Sun Security Blog
|
A security vulnerability in the TLS protocol (TLS 1.0 or later and SSLv3) may allow an unauthenticated, remote attacker to conduct man-in-the-middle (MITM) type of attacks where chosen plain text may be injected as a prefix in an user's TLS session. This vulnerability does not allow one to decrypt the intercepted network communication. This issue is referenced in CVE-2009-3555 Exact nature of the impact depends on the application making use of the TLS facility. Applications which use Network Security Services (NSS), Java Secure Socket Extensions (JSSE), OpenSSL or GnuTLS libraries may be affected. Sun is evaluating the impact of the issue on various products which make use of the TLS libraries. We are working to fix the TLS implementations according to the TLS protocol standard extensions currently being developed. tags: gnutls jsse nss openssl security tls vulnerability Permalink | Comments [0]
05 Nov 2009
Sun Alert 272230 Security Vulnerabilities in the Apache 2 "mod_perl2" Module Components "PerlRun.pm" and "Status.pm" May Lead to Denial of Service (DoS) or Unauthorized Access to Data
Product: Solaris 10, OpenSolaris Two security vulnerabilities exist in the Apache 2 mod_perl2(3) module CVE-2007-1349 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1349CVE-2009-0796 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0796State: Preliminary First released: 05-Nov-2009
Permalink
|
Comments [0]
Product: Solaris 8, Solaris 9, Solaris 10 A remote unprivileged user may be able to crash an application which dynamically links to the Portable Network Graphics library (libpng(3)) due to a security vulnerability in libpng(3). The ability to crash an application is a type of Denial of Service (DoS). A number of applications which comprise the GNOME desktop environment dynamically link with libpng(3). This issue is described in the following documents:
State: Workaround First released: 28-Jun-2007
Permalink
|
Comments [0]
04 Nov 2009
Sun Alert 266388 Security Vulnerability in Solaris SCTP (Stream Control Transmission Protocol (see sctp(7P)) and SDP (Sockets Direct Protocol driver (see sdp(7D)) sockets May Allow Unprivileged Users to Cause a Denial of Service (DoS) Condition
Product: OpenSolaris A security vulnerability in SCTP (Stream Control Transmission Protocol (see sctp(7P))) and SDP (Sockets Direct Protocol driver (see sdp(7D))) sockets may allow local unprivileged users to leak kernel memory, thereby causing a Denial of Service (DoS) condition. State: Resolved First released: 04-Nov-2009
Permalink
|
Comments [0]
03 Nov 2009
Sun Alert 269868 The Java Update Mechanism on Non-English Versions Does Not Update the JRE When a New Version is Available
Product: Java Platform, Standard Edition (Java SE) The Java Runtime Environment (JRE) Java Update mechanism running on non-English versions of the Windows operating system does not update the JRE when a new version is available. Sun acknowledges with thanks, Tomasz "Tometzky" Ostrowski for bringing this issue to our attention. State: Resolved First released: 03-Nov-2009
Permalink
|
Comments [0]
03 Nov 2009
Sun Alert 270476 Two Security Vulnerabilities in the Java Runtime Environment With Decoding DER Encoded Data and Parsing HTTP Headers may Result in a Denial of Service (DoS)
Product: Java Platform, Standard Edition (Java SE) Two vulnerabilities in the Java Runtime Environment with decoding DER encoded data and parsing HTTP headers may separately allow a remote client to cause the JRE on the server to run out of memory, resulting in a DoS (Denial of Service) condition. Sun acknowledges with thanks, BFK edv-consulting GmbH, for bringing the first issue to our attention. State: Resolved First released: 03-Nov-2009
Permalink
|
Comments [0]
03 Nov 2009
Sun Alert 270475 A Security Vulnerability in the Java Runtime Environment With Verifying HMAC Digests may Allow Authentication to be Bypassed
Product: Java Platform, Standard Edition (Java SE) A security vulnerability in the Java Runtime Environment with verifying HMAC digests may allow authentication to be bypassed. This could allow a user to forge a digital signature that would be accepted as valid. Applications that validate HMAC-based digital signatures may be vulnerable to this type of attack. Note: This vulnerability cannot be exploited by an untrusted applet or Java Web Start application. Sun acknowledges, with thanks, Coda Hale for bringing this issue to our attention. State: Resolved First released: 03-Nov-2009
Permalink
|
Comments [0]
03 Nov 2009
Sun Alert 269869 Command Execution Vulnerability in the Java Runtime Environment Deployment Toolkit May be Leveraged to Execute Arbitrary Code
Product: Java Platform, Standard Edition (Java SE) A command execution vulnerability in the Java Runtime Environment Deployment Toolkit may be leveraged to execute arbitrary code. This may occur as the result of a user of the Java Runtime Environment viewing a specially crafted web page that exploits this vulnerability. Sun acknowledges with thanks, an anonymous researcher working with iDefense for bringing this issue to our attention. State: Resolved First released: 03-Nov-2009
Permalink
|
Comments [0]
03 Nov 2009
Sun Alert 270474 Buffer and Integer Overflow Vulnerabilities in the Java Runtime Environment With Processing Audio and Image Files May Allow Privileges to be Escalated
Product: Java Platform, Standard Edition (Java SE) Multiple buffer and integer overflow vulnerabilities in the Java Runtime Environment with processing audio and image files may allow an untrusted applet or Java Web Start application to escalate privileges. For example, an untrusted applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet. Sun acknowledges with thanks, the following researchers for bringing these issues to our attention: CR 6854303: An anonymous researcher, working with the Zero Day Initiative (http://www.zerodayinitiative.com) and TippingPoint (http://www.tippingpoint.com). CR 6862970: An anonymous researcher working with the iDefense VCP (http://labs.idefense.com/vcp/). CR 6872357 and CR 6872358: Peter Vreugdenhil, working with the Zero Day Initiative (http://www.zerodayinitiative.com) and TippingPoint (http://www.tippingpoint.com). CR 6872358, CR 6862969 and CR 6862968: regenrecht working with iDefense VCP (http://labs.idefense.com/vcp/). CR 6874643: regenrecht working with Zero Day Initiative (http://www.zerodayinitiative.com) and TippingPoint (http://www.tippingpoint.com). State: Resolved First released: 03-Nov-2009
Permalink
|
Comments [0]
03 Nov 2009
Sun Alert 268328 A Security Vulnerability in Sun Virtual Desktop Infrastructure (VDI) Software 3.0 may Lead to Unauthorized Access to the VirtualBox Web Service
Product: Sun Virtual Desktop Infrastructure (VDI) Software 3.0 State: Resolved First released: 03-Nov-2009
Permalink
|
Comments [0]
03 Nov 2009
Sun Alert 269870 Security Vulnerability in the Java Web Start Installer May be Leveraged to Allow Untrusted Java Web Start Application to Run As Trusted Application
Product: Java Platform, Standard Edition (Java SE) A security vulnerability in the Java Web Start Installer may be leveraged to allow an untrusted Java Web Start application to run as a trusted application and execute arbitrary code. This may occur when a user opens a specially crafted web page that exploits this vulnerability. Sun acknowledges with thanks, Peter Csepely, working with the Zero Day Initiative (http://www.zerodayinitiative.com/) and TippingPoint (http://www.tippingpoint.com/) for bringing this issue to our attention. State: Resolved First released: 03-Nov-2009
Permalink
|
Comments [0]
02 Nov 2009
Sun Alert 270408 Security Vulnerabilities in PostgreSQL Shipped with Solaris may Allow a Denial of Service (DoS) or Privilege Escalation
Product: Solaris 10, OpenSolaris Security vulnerabilities affecting the PostgreSQL software shipped with Solaris may allow an authenticated PostgreSQL user to cause a denial of service (DoS) to the PostgreSQL server by "re-LOAD-ing" libraries from a certain plugins directory. However, the PostgreSQL versions shipped with Solaris do not include any plugins. In addition, an issue with the privileges for RESET ROLE and RESET SESSION AUTHORIZATION operations may allow any authenticated users to gain extra privileges. These issues are described in the following documents: Official PostgreSQL announcement at: http://www.postgresql.org/about/news.1135 CVE-2009-3229 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3229 CVE-2009-3230 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3230 Note: PostgreSQL is not compiled with LDAP support on Solaris. Solaris is not affected with CVE-2009-3231. State: Resolved First released: 26-Oct-2009
Permalink
|
Comments [0]
02 Nov 2009
Sun Alert 266348 Security Vulnerability in the w(1) Utility may Lead to Execution of Arbitrary Code
Product: Solaris 8, Solaris 9, Solaris 10, OpenSolaris A heap overflow vulnerability in the w(1) utility may allow a local unprivileged user to execute arbitrary code with root privileges. Sun acknowledges with thanks, Monarch Rich "1c239c43f521145fa8385d64a9c32243 http://unsecurityresearch.blogspot.com" for discovering and reporting this issue. State: Resolved First released: 10-Sep-2009
Permalink
|
Comments [0]
02 Nov 2009
Sun Alert 264730 A Security Vulnerability in Solaris Sockets Direct Protocol (SDP) Driver (sdp(7D)) may Allow Users to Exhaust Kernel Memory
Product: Solaris 10, OpenSolaris A security vulnerability in Solaris Sockets Direct Protocol (SDP) driver (sdp(7D)) may allow a local or remote unprivileged user to exhaust all kernel memory. This is a type of Denial of Service (DoS). Note: No applications bundled with Solaris are affected by this issue however third-party applications which make use of SDP may be affected. State: Resolved First released: 02-Nov-2009
Permalink
|
Comments [0]
29 Oct 2009
Sun Alert 270809 Security Vulnerability in Solaris Trusted Extensions may Prevent XScreenSaver (xscreensaver(1)) From Running
Product: Solaris 10 A security vulnerability in Solaris Trusted Extensions may result in a condition that prevents XScreenSaver (xscreensaver(1)) from running. The screen may not lock if a user chooses to lock the screen from the JDS menu or if the screen is left unattended. This condition occurs when trying to restart XScreenSaver using "xscreensaver-demo". State: Resolved First released: 29-Oct-2009
Permalink
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||