Sun Security Blog
|
On November 3, 2009, Sun will release the following security updates:
Permalink | Comments [1]
29 Oct 2009
Sun Alert 270809 Security Vulnerability in Solaris Trusted Extensions may Prevent XScreenSaver (xscreensaver(1)) From Running
Product: Solaris 10 A security vulnerability in Solaris Trusted Extensions may result in a condition that prevents XScreenSaver (xscreensaver(1)) from running. The screen may not lock if a user chooses to lock the screen from the JDS menu or if the screen is left unattended. This condition occurs when trying to restart XScreenSaver using "xscreensaver-demo". State: Resolved First released: 29-Oct-2009
Permalink
|
29 Oct 2009
Sun Alert 269208 A Security Vulnerability With Verifying HMAC-based XML Digital Signatures in the XML Digital Signature Implementation Included With the Sun GlassFish Enterprise Server v2.1 may Allow Authentication to be Bypassed
Product: Sun GlassFish Enterprise Server v2.1 A security vulnerability with verifying HMAC-based XML digital signatures in the XML Digital Signature implementation included with webservices component of Sun GlassFish Enterprise Server may allow authentication to be bypassed. This could allow a user to forge an XML digital signature that would be accepted as valid. Applications that validate HMAC-based XML digital signatures may be vulnerable to this issue. This issue is also described in the following documents: CERT VU#466161 at: CVE-2009-0217 at: Sun acknowledges, with thanks, Thomas Roessler from the W3C for bringing this issue to our attention. State: Resolved First released: 29-Oct-2009
Permalink
|
26 Oct 2009
Sun Alert 270969 A Security Weakness in Solaris Trusted Extensions May Facilitate Privilege Escalation
Product: Solaris 10, OpenSolaris A security weakness in Solaris Trusted Extensions Policy configuration State: Resolved First released: 26-Oct-2009
Permalink
|
26 Oct 2009
Sun Alert 270268 Multiple Integer Overflow Vulnerabilities in the FreeType 2 Font Engine May Lead to a Denial of Service (DoS) or Allow Execution of Arbitrary Code
Product: Solaris 8, Solaris 9, Solaris 10, OpenSolaris Multiple integer overflow vulnerabilities in the FreeType 2 Font Library State: Preliminary First released: 26-Oct-2009
Permalink
|
26 Oct 2009
Sun Alert 270669 Multiple Security Vulnerabilities in Adobe Reader for Solaris 10 May Allow Execution of Arbitrary Code or Cause Denial of Service (DoS) - Adobe Security Bulletin APSB09-15
Product: Solaris 10 Multiple security vulnerabilities in Adobe Reader versions 9.x before 9.1.4, 8.x before 8.1.7 and 7.x before 7.1.4 may allow remote unprivileged users to execute arbitrary code or crash the Adobe Reader application, thereby causing a Denial of Service (DoS) condition. These vulnerabilities may be exploited via specially crafted PDF files. The following resources document these issues in more detail: Adobe Security Bulletin APSB09-15 at http://www.adobe.com/support/security/bulletins/apsb09-15.html CVE-2009-2564 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2564 CVE-2009-2979 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2979 CVE-2009-2980 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2980 CVE-2009-2981 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2981 CVE-2009-2982 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2982 CVE-2009-2983 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2983 CVE-2009-2984 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2984 CVE-2009-2985 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2985 CVE-2009-2986 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2986 CVE-2009-2987 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2987 CVE-2009-2988 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2988 CVE-2009-2989 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2989 CVE-2009-2990 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2990 CVE-2009-2991 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2991 CVE-2009-2992 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2992 CVE-2009-2993 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2993 CVE-2009-2994 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2994 CVE-2009-2995 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2995 CVE-2009-2996 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2996 CVE-2009-2997 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2997 CVE-2009-2998 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2998 CVE-2009-3431 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3431 CVE-2009-3458 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3458 CVE-2009-3459 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3459 CVE-2009-3460 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3460 CVE-2009-3461 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3461 CVE-2009-3462 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3462 CVE-2007-0045 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045 CVE-2007-0048 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0048 State: Workaround First released: 22-Oct-2009
Permalink
|
20 Oct 2009
Sun Alert 268288 A Regression in the Solaris 10 Gnome-XScreenSaver (see xscreensaver(1)) may Allow Pop-up Windows to Appear through XScreenSaver when the Accessibility Feature is On
Product: Solaris 10 A regression introduced in the Solaris 10 XScreenSaver(see xscreensaver(1)) State: Resolved First released: 20-Oct-2009
Permalink
|
14 Oct 2009
Sun Alert 265908 A Security Vulnerability in the ZFS Filesystem May Allow An Unprivileged User to Take Ownership of Files Belonging to Another User
Product: Solaris 10 Operating System OpenSolaris A security vulnerability in the ZFS file system in OpenSolaris and Solaris 10 systems with patches 137137-09 (SPARC) or 137138-09 (x86) installed may allow a local unprivileged user with the 'file_chown_self' privilege to take ownership of files belonging to another user. State: Resolved First released: 14-Oct-2009
Permalink
|
Product: Sun Security Services Certain Sun products (including some bundled third party products) may be vulnerable to an RSA(1) Signature Verification vulnerability that allows unauthorized forged certificates to be validated. This may result in a number of different types of remote exploits. The specific impact will vary from product to product. Please see the "Contributing Factors" section for further details. More details of the issue are available from CERT Vulnerability VU#845620 at http://www.kb.cert.org/vuls/id/845620 which is also mentioned at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4339 State: Preliminary First released: 13-Oct-2009
Permalink
|
13 Oct 2009
Sun Alert 102648 Security Vulnerability in RSA Signature Verification Impacting Multiple SUN Products
Product: Sun Security Services Certain Sun products (including some bundled third party products) may be vulnerable to an RSA(1) Signature Verification vulnerability that allows unauthorized forged certificates to be validated. This may result in a number of different types of remote exploits. The specific impact will vary from product to product; see the "Contributing Factors" section for further details. More details of the issue are available from CERT Vulnerability VU#845620 at http://www.kb.cert.org/vuls/id/845620 which is also mentioned at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4339 State: Preliminary First released: 02-Oct-2006
Permalink
|
Comments [0]
13 Oct 2009
Sun Alert 269008 Multiple Security Vulnerabilities in the JBIG2 Decoder in the OpenSolaris GNOME PDF Viewer may Lead to Execution of Arbitrary Code
Product: OpenSolaris Multiple security vulnerabilities in the JBIG2 decoding feature in the Poppler PDF Rendering Library (libpoppler) may allow a local or remote unprivileged user to cause the OpenSolaris GNOME PDF Viewer (Evince) to crash and potentially execute arbitrary code with the privileges of the user running the application, when the user has loaded a specially crafted PDF file. These issues are also referenced in the following documents: CVE-2009-0165 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0165 CVE-2009-0146 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146 CVE-2009-0147 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147 CVE-2009-0166 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166 CVE-2009-1187 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1187 CVE-2009-1188 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188 Sun acknowledges with thanks, Braden Thomas and Drew Yao of Apple Product Security for bringing the issues described in CVE-2009-0165, CVE-2009-0146, CVE-2009-0147 and CVE-2009-0166 to our attention. State: Resolved First released: 13-Oct-2009
Permalink
|
13 Oct 2009
Sun Alert 268448 Multiple Security Vulnerabilities in Firefox Versions Before 3.5.3 May Allow Execution of Arbitrary Code, Access to Unauthorized Data, or Denial of Service (DoS)
Product: OpenSolaris Multiple security vulnerabilities with varying impacts affect Firefox (see firefox(1)) versions prior to 3.5.3 as shipped with OpenSolaris. These vulnerabilities may allow an unprivileged remote user to crash the Firefox application or possibly execute arbitrary code on the system where Firefox is being run, resulting in a Denial of service (DoS). Further vulnerabilities may allow a remote user to mislead a Firefox user into incorrectly trusting a site by providing a URL in the location bar which may appear to be another URL, or to compromise the cryptography features that are active within the browser application. The following Mozilla advisories describe the vulnerabilities: MFSA 2009-51 at http://www.mozilla.org/security/announce/2009/mfsa2009-51.html MFSA 2009-50 at http://www.mozilla.org/security/announce/2009/mfsa2009-50.html MFSA 2009-49 at http://www.mozilla.org/security/announce/2009/mfsa2009-49.html MFSA 2009-48 at http://www.mozilla.org/security/announce/2009/mfsa2009-48.html MFSA 2009-47 at http://www.mozilla.org/security/announce/2009/mfsa2009-47.html
CVE-2009-3069 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3069 CVE-2009-3070 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3070 CVE-2009-3071 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3071 CVE-2009-3072 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3072 CVE-2009-3073 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3073 CVE-2009-3074 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3074 CVE-2009-3075 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3075 CVE-2009-3076 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3076 CVE-2009-3077 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3077 CVE-2009-3078 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3078 CVE-2009-3079 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3079 State: Resolved First released: 30-Sep-2009
Permalink
|
13 Oct 2009
Sun Alert 267031 Heap Overflow in a Regular Expression Parser in Network Security Services (NSS) may Affect SSL Clients (CVE-2009-2404)
Product: Solaris 9 Operating System Solaris 10 Operating System Sun Java Enterprise System 5 Sun Java Enterprise System 2005 A heap overflow vulnerability in Network Security Services (NSS) may allow a remote SSL server to cause a Denial of Service (DoS) to SSL client applications or to possibly execute arbitrary code with the privileges of the SSL client application, via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the "cert_TestHostName" function. Firefox, Thunderbird, Pidgin and Evolution are examples of vulnerable SSL client applications. This issue is also described in the following document: CVE-2009-2404 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2404 State: Resolved First released: 13-Oct-2009
Permalink
|
09 Oct 2009
Sun Alert 266908 Security vulnerability in Solaris Pidgin (see pidgin(1)), Versions Prior to 2.5.9 may Lead to Execution of Arbitrary Code or a Denial of Service (DoS) Condition
Product: Solaris 10 Operating System OpenSolaris A heap-based buffer overflow vulnerability in the MSN protocol handler of libpurple(3), the shared library that adds support for various instant messaging networks to the pidgin(1) Instant Messaging client (previously known as Gaim), may allow remote unprivileged users to execute arbitrary code or cause a Denial of Service (DoS) through an application crash. Additional information on this issue can be found in the following document: CVE-2009-2694 at: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694 State: Workaround First released: 14-Sep-2009
Permalink
|
09 Oct 2009
Sun Alert 269468 Security Vulnerability in Mozilla Thunderbird Related to SSL Certificates May Cause Arbitrary Code Execution
Product: Solaris 10 Operating System OpenSolaris Security vulnerabilities in thunderbird(1) related to handling of SSL server certificates http://www.mozilla.org/security/announce/2009/mfsa2009-43.html
CVE-2009-2408 at http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2408 State: Preliminary First released: 09-Oct-2009
Permalink
|
|
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||