Sun Security Blog
|
29 Sep 2006
Sun Alert 102650 Cross-site Scripting Vulnerabilities in the Sun Secure Global Desktop Software
Product: Sun Secure Global Desktop Software 4.2 Two Cross Site Scripting vulnerabilities in the Sun Secure Global Desktop (SSGD) software may allow a local or remote unprivileged user to execute arbitrary script commands in another user's context, potentially allowing an unprivileged remote user to steal cookie information, hijack sessions, or cause a loss of data privacy between a client and the server. Sun acknowledges, with thanks, Marc Ruef of scip AG for bringing this issue to our attention. Avoidance: Upgrade State: Resolved First released: 29-Sep-2006
Permalink
|
Comments [0]
28 Sep 2006
Sun Alert 102144 Vulnerability With Solaris IPv6 May Allow a Remote User the Ability to Create a Denial of Service Condition
Product: Solaris 9 Operating System, Solaris 10 Operating System, Solaris 8 Operating System On Solaris 8, 9 and 10 systems utilizing an IPv6 address, a remote unprivileged user may be able to panic the system, causing a Denial of Service (DoS) condition. Avoidance: Patch State: Resolved First released: 28-Sep-2006
Permalink
|
Comments [0]
26 Sep 2006
Sun Alert 102563 A Remote SSL Client May be Able to Cause a Denial of Service (DoS) of a Solaris 10 System Running a Kernel SSL Service Instance
Product: Solaris 10 Operating System A security vulnerability in the Solaris 10 kernel SSL feature may allow a remote unprivileged user acting as an SSL client to panic the system, creating a Denial of Service (DoS) condition. Avoidance: Patch, Workaround State: Resolved First released: 26-Sep-2006
Permalink
|
Comments [0]
25 Sep 2006
Sun Alert 102568 A Security Issue With Solaris 10 x64 Systems Using IPv6 Forwarding May Result in a Denial of Service (DoS)
Product: Solaris 10 Operating System for x86 Platforms Solaris 10 x64 systems configured to use Internet Protocol Version 6 (ip6(7P)) may panic when processing certain IPv6 packets. A local or remote unprivileged user may be able to send IPv6 packets that could panic the system causing a Denial of Service (DoS). Avoidance: Patch, Workaround State: Resolved First released: 25-Sep-2006
Permalink
|
Comments [0]
Product: Solaris 9 Operating System, Solaris 10 Operating System, Solaris 8 Operating System A security vulnerability may allow a local unprivileged user to disable the syslog(3c) function, resulting in the failure of messages to be written to the system log. Disabling of system logging constitutes a Denial of Service (DoS). Avoidance: Patch State: Resolved First released: 25-Sep-2006
Permalink
|
Comments [0]
Product: Solaris 9 Operating System, Solaris 10 Operating System, Solaris 8 Operating System A buffer overflow vulnerability in libX11 may allow local unprivileged users to be able to execute arbitrary code or commands with elevated privileges. The code or commands executed would run with the privileges of the application dynamically linked to the libX11 library. A number of programs shipped in Solaris and by third parties dynamically link with the libX11 library and run with elevated privileges. Sun acknowledges with thanks, RISE Security, for bringing this issue to our attention. This issue is also referenced in: http://www.risesecurity.org/advisory/RISE-2006001.txt Avoidance: Patch, Workaround State: Resolved First released: 07-Sep-2006
Permalink
|
Comments [0]
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||