Sun Security Blog
|
29 Nov 2005
Sun Alert 101974 OpenSSL (see openssl(5)) May Allow an Agent to Force a Rollback to a Cryptographically Weak Protocol Version
Product: Solaris 10 Operating System A vulnerability in the OpenSSL (see openssl(5)) toolkit may allow active protocol-version rollback attacks, where an attacker acting as a "man in the middle" can force a client and a server to negotiate the SSL 2.0 protocol even if these parties both support SSL 3.0 or TLS 1.0. The SSL 2.0 protocol is known to have severe cryptographic weaknesses and is supported as a fallback only. This issue is described in the following OpenSSL Advisory: http://www.openssl.org/news/secadv_20051011.txt and referenced in CAN-2005-2969 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-2969 Avoidance: Patch State: Resolved First released: 11-Oct-2005
Permalink
|
Comments [0]
28 Nov 2005
Sun Alert 102017 Security Vulnerability With Java Management Extensions in the Java Runtime Environment may Allow Untrusted Applet to Elevate Privileges
Product: Java 2 Platform, Standard Edition A vulnerability with the Java Management Extensions (JMX) implementation included with the Java Runtime Environment (JRE) may allow an untrusted applet to elevate its privileges. For example an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet. Sun acknowledges, with thanks, Adam Gowdiak, for bringing this issue to our attention. Avoidance: Upgrade State: Resolved First released: 28-Nov-2005
Permalink
|
Comments [0]
28 Nov 2005
Sun Alert 102050 Security Vulnerability With Java Runtime Environment May Allow Untrusted Applet to Elevate Privileges
Product: Java 2 Platform, Standard Edition A vulnerability in the Java Runtime Environment may allow an untrusted applet to elevate its privileges. For example, an applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet. Sun acknowledges, with thanks, Adam Gowdiak, for bringing this issue to our attention. Avoidance: Upgrade State: Resolved First released: 28-Nov-2005
Permalink
|
Comments [0]
28 Nov 2005
Sun Alert 102003 Security Vulnerabilities in the Java Runtime Environment May Allow an Untrusted Applet to Elevate Its Privileges
Product: Java 2 Platform, Standard Edition Three (3) security vulnerabilities with the use of "reflection" APIs in the Java Runtime Environment (JRE) may (independently) allow an untrusted applet to elevate its privileges. For example, an untrusted applet may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet. Sun acknowledges, with thanks, Adam Gowdiak, for bringing these issues to our attention. Avoidance: Upgrade State: Resolved First released: 28-Nov-2005
Permalink
|
Comments [0]
Product: VERITAS NetBackup 6.0, VERITAS NetBackup 5.1 Software, VERITAS NetBackup 4.5 Software, VERITAS NetBackup 3.4 Software, VERITAS NetBackup 5.0 Software A Security vulnerability affecting Java GUI applications "jnbSA" and "jbpSA" within Symantec/VERITAS NetBackup may allow a remote unprivileged user the ability to execute arbitrary code with elevated privileges on a targeted system. This issue is also described in VERITAS support document 279085: Avoidance: Patch, Upgrade, Workaround State: Resolved First released: 28-Nov-2005
Permalink
|
Comments [0]
Product: Solaris 9 Operating System, Solaris 10 Operating System, Sun Java Desktop System Release 2, Sun Java Desktop System 2003 A security vulnerability in the libexif JPEG image processing library may allow a remote unprivileged user who provides a carefully crafted JPEG image the ability to execute arbitrary code with the privileges of a local user who opens that image. Furthermore, a remote user may be able to create a Denial of Service (DOS) attack by using a carefully crafted JPEG image. This issue may occur with applications linked against the libexif library, including (but not limited to), the Eye of Gnome (eog) application, which is distributed as part of the Java Desktop System. Note: Most digital cameras produce EXIF files, which are Joint Photographic Experts Group (JPEG) files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags. This issue is described in the following documents: Avoidance: Patch, Workaround State: Resolved First released: 23-Nov-2005
Permalink
|
Comments [0]
23 Nov 2005
Sun Alert 102060 Security Vulnerabilities in the traceroute(1M) Utility may Allow Elevated Privileges
Product: Solaris 10 Operating System Multiple security vulnerabilities in the traceroute(1M) utility may allow an unauthorized local user the ability to execute arbitrary code with elevated privileges. The traceroute(1M) utility in Solaris 10 is privilege aware and thus the only additional privilege available is PRIV_NET_RAWACCESS (see privileges(5)). This limits the impact by only allowing access to the network layer. These issues are described in the following document: Avoidance: Patch, Workaround State: Resolved First released: 23-Nov-2005
Permalink
|
Comments [0]
22 Nov 2005
Sun Alert 102002 Security Vulnerability in the Sun ONE and Sun Java System Directory Server's and the Sun Java System Directory Proxy Server's HTTP Administrative Interface
Product: Sun Java System Directory Proxy Server 5.2, Sun Java System Directory Server 5.2, Sun ONE Directory Server 5.1, Sun ONE Administration Server 5.2 Software A security vulnerability in the Sun ONE and Sun Java System Directory Server's HTTP administrative interface may allow a local or remote unprivileged user the ability to kill the admin server or execute arbitrary commands on the system with the privileges of the admin server process. The admin server process normally runs as the privileged "root" user. The ability to kill the admin server is a type of Denial of Service. This issue is described in NGSSoftware SecurityTracker Alert ID 1015014 at: Sun acknowledges, with thanks, Peter Winter-Smith of NGSSoftware, for bringing this issue to our attention. Avoidance: Patch, Workaround State: Workaround First released: 22-Nov-2005
Permalink
|
Comments [1]
08 Nov 2005
Sun Alert 102030 The in.named(1M) Process May Make Unnecessary Queries Causing a Denial of Service
Product: Solaris 9 Operating System An unprivileged remote user may be able to cause a Denial of Service (DoS) of the Domain Name System (DNS) by causing in.named(1M) to make unnecessary queries to root servers for address records. Applications, systems and devices relying on the Domain Name System may then fail. Avoidance: Patch, Workaround State: Resolved First released: 08-Nov-2005
Permalink
|
Comments [0]
01 Nov 2005
Sun Alert 101948 Security Vulnerability in Sun Java System Communications Express Software
Product: Sun Java System Communications Express 2005Q1, Sun Java System Communications Express 2004Q2 A security vulnerability in the Sun Java Communications Express software may allow a local or remote unprivileged user the ability to read the Communications Express application configuration files which contain sensitive information. Avoidance: Patch State: Resolved First released: 01-Nov-2005
Permalink
|
Comments [0]
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||