New Security Vulnerabilities 13th May 2008
The following new security tests were added to Telspace' database:
TOTAL THREATS IN THE DATABASE 21347
NEW THREATS RISK FACTOR SUMMARY
(*****) Urgent Risk 2
(**** ) Critical Risk 65
(*** ) High Risk 7
(** ) Medium Risk 15
(* ) Low Risk 0
NEW THREATS FAMILY SUMMARY
Remote Shell Access 1
Slackware Local Checks 2
Web Services 3
Windows 3
Red Hat Local Checks 5
Centos Local Checks 8
Gentoo Local Checks 9
Ubuntu Local Checks 9
Fedora Local Checks 9
FreeBSD Local Checks 12
SuSE Local Checks 13
Debian Local Checks 15
(*****) Urgent Risk - Windows
SNMPc < 7.1.1 Buffer Overflow Vulnerability
(*****) Urgent Risk - Web Services
Red Hat 'redhat-ds-admin' Shell Command Injection and Security Bypass Vulnerabilities
(**** ) Critical Risk - SuSE Local Checks
SuSE Security Update: audit security update (audit-5212)
(**** ) Critical Risk - Red Hat Local Checks
RHSA-2008-0175: openoffice.org
(**** ) Critical Risk - Debian Local Checks
1560] DSA-1560-1 kronolith2
(**** ) Critical Risk – Debian Local Checks
[DSA1564] DSA-1564-1 wordpress
(**** ) Critical Risk - Ubuntu Local Checks
USN605-1 : Thunderbird vulnerabilities
(**** ) Critical Risk - Centos Local Checks
CentOS : RHSA-2008-0240
(**** ) Critical Risk – Centos Local Checks
CentOS : RHSA-2008-0223
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 8 2008-3264: seamonkey
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: Security update for clamav (clamav-5200)
(**** ) Critical Risk - Centos Local Checks
CentOS : RHSA-2008-0145
(**** ) Critical Risk – Centos Local Checks
CentOS : RHSA-2008-0238
(**** ) Critical Risk - Windows
HP HPeDiag ActiveX Control Multiple Information Disclosure and Remote Code Execution Vulnerabilities
(**** ) Critical Risk - Debian Local Checks
[DSA1565] DSA-1565-1 linux-2.6
(**** ) Critical Risk - Red Hat Local Checks
RHSA-2008-0238: kdegraphics
(**** ) Critical Risk - SuSE Local Checks
SuSE Security Update: Security update for libpng (libpng-5181)
(**** ) Critical Risk - Debian Local Checks
[DSA1556] DSA-1556-2 perl
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 7 2008-3231: seamonkey
(**** ) Critical Risk – Centos Local Checks
CentOS : RHSA-2008-0222
(**** ) Critical Risk – Remote Shell Access
Firefly Media Server ‘Content-Length’ Buffer Overflow Vulnerability
(**** ) Critical Risk – Fedora Local Checks
Fedora Core 8 2008-3220: fedora-ds-admin
(**** ) Critical Risk - Red Hat Local Checks
RHSA-2008-0239: poppler
(**** ) Critical Risk – Debian Local Checks
[DSA1568] DSA-1568-1 b2evolution
(**** ) Critical Risk – Ubuntu Local Checks
USN607-1 : Emacs vulnerabilities
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 8 2008-3250: mt-daapd
(**** ) Critical Risk - Windows
Akamai Download Manager ActiveX Control < 2.2.3.5 Remote Code Execution Vulnerability
(**** ) Critical Risk - SuSE Local Checks
SuSE Security Update: libpng security update (libpng-5180)
(**** ) Critical Risk – Centos Local Checks
CentOS : RHSA-2008-0176
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: clamav security update (clamav-5199)
(**** ) Critical Risk – Debian Local Checks
[DSA1559] DSA-1559-1 phpgedview
(**** ) Critical Risk - SuSE Local Checks
SuSE Security Update: seamonkey: Security update (seamonkey-5167)
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: openldap2 security update (openldap2-4999)
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 7 2008-3214: fedora-ds-admin
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: OpenOffice: Fix for multiple vulnerabilities.
(OpenOffice_org-5053)
(**** ) Critical Risk - Debian Local Checks
[DSA1566] DSA-1566-1 cpio
(**** ) Critical Risk – Debian Local Checks
[DSA1562] DSA-1562-1 iceape
(**** ) Critical Risk – Debian Local Checks
[DSA1558] DSA-1558-1 xulrunner
(**** ) Critical Risk – Centos Local Checks
CentOS : RHSA-2008-0235
(**** ) Critical Risk – Red Hat Local Checks
RHSA-2008-0176: openoffice.org
(**** ) Critical Risk - Ubuntu Local Checks
USN606-1 : CUPS vulnerability
(**** ) Critical Risk - Debian Local Checks
[DSA1557] DSA-1557-1 phpmyadmin
(**** ) Critical Risk – Fedora Local Checks
Fedora Core 8 2008-3283: chmsee
(**** ) Critical Risk - SuSE Local Checks
SuSE Security Update: mozilla-xulrunner181 security fixes
(mozilla-xulrunner181-5158)
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: klamav security update (klamav-5206)
(**** ) Critical Risk – Debian Local Checks
[DSA1570] DSA-1570-1 kazehakase
(**** ) Critical Risk – Gentoo Local Checks
[GLSA-200804-30] KDE start_kdeinit: Multiple vulnerabilities
(**** ) Critical Risk - Debian Local Checks
[DSA1563] DSA-1563-1 asterisk
(**** ) Critical Risk – Ubuntu Local Checks
USN611-2 : vorbis-tools vulnerability
(**** ) Critical Risk – Web Services
XOOPS Article Module 'article.php' SQL Injection Vulnerability
(**** ) Critical Risk - Debian Local Checks
[DSA1567] DSA-1567-1 blender
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: Security update for OpenLDAP 2 (openldap2-4989)
(**** ) Critical Risk - Gentoo Local Checks
[GLSA-200805-04] eGroupWare: Multiple vulnerabilities
(**** ) Critical Risk – Ubuntu Local Checks
USN609-1 : OpenOffice.org vulnerabilities
(**** ) Critical Risk – Red Hat Local Checks
RHSA-2008-0240: xpdf
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 7 2008-3249: yelp
(**** ) Critical Risk – Debian Local Checks
[DSA1561] DSA-1561-1 ldm
(**** ) Critical Risk – Debian Local Checks
[DSA1569] DSA-1569-2 cacti
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: mozilla-xulrunner security update
(mozilla-xulrunner-5163)
(**** ) Critical Risk – Ubuntu Local Checks
USN611-1 : Speex vulnerability
(**** ) Critical Risk – Ubuntu Local Checks
USN611-3 : GStreamer Good Plugins vulnerability
(**** ) Critical Risk – Fedora Local Checks
Fedora Core 8 2008-3229: kazehakase
(**** ) Critical Risk – Ubuntu Local Checks
USN608-1 : KDE vulnerability
(**** ) Critical Risk - Ubuntu Local Checks
USN610-1 : LTSP vulnerability
(**** ) Critical Risk - Fedora Local Checks
Fedora Core 8 2008-3251: openoffice.org
(**** ) Critical Risk – SuSE Local Checks
SuSE Security Update: licq: fixed a remote DoS condition (licq-5214)
(**** ) Critical Risk - Centos Local Checks
CentOS : RHSA-2008-0175
(*** ) High Risk – Gentoo Local Checks
[GLSA-200804-27] SILC: Multiple vulnerabilities
(*** ) High Risk - Gentoo Local Checks
[GLSA-200804-29] Comix: Multiple vulnerabilities
(*** ) High Risk - Gentoo Local Checks
[GLSA-200805-01] Horde Application Framework: Multiple vulnerabilities
(*** ) High Risk - Web Services
WordPress cat Parameter Local File Include Vulnerability
(*** ) High Risk - Gentoo Local Checks
[GLSA-200805-03] Multiple X11 terminals: Local privilege escalation
(*** ) High Risk - Gentoo Local Checks
[GLSA-200804-28] JRockit: Multiple vulnerabilities
(*** ) High Risk - Gentoo Local Checks
[GLSA-200805-05] Wireshark: Denial of Service
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : openfire – unspecified denial of service (1110)
(** ) Medium Risk – FreeBSD Local Checks
FreeBSD : python -- Integer Signedness Error in zlib Module (1111)
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : mksh – TTY attachment privilege escalation (1108)
(** ) Medium Risk – FreeBSD Local Checks
FreeBSD : firefox -- javascript garbage collector vulnerability (1105)
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : phpmyadmin – Username/Password Session File Information Disclosure (1106)
(** ) Medium Risk – FreeBSD Local Checks
FreeBSD : mailman – script insertion vulnerability (1114)
(** ) Medium Risk – Gentoo Local Checks
[GLSA-200805-02] phpMyAdmin: Information disclosure
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : serendipity – multiple cross site scripting vulnerabilities
(1109)
(** ) Medium Risk – Slackware Local Checks
SSA-2008-119-01 libpng
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : extman – password bypass vulnerability (1113)
(** ) Medium Risk – FreeBSD Local Checks
FreeBSD : gnupg – memory corruption vulnerability (1115)
(** ) Medium Risk – Slackware Local Checks
SSA-2008-116-01 kdelibs
(** ) Medium Risk – FreeBSD Local Checks
FreeBSD : phpmyadmin – Shared Host Information Disclosure (1112)
(** ) Medium Risk – FreeBSD Local Checks
FreeBSD : postgresql -- multiple vulnerabilities (1104)
(** ) Medium Risk - FreeBSD Local Checks
FreeBSD : libxine – array index vulnerability (1107)
|