Sun Security Blog
|
31 Oct 2006
Sun Alert 102670 A Vulnerability in Network Security Services (NSS) Affects Sun Java System Web Server and Sun ONE Application Server
Product: Sun ONE Application Server 7, Standard Edition, Sun Java System Web Server 6.0 Service Pack 8 A local or remote unprivileged user may be able to cause the Sun Java System Web Server or the Sun ONE Application Server to exit unexpectedly due to a security vulnerability in Network Security Services (NSS). The ability to disable a Sun Java System Web Server or a Sun ONE Application Server is a type of Denial of Service (DoS). Additional information about Network Security Services (NSS) is available at: Avoidance: Upgrade State: Resolved First released: 31-Oct-2006
Permalink
|
Comments [0]
28 Oct 2006
Sun Alert 102496 Security Vulnerability May Allow a Local Unprivileged User to Partially Read Arbitrary Files
Product: iPlanet Messaging Server 5.2 Patch 1, Sun Java System Messaging Server 6.0 A security vulnerability in the iPlanet Messaging Server and Sun Java System Messaging Server may allow a local unprivileged user to be able to read some data from any file on the system. This issue is also described in CVE-2006-3159: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3159 Avoidance: Patch, Workaround State: Resolved First released: 30-Jun-2006
Permalink
|
Comments [0]
24 Oct 2006
Sun Alert 102497 Security Vulnerability in Webmail May Allow Messages Embedded With Javascript to be Executed in End User's Browser
Product: Sun Java System Messaging Server 6.0, iPlanet Messaging Server 5.2 A security vulnerability in Sun Java System or iPlanet Messaging Servers may allow remote unprivileged users to craft specific messages which contain Javascript to be executed in the end user's browser. Sun acknowledges, with thanks, Seth Hall of Ohio State University, for bringing this issue to our attention. Avoidance: Patch State: Resolved First released: 24-Oct-2006
Permalink
|
Comments [0]
18 Oct 2006
Sun Alert 101643 Security Vulnerability in Samba(7) Versions Prior to 3.0.10 May Allow Unauthorized Root Privileges
Product: Solaris 9 Operating System, Solaris 10 Operating System An integer overflow security issue with the Samba(7) smbd(1m) daemon may allow a local or remote authenticated user the ability to execute arbitrary commands with the privileges of Super User (typically root), on a Solaris 9 or Solaris 10 system running as a Samba(7) server. More information on this issue is available at:
Avoidance: Patch, Workaround State: Resolved First released: 24-Jan-2005
Permalink
|
Comments [0]
17 Oct 2006
Sun Alert 101479 CDE dtsession Patches 113240-07, 113240-08, 109354-21, and 109354-22 WITHDRAWN, May Cause Lockscreen to Fail or Hang
Product: Solaris 9 Operating System, Solaris 8 Operating System Sun Ray servers running Solaris 8 or Solaris 9 with patches 113240-07, 113240-08, 109354-21, or 109354-22 installed, may fail to lock the screen when a Smartcard is removed and reinserted more than 90 seconds later. Removing and reinserting the Smartcard a second time may cause the lockscreen session to hang. Note: Patches 113240-07, 113240-08, 109354-21, and 109354-22 have been WITHDRAWN and are no longer available on SunSolve. Avoidance: Patch, Workaround State: Resolved First released: 09-Apr-2004
Permalink
|
Comments [0]
17 Oct 2006
Sun Alert 101783 Security Vulnerability in Samba's "ms_fnmatch()" Function May Result in a Denial of Service (DoS)
Product: Solaris 9 Operating System, Solaris 10 Operating System A security vulnerability in Samba's "ms_fnmatch()" function may allow a remote unprivileged user the ability to create a Denial of Service (DoS) by causing excessive CPU consumption via a Samba request that contains multiple wildcard characters. This issue is referenced in the following document:
Avoidance: Patch, Workaround State: Resolved First released: 23-Jun-2005
Permalink
|
Comments [0]
17 Oct 2006
Sun Alert 102667 Security Vulnerability in the Solaris 10 TCP Fusion Code May Lead to a System Panic, Resulting in a Denial of Service (DoS)
Product: Solaris 10 Operating System Solaris 10 systems may panic in the tcp_fuse_rcv_drain() TCP/IP function when using TCP loopback connections, where both ends of the connection are on the same system. This may allow a local unprivileged user to cause a Denial of Service (DoS) condition on the affected host. Avoidance: Patch, Workaround State: Resolved First released: 17-Oct-2006
Permalink
|
Comments [0]
11 Oct 2006
Sun Alert 102658 Security Vulnerability in the Netscape Portable Runtime (NSPR) API Affects Solaris
Product: Solaris 10 Operating System A security vulnerability in the Netscape Portable Runtime (NSPR) API may allow a local unprivileged user to overwrite or create any file on the system which could lead to privilege escalation or a Denial of Service (DoS). Additional information regarding this issue is available at:
Sun acknowledges with thanks, iDefense ( iDefense credits an anonymous researcher working with the iDefense Vulnerability Contributor Program for the discovery of this issue. Avoidance: Patch State: Resolved First released: 11-Oct-2006
Permalink
|
Comments [0]
06 Oct 2006
Sun Alert 102606 Security Vulnerability in Solaris 10 Link Aggregation may Allow Local Users Total Access to Network Packets
Product: Solaris 10 Operating System A security vulnerability resulting from incorrect and insufficient permission checks in the default Solaris 10 configuration may allow a local unprivileged user to create a raw socket on a Solaris link aggregation, resulting in unrestricted access to network packets. Avoidance: Patch State: Resolved First released: 06-Oct-2006
Permalink
|
Comments [0]
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||