Sun Security Blog
|
02 Dec 2009
Sun Alert 273630 Multiple Security Vulnerabilities in the libexpat Library May Lead to a Denial of Service (DoS) Condition
Product: Solaris 10, OpenSolaris Multiple security vulnerabilities have been identified in libexpat, a library for parsing XML files. These vulnerabilities may allow a local or remote unprivileged user to create a crafted XML file that may cause an application linked with libexpat to crash, resulting in a Denial of Service (DoS) condition. Additional information regarding these issues is available at: CVE-2009-3720 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720 CVE-2009-3560 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560 State: Workaround First released: 02-Dec-2009
Permalink
|
Comments [0]
02 Dec 2009
Sun Alert 273551 Two Security Vulnerabilities in GNU tar (see gtar(1)) May Lead to Files Being Overwritten, Execution of Arbitrary Code, or a Denial of Service (DoS)
Product: Solaris 9, Solaris 10, OpenSolaris Two security vulnerabilities have been found in the GNU tar gtar(1) archiving program bundled with Solaris 9, Solaris 10 and OpenSolaris. The first issue is a directory traversal vulnerability that may allow a local or remote unprivileged user who provides a specially crafted archive to overwrite arbitrary files which the user executing gtar(1) has permission to modify. The second issue is a buffer overflow which may allow a local or remote unprivileged user who provides a specially crafted tar archive to execute arbitrary commands with the privileges of the user executing gtar(1) or to cause gtar(1) to crash. The ability to cause a program crash is a type of Denial of Service (DoS). Additional information regarding these issues is available at:
State: Workaround First released: 02-Dec-2009
Permalink
|
Comments [0]
02 Dec 2009
Sun Alert 266428 Multiple Security Vulnerabilities in the XML Library (see libxml2(3)) Bundled With Sun Management Center (SunMC) May Result in Arbitrary Code Execution or a Denial of Service (DoS)
Product: Sun Management Center 3.6, Sun Management Center 3.6.1, Sun Management Center 4.0 Multiple security vulnerabilities in the XML library (see libxml2(3)) bundled with Sun Management Center 3.6.1 and 4.0 may allow a local or remote unprivileged user to execute arbitrary code with the privileges of the SunMC application or crash the SunMC application causing a Denial of Service (DoS) by providing a specially crafted XML file. The SunMC application runs with root privileges. Additional information regarding these issues is available in the following documents: CVE-2008-3529 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3529 CVE-2008-4225 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4225 CVE-2008-4226 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4226 State: Resolved First released: 02-Dec-2009
Permalink
|
Comments [0]
A security vulnerability in the TLS protocol (TLS 1.0 or later and SSLv3) may allow an unauthenticated, remote attacker to conduct man-in-the-middle (MITM) type of attacks where chosen plain text may be injected as a prefix in an user's TLS session. This vulnerability does not allow one to decrypt the intercepted network communication. This issue is referenced in CVE-2009-3555 and US-CERT VU#120541 Exact nature of the impact depends on the application making use of the TLS facility. Applications which use Network Security Services (NSS), Java Secure Socket Extensions (JSSE), OpenSSL or GnuTLS libraries may be affected. Sun is evaluating the impact of the issue on various products which make use of the TLS libraries. We are working to fix the TLS implementations according to the TLS protocol standard extensions currently being developed. Solaris Kernel SSL proxy module KSSL does not support client renegotiation or rehandshake. It ignores the rehandshake message which is an allowed behavior by the SSL/TLS specification. Hence it is not vulnerable to this issue. KSSL (see ksslcfg(1M)) is available in Solaris 10 and OpenSolaris. It may be used to workaround the described issue in server applications. The issue does not affect any server applications distributed with Solaris which use the GnuTLS library. At this time we do not plan to issue any interim fixes to GnuTLS libraries. Fixes to GnuTLS distributed with Solaris would be provided when the proposed TLS extensions become a standard. Following Sun Alerts provide more information about this issue:
tags: gnutls jsse nss openssl security tls vulnerability Permalink | Comments [0]
01 Dec 2009
Sun Alert 273350 Security Vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer 3.0 (SSLv3) Protocols Involving Handshake Renegotiation Affects Network Security Services (NSS)
Product: Sun Java Enterprise System 5, Sun Java Enterprise System 2005Q4, Solaris 8, Solaris 9, Solaris 10, OpenSolaris A security vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer 3.0 (SSLv3) protocols in the handling of session renegotiations affects Network Security Services (NSS). This issue may allow a remote unauthenticated user with the ability to intercept and control network traffic to perform a man-in-the-middle (MITM) attack to inject arbitrary plain text at the beginning of the application protocol stream, thus compromising the integrity of the communication. This vulnerability does not allow one to decrypt the intercepted network communication. Sun acknowledges with thanks, Marsh Ray and Steve Dispensa of PhoneFactor for bringing this issue to our attention. This issue is also referenced in the following documents: CVE-2009-3555 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555 US-CERT VU#120541 at http://www.kb.cert.org/vuls/id/120541 State: Workaround First released: 01-Dec-2009
Permalink
|
Comments [2]
01 Dec 2009
Sun Alert 269468 Security Vulnerability in Mozilla Thunderbird Related to SSL Certificates May Cause Arbitrary Code Execution
Product: Solaris 10, OpenSolaris Security vulnerabilities in thunderbird(1) related to handling of SSL server certificates http://www.mozilla.org/security/announce/2009/mfsa2009-43.html
CVE-2009-2408 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408 State: Preliminary First released: 09-Oct-2009
Permalink
|
Comments [0]
01 Dec 2009
Sun Alert 269368 Cross-Site Scripting (XSS) Vulnerabilities in Sun Java System Portal Server's Gateway May Lead to Execution of Arbitrary Code
Product: Sun Java System Portal Server 6.3.1, Sun Java System Portal Server 7.1, Sun Java System Portal Server 7.2 Multiple Cross-Site Scripting (XSS) security vulnerabilities exist in Sun Java System Portal Server's Gateway that may allow remote users to execute arbitrary JavaScript code in a user's web browser. State: Resolved First released: 01-Dec-2009
Permalink
|
Comments [0]
30 Nov 2009
Sun Alert 270669 Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 May Allow Execution of Arbitrary Code or Cause Denial of Service (DoS) - Adobe Security Bulletin APSB09-15
Product: Solaris 10 Multiple security vulnerabilities in Adobe Reader versions 9.x before 9.1.4, 8.x before 8.1.7 and 7.x before 7.1.4 may allow remote unprivileged users to execute arbitrary code or crash the Adobe Reader application, thereby causing a Denial of Service (DoS) condition. These vulnerabilities may be exploited via specially crafted PDF files. The following resources document these issues in more detail: Adobe Security Bulletin APSB09-15 at http://www.adobe.com/support/security/bulletins/apsb09-15.html CVE-2009-2564 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2564 CVE-2009-2979 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2979 CVE-2009-2980 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2980 CVE-2009-2981 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2981 CVE-2009-2982 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2982 CVE-2009-2983 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2983 CVE-2009-2984 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2984 CVE-2009-2985 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2985 CVE-2009-2986 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2986 CVE-2009-2987 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2987 CVE-2009-2988 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2988 CVE-2009-2989 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2989 CVE-2009-2990 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2990 CVE-2009-2991 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2991 CVE-2009-2992 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2992 CVE-2009-2993 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2993 CVE-2009-2994 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2994 CVE-2009-2995 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2995 CVE-2009-2996 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2996 CVE-2009-2997 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2997 CVE-2009-2998 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2998 CVE-2009-3431 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3431 CVE-2009-3458 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3458 CVE-2009-3459 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3459 CVE-2009-3460 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3460 CVE-2009-3461 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3461 CVE-2009-3462 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3462 CVE-2007-0045 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045 CVE-2007-0048 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0048 State: Resolved First released: 22-Oct-2009
Permalink
|
Comments [0]
29 Nov 2009
Sun Alert 273169 Security Vulnerability in BIND DNS Software Shipped With Solaris May Allow DNS Cache Poisoning
Product: Solaris 9, Solaris 10, OpenSolaris A security vulnerability in the BIND DNS software shipped with Solaris may allow a remote user who is able to perform recursive queries to cause a server that is configured to support DNSSEC validation and recursive client queries to return incorrect addresses for Internet hosts, thereby redirecting end users to unintended hosts or services. This issue is also mentioned in the following document: State: Workaround First released: 24-Nov-2009
Permalink
|
25 Nov 2009
Sun Alert 269869 Command Execution Vulnerability in the Java Runtime Environment Deployment Toolkit May be Leveraged to Execute Arbitrary Code
Product: Java Platform, Standard Edition (Java SE) A command execution vulnerability in the Java Runtime Environment Deployment Toolkit may be leveraged to execute arbitrary code. This may occur as the result of a user of the Java Runtime Environment viewing a specially crafted web page that exploits this vulnerability. Sun acknowledges with thanks, an anonymous researcher working with iDefense for bringing this issue to our attention. State: Resolved First released: 03-Nov-2009
Permalink
|
Product: Solaris 8, Solaris 9, Solaris 10, OpenSolaris Multiple security vulnerabilities in the LDAP client configuration cache daemon (ldap_cachemgr(1M)) may allow a local unprivileged user to terminate the ldap_cachemgr daemon. On Solaris 9 and 10 systems this will prevent LDAP name service requests from succeeding. This is a type of Denial of Service (DoS) as LDAP name service requests will hang and users may no longer be able to login to LDAP client systems. On Solaris 8 systems, LDAP name service requests will be slower, as caching will not occur which is also a type of Denial of Service (DoS). State: Workaround First released: 24-Nov-2009
Permalink
|
24 Nov 2009
Sun Alert 272909 Multiple Security Vulnerabilities in Firefox Versions Before 3.5.5 May Allow Execution of Arbitrary Code or Unauthorized Access to Certain Data
Product: OpenSolaris Multiple security vulnerabilities with varying impacts affect Firefox (see firefox(1)) versions prior to 3.5.3 as shipped with OpenSolaris. These vulnerabilities may allow an unprivileged remote user to steal content from the "History" or "Smart Location" bar, or to possibly execute arbitrary code on the system where Firefox is being run. Further vulnerabilities may allow a remote user to run malicious JavaScript at Chrome privileges or perform a cross-origin data theft. The following Mozilla advisories describe the vulnerabilities: MFSA 2009-64 at http://www.mozilla.org/security/announce/2009/mfsa2009-64.html MFSA 2009-63 at http://www.mozilla.org/security/announce/2009/mfsa2009-63.html MFSA 2009-62 at http://www.mozilla.org/security/announce/2009/mfsa2009-62.html MFSA 2009-61 at http://www.mozilla.org/security/announce/2009/mfsa2009-61.html MFSA 2009-59 at http://www.mozilla.org/security/announce/2009/mfsa2009-59.html MFSA 2009-57 at http://www.mozilla.org/security/announce/2009/mfsa2009-57.html MFSA 2009-56 at http://www.mozilla.org/security/announce/2009/mfsa2009-56.html MFSA 2009-55 at http://www.mozilla.org/security/announce/2009/mfsa2009-55.html MFSA 2009-54 at http://www.mozilla.org/security/announce/2009/mfsa2009-54.html MFSA 2009-53 at http://www.mozilla.org/security/announce/2009/mfsa2009-53.html MFSA 2009-52 at http://www.mozilla.org/security/announce/2009/mfsa2009-52.html
CVE-2009-3383 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3383 CVE-2009-3382 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3382 CVE-2009-3381 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3381 CVE-2009-3380 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3380 CVE-2009-3379 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3379 CVE-2009-3378 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3378 CVE-2009-3377 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3377 CVE-2009-3376 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3376 CVE-2009-3375 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3375 CVE-2009-1563 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1563 CVE-2009-3374 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3374 CVE-2009-3373 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3373 CVE-2009-3372 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3372 CVE-2009-3371 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3371 CVE-2009-3274 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3274 CVE-2009-3370 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3370 State: Resolved First released: 24-Nov-2009
Permalink
|
23 Nov 2009
Sun Alert 272629 Security Vulnerability in the Timeout Mechanism of Solaris sshd(1M) may Lead to a Denial of Service (DoS)
Product: Solaris 10, OpenSolaris A security vulnerability in the timeout mechanism of Solaris sshd(1M) may allow a remote unprivileged user to cause a Denial of Service (DoS) condition. If this issue is exploited, the sshd(1M) daemon will stop accepting new ssh(1) connections. State: Resolved First released: 23-Nov-2009
Permalink
|
Comments [1]
17 Nov 2009
Sun Alert 271069 Two Security Vulnerabilities in SAMBA(7) May Allow Unauthorized Access to the Remote Root Filesystem or May Lead to a Denial of Service (DoS) Condition
Product: Samba 3.0.36, Solaris 9, Solaris 10 operating System, OpenSolaris Two security vulnerabilities in SAMBA(7) may result in one or both of the following issues: 1. A remote unprivileged user with a valid SAMBA account may gain unauthorized access to the remote root file system. This issue is referenced in the following CVE document:
State: Workaround First released: 17-Nov-2009
Permalink
|
11 Nov 2009
Sun Alert 263388 Security Vulnerabilities in Solaris IP(7P) Module and STREAMS Framework May Lead to a Denial of Service (DoS) Condition
Product: Solaris 8, Solaris 9, Solaris 10, OpenSolaris Security vulnerabilities in the Solaris IP(7P) module and STREAMS Framework may allow an unprivileged local user to leak kernel memory, eventually causing the system to hang. This is a type of Denial of Service (DoS). State: Resolved First released: 30-Sep-2009
Permalink
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||