ID

VAR-200901-0290


CVE

CVE-2009-0053


TITLE

Cisco IronPort Encryption Appliance and Cisco IronPort PostX of PXE Encryption Vulnerability in obtaining decryption key

Trust: 0.8

sources: JVNDB: JVNDB-2009-001684

DESCRIPTION

PXE Encryption in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to obtain the decryption key via unspecified vectors, related to a "logic error.". Cisco IronPort Encryption Appliance and PostX are prone to multiple information-disclosure and cross-site request-forgery vulnerabilities. Attackers may exploit these issues to obtain sensitive information, including user passwords, or to modify user information through the web administration interface. This may aid in further attacks. IronPort series products are widely used email encryption gateways, which can seamlessly complete the encryption, decryption and digital signature of confidential emails. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: IronPort Encryption Appliance / PostX and PXE Encryption Vulnerabilities Advisory ID: cisco-sa-20090114-ironport Revision 1.0 For Public Release 2009 January 14 1600 UTC (GMT) +--------------------------------------------------------------------- Summary ======= IronPort PXE Encryption is an e-mail encryption solution that is designed to secure e-mail communications without the need for a Public Key Infrastructure (PKI) or special agents on receiving systems. When an e-mail message is targeted for encryption, the PXE encryption engine on an IronPort e-mail gateway encrypts the original e-mail message as an HTML file and attaches it to a notification e-mail message that is sent to the recipient. The per-message key used to decrypt the HTML file attachment is stored on a local IronPort Encryption Appliance, PostX software installation or the Cisco Registered Envelope Service, which is a Cisco-managed software service. PXE Encryption Privacy Vulnerabilities +------------------------------------- The IronPort PXE Encryption solution is affected by two vulnerabilities that could allow unauthorized individuals to view the contents of secure e-mail messages. To exploit the vulnerabilities, attackers must first intercept secure e-mail messages on the network or via a compromised e-mail account. These vulnerabilities do not affect Cisco Registered Envelope Service users. Cisco has released free software updates that address these vulnerabilities. There are no workarounds for the vulnerabilities that are described in this advisory. This advisory is posted at: http://www.cisco.com/warp/public/707/cisco-sa-20090114-ironport.shtml Affected Products ================= Vulnerable Products +------------------ The following IronPort Encryption Appliance/PostX versions are affected by these vulnerabilities: * All PostX 6.2.1 versions prior to 6.2.1.1 * All PostX 6.2.2 versions prior to 6.2.2.3 * All IronPort Encryption Appliance/PostX 6.2.4 versions prior to 6.2.4.1.1 * All IronPort Encryption Appliance/PostX 6.2.5 versions * All IronPort Encryption Appliance/PostX 6.2.6 versions * All IronPort Encryption Appliance/PostX 6.2.7 versions prior to 6.2.7.7 * All IronPort Encryption Appliance 6.3 versions prior to 6.3.0.4 * All IronPort Encryption Appliance 6.5 versions prior to 6.5.0.2 The version of software that is running on an IronPort Encryption Appliance is located on the About page of the IronPort Encryption Appliance administration interface. Note: Customers should contact IronPort support to determine which software fixes are applicable for their environment. Please consult the Obtaining Fixed Software section of this advisory for more information. Products Confirmed Not Vulnerable +-------------------------------- IronPort C, M and S-Series appliances are not affected by these vulnerabilities. Although C-Series appliances can be configured to use a local IronPort Encryption Appliance for per-message key retention, the C-Series appliances are not vulnerable. The Cisco Registered Envelope Service is not vulnerable. No other Cisco products are currently known to be affected by these vulnerabilities. Details ======= Note: IronPort tracks bugs using an internal system that is not available to customers. The IronPort bug tracking identifiers are provided for reference only. PXE Encryption Privacy Vulnerabilities +------------------------------------- Individual PXE Encryption users are vulnerable to two message privacy vulnerabilities that could allow an attacker to gain access to sensitive information. All the vulnerabilities require an attacker to first intercept a secure e-mail message as a condition for successful exploitation. Attackers can obtain secure e-mail messages by monitoring a network or a compromised user e-mail account. Using the decryption key, an attacker could decrypt the contents of the secure e-mail message. This vulnerability is documented in IronPort bug 8062 and has been assigned Common Vulnerabilities and Exposures (CVE) identifier CVE-2009-0053. By modifying the contents of intercepted secure e-mail messages or by forging a close copy of the e-mail message, it may be possible for an attacker to convince a user to view a modified secure e-mail message and then cause the exposure of the user's credentials and message content. Please see the Workarounds section for more information on mitigations available to reduce exposure to these phishing-style attacks. This vulnerability is documented in IronPort bug 8149 and has been assigned Common Vulnerabilities and Exposures (CVE) identifier CVE-2009-0054. IronPort Encryption Appliance Administration Interface Vulnerabilities +--------------------------------------------------------------------- The administration interface of IronPort Encryption Appliance devices contains a cross-site request forgery (CSRF) vulnerability that could allow an attacker to modify a user's IronPort Encryption Appliance preferences, including their user name and personal security pass phrase, if the user is logged into the IronPort Encryption Appliance administration interface. Exploitation of the vulnerability will not allow an attacker to change a user's password. This vulnerability is documented in IronPort bug 5806 and has been assigned Common Vulnerabilities and Exposures (CVE) identifier CVE-2009-0055. Exploitation of the vulnerability will not allow an attacker to change a user's password. This vulnerability is documented in IronPort bug 6403 and has been assigned Common Vulnerabilities and Exposures (CVE) identifier CVE-2009-0056. Vulnerability Scoring Details ============================= Cisco has provided scores for the vulnerabilities in this advisory based on the Common Vulnerability Scoring System (CVSS). The CVSS scoring in this Security Advisory is done in accordance with CVSS version 2.0. CVSS is a standards-based scoring method that conveys vulnerability severity and helps determine urgency and priority of response. Cisco has provided a base and temporal score. Customers can then compute environmental scores to assist in determining the impact of the vulnerability in individual networks. Cisco has provided an FAQ to answer additional questions regarding CVSS at: http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html Cisco has also provided a CVSS calculator to help compute the environmental impact for individual networks at: http://intellishield.cisco.com/security/alertmanager/cvss PXE Encryption Message Decryption Vulnerability - IronPort Bug 8062 CVSS Base Score - 7.1 Access Vector - Network Access Complexity - Medium Authentication - None Confidentiality Impact - Complete Integrity Impact - None Availability Impact - None CVSS Temporal Score - 5.9 Exploitability - Functional Remediation Level - Official Fix Report Confidence - Confirmed PXE Encryption Phishing Vulnerabilities - IronPort Bug 8149 CVSS Base Score - 6.1 Access Vector - Network Access Complexity - High Authentication - None Confidentiality Impact - Complete Integrity Impact - Partial Availability Impact - None CVSS Temporal Score - 5 Exploitability - Functional Remediation Level - Official Fix Report Confidence - Confirmed IronPort Encryption Appliance CSRF Vulnerability - IronPort Bug 5806 CVSS Base Score - 5.8 Access Vector - Network Access Complexity - Medium Authentication - None Confidentiality Impact - Partial Integrity Impact - Partial Availability Impact - None CVSS Temporal Score - 4.8 Exploitability - Functional Remediation Level - Official Fix Report Confidence - Confirmed IronPort Encryption Appliance Logout Action CSRF Vulnerability - IronPort Bug 6403 CVSS Base Score - 5.8 Access Vector - Network Access Complexity - Medium Authentication - None Confidentiality Impact - Partial Integrity Impact - Partial Availability Impact - None CVSS Temporal Score - 4.8 Exploitability - Functional Remediation Level - Official Fix Report Confidence - Confirmed Impact ====== PXE Encryption Privacy Vulnerabilities +------------------------------------- Successful exploitation of these vulnerabilities could allow an attacker to obtain user credentials and view the contents of intercepted secure e-mail messages, which could result in the disclosure of sensitive information. IronPort Encryption Appliance Administration Interface Vulnerabilities +--------------------------------------------------------------------- Successful exploitation of these vulnerabilities could allow an attacker to access user accounts on an IronPort Encryption Appliance device, which could result in the modification of user preferences. Software Versions and Fixes =========================== When considering software upgrades, also consult http://www.cisco.com/go/psirt and any subsequent advisories to determine exposure and a complete upgrade solution. Workarounds =========== There are no workarounds for the vulnerabilities that are described in this advisory. There are mitigations available to help prevent exploitation of the PXE Encryption phishing-style vulnerability. Phishing attacks can be greatly reduced if DomainKeys Identified Mail (DKIM) and Sender Policy Framework (SPF) are implemented on IronPort e-mail gateways to help ensure message integrity and source origin. Additionally, the PXE Encryption solution contains an anti-phishing Secure Pass Phrase feature to ensure that secure notification e-mail messages are valid. This feature is enabled by recipients when configuring their PXE user profile. Cisco has released a best practices document that describes several techniques to mitigate against the phishing-style attacks that is available at the following link: http://www.cisco.com/web/about/security/intelligence/bpiron.html Obtaining Fixed Software ======================== Cisco has released free software updates that address these vulnerabilities. The affected products in this advisory are directly supported by IronPort, and not via the Cisco TAC organization. Customers should contact IronPort technical support at the link below to obtain software fixes. IronPort technical support will assist customers in determining the correct fixes and installation procedures. Customers should direct all warranty questions to IronPort technical support. Do not contact psirt@cisco.com or security-alert@cisco.com for software upgrades. http://www.ironport.com/support/contact_support.html Exploitation and Public Announcements ===================================== The Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerabilities that are described in this advisory. J.B. Snyder of Brintech reported a method for obtaining PXE Encryption user credentials via a phishing-style attack to Cisco. All other vulnerabilities were discovered by Cisco or reported by customers. Status of this Notice: FINAL ============================ THIS DOCUMENT IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. CISCO RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME. A stand-alone copy or Paraphrase of the text of this document that omits the distribution URL in the following section is an uncontrolled copy, and may lack important information or contain factual errors. Distribution ============ This advisory is posted on Cisco's worldwide website at: http://www.cisco.com/warp/public/707/cisco-sa-20090114-ironport.shtml In addition to worldwide web posting, a text version of this notice is clear-signed with the Cisco PSIRT PGP key and is posted to the following e-mail and Usenet news recipients. * cust-security-announce@cisco.com * first-bulletins@lists.first.org * bugtraq@securityfocus.com * vulnwatch@vulnwatch.org * cisco@spot.colorado.edu * cisco-nsp@puck.nether.net * full-disclosure@lists.grok.org.uk * comp.dcom.sys.cisco@newsgate.cisco.com Future updates of this advisory, if any, will be placed on Cisco's worldwide website, but may or may not be actively announced on mailing lists or newsgroups. Users concerned about this problem are encouraged to check the above URL for any updates. Revision History ================ +---------------------------------------+ | Revision | | Initial | | 1.0 | 2009-January-14 | public | | | | release | +---------------------------------------+ Cisco Security Procedures ========================= Complete information on reporting security vulnerabilities in Cisco products, obtaining assistance with security incidents, and registering to receive security information from Cisco, is available on Cisco's worldwide website at: http://www.cisco.com/en/US/products/products_security_vulnerability_policy.html This includes instructions for press inquiries regarding Cisco security notices. All Cisco security advisories are available at: http://www.cisco.com/go/psirt -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (SunOS) iD8DBQFJbhoo86n/Gc8U/uARAjuxAJ4oLc1JjS7N9728Ueb6JB7Y2LVJtACfaSfA A6WIz481vajHya3jIlp+/Xc= =cFJ6 -----END PGP SIGNATURE----- . ---------------------------------------------------------------------- Did you know that a change in our assessment rating, exploit code availability, or if an updated patch is released by the vendor, is not part of this mailing-list? Click here to learn more: http://secunia.com/advisories/business_solutions/ ---------------------------------------------------------------------- TITLE: Cisco IronPort Products Multiple Vulnerabilities SECUNIA ADVISORY ID: SA33479 VERIFY ADVISORY: http://secunia.com/advisories/33479/ CRITICAL: Moderately critical IMPACT: Cross Site Scripting, Exposure of sensitive information WHERE: >From remote OPERATING SYSTEM: Cisco IronPort Encryption Appliance 6.x http://secunia.com/advisories/product/20990/ SOFTWARE: Cisco IronPort PostX 6.x http://secunia.com/advisories/product/20991/ DESCRIPTION: Some vulnerabilities have been reported in Cisco IronPort products, which can be exploited by malicious people to disclose sensitive information or conduct cross-site request forgery attacks. 3) The web-based administration interface allows user to perform certain actions via HTTP request without performing any validity checks to verify the requests. This can be exploited to e.g. http://www.ironport.com/support/contact_support.html PROVIDED AND/OR DISCOVERED BY: 2) The vendor credits J.B. Snyder of Brintech ORIGINAL ADVISORY: Cisco (cisco-sa-20090114-ironport): http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.16

sources: NVD: CVE-2009-0053 // JVNDB: JVNDB-2009-001684 // BID: 33268 // VULHUB: VHN-37499 // PACKETSTORM: 73911 // PACKETSTORM: 74003

AFFECTED PRODUCTS

vendor:ciscomodel:ironport postxscope:eqversion:6.2.2

Trust: 1.9

vendor:ciscomodel:ironport postxscope:eqversion:6.2.1

Trust: 1.9

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.5

Trust: 1.9

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.3

Trust: 1.9

vendor:ciscomodel:ironport postxscope:eqversion:6.2.2.2

Trust: 1.6

vendor:ciscomodel:ironport postxscope:eqversion:6.2.2.1

Trust: 1.6

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.3.0.3

Trust: 1.6

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.3.0.2

Trust: 1.6

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.5.0.1

Trust: 1.6

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.3.0.1

Trust: 1.6

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.7

Trust: 1.3

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.6

Trust: 1.3

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.5

Trust: 1.3

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.4

Trust: 1.3

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.4.1

Trust: 1.0

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.7.3

Trust: 1.0

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.7.6

Trust: 1.0

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.7.2

Trust: 1.0

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.7.4

Trust: 1.0

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.7.5

Trust: 1.0

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.7.1

Trust: 1.0

vendor:ciscomodel:ironport encryption appliancescope:ltversion:6.2.4 - 6.2.4.1.1

Trust: 0.8

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.5.x

Trust: 0.8

vendor:ciscomodel:ironport encryption appliancescope:eqversion:6.2.6.x

Trust: 0.8

vendor:ciscomodel:ironport encryption appliancescope:ltversion:6.2.7 - 6.2.7.7

Trust: 0.8

vendor:ciscomodel:ironport encryption appliancescope:ltversion:6.3 - 6.3.0.4

Trust: 0.8

vendor:ciscomodel:ironport encryption appliancescope:ltversion:6.5 - 6.5.0.2

Trust: 0.8

vendor:ciscomodel:ironport postxscope:ltversion:6.2.1 - 6.2.1.1

Trust: 0.8

vendor:ciscomodel:ironport postxscope:ltversion:6.2.2 - 6.2.2.3

Trust: 0.8

vendor:ciscomodel:ironport postxscope:neversion:6.2.23

Trust: 0.3

vendor:ciscomodel:ironport postxscope:neversion:6.2.11

Trust: 0.3

vendor:ciscomodel:ironport encryption appliancescope:neversion:6.52

Trust: 0.3

vendor:ciscomodel:ironport encryption appliancescope:neversion:6.34

Trust: 0.3

vendor:ciscomodel:ironport encryption appliancescope:neversion:6.2.77

Trust: 0.3

vendor:ciscomodel:ironport encryption appliancescope:neversion:6.2.41

Trust: 0.3

sources: BID: 33268 // JVNDB: JVNDB-2009-001684 // CNNVD: CNNVD-200901-206 // NVD: CVE-2009-0053

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2009-0053
value: MEDIUM

Trust: 1.0

NVD: CVE-2009-0053
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-200901-206
value: MEDIUM

Trust: 0.6

VULHUB: VHN-37499
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2009-0053
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-37499
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-37499 // JVNDB: JVNDB-2009-001684 // CNNVD: CNNVD-200901-206 // NVD: CVE-2009-0053

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.9

sources: VULHUB: VHN-37499 // JVNDB: JVNDB-2009-001684 // NVD: CVE-2009-0053

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200901-206

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-200901-206

CONFIGURATIONS

sources: JVNDB: JVNDB-2009-001684

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-37499

PATCH

title:cisco-sa-20090114-ironporturl:http://www.cisco.com/en/US/products/products_security_advisory09186a0080a5c4f7.shtml

Trust: 0.8

sources: JVNDB: JVNDB-2009-001684

EXTERNAL IDS

db:NVDid:CVE-2009-0053

Trust: 2.9

db:BIDid:33268

Trust: 2.0

db:SECUNIAid:33479

Trust: 1.8

db:VUPENid:ADV-2009-0140

Trust: 1.7

db:SECTRACKid:1021593

Trust: 1.7

db:OSVDBid:51395

Trust: 1.7

db:JVNDBid:JVNDB-2009-001684

Trust: 0.8

db:CNNVDid:CNNVD-200901-206

Trust: 0.7

db:CISCOid:20090114 IRONPORT ENCRYPTION APPLIANCE / POSTX AND PXE ENCRYPTION VULNERABILITIES

Trust: 0.6

db:PACKETSTORMid:73911

Trust: 0.2

db:VULHUBid:VHN-37499

Trust: 0.1

db:PACKETSTORMid:74003

Trust: 0.1

sources: VULHUB: VHN-37499 // BID: 33268 // JVNDB: JVNDB-2009-001684 // PACKETSTORM: 73911 // PACKETSTORM: 74003 // CNNVD: CNNVD-200901-206 // NVD: CVE-2009-0053

REFERENCES

url:http://www.cisco.com/en/us/products/products_security_advisory09186a0080a5c4f7.shtml

Trust: 1.8

url:http://www.securityfocus.com/bid/33268

Trust: 1.7

url:http://osvdb.org/51395

Trust: 1.7

url:http://securitytracker.com/id?1021593

Trust: 1.7

url:http://secunia.com/advisories/33479

Trust: 1.7

url:http://www.vupen.com/english/advisories/2009/0140

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2009-0053

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2009-0053

Trust: 0.8

url:http://www.frsirt.com/english/advisories/2009/0140

Trust: 0.6

url:http://www.cisco.com/warp/public/707/cisco-sa-20090114-ironport.shtml

Trust: 0.4

url:http://www.cisco.com

Trust: 0.3

url:http://www.ironport.com/products/ironport_encryption.html

Trust: 0.3

url:http://www.ironport.com/support/contact_support.html

Trust: 0.2

url:http://www.cisco.com/go/psirt

Trust: 0.1

url:http://www.cisco.com/web/about/security/intelligence/bpiron.html

Trust: 0.1

url:http://www.cisco.com/en/us/products/products_security_vulnerability_policy.html

Trust: 0.1

url:http://www.cisco.com/web/about/security/intelligence/cvss-qandas.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0056

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0055

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0054

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0053

Trust: 0.1

url:http://intellishield.cisco.com/security/alertmanager/cvss

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/advisories/33479/

Trust: 0.1

url:http://secunia.com/advisories/product/20990/

Trust: 0.1

url:http://secunia.com/advisories/business_solutions/

Trust: 0.1

url:http://secunia.com/advisories/product/20991/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-37499 // BID: 33268 // JVNDB: JVNDB-2009-001684 // PACKETSTORM: 73911 // PACKETSTORM: 74003 // CNNVD: CNNVD-200901-206 // NVD: CVE-2009-0053

CREDITS

J.B. Snyder

Trust: 0.6

sources: CNNVD: CNNVD-200901-206

SOURCES

db:VULHUBid:VHN-37499
db:BIDid:33268
db:JVNDBid:JVNDB-2009-001684
db:PACKETSTORMid:73911
db:PACKETSTORMid:74003
db:CNNVDid:CNNVD-200901-206
db:NVDid:CVE-2009-0053

LAST UPDATE DATE

2025-04-10T22:56:46.282000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-37499date:2011-03-08T00:00:00
db:BIDid:33268date:2009-01-14T20:12:00
db:JVNDBid:JVNDB-2009-001684date:2009-07-08T00:00:00
db:CNNVDid:CNNVD-200901-206date:2009-02-05T00:00:00
db:NVDid:CVE-2009-0053date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-37499date:2009-01-16T00:00:00
db:BIDid:33268date:2009-01-14T00:00:00
db:JVNDBid:JVNDB-2009-001684date:2009-07-08T00:00:00
db:PACKETSTORMid:73911date:2009-01-15T01:15:11
db:PACKETSTORMid:74003date:2009-01-16T13:12:57
db:CNNVDid:CNNVD-200901-206date:2009-01-16T00:00:00
db:NVDid:CVE-2009-0053date:2009-01-16T21:30:03.407