Sun Security Blog
|
31 Aug 2009
Sun Alert 266108 Multiple Security Vulnerabilities in the Flash Player for Solaris 10 (Adobe Security Bulletin APSB09-10)
Product: Solaris 10 Operating System OpenSolaris Multiple security vulnerabilities in Adobe Flash Player 9.0.159.0 and earlier 9.x versions and 10.0.22.87 and earlier 10.x versions may allow remote unprivileged users to execute arbitrary code with the privileges of a local user on the system or to cause Adobe Flash Player to crash which is a type of Denial of Service (DoS). Also a clickjacking vulnerability in the Adobe Flash Player may allow a remote user to trick a user into selecting a link or completing a dialog. In addition, a local sandbox vulnerability in the Adobe Flash Player may allow a remote user to obtain sensitive information via vectors involving saving a malicious SWF file to a hard drive. These issues are also described in the following documents: APSA09-03 at: http://www.adobe.com/support/security/advisories/apsa09-03.html APSB09-10 at: http://www.adobe.com/support/security/bulletins/apsb09-10.html CVE-2009-1862 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1862 CVE-2009-1864 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1864 CVE-2009-1865 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1865 CVE-2009-1866 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1866 CVE-2009-1867 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1867 CVE-2009-1868 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1868 CVE-2009-1869 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1869 CVE-2009-1870 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1870 State: Resolved First released: 21-Aug-2009
Permalink
|
27 Aug 2009
Sun Alert 255308 A Security Vulnerability May Allow Popup Windows to Appear Through the Solaris XScreenSaver Program
Product: Solaris 8 Operating System Solaris 9 Operating System Solaris 10 Operating System OpenSolaris A security vulnerability in the Solaris XScreenSaver (see xscreensaver(1)) program may allow popup windows to appear through the lock screen and expose sensitive data. An example application affected by this issue is Thunderbird, which notifies users about new mail through popup windows. State: Resolved First released: 07-Apr-2009
Permalink
|
25 Aug 2009
Sun Alert 264608 A Security Vulnerability in the Solaris Print Service (in.lpd(1M)) May Lead to a Denial of Service (DoS) Condition
Product: Solaris 8 Operating System Solaris 9 Operating System A security vulnerability in the Solaris print service (see in.lpd(1M)) may allow a local or remote unprivileged user to cause the system to slow down and become unresponsive. This is a type of Denial of Service (DoS). State: Resolved First released: 25-Aug-2009
Permalink
|
21 Aug 2009
Sun Alert 265248 Security Vulnerability in Solaris pollwakeup(9F) May Allow an Unprivileged User to Panic the System
Product: Solaris 10 Operating System OpenSolaris A security vulnerability in Solaris pollwakeup(9F) may allow a local unprivileged user Sun acknowledges, with thanks, Jason Hoos for bringing this issue to our attention. State: Resolved First released: 21-Aug-2009
Permalink
|
21 Aug 2009
Sun Alert 266148 Multiple Security Vulnerabilities in Firefox Versions Prior to 3.5.2 May Allow Execution of Arbitrary Code or Application Crash
Product: OpenSolaris Multiple security vulnerabilities with varying impacts affect Firefox (see firefox(1)) versions prior to 3.5.2 as shipped with OpenSolaris. These vulnerabilities may allow an unprivileged remote user to execute arbitrary code on the system where Firefox is being run or to crash the Firefox application which is a type of Denial of Service (DoS). The following URL provides additional details about the vulnerabilities addressed in Firefox versions 3.5.1 and 3.5.2:
MFSA 2009-35 at http://www.mozilla.org/security/announce/2009/mfsa2009-35.html MFSA 2009-38 at http://www.mozilla.org/security/announce/2009/mfsa2009-38.html MFSA 2009-41 at http://www.mozilla.org/security/announce/2009/mfsa2009-41.html MFSA 2009-44 at http://www.mozilla.org/security/announce/2009/mfsa2009-44.html MFSA 2009-45 at http://www.mozilla.org/security/announce/2009/mfsa2009-45.html MFSA 2009-46 at http://www.mozilla.org/security/announce/2009/mfsa2009-46.html
CVE-2009-2467 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2467 CVE-2009-2470 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2470 CVE-2009-2477 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2477 CVE-2009-2654 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2654 State: Resolved First released: 21-Aug-2009
Permalink
|
21 Aug 2009
Sun Alert 239392 Security Vulnerability in the DNS Protocol May Lead to DNS Cache Poisoning
Product: Solaris 8 Operating System Solaris 9 Operating System Solaris 10 Operating System OpenSolaris A security vulnerability in the DNS protocol may allow remote unprivileged users to cause named(1M) to return incorrect addresses for Internet hosts, thereby redirecting end users to unintended hosts or services. This issue is also referenced in the following documents: US-CERT Vulnerability Note VU#800113 at http://www.kb.cert.org/vuls/id/800113 CVE-2008-1447 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447 State: Resolved First released: 08-Jul-2008
Permalink
|
Comments [4]
20 Aug 2009
Sun Alert 265808 Multiple Integer Overflow Vulnerabilities in the libtiff(3) Image Conversion Tools 'tiff2rgba' and 'rgb2ycbcr' May Lead to Arbitrary Code Execution
Product: Solaris 8 Operating System Solaris 9 Operating System Solaris 10 Operating System OpenSolaris Multiple integer overflow vulnerabilities in the libtiff(3) image conversion tools 'tiff2rgba' and 'rgb2ycbcr' may allow a local or remote unprivileged user to execute arbitrary code via a TIFF image with large width and height values. This issue is also described in the following document: CVE-2009-2347 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2347 State: Workaround First released: 14-Aug-2009
Permalink
|
19 Aug 2009
Sun Alert 246746 An IP(7P) Spoofing Security Vulnerability in Mid-range Sun Fire Server's Firmware May Allow Unauthorized Access to System Controllers
Product: Sun Fire 3800 Server Sun Fire 4800 Server Sun Fire 4810 Server Sun Fire 6800 Server Sun Fire E2900 Server Sun Fire E4900 Server Sun Fire E6900 Server Sun Fire V1280 Server Netra 1280 Server Sun Netra 1290 Server An IP(7P) spoofing security vulnerability in certain Mid-range Sun Fire Server's firmware may allow a remote privileged/unprivileged user to gain unauthorized access to the System Controller (SC). Such users may also gain access to the system console and possibly the host operating system running on these servers.This may allow such users to power off or reset the system which is a type of Denial of Service (DoS). State: Resolved First released: 12-Dec-2008
Permalink
|
18 Aug 2009
Sun Alert 258588 Security Vulnerability in the Solaris sendfile(3EXT) and sendfilev(3EXT) Extended Library Functions may Result in a Denial of Service (DoS) Condition due to a System Panic
Product: Solaris 8 Solaris 9 Solaris 10 OpenSolaris A security vulnerability in the Solaris sendfile(3EXT) and sendfilev(3EXT) extended library functions may allow a local unprivileged user to panic the system, causing a Denial of Service (DoS). State: Resolved First released: 18-Aug-2009
Permalink
|
17 Aug 2009
Sun Alert 257848 Security Vulnerability in the Solaris Kernel Involving the Interaction of the Filesystem and Virtual Memory Subsystems
Product: Solaris 8 Operating System Solaris 9 Operating System Solaris 10 Operating System OpenSolaris A security vulnerability in the Solaris kernel related to the interaction of the filesystem and virtual memory subsystems may allow a local unprivileged user to cause the system to slow down and eventually cease operating, thereby resulting in a Denial of Service (DoS). State: Resolved First released: 17-Aug-2009
Permalink
|
14 Aug 2009
Sun Alert 257329 A Security Vulnerability in Certain System Board Firmware Revisions of Sun Fire V215 Servers with XVR-100 Graphic Cards may Allow an Unprivileged User to Panic the System
Product: Sun Fire V215 Server On Sun Fire V215 servers with XVR-100 graphic cards and certain system board revisions, a security vulnerability in the system board firmware may allow a local or remote unprivileged user to panic the system and thereby cause a Denial of Service (DoS). State: Resolved First released: 13-Jul-2009
Permalink
|
14 Aug 2009
Sun Alert 265488 A Security Vulnerability in Sun Virtual Desktop Infrastructure (VDI) Software 3.0 may Lead to Inadvertent use of an Insecure LDAP Connection
Product: Sun Virtual Desktop Infrastructure A security vulnerability in Sun Virtual Desktop Infrastructure (VDI) Software 3.0 may allow a remote privileged user to be able to view client LDAP requests for VDI configuration data. State: Resolved First released: 14-Aug-2009
Permalink
|
12 Aug 2009
Sun Alert 265030 Multiple Security Vulnerabilities in libtiff(3) Handling of CODE_CLEAR Code
Product: Solaris 8 Operating System Solaris 9 Operating System Solaris 10 Operating System OpenSolaris Multiple security vulnerabilities have been found in libtiff(3), a library for reading and writing Tag Image File Format (TIFF) files. These vulnerabilities may allow a local or remote unprivileged user to create a carefully crafted LZW-encoded TIFF file that may cause an application linked with libtiff(3) to crash or possibly execute arbitrary code. These issues are also described in the following document: CVE-2008-2327 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2327 State: Workaround First released: 03-Aug-2009
Permalink
|
Comments [1]
11 Aug 2009
Sun Alert 259388 A Security Vulnerability Involving xscreensaver(1) and Assistive Technology Support May Allow an Unauthorized User to Access the System
Product: Solaris 10 Operating System OpenSolaris A security vulnerability involving xscreensaver(1) and Assistive Technology Support may allow a local user with physical access to a system to be able to unlock an X display which has been locked using xscreensaver(1) and thus gain unauthorized access to the system. State: Resolved First released: 11-Aug-2009
Permalink
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||