <br />
- ruby1.8-examples <br />
<br />
<br />
Description :<br />
<br />
Drew Yao discovered several vulnerabilities in Ruby which lead to integer<br />
overflows. If a user or automated system were tricked into running a<br />
malicious script, an attacker could cause a denial of service or execute<br />
arbitrary code with the privileges of the user invoking the program.<br />
(CVE-2008-2662, CVE-2008-2663, CVE-2008-2725, CVE-2008-2726)<br />
<br />
Drew Yao discovered that Ruby did not sanitize its input when using ALLOCA.<br />
If a user or automated system were tricked into running a malicious script,<br />
an attacker could cause a denial of service via memory corruption.<br />
(CVE-2008-2664)<br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
- irb1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- libdbm-ruby1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- libgdbm-ruby1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- libopenssl-ruby1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- libreadline-ruby1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- libruby1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- libruby1.8-dbg-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- libtcltk-ruby1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- rdoc1.8-1.8.6.111-2ubuntu1.1 (Ubuntu 8.04)<br />
- ri1.8-1.8.6.111-2ubuntu1.1 (Ubuntu<br />
[...]<br />
<br />
<br />
Risk factor : High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33390</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33389">
<title>USN620-1 : OpenSSL vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
These remote packages are missing security patches :<br />
- libssl-dev <br />
- libssl0.9.8 <br />
- libssl0.9.8-dbg <br />
- openssl <br />
- openssl-doc <br />
<br />
<br />
Description :<br />
<br />
It was discovered that OpenSSL was vulnerable to a double-free<br />
when using TLS server extensions. A remote attacker could send a<br />
crafted packet and cause a denial of service via application crash<br />
in applications linked against OpenSSL. Ubuntu 8.04 LTS does not<br />
compile TLS server extensions by default. (CVE-2008-0891)<br />
<br />
It was discovered that OpenSSL could dereference a NULL pointer.<br />
If a user or automated system were tricked into connecting to a<br />
malicious server with particular cipher suites, a remote attacker<br />
could cause a denial of service via application crash.<br />
(CVE-2008-1672)<br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
- libssl-dev-0.9.8g-4ubuntu3.3 (Ubuntu 8.04)<br />
- libssl0.9.8-0.9.8g-4ubuntu3.3 (Ubuntu 8.04)<br />
- libssl0.9.8-dbg-0.9.8g-4ubuntu3.3 (Ubuntu 8.04)<br />
- openssl-0.9.8g-4ubuntu3.3 (Ubuntu 8.04)<br />
- openssl-doc-0.9.8g-4ubuntu3.3 (Ubuntu 8.04)<br />
<br />
<br />
<br />
Risk factor : High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33389</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33388">
<title>USN617-2 : Samba regression</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
These remote packages are missing security patches :<br />
- libpam-smbpass <br />
- libsmbclient <br />
- libsmbclient-dev <br />
- python-samba <br />
- python2.4-samba <br />
- samba <br />
- samba-common <br />
- samba-dbg <br />
- samba-doc <br />
- samba-doc-pdf <br />
- smbclient <br />
- smbfs <br />
- swat <br />
- winbind <br />
<br />
<br />
Description :<br />
<br />
USN-617-1 fixed vulnerabilities in Samba. The upstream patch<br />
introduced a regression where under certain circumstances accessing<br />
large files might cause the client to report an invalid packet<br />
length error. This update fixes the problem.<br />
<br />
We apologize for the inconvenience.<br />
<br />
Original advisory details:<br />
<br />
 Samba developers discovered that nmbd could be made to overrun<br />
 a buffer during the processing of GETDC logon server requests.<br />
 When samba is configured as a Primary or Backup Domain Controller,<br />
 a remote attacker could send malicious logon requests and possibly<br />
 cause a denial of service. (CVE-2007-4572)<br />
 <br />
 Alin Rad Pop of Secunia Research discovered that Samba did not<br />
 properly perform bounds checking when parsing SMB replies. A remote<br />
 attacker could send crafted SMB packets and execute arbitrary code.<br />
 (CVE-2008-1105)<br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
- libpam-smbpass-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- libsmbclient-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- libsmbclient-dev-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- python-samba-3.0.24-2ubuntu1.7 (Ubuntu 7.04)<br />
- python2.4-samba-3.0.22-1ubuntu3.8 (Ubuntu 6.06)<br />
- samba-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- samba-common-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- samba-dbg-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- samba-doc-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- samba-doc-pdf-3.0.28a-1ubuntu4.4 (Ubuntu 8.04)<br />
- smbclient-3.0.28a-1u<br />
[...]<br />
<br />
<br />
Risk factor : High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33388</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33387">
<title>SuSE Security Update: Security update for mtr (mtr-5291)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch mtr-5291.<br />
<br />
Description :<br />
<br />
This update fixes a stack based buffer overflow which could<br />
potentially be exploited by a remote attacker to execute<br />
arbitrary code (CVE-2008-2357).<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch mtr-5291.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33387</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33386">
<title>SuSE Security Update: mtr security update (mtr-5289)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch mtr-5289.<br />
<br />
Description :<br />
<br />
This update fixes a stack based buffer overflow which could<br />
potentially be exploited by a remote attacker to execute<br />
arbitrary code (CVE-2008-2357).<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch mtr-5289.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33386</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33385">
<title>SuSE Security Update: Security update for clamav (clamav-5359)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch clamav-5359.<br />
<br />
Description :<br />
<br />
Clamav was updated to version 0.93.1. It fixes various bugs<br />
and one security issue:<br />
<br />
CVE-2008-2713: libclamav/petite.c in ClamAV before 0.93.1<br />
allows remote attackers to cause a denial of service via a<br />
crafted Petite file that triggers an out-of-bounds read.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch clamav-5359.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33385</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33384">
<title>SuSE Security Update: clamav: security update to 0.93.1 (clamav-5356)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch clamav-5356.<br />
<br />
Description :<br />
<br />
This update brings clamav to version 0.93.1. It fixes<br />
various bugs and one security issue:<br />
<br />
CVE-2008-2713: libclamav/petite.c in ClamAV before 0.93.1<br />
allows remote attackers to cause a denial of service via a<br />
crafted Petite file that triggers an out-of-bounds read.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch clamav-5356.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33384</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33383">
<title>SuSE Security Update: Security update for bind (bind-5274)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch bind-5274.<br />
<br />
Description :<br />
<br />
The IP number for the 'L' root DNS server changed.<br />
<br />
This patch updates the root.hint zone file to get the new<br />
IP number.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch bind-5274.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33383</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33382">
<title>SuSE Security Update: bind: root.hint change (bind-5269)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch bind-5269.<br />
<br />
Description :<br />
<br />
The IP number for the 'L' root DNS server changed.<br />
<br />
This patch updates the root.hint zone file to get the new<br />
IP number.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch bind-5269.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33382</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33381">
<title>SuSE Security Update: php5: fixes multiple vulnerabilities (apache2-mod_php5-5379)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch apache2-mod_php5-5379.<br />
<br />
Description :<br />
<br />
This update of php5 fixes:<br />
- possible stack-based buffer overflow CVE-2008-2050<br />
- incomplete escapeshellcmd() CVE-2008-2051<br />
- printf() integer overflow CVE-2008-1384<br />
- insecure GENERATE_SEED macro CVE-2008-2107<br />
- timezone update for DST in Pakistan<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch apache2-mod_php5-5379.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33381</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33380">
<title>SuSE Security Update: Security update for ImageMagick (ImageMagick-5278)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch ImageMagick-5278.<br />
<br />
Description :<br />
<br />
ImageMagick and GraphicsMagick are affected by two security<br />
problems:<br />
<br />
CVE-2008-1096: Buffer overflow in the handling of XCF files<br />
CVE-2008-1097: Heap buffer overflow in the handling of PCX<br />
files<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch ImageMagick-5278.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33380</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33379">
<title>SuSE Security Update: ImageMagick: Fix security problems in XCF and PCX decoders (ImageMagick-5277)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch ImageMagick-5277.<br />
<br />
Description :<br />
<br />
ImageMagick is affected by two security problems:<br />
<br />
CVE-2008-1096: Buffer overflow in the handling of XCF files<br />
CVE-2008-1097: Heap buffer overflow in the handling of PCX<br />
files<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch ImageMagick-5277.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33379</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33378">
<title>SuSE Security Update: GraphicsMagick: Fix security problems in XCF and PCX decoders (GraphicsMagick-5276)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch GraphicsMagick-5276.<br />
<br />
Description :<br />
<br />
GraphicsMagick is affected by two security problems:<br />
<br />
CVE-2008-1096: Buffer overflow in the handling of XCF files<br />
CVE-2008-1097: Heap buffer overflow in the handling of PCX<br />
files<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch GraphicsMagick-5276.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33378</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=33377">
<title>RHSA-2008-0519: kernel</title>
<description><![CDATA[<br />
<br />
  Updated kernel packages that fix various security issues and a bug are now<br />
  available for Red Hat Enterprise Linux 5.<br />
<br />
  This update has been rated as having important security impact by the Red<br />
  Hat Security Response Team.<br />
<br />
  The kernel packages contain the Linux kernel, the core of any Linux<br />
  operating system.<br />
<br />
  These updated packages fix the following security issues:<br />
<br />
  * A security flaw was found in the Linux kernel memory copy routines, when<br />
  running on certain AMD64 systems. If an unsuccessful attempt to copy kernel<br />
  memory from source to destination memory locations occurred, the copy<br />
  routines did not zero the content at the destination memory location. This<br />
  could allow a local unprivileged user to view potentially sensitive data.<br />
  (CVE-2008-2729, Important)<br />
<br />
  * Tavis Ormandy discovered a deficiency in the Linux kernel 32-bit and<br />
  64-bit emulation. This could allow a local unprivileged user to prepare and<br />
  run a specially crafted binary, which would use this deficiency to leak<br />
  uninitialized and potentially sensitive data. (CVE-2008-0598, Important)<br />
<br />
  * Brandon Edwards discovered a missing length validation check in the Linux<br />
  kernel DCCP module reconciliation feature. This could allow a local<br />
  unprivileged user to cause a heap overflow, gaining privileges for<br />
  arbitrary code execution. (CVE-2008-2358, Moderate)<br />
<br />
  As well, these updated packages fix the following bug:<br />
<br />
  * Due to a regression, &quot;gettimeofday&quot; may have gone backwards on certain<br />
  x86 hardware. This issue was quite dangerous for time-sensitive systems,<br />
  such as those used for transaction systems and databases, and may have<br />
  caused applications to produce incorrect results, or even crash.<br />
<br />
  Red Hat Enterprise Linux 5 users are advised to upgrade to these updated<br />
  packages, which contain backported patches to resolve these issues.<br />
<br />
<br />
<br />
<br />
Solution : <a href="http://rhn.redhat.com/errata/RHSA-2008-0519.html" target="_blank">http://rhn.redhat.com/errata/RHSA-2008-0519.html</a><br />
Risk factor : High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=33377</link>
<dc:date>?</dc:date>
</item>
</rdf:RDF>
