VARIoT IoT vulnerabilities database
 
    | VAR-200610-0017 | CVE-2006-4392 | Apple Workgroup Manager fails to properly enable ShadowHash passwords | CVSS V2: 7.2 CVSS V3: - Severity: HIGH | 
                            The Mach kernel, as used in operating systems including (1) Mac OS X 10.4 through 10.4.7 and (2) OpenStep before 4.2, allows local users to gain privileges via a parent process that forces an exception in a setuid child and uses Mach exception ports to modify the child's thread context and task address space in a way that causes the child to call a parent-controlled function. Apple Workgroup Manager fails to properly enable ShadowHash passwords in a NetInfo parent. Workgroup Manager may appear to use ShadowHash passwords when crypt is used. A vulnerability exists in how Apple OS X  handles PICT images. If successfully exploited, this vulnerability may allow a remote attacker  to execute arbitrary code, or create a denial-of-service condition. This vulnerability may allow remote users with a valid network account to bypass LoginWindow service access controls. Adobe Flash Player fails to properly handle malformed strings. Apple Mac OS X of Mach A flaw exists in the kernel's error handling mechanism called exception ports, which allows the execution of privileged crafted programs when certain types of errors occur.By executing a program crafted by a third party, arbitrary code may be executed. 
These issue affect Mac OS X and various applications including CFNetwork, Safari, Kernel, ImageIO, LoginWindow, System Preferences, QuickDraw Manager, and Workgroup Manager. Impacts of other vulnerabilities include bypass of security
   restrictions and denial of service. 
I. 
   Further details are available in the individual Vulnerability Notes
   for Apple Security Update 2006-006. More information on those vulnerabilities can
   be found in Adobe Security Bulletin APSB06-11 and the Vulnerability
   Notes for Adobe Security Bulletin APSB06-11. 
II. Impact
   The impacts of these vulnerabilities vary. For information about
   specific impacts, please see the Vulnerability Notes for Apple
   Security Update 2006-006. Potential consequences include remote
   execution of arbitrary code or commands, bypass of security
   restrictions, and denial of service. 
III. This and other updates are
   available via Apple Update or via Apple Downloads. 
IV. Please send
 email to <cert@cert.org> with "TA06-275A Feedback VU#546772" in the
 subject. 
 _________________________________________________________________
 Produced 2006 by US-CERT, a government organization. 
 Terms of use:
   <http://www.us-cert.gov/legal.html>
 _________________________________________________________________
   Revision History
   October 02, 2006: Initial release
  
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iQEVAwUBRSFT/exOF3G+ig+rAQIF0gf+KI8EWp1iNaVOYe2YgcRRMF27K8VFz5Rn
Y81SRMZk4M1m9/4/7oJG7obEiGr4LqD/EjxT23ctuQ4KBKysokv7F+FrLwMHbRGY
my6x7mmLy+JEydQrMFk8u/2ZdVZjvxnhBUmH9nuwgjhqaJ0Ez1GAbmkmJ/TV5pbY
gOWOu5oe2zpkf3fpLRWY+XxctHukgl8SlN0ucyRSRPlWmO7rR8di/rujWMRRAlep
fEkTeq6Z5X4Ep6lwxoWX5z+a5oPz4tLHMIbjGZlV3FGa7ii6GTBWmQSN42yTW9tZ
ELoLtXeHgiSy27n7G6VMOIzKEu7V8mHt3L3ZFrF+O/Xx5KBb/b/xQg==
=nP7Y
-----END PGP SIGNATURE-----
. 
----------------------------------------------------------------------
Want to work within IT-Security?
Secunia is expanding its team of highly skilled security experts. 
We will help with relocation and obtaining a work permit. 
Currently the following type of positions are available:
http://secunia.com/quality_assurance_analyst/
http://secunia.com/web_application_security_specialist/ 
http://secunia.com/hardcore_disassembler_and_reverse_engineer/
----------------------------------------------------------------------
TITLE:
Mac OS X Security Update Fixes Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA22187
VERIFY ADVISORY:
http://secunia.com/advisories/22187/
CRITICAL:
Highly critical
IMPACT:
Security Bypass, Spoofing, Exposure of sensitive information,
Privilege escalation, DoS, System access
WHERE:
>From remote
OPERATING SYSTEM:
Apple Macintosh OS X
http://secunia.com/product/96/
DESCRIPTION:
Apple has issued a security update for Mac OS X, which fixes multiple
vulnerabilities. 
1) An error in the CFNetwork component may allow a malicious SSL site
to pose as a trusted SLL site to CFNetwork clients (e.g. Safari). 
5) An unchecked error condition in the LoginWindow component may
result in Kerberos tickets being accessible to other local users
after an unsuccessful attempt to log in. 
6) Another error in the LoginWindow component during the handling of
"Fast User Switching" may result in Kerberos tickets being accessible
to other local users. 
8) An error makes it possible for an account to manage WebObjects
applications after the "Admin" privileges have been revoked. 
9) A memory corruption error in QuickDraw Manager when processing
PICT images can potentially be exploited via a specially crafted PICT
image to execute arbitrary code. 
10) An error in SASL can be exploited by malicious people to cause a
DoS (Denial of Service) against the IMAP service. 
For more information:
SA19618
11) A memory management error in WebKit's handling of certain HTML
can be exploited by malicious people to compromise a user's system. 
SOLUTION:
Update to version 10.4.8 or apply Security Update 2006-006. 
3) The vendor credits Tom Saxton, Idle Loop Software Design. 
4) The vendor credits Dino Dai Zovi, Matasano Security. 
5) The vendor credits Patrick Gallagher, Digital Peaks Corporation. 
6) The vendor credits Ragnar Sundblad, Royal Institute of
Technology. 
8) The vendor credits Phillip Tejada, Fruit Bat Software. 
12) The vendor credits Chris Pepper, The Rockefeller University. 
ORIGINAL ADVISORY:
Apple:
http://docs.info.apple.com/article.html?artnum=304460
OTHER REFERENCES:
SA19618:
http://secunia.com/advisories/19618/
SA20971:
http://secunia.com/advisories/20971/
SA21271:
http://secunia.com/advisories/21271/
SA21865:
http://secunia.com/advisories/21865/
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
. visiting a malicious website. 
2) An unspecified error can be exploited to bypass the
"allowScriptAccess" option. 
3) Unspecified errors exist in the way the ActiveX control is invoked
by Microsoft Office products on Windows. 
PROVIDED AND/OR DISCOVERED BY:
1) The vendor credits Stuart Pearson, Computer Terrorism UK Ltd, for
reporting one of the vulnerabilities. 
2) Reported by the vendor. 
3) Reported by the vendor
                        
| VAR-200609-0169 | CVE-2006-4765 | NetGear Denial of Service Vulnerability | CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM | 
                            NETGEAR DG834GT Wireless ADSL router running firmware 1.01.28 allows attackers to cause a denial of service (device hang) via a long string in the username field in the login window. The NetGear DG834GT device is prone to a denial-of-service vulnerability because it fails to properly validate user-supplied input. 
This issue allows attackers to cause the device to stop responding to network requests, effectively denying service to legitimate users
                        
| VAR-200609-0310 | CVE-2006-4382 | Apple QuickTime fails to properly handle SGI images | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Multiple buffer overflows in Apple QuickTime before 7.1.3 allow user-assisted remote attackers to execute arbitrary code via a crafted QuickTime movie. Apple QuickTime fails to properly handle SGI images. Successful exploits may facilitate a remote compromise of affected computers. Apple QuickTime is a popular multimedia player that supports a wide variety of media formats. 
McAfee, Inc. QuickTime is used by the Mac OS X operating system and
by the QuickTime media player for Microsoft Windows. 
Seven code execution vulnerabilities are present in QuickTime support
for various multimedia formats including: MOV, H.264, FLC, FPX and SGI. 
Exploitation could lead to execution of arbitrary code. User interaction
is required for an attack to succeed. 
The risk rating for these issues is medium. 
_________________________________________________
*	Vulnerable Systems
QuickTime 7.1.2 and below for Mac OS X
QuickTime for Windows 7.1.2 and below
_________________________________________________
*	Vulnerability Information
CVE-2006-4382
Two buffer overflow vulnerabilities are present in QuickTime MOV format
support. 
CVE-2006-4384
On heap overflow vulnerability is present in QuickTime FLC format
support. 
CVE-2006-4385
One buffer overflow vulnerability is present in QuickTime SGI format
support. 
CVE-2006-4386
One buffer overflow vulnerability is present in QuickTime MOV H.264
format support. 
CVE-2006-4388
One buffer overflow vulnerability is present in QuickTime FlashPix (FPX)
format support. 
CVE-2006-4389
One uninitialized memory access vulnerability is present in QuickTime
FlashPix (FPX) format support. 
_________________________________________________
*	Resolution
Apple has included fixes for the QuickTime issues in QuickTime version
7.1.3 for Mac OS X and for Microsoft Windows.  
Further information is available at:
http://docs.info.apple.com/article.html?artnum=304357
_________________________________________________
*	Credits
These vulnerabilities were discovered by Mike Price of McAfee Avert
Labs. 
_________________________________________________
*	Legal Notice
Copyright (C) 2006 McAfee, Inc. 
The information contained within this advisory is provided for the
convenience of McAfee's customers, and may be redistributed provided
that no fee is charged for distribution and that the advisory is not
modified in any way. McAfee makes no representations or warranties
regarding the accuracy of the information referenced in this document,
or the suitability of that information for your purposes. 
McAfee, Inc. and McAfee Avert Labs are registered Trademarks of McAfee,
Inc. and/or its affiliated companies in the United States and/or other
Countries.  All other registered and unregistered trademarks in this
document are the sole property of their respective owners. 
Best regards,
Dave Marcus, B.A., CCNA, MCSE
Security Research and Communications Manager
McAfee(r) Avert(r) Labs
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  Severity: Normal
     Title: Win32 binary codecs: Multiple vulnerabilities
      Date: March 04, 2008
      Bugs: #150288
        ID: 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities in the Win32 codecs for Linux may result in
the remote execution of arbitrary code. 
Background
==========
Win32 binary codecs provide support for video and audio playback. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All Win32 binary codecs users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose
">=media-libs/win32codecs-20071007-r2"
Note: Since no updated binary versions have been released, the
Quicktime libraries have been removed from the package. Please use the
free alternative Quicktime implementations within VLC, MPlayer or Xine
for playback. 
References
==========
  [ 1 ] CVE-2006-4382
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4382
  [ 2 ] CVE-2006-4384
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4384
  [ 3 ] CVE-2006-4385
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4385
  [ 4 ] CVE-2006-4386
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4386
  [ 5 ] CVE-2006-4388
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4388
  [ 6 ] CVE-2006-4389
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4389
  [ 7 ] CVE-2007-4674
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4674
  [ 8 ] CVE-2007-6166
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6166
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200803-08.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2008 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
http://creativecommons.org/licenses/by-sa/2.5
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFHzc+AuhJ+ozIKI5gRAkBQAJ45BLSUrSDb21Ro/ZHEimwyzBpqqQCcD15e
VpxOGmsa3V34PILWdYXqoXE=
=70De
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
                        
| VAR-200609-0312 | CVE-2006-4385 | Apple QuickTime fails to properly handle SGI images | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted SGI image. Apple QuickTime fails to properly handle SGI images. Successful exploits may facilitate a remote compromise of affected computers. Apple QuickTime is a popular multimedia player that supports a wide variety of media formats. 
McAfee, Inc. QuickTime is used by the Mac OS X operating system and
by the QuickTime media player for Microsoft Windows. 
Seven code execution vulnerabilities are present in QuickTime support
for various multimedia formats including: MOV, H.264, FLC, FPX and SGI. 
Exploitation could lead to execution of arbitrary code. User interaction
is required for an attack to succeed. 
The risk rating for these issues is medium. 
_________________________________________________
*	Vulnerable Systems
QuickTime 7.1.2 and below for Mac OS X
QuickTime for Windows 7.1.2 and below
_________________________________________________
*	Vulnerability Information
CVE-2006-4382
Two buffer overflow vulnerabilities are present in QuickTime MOV format
support. 
CVE-2006-4384
On heap overflow vulnerability is present in QuickTime FLC format
support. 
CVE-2006-4386
One buffer overflow vulnerability is present in QuickTime MOV H.264
format support. 
CVE-2006-4388
One buffer overflow vulnerability is present in QuickTime FlashPix (FPX)
format support. 
CVE-2006-4389
One uninitialized memory access vulnerability is present in QuickTime
FlashPix (FPX) format support. 
_________________________________________________
*	Resolution
Apple has included fixes for the QuickTime issues in QuickTime version
7.1.3 for Mac OS X and for Microsoft Windows.  
Further information is available at:
http://docs.info.apple.com/article.html?artnum=304357
_________________________________________________
*	Credits
These vulnerabilities were discovered by Mike Price of McAfee Avert
Labs. 
_________________________________________________
*	Legal Notice
Copyright (C) 2006 McAfee, Inc. 
The information contained within this advisory is provided for the
convenience of McAfee's customers, and may be redistributed provided
that no fee is charged for distribution and that the advisory is not
modified in any way. McAfee makes no representations or warranties
regarding the accuracy of the information referenced in this document,
or the suitability of that information for your purposes. 
McAfee, Inc. and McAfee Avert Labs are registered Trademarks of McAfee,
Inc. and/or its affiliated companies in the United States and/or other
Countries.  All other registered and unregistered trademarks in this
document are the sole property of their respective owners. 
Best regards,
Dave Marcus, B.A., CCNA, MCSE
Security Research and Communications Manager
McAfee(r) Avert(r) Labs
. 
I. Since QuickTime configures most web browsers to
   handle QuickTime media files, an attacker could exploit these
   vulnerabilities using a web page. 
   For more information, please refer to the Vulnerability Notes. 
II. For further information, please see
   the Vulnerability Notes. 
III. Solution
Upgrade QuickTime
   Upgrade to QuickTime 7.1.3. 
Disable QuickTime in your web browser
   An attacker may be able to exploit this vulnerability by persuading
   a user to access a specially crafted file with a web
   browser. Disabling QuickTime in your web browser will defend
   against this attack vector.  For more information, refer to the
   Securing Your Web Browser document. Please send
   email to <cert@cert.org> with "TA06-256A Feedback VU#540348" in the
   subject. 
 ____________________________________________________________________
  Produced 2006 by US-CERT, a government organization. 
   Terms of use:
     <http://www.us-cert.gov/legal.html>
 ____________________________________________________________________
  
   Revision History
   September 13, 2006: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iQEVAwUBRQg23exOF3G+ig+rAQK7LggAt0RUIz3jewgQYrRYp9bMDBkS61Bvh2OO
8Gp2H472UXA0ucElK/1hAXtPXU2Pmf/EjrCqSImO+srV4i0x5QIFJDo41HtbDo9s
FzQC/rmJ3YWl15L+uIjG0S1wxWwH5GyzQj4xaZCMdNLYEN7LVe31ETDsXJ3kEMMa
m19M4GLOXAFfmjyGgky4Nux0RJU1UE/0w9pZESOXg+7WXFY8skOZ8YfqBvunjqtE
pZa3LWoOcDtP/ORoEn7GY83v/uQqkX8uoAxwe9nuGXbyssvj7BQxDPvnwSWrXzUG
R59/r1NA4i/EtYNV1ONW2Pntqc5/vv0OGcs1JFM9tazV3aRbgHfCVg==
=nQVd
-----END PGP SIGNATURE-----
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  Severity: Normal
     Title: Win32 binary codecs: Multiple vulnerabilities
      Date: March 04, 2008
      Bugs: #150288
        ID: 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities in the Win32 codecs for Linux may result in
the remote execution of arbitrary code. 
Background
==========
Win32 binary codecs provide support for video and audio playback. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All Win32 binary codecs users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose
">=media-libs/win32codecs-20071007-r2"
Note: Since no updated binary versions have been released, the
Quicktime libraries have been removed from the package. Please use the
free alternative Quicktime implementations within VLC, MPlayer or Xine
for playback. 
References
==========
  [ 1 ] CVE-2006-4382
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4382
  [ 2 ] CVE-2006-4384
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4384
  [ 3 ] CVE-2006-4385
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4385
  [ 4 ] CVE-2006-4386
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4386
  [ 5 ] CVE-2006-4388
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4388
  [ 6 ] CVE-2006-4389
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4389
  [ 7 ] CVE-2007-4674
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4674
  [ 8 ] CVE-2007-6166
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6166
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200803-08.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2008 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
                        
| VAR-200609-0309 | CVE-2006-4381 | Apple QuickTime fails to properly handle FLC movies | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie. Apple QuickTime fails to properly handle SGI images. Successful exploits may facilitate a remote compromise of affected computers. Apple QuickTime is a popular multimedia player that supports a wide variety of media formats. 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
                        National Cyber Alert System
                 Technical Cyber Security Alert TA06-256A
Apple QuickTime Vulnerabilities
   Original release date: September 13, 2006
   Last revised: --
   Source: US-CERT
Systems Affected
   Apple QuickTime on systems running
     * Apple Mac OS X
     * Microsoft Windows
Overview
   Apple QuickTime contains multiple vulnerabilities. 
I. Since QuickTime configures most web browsers to
   handle QuickTime media files, an attacker could exploit these
   vulnerabilities using a web page. 
   Note that QuickTime ships with Apple iTunes. 
   For more information, please refer to the Vulnerability Notes. 
II. For further information, please see
   the Vulnerability Notes. 
III. Solution
Upgrade QuickTime
   Upgrade to QuickTime 7.1.3. This and other updates for Mac OS X are
   available via Apple Update. 
Disable QuickTime in your web browser
   An attacker may be able to exploit this vulnerability by persuading
   a user to access a specially crafted file with a web
   browser. Disabling QuickTime in your web browser will defend
   against this attack vector.  For more information, refer to the
   Securing Your Web Browser document. 
References
     * Vulnerability Notes for QuickTime 7.1.3 -
       <http://www.kb.cert.org/vuls/byid?searchview&query=QuickTime_713>
     * About the security content of the QuickTime 7.1.3 Update -
       <http://docs.info.apple.com/article.html?artnum=304357>
     * Apple QuickTime 7.1.3 -
       <http://www.apple.com/support/downloads/quicktime713.html>
     * Standalone Apple QuickTime Player -
       <http://www.apple.com/quicktime/download/standalone.html>
     * Mac OS X: Updating your software -
       <http://docs.info.apple.com/article.html?artnum=106704>
     * Securing Your Web Browser -
       <http://www.us-cert.gov/reading_room/securing_browser/>
 ____________________________________________________________________
   The most recent version of this document can be found at:
     <http://www.us-cert.gov/cas/techalerts/TA06-256A.html>
 ____________________________________________________________________
   
   Feedback can be directed to US-CERT Technical Staff. Please send
   email to <cert@cert.org> with "TA06-256A Feedback VU#540348" in the
   subject. 
 ____________________________________________________________________
  Produced 2006 by US-CERT, a government organization. 
   Terms of use:
     <http://www.us-cert.gov/legal.html>
 ____________________________________________________________________
  
   Revision History
   September 13, 2006: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iQEVAwUBRQg23exOF3G+ig+rAQK7LggAt0RUIz3jewgQYrRYp9bMDBkS61Bvh2OO
8Gp2H472UXA0ucElK/1hAXtPXU2Pmf/EjrCqSImO+srV4i0x5QIFJDo41HtbDo9s
FzQC/rmJ3YWl15L+uIjG0S1wxWwH5GyzQj4xaZCMdNLYEN7LVe31ETDsXJ3kEMMa
m19M4GLOXAFfmjyGgky4Nux0RJU1UE/0w9pZESOXg+7WXFY8skOZ8YfqBvunjqtE
pZa3LWoOcDtP/ORoEn7GY83v/uQqkX8uoAxwe9nuGXbyssvj7BQxDPvnwSWrXzUG
R59/r1NA4i/EtYNV1ONW2Pntqc5/vv0OGcs1JFM9tazV3aRbgHfCVg==
=nQVd
-----END PGP SIGNATURE-----
. 
----------------------------------------------------------------------
Want to work within IT-Security?
Secunia is expanding its team of highly skilled security experts. 
We will help with relocation and obtaining a work permit. 
Currently the following type of positions are available:
http://secunia.com/quality_assurance_analyst/
http://secunia.com/web_application_security_specialist/ 
http://secunia.com/hardcore_disassembler_and_reverse_engineer/
----------------------------------------------------------------------
TITLE:
Apple QuickTime Multiple Vulnerabilities
SECUNIA ADVISORY ID:
SA21893
VERIFY ADVISORY:
http://secunia.com/advisories/21893/
CRITICAL:
Highly critical
IMPACT:
System access
WHERE:
>From remote
SOFTWARE:
Apple QuickTime 7.x
http://secunia.com/product/5090/
DESCRIPTION:
Multiple vulnerabilities have been reported in Apple QuickTime, which
can be exploited by malicious people to compromise a user's system. 
2) A boundary error within the processing of QuickTime movies can be
exploited to cause a buffer overflow. 
3) A boundary error within the processing of FLC movies can be
exploited to cause a heap-based buffer overflow via a FLC movie with
a specially crafted COLOR_64 chunk. 
4) Errors within the processing of FlashPix files can be exploited to
cause an integer overflow or buffer overflow. 
5) An error within the processing of FlashPix files can be exploited
to trigger an exception leaving an uninitialised object. 
6) A boundary error within the processing of SGI images can be
exploited to cause a buffer overflow. 
SOLUTION:
Update to version 7.1.3. 
http://www.apple.com/quicktime/download/
PROVIDED AND/OR DISCOVERED BY:
The vendor credits:
1) Sowhat of Nevis Labs, Mike Price of McAfee AVERT Labs, and Piotr
Bania. 
2) Mike Price of McAfee AVERT Labs. 
3) Mike Price of McAfee AVERT Labs and Ruben Santamarta. 
4) Mike Price of McAfee AVERT Labs. 
5) Mike Price of McAfee AVERT Labs. 
6) Mike Price of McAfee AVERT Labs
ORIGINAL ADVISORY:
Apple:
http://docs.info.apple.com/article.html?artnum=304357
iDEFENSE:
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=413
Reverse Mode:
http://www.reversemode.com/index.php?option=com_remository&Itemid=2&func=fileinfo&id=25
Piotr Bania:
http://pb.specialised.info/all/adv/quicktime-integer-overflow-h264-adv-7.1.txt
----------------------------------------------------------------------
About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities. 
Subscribe:
http://secunia.com/secunia_security_advisories/
Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/
Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link. 
Secunia NEVER sends attached files with advisories. 
Secunia does not advise people to install third party patches, only
use those supplied by the vendor. 
----------------------------------------------------------------------
Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org
----------------------------------------------------------------------
                        
| VAR-200609-0313 | CVE-2006-4386 | Apple QuickTime fails to properly handle SGI images | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted H.264 movie, a different issue than CVE-2006-4381. Apple QuickTime fails to properly handle SGI images. Apple From, as a countermeasure version Quicktime 7.1.3 Has been released.Arbitrary code or commands can be executed by a remote third party, DoS You can be attacked. Successful exploits may facilitate a remote compromise of affected computers. 
	CVE:			CVE-2006-4386
	Orginal URL:	 
http://piotrbania.com/all/adv/quicktime-integer-overflow-h264-adv-7.1.txt
	Software affected:	Tested on QucikTime 7.1 (Windows version), with
				all newest add-ons. 
	0.   DISCLAIMER
	Author takes no responsibility for any actions with provided 
informations or
	codes. The copyright for any material created by the author is 
reserved. Any
	duplication of codes or texts provided here in electronic or printed
	publications is not permitted without the author's agreement. 
	I. 
	II. 
The overflow
	occurs in the H.264 codec. 
	
	Vulnerable code:
	6825a28f 668b4806         mov     cx,[eax+0x6]		; cx = controled by 
attacker
	6825a293 660fb6d5         movzx   dx,ch			; dx = 0x00XX (XX - controled 
by attacker)
	6825a297 8af1             mov     dh,cl			; dx = 0xXXXX (-//-)
	6825a299 8bca             mov     ecx,edx		; ecx = edx
	6825a29b 6681f90001       cmp     cx,0x100		; compare cx with 0x100
	6825a2a0 7f3d     jg QuickTimeH264!JVTCompComponentDispatch+0x917c 
(6825a2df) ; (*1*)
	6825a2a2 0fbfd1           movsx   edx,cx		; (*2*)
	6825a2a5 8bca             mov     ecx,edx
	6825a2a7 8bd9             mov     ebx,ecx
	6825a2a9 c1e902           shr     ecx,0x2
	6825a2ac 8d7008           lea     esi,[eax+0x8]
	6825a2af 8d7c2418         lea     edi,[esp+0x18]
	6825a2b3 f3a5             rep  movsd ds:00fb8000=????????
	*1 - JG jumps, takes care of the sign so in this case we have an 
security check for upper
	     bounds, but when cx is a negative number this check is bypassed. 
No lower bounds
	     checks were applied - bad. 
	*2 - Due to the bypass of the point *1 EDX is now CX extended by sign 
(in this case its
	     negative), EDX now looks like 0xFFFFXXXX, the integer is 
overflowed and rep movsd
	     causes an memory corruption (obvious fact is that ECX is related 
to EDX). 
		
	Debugger output:
	eax=00fb2028 ebx=ffffc9c9 ecx=3fffda7e edx=ffffc9c9 esi=00fb8000 
edi=00141688
	eip=6825a2b3 esp=0013b6a0 ebp=0013b8c4 iopl=0         nv up ei pl nz ac 
po nc
	cs=001b  ss=0023  ds=0023  es=0023  fs=0038  gs=0000 
efl=00010216
	*** ERROR: Symbol file could not be found.  Defaulted to export symbols 
for E:\Quicktime\QTSystem\QuickTimeH264.qtx -
	QuickTimeH264!JVTCompComponentDispatch+0x9150:
	6825a2b3 f3a5            rep  movsd ds:00fb8000=???????? 
es:00141688=00000000
	The vulnerability may lead to remote code execution when specially
	crafted video file (MOV file) is being loaded. 
	
	III. POC CODE
	Due to severity of this bug i will not release any proof of concept
         codes for this issue. 
	IV.  VENDOR RESPONSE
	Check: http://docs.info.apple.com/article.html?artnum=61798
	
	
. 
McAfee, Inc. QuickTime is used by the Mac OS X operating system and
by the QuickTime media player for Microsoft Windows. 
Seven code execution vulnerabilities are present in QuickTime support
for various multimedia formats including: MOV, H.264, FLC, FPX and SGI. 
Exploitation could lead to execution of arbitrary code. User interaction
is required for an attack to succeed. 
The risk rating for these issues is medium. 
_________________________________________________
*	Vulnerable Systems
QuickTime 7.1.2 and below for Mac OS X
QuickTime for Windows 7.1.2 and below
_________________________________________________
*	Vulnerability Information
CVE-2006-4382
Two buffer overflow vulnerabilities are present in QuickTime MOV format
support. 
CVE-2006-4384
On heap overflow vulnerability is present in QuickTime FLC format
support. 
CVE-2006-4385
One buffer overflow vulnerability is present in QuickTime SGI format
support. 
CVE-2006-4386
One buffer overflow vulnerability is present in QuickTime MOV H.264
format support. 
CVE-2006-4388
One buffer overflow vulnerability is present in QuickTime FlashPix (FPX)
format support. 
CVE-2006-4389
One uninitialized memory access vulnerability is present in QuickTime
FlashPix (FPX) format support. 
_________________________________________________
*	Resolution
Apple has included fixes for the QuickTime issues in QuickTime version
7.1.3 for Mac OS X and for Microsoft Windows.  
Further information is available at:
http://docs.info.apple.com/article.html?artnum=304357
_________________________________________________
*	Credits
These vulnerabilities were discovered by Mike Price of McAfee Avert
Labs. 
_________________________________________________
*	Legal Notice
Copyright (C) 2006 McAfee, Inc. 
The information contained within this advisory is provided for the
convenience of McAfee's customers, and may be redistributed provided
that no fee is charged for distribution and that the advisory is not
modified in any way. McAfee makes no representations or warranties
regarding the accuracy of the information referenced in this document,
or the suitability of that information for your purposes. 
McAfee, Inc. and McAfee Avert Labs are registered Trademarks of McAfee,
Inc. and/or its affiliated companies in the United States and/or other
Countries.  All other registered and unregistered trademarks in this
document are the sole property of their respective owners. 
Best regards,
Dave Marcus, B.A., CCNA, MCSE
Security Research and Communications Manager
McAfee(r) Avert(r) Labs
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  Severity: Normal
     Title: Win32 binary codecs: Multiple vulnerabilities
      Date: March 04, 2008
      Bugs: #150288
        ID: 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities in the Win32 codecs for Linux may result in
the remote execution of arbitrary code. 
Background
==========
Win32 binary codecs provide support for video and audio playback. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All Win32 binary codecs users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose
">=media-libs/win32codecs-20071007-r2"
Note: Since no updated binary versions have been released, the
Quicktime libraries have been removed from the package. Please use the
free alternative Quicktime implementations within VLC, MPlayer or Xine
for playback. 
References
==========
  [ 1 ] CVE-2006-4382
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4382
  [ 2 ] CVE-2006-4384
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4384
  [ 3 ] CVE-2006-4385
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4385
  [ 4 ] CVE-2006-4386
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4386
  [ 5 ] CVE-2006-4388
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4388
  [ 6 ] CVE-2006-4389
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4389
  [ 7 ] CVE-2007-4674
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4674
  [ 8 ] CVE-2007-6166
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6166
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200803-08.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2008 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
http://creativecommons.org/licenses/by-sa/2.5
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org
iD8DBQFHzc+AuhJ+ozIKI5gRAkBQAJ45BLSUrSDb21Ro/ZHEimwyzBpqqQCcD15e
VpxOGmsa3V34PILWdYXqoXE=
=70De
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
                        
| VAR-200609-0314 | CVE-2006-4388 | Apple QuickTime fails to properly handle SGI images | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Integer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via a crafted FlashPix file. Apple QuickTime fails to properly handle SGI images. Successful exploits may facilitate a remote compromise of affected computers. Apple QuickTime is a multimedia playback software developed by Apple (Apple). The software is capable of handling multiple sources such as digital video, media segments, and more. 
McAfee, Inc. QuickTime is used by the Mac OS X operating system and
by the QuickTime media player for Microsoft Windows. 
Seven code execution vulnerabilities are present in QuickTime support
for various multimedia formats including: MOV, H.264, FLC, FPX and SGI. 
Exploitation could lead to execution of arbitrary code. User interaction
is required for an attack to succeed. 
The risk rating for these issues is medium. 
_________________________________________________
*	Vulnerable Systems
QuickTime 7.1.2 and below for Mac OS X
QuickTime for Windows 7.1.2 and below
_________________________________________________
*	Vulnerability Information
CVE-2006-4382
Two buffer overflow vulnerabilities are present in QuickTime MOV format
support. 
CVE-2006-4384
On heap overflow vulnerability is present in QuickTime FLC format
support. 
CVE-2006-4385
One buffer overflow vulnerability is present in QuickTime SGI format
support. 
CVE-2006-4386
One buffer overflow vulnerability is present in QuickTime MOV H.264
format support. 
CVE-2006-4388
One buffer overflow vulnerability is present in QuickTime FlashPix (FPX)
format support. 
CVE-2006-4389
One uninitialized memory access vulnerability is present in QuickTime
FlashPix (FPX) format support. 
_________________________________________________
*	Resolution
Apple has included fixes for the QuickTime issues in QuickTime version
7.1.3 for Mac OS X and for Microsoft Windows.  
Further information is available at:
http://docs.info.apple.com/article.html?artnum=304357
_________________________________________________
*	Credits
These vulnerabilities were discovered by Mike Price of McAfee Avert
Labs. 
_________________________________________________
*	Legal Notice
Copyright (C) 2006 McAfee, Inc. 
The information contained within this advisory is provided for the
convenience of McAfee's customers, and may be redistributed provided
that no fee is charged for distribution and that the advisory is not
modified in any way. McAfee makes no representations or warranties
regarding the accuracy of the information referenced in this document,
or the suitability of that information for your purposes. 
McAfee, Inc. and McAfee Avert Labs are registered Trademarks of McAfee,
Inc. and/or its affiliated companies in the United States and/or other
Countries.  All other registered and unregistered trademarks in this
document are the sole property of their respective owners. 
Best regards,
Dave Marcus, B.A., CCNA, MCSE
Security Research and Communications Manager
McAfee(r) Avert(r) Labs
. 
I. Since QuickTime configures most web browsers to
   handle QuickTime media files, an attacker could exploit these
   vulnerabilities using a web page. 
   Note that QuickTime ships with Apple iTunes. 
   For more information, please refer to the Vulnerability Notes. 
II. For further information, please see
   the Vulnerability Notes. 
III. Solution
Upgrade QuickTime
   Upgrade to QuickTime 7.1.3. 
Disable QuickTime in your web browser
   An attacker may be able to exploit this vulnerability by persuading
   a user to access a specially crafted file with a web
   browser. Disabling QuickTime in your web browser will defend
   against this attack vector.  For more information, refer to the
   Securing Your Web Browser document. Please send
   email to <cert@cert.org> with "TA06-256A Feedback VU#540348" in the
   subject. 
 ____________________________________________________________________
  Produced 2006 by US-CERT, a government organization. 
   Terms of use:
     <http://www.us-cert.gov/legal.html>
 ____________________________________________________________________
  
   Revision History
   September 13, 2006: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iQEVAwUBRQg23exOF3G+ig+rAQK7LggAt0RUIz3jewgQYrRYp9bMDBkS61Bvh2OO
8Gp2H472UXA0ucElK/1hAXtPXU2Pmf/EjrCqSImO+srV4i0x5QIFJDo41HtbDo9s
FzQC/rmJ3YWl15L+uIjG0S1wxWwH5GyzQj4xaZCMdNLYEN7LVe31ETDsXJ3kEMMa
m19M4GLOXAFfmjyGgky4Nux0RJU1UE/0w9pZESOXg+7WXFY8skOZ8YfqBvunjqtE
pZa3LWoOcDtP/ORoEn7GY83v/uQqkX8uoAxwe9nuGXbyssvj7BQxDPvnwSWrXzUG
R59/r1NA4i/EtYNV1ONW2Pntqc5/vv0OGcs1JFM9tazV3aRbgHfCVg==
=nQVd
-----END PGP SIGNATURE-----
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  Severity: Normal
     Title: Win32 binary codecs: Multiple vulnerabilities
      Date: March 04, 2008
      Bugs: #150288
        ID: 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities in the Win32 codecs for Linux may result in
the remote execution of arbitrary code. 
Background
==========
Win32 binary codecs provide support for video and audio playback. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All Win32 binary codecs users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose
">=media-libs/win32codecs-20071007-r2"
Note: Since no updated binary versions have been released, the
Quicktime libraries have been removed from the package. Please use the
free alternative Quicktime implementations within VLC, MPlayer or Xine
for playback. 
References
==========
  [ 1 ] CVE-2006-4382
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4382
  [ 2 ] CVE-2006-4384
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4384
  [ 3 ] CVE-2006-4385
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4385
  [ 4 ] CVE-2006-4386
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4386
  [ 5 ] CVE-2006-4388
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4388
  [ 6 ] CVE-2006-4389
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4389
  [ 7 ] CVE-2007-4674
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4674
  [ 8 ] CVE-2007-6166
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6166
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200803-08.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2008 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
                        
| VAR-200609-0311 | CVE-2006-4384 | Apple QuickTime fails to properly handle FLC movies | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Heap-based buffer overflow in Apple QuickTime before 7.1.3 allows user-assisted remote attackers to execute arbitrary code via the COLOR_64 chunk in a FLIC (FLC) movie. Apple QuickTime fails to properly handle SGI images. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial-of-service condition. Successful exploits may facilitate a remote compromise of affected computers. Apple QuickTime FLIC File Heap Overflow Vulnerability
iDefense Security Advisory 09.12.06
http://www.idefense.com/intelligence/vulnerabilities/
Sep 12, 2006
I. BACKGROUND
Quicktime is Apple's media player product used to render video and other
media.  For more information visit http://www.apple.com/quicktime/
II. 
A FLIC file is an animation file consisting of a number of frames, each
of which is made up of an image and may contain other information such
as a palette or a label. 
The vulnerability specifically exists in the handling of the COLOR_64
chunk in FLIC format files. QuickTime does not validate that the data
size allocated to store the palette is large enough, allowing a
malformed file to cause controllable heap corruption. 
III. In order to exploit this
vulnerability, attackers must social engineer victims into visiting a
website under their control. 
The QuickTime plugin can be forced to load in Firefox and Internet
Explorer. Furthermore, testing shows that either browser can be used as
an attack vector. It is also possible to open this type of file directly
from within QuickTime or from a playlist that QuickTime has opened. 
The data being used to overwrite the heap is in the form 0x00XXYYZZ,
where XX, YY and ZZ are controllable. This limits the range of values
that can be overwritten, but does not prevent it. 
IV. DETECTION
iDefense Labs confirmed that version 7.1 of the QuickTime player is
vulnerable. It is suspected that all previous versions are also
affected. 
V. WORKAROUND
iDefense is currently unaware of any effective workarounds for this
vulnerability. 
VI. VENDOR RESPONSE
"
QuickTime 7.1.3 may be obtained from the Software Update pane in
System Preferences, or from the Download tab in the QuickTime site
http://www.apple.com/quicktime/
For Mac OS X v10.3.9 or later
The download file is named:  "QuickTimeInstallerX.dmg"
Its SHA-1 digest is:  55cfeb0d92d8e0a0694267df58d2b53526d24d3d
QuickTime 7.1.3 for Windows 2000/XP
The download file is named:  "QuickTimeInstaller.exe"
Its SHA-1 digest is:  047a9f2d88c8a865b4ad5f24c9904b8727ba71e7
QuickTime 7.1.3 with iTunes for Windows 2000/XP
The download file is named:  "iTunesSetup.exe"
Its SHA-1 digest is:  5cdc86b2edb1411b9a022f05b1bfbe858fbcf901
Information will also be posted to the Apple Product Security
web site:  http://docs.info.apple.com/article.html?artnum=61798
"
VII. CVE INFORMATION
The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CAN-2006-4384 to this issue. This is a candidate for inclusion in
the CVE list (http://cve.mitre.org), which standardizes names for
security problems. 
VIII. DISCLOSURE TIMELINE
08/16/2006  Initial vendor notification
08/16/2006  Initial vendor response
09/12/2006  Coordinated public disclosure
IX. CREDIT
This vulnerability was reported to iDefense by Rub\xe9n Santamarta of
reversemode.com. 
Get paid for vulnerability research
http://www.idefense.com/methodology/vulnerability/vcp.php
Free tools, research and upcoming events
http://labs.iDefense.com/
X. LEGAL NOTICES
Copyright \xa9 2006 iDefense, Inc. 
Permission is granted for the redistribution of this alert
electronically. It may not be edited in any way without the express
written consent of iDefense. If you wish to reprint the whole or any
part of this alert in any other medium other than electronically, please
email customerservice@iDefense.com for permission. 
Disclaimer: The information in the advisory is believed to be accurate
at the time of publishing based on currently available information. Use
of the information constitutes acceptance for use in an AS IS condition. 
There are no warranties with regard to this information. Neither the
author nor the publisher accepts any liability for any direct, indirect,
or consequential loss or damage arising from use of, or reliance on,
this information. 
McAfee, Inc. QuickTime is used by the Mac OS X operating system and
by the QuickTime media player for Microsoft Windows. 
Seven code execution vulnerabilities are present in QuickTime support
for various multimedia formats including: MOV, H.264, FLC, FPX and SGI. 
Exploitation could lead to execution of arbitrary code. User interaction
is required for an attack to succeed. 
The risk rating for these issues is medium. 
_________________________________________________
*	Vulnerable Systems
QuickTime 7.1.2 and below for Mac OS X
QuickTime for Windows 7.1.2 and below
_________________________________________________
*	Vulnerability Information
CVE-2006-4382
Two buffer overflow vulnerabilities are present in QuickTime MOV format
support. 
CVE-2006-4385
One buffer overflow vulnerability is present in QuickTime SGI format
support. 
CVE-2006-4386
One buffer overflow vulnerability is present in QuickTime MOV H.264
format support. 
CVE-2006-4389
One uninitialized memory access vulnerability is present in QuickTime
FlashPix (FPX) format support. 
_________________________________________________
*	Resolution
Apple has included fixes for the QuickTime issues in QuickTime version
7.1.3 for Mac OS X and for Microsoft Windows.  
Further information is available at:
http://docs.info.apple.com/article.html?artnum=304357
_________________________________________________
*	Credits
These vulnerabilities were discovered by Mike Price of McAfee Avert
Labs. 
The information contained within this advisory is provided for the
convenience of McAfee's customers, and may be redistributed provided
that no fee is charged for distribution and that the advisory is not
modified in any way. McAfee makes no representations or warranties
regarding the accuracy of the information referenced in this document,
or the suitability of that information for your purposes. 
McAfee, Inc. and McAfee Avert Labs are registered Trademarks of McAfee,
Inc. and/or its affiliated companies in the United States and/or other
Countries.  All other registered and unregistered trademarks in this
document are the sole property of their respective owners. 
Best regards,
Dave Marcus, B.A., CCNA, MCSE
Security Research and Communications Manager
McAfee(r) Avert(r) Labs
. 
I. Since QuickTime configures most web browsers to
   handle QuickTime media files, an attacker could exploit these
   vulnerabilities using a web page. 
   Note that QuickTime ships with Apple iTunes. 
   For more information, please refer to the Vulnerability Notes. Solution
Upgrade QuickTime
   Upgrade to QuickTime 7.1.3. 
Disable QuickTime in your web browser
   An attacker may be able to exploit this vulnerability by persuading
   a user to access a specially crafted file with a web
   browser.  For more information, refer to the
   Securing Your Web Browser document. Please send
   email to <cert@cert.org> with "TA06-256A Feedback VU#540348" in the
   subject. 
 ____________________________________________________________________
  Produced 2006 by US-CERT, a government organization. 
   Terms of use:
     <http://www.us-cert.gov/legal.html>
 ____________________________________________________________________
  
   Revision History
   September 13, 2006: Initial release
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)
iQEVAwUBRQg23exOF3G+ig+rAQK7LggAt0RUIz3jewgQYrRYp9bMDBkS61Bvh2OO
8Gp2H472UXA0ucElK/1hAXtPXU2Pmf/EjrCqSImO+srV4i0x5QIFJDo41HtbDo9s
FzQC/rmJ3YWl15L+uIjG0S1wxWwH5GyzQj4xaZCMdNLYEN7LVe31ETDsXJ3kEMMa
m19M4GLOXAFfmjyGgky4Nux0RJU1UE/0w9pZESOXg+7WXFY8skOZ8YfqBvunjqtE
pZa3LWoOcDtP/ORoEn7GY83v/uQqkX8uoAxwe9nuGXbyssvj7BQxDPvnwSWrXzUG
R59/r1NA4i/EtYNV1ONW2Pntqc5/vv0OGcs1JFM9tazV3aRbgHfCVg==
=nQVd
-----END PGP SIGNATURE-----
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  Severity: Normal
     Title: Win32 binary codecs: Multiple vulnerabilities
      Date: March 04, 2008
      Bugs: #150288
        ID: 200803-08
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities in the Win32 codecs for Linux may result in
the remote execution of arbitrary code. 
Background
==========
Win32 binary codecs provide support for video and audio playback. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All Win32 binary codecs users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose
">=media-libs/win32codecs-20071007-r2"
Note: Since no updated binary versions have been released, the
Quicktime libraries have been removed from the package. Please use the
free alternative Quicktime implementations within VLC, MPlayer or Xine
for playback. 
References
==========
  [ 1 ] CVE-2006-4382
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4382
  [ 2 ] CVE-2006-4384
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4384
  [ 3 ] CVE-2006-4385
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4385
  [ 4 ] CVE-2006-4386
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4386
  [ 5 ] CVE-2006-4388
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4388
  [ 6 ] CVE-2006-4389
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4389
  [ 7 ] CVE-2007-4674
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4674
  [ 8 ] CVE-2007-6166
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6166
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200803-08.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2008 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
                        
| VAR-200609-0811 | CVE-2006-2937 | OpenSSL may fail to properly parse invalid ASN.1 structures | CVSS V2: 7.8 CVSS V3: - Severity: HIGH | 
                            OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. 
An attacker may exploit this issue to cause applications that use the vulnerable library to consume excessive CPU and memory resources and crash, denying further service to legitimate users. This can result in an infinite loop which
     consumes system memory. The Common Vulnerabilities and Exposures
     (CVE) project assigned the id CVE-2006-2937 [2] to the problem. 
  2. ASN.1 Denial of Service Attack (2/2)
     Certain types of public key can take disproportionate amounts of
     time to process. This could be used by an attacker in a denial of
     service attack. The Common Vulnerabilities and Exposures (CVE)
     project assigned the id CVE-2006-2940 [3] to the problem. 
  3. SSL_get_shared_ciphers() Buffer Overflow
     A buffer overflow was discovered in the SSL_get_shared_ciphers()
     utility function. An attacker could send a list of ciphers to an
     application that uses this function and overrun a buffer. The
     Common Vulnerabilities and Exposures (CVE) project assigned the id
     CVE-2006-3780 [4] to the problem. 
  4. SSLv2 Client Crash
 
     A flaw in the SSLv2 client code was discovered. The
     Common Vulnerabilities and Exposures (CVE) project assigned the id
     CVE-2006-4343 [5] to the problem. 
________________________________________________________________________
References:
  [0] http://www.openssl.org/news/secadv_20060928.txt 
  [1] http://www.openssl.org/
  [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
  [3] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
  [4] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
  [5] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
________________________________________________________________________
For security reasons, this advisory was digitally signed with the
OpenPGP public key "OpenPKG <openpkg@openpkg.org>" (ID 63C4CB9F) of the
OpenPKG project which you can retrieve from http://pgp.openpkg.org and
hkp://pgp.openpkg.org. Follow the instructions on http://pgp.openpkg.org
for details on how to verify the integrity of this advisory. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
SUPPORT COMMUNICATION - SECURITY BULLETIN
Document ID: c01118771
Version: 1
HPSBMA02250 SSRT061275 rev.1 - HP System Management Homepage (SMH) for Linux and Windows, Remote Execution of Arbitrary Code and Denial of Service (DoS)
NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. 
Release Date: 2007-08-01
Last Updated: 2007-08-01
Potential Security Impact: Remote execution of arbitrary code and Denial of Service (DoS)
Source: Hewlett-Packard Company, HP Software Security Response Team
VULNERABILITY SUMMARY
Potential security vulnerabilities have been identified HP System Management Homepage (SMH) for Linux and Windows. These vulnerabilities could by exploited remotely resulting in the execution of arbitrary code or a Denial of Service (DoS). 
References: CVE-2006-2937, CVE-2006-2940, CVE-2006-3738, CVE-2006-3747, CVE-2006-4339, CVE-2006-4343
SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. 
HP System Management Homepage (SMH) versions prior to 2.1.7 running on Linux and Windows. 
BACKGROUND
RESOLUTION
HP has provided System Management Homepage (SMH) version 2.1.7 or subsequent for each platform to resolve this issue. 
A more recent version is available: System Management Homepage (SMH) version 2.1.8 
HP System Management Homepage for Linux (x86) version 2.1.8-177 can be downloaded from 
http://h18023.www1.hp.com/support/files/server/us/download/26864.html 
HP System Management Homepage for Linux (AMD64/EM64T) version 2.1.8-177 can be downloaded from 
http://h18023.www1.hp.com/support/files/server/us/download/26866.html 
HP System Management Homepage for Windows version 2.1.8-179 can be downloaded from 
http://h18023.www1.hp.com/support/files/server/us/download/26977.html 
PRODUCT SPECIFIC INFORMATION 
HISTORY: 
Version:1 (rev.1) - 1 August 2007 Initial Release 
Third Party Security Patches: Third party security patches which are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. 
Support: For further information, contact normal HP Services support channel. 
Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com 
It is strongly recommended that security related information being communicated to HP be encrypted using PGP, especially exploit information. 
To get the security-alert PGP key, please send an e-mail message as follows:
  To: security-alert@hp.com 
  Subject: get key
Subscribe: To initiate a subscription to receive future HP Security Bulletins via Email: 
http://h30046.www3.hp.com/driverAlertProfile.php?regioncode=NA&langcode=USENG&jumpid=in_SC-GEN__driverITRC&topiccode=ITRC 
On the web page: ITRC security bulletins and patch sign-up 
Under Step1: your ITRC security bulletins and patches 
  - check ALL categories for which alerts are required and continue. 
Under Step2: your ITRC operating systems 
  - verify your operating system selections are checked and save. 
To update an existing subscription: http://h30046.www3.hp.com/subSignIn.php 
Log in on the web page: Subscriber's choice for Business: sign-in. 
On the web page: Subscriber's Choice: your profile summary - use Edit Profile to update appropriate sections. 
To review previously published Security Bulletins visit: http://www.itrc.hp.com/service/cki/secBullArchive.do 
* The Software Product Category that this Security Bulletin relates to is represented by the 5th and 6th characters of the Bulletin number in the title: 
GN = HP General SW
MA = HP Management Agents
MI = Misc. 3rd Party SW
MP = HP MPE/iX
NS = HP NonStop Servers
OV = HP OpenVMS
PI = HP Printing & Imaging
ST = HP Storage SW
TL = HP Trusted Linux 
TU = HP Tru64 UNIX
UX = HP-UX
VV = HP VirtualVault
 
System management and security procedures must be reviewed frequently to maintain system integrity. HP is continually reviewing and enhancing the security features of software products to provide customers with current secure solutions. 
"HP is broadly distributing this Security Bulletin in order to bring to the attention of users of the affected HP products the important security information contained in this Bulletin. HP recommends that all users determine the applicability of this information to their individual situations and take appropriate action. HP does not warrant that this information is necessarily accurate or complete for all user situations and, consequently, HP will not be responsible for any damages resulting from user's use or disregard of the information provided in this Bulletin. To the extent permitted by law, HP disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement."
\xa9Copyright 2007 Hewlett-Packard Development Company, L.P. 
Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental, special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. 
-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1
iQA/AwUBRrIKieAfOvwtKn1ZEQJUJACfakfLP0u32ySuj4KuXa+P2KgKODEAoIag
4otTq1h8U9Q2sa0noibOymby
=jOXf
-----END PGP SIGNATURE-----
. 
--WfZ7S8PLGjBY9Voh
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200610-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  Severity: High
     Title: OpenSSL: Multiple vulnerabilities
      Date: October 24, 2006
      Bugs: #145510
        ID: 200610-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
OpenSSL contains multiple vulnerabilities including the possible remote
execution of arbitrary code. 
Background
==========
OpenSSL is a toolkit implementing the Secure Sockets Layer, Transport
Layer Security protocols and a general-purpose cryptography library. Additionally Dr. Stephen N. 
Workaround
==========
There is no known workaround at this time. 
Resolution
==========
All OpenSSL 0.9.8 users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-libs/openssl-0.9.8d"
All OpenSSL 0.9.7 users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-libs/openssl-0.9.7l"
References
==========
  [ 1 ] CVE-2006-2937
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
  [ 2 ] CVE-2006-2940
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
  [ 3 ] CVE-2006-3738
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
  [ 4 ] CVE-2006-4343
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200610-11.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. (CVE-2006-4343)
 Updated packages are patched to address these issues. 
 _______________________________________________________________________
 References:
 
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
 _______________________________________________________________________
 
 Updated Packages:
 
 Mandriva Linux 2006.0:
 17e2d82c3f6c0afbf48eccbfbcc17b55  2006.0/i586/libopenssl0.9.7-0.9.7g-2.4.20060mdk.i586.rpm
 8c3f89e1900f069d4a4ad3162a9f7d78  2006.0/i586/libopenssl0.9.7-devel-0.9.7g-2.4.20060mdk.i586.rpm
 3a68c653ba0339ba99162459385c72e2  2006.0/i586/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mdk.i586.rpm
 8291bde3bd9aa95533aabc07280203b8  2006.0/i586/openssl-0.9.7g-2.4.20060mdk.i586.rpm 
 52b3fbfc1389bcd73e406d6ff741e9dc  2006.0/SRPMS/openssl-0.9.7g-2.4.20060mdk.src.rpm
 Mandriva Linux 2006.0/X86_64:
 b2ce6e6bb7e3114663d3a074d0cc7da5  2006.0/x86_64/lib64openssl0.9.7-0.9.7g-2.4.20060mdk.x86_64.rpm
 f7c8dbc2eda0c90547d43661454d1068  2006.0/x86_64/lib64openssl0.9.7-devel-0.9.7g-2.4.20060mdk.x86_64.rpm
 7c9ebd9f9179f4e93627dcf0f3442335  2006.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7g-2.4.20060mdk.x86_64.rpm
 17e2d82c3f6c0afbf48eccbfbcc17b55  2006.0/x86_64/libopenssl0.9.7-0.9.7g-2.4.20060mdk.i586.rpm
 8c3f89e1900f069d4a4ad3162a9f7d78  2006.0/x86_64/libopenssl0.9.7-devel-0.9.7g-2.4.20060mdk.i586.rpm
 3a68c653ba0339ba99162459385c72e2  2006.0/x86_64/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mdk.i586.rpm
 6ce5832a59b8b67425cb7026ea9dc876  2006.0/x86_64/openssl-0.9.7g-2.4.20060mdk.x86_64.rpm 
 52b3fbfc1389bcd73e406d6ff741e9dc  2006.0/SRPMS/openssl-0.9.7g-2.4.20060mdk.src.rpm
 Mandriva Linux 2007.0:
 1bfeff47c8d2f6c020c459881be68207  2007.0/i586/libopenssl0.9.8-0.9.8b-2.1mdv2007.0.i586.rpm
 1e1a4db54ddfaedb08a6d847422099ff  2007.0/i586/libopenssl0.9.8-devel-0.9.8b-2.1mdv2007.0.i586.rpm
 59c80405f33b2e61ffd3cef025635e21  2007.0/i586/libopenssl0.9.8-static-devel-0.9.8b-2.1mdv2007.0.i586.rpm
 3a6657970a2e7661bd869d221a69c8da  2007.0/i586/openssl-0.9.8b-2.1mdv2007.0.i586.rpm 
 aad29e57ddceb66105af5d6434de9a62  2007.0/SRPMS/openssl-0.9.8b-2.1mdv2007.0.src.rpm
 Mandriva Linux 2007.0/X86_64:
 af679c647d97214244a8423dc1a766b7  2007.0/x86_64/lib64openssl0.9.8-0.9.8b-2.1mdv2007.0.x86_64.rpm
 d7b1ed07df4115b3bcc3907e00d25a89  2007.0/x86_64/lib64openssl0.9.8-devel-0.9.8b-2.1mdv2007.0.x86_64.rpm
 5bd3ece2c0ec7a3201c29fa84e25a75a  2007.0/x86_64/lib64openssl0.9.8-static-devel-0.9.8b-2.1mdv2007.0.x86_64.rpm
 9b028020dba009eddbf06eeb8607b87f  2007.0/x86_64/openssl-0.9.8b-2.1mdv2007.0.x86_64.rpm 
 aad29e57ddceb66105af5d6434de9a62  2007.0/SRPMS/openssl-0.9.8b-2.1mdv2007.0.src.rpm
 Corporate 3.0:
 c99ea58f6f4959a4c36398cc6b2b4ee2  corporate/3.0/i586/libopenssl0.9.7-0.9.7c-3.6.C30mdk.i586.rpm
 98a925c5ba2ecc9d704b1e730035755e  corporate/3.0/i586/libopenssl0.9.7-devel-0.9.7c-3.6.C30mdk.i586.rpm
 151493a50693e3b9cc67bfafadb9ce42  corporate/3.0/i586/libopenssl0.9.7-static-devel-0.9.7c-3.6.C30mdk.i586.rpm
 82b4709bdbb9128746887013a724356a  corporate/3.0/i586/openssl-0.9.7c-3.6.C30mdk.i586.rpm 
 a5bdbe6afa52005a734dc18aa951677d  corporate/3.0/SRPMS/openssl-0.9.7c-3.6.C30mdk.src.rpm
 Corporate 3.0/X86_64:
 01a922d80d6fc9d1b36dde15ee27747e  corporate/3.0/x86_64/lib64openssl0.9.7-0.9.7c-3.6.C30mdk.x86_64.rpm
 30268f0b70862d1f5998694ac8b4addc  corporate/3.0/x86_64/lib64openssl0.9.7-devel-0.9.7c-3.6.C30mdk.x86_64.rpm
 e0388ff1efa34ea55d033e95b4e9bb63  corporate/3.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7c-3.6.C30mdk.x86_64.rpm
 c99ea58f6f4959a4c36398cc6b2b4ee2  corporate/3.0/x86_64/libopenssl0.9.7-0.9.7c-3.6.C30mdk.i586.rpm
 83759622f0cc8ea9c0f6d32671283354  corporate/3.0/x86_64/openssl-0.9.7c-3.6.C30mdk.x86_64.rpm 
 a5bdbe6afa52005a734dc18aa951677d  corporate/3.0/SRPMS/openssl-0.9.7c-3.6.C30mdk.src.rpm
 Corporate 4.0:
 6d71d2358738be9967b2dfe19d3642f1  corporate/4.0/i586/libopenssl0.9.7-0.9.7g-2.4.20060mlcs4.i586.rpm
 22890554d3096ce596eeec7393ee3fcf  corporate/4.0/i586/libopenssl0.9.7-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 679fe740859fa35b2bb77b19c4a0e787  corporate/4.0/i586/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 d8477333b67ec3a36ba46c50e6183993  corporate/4.0/i586/openssl-0.9.7g-2.4.20060mlcs4.i586.rpm 
 b65dbbd9fb3d74d302478640476a2cd2  corporate/4.0/SRPMS/openssl-0.9.7g-2.4.20060mlcs4.src.rpm
 Corporate 4.0/X86_64:
 746e5e916d1e05379373138a5db20923  corporate/4.0/x86_64/lib64openssl0.9.7-0.9.7g-2.4.20060mlcs4.x86_64.rpm
 a2b1d750075a32fe8badbdf1f7febafe  corporate/4.0/x86_64/lib64openssl0.9.7-devel-0.9.7g-2.4.20060mlcs4.x86_64.rpm
 47c464cf890a004f772c1db3e839fa12  corporate/4.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7g-2.4.20060mlcs4.x86_64.rpm
 6d71d2358738be9967b2dfe19d3642f1  corporate/4.0/x86_64/libopenssl0.9.7-0.9.7g-2.4.20060mlcs4.i586.rpm
 22890554d3096ce596eeec7393ee3fcf  corporate/4.0/x86_64/libopenssl0.9.7-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 679fe740859fa35b2bb77b19c4a0e787  corporate/4.0/x86_64/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 1030a6124a9fa4fd5a41bdff077301bf  corporate/4.0/x86_64/openssl-0.9.7g-2.4.20060mlcs4.x86_64.rpm 
 b65dbbd9fb3d74d302478640476a2cd2  corporate/4.0/SRPMS/openssl-0.9.7g-2.4.20060mlcs4.src.rpm
 Multi Network Firewall 2.0:
 19055eda58e1f75814e594ce7709a710  mnf/2.0/i586/libopenssl0.9.7-0.9.7c-3.6.M20mdk.i586.rpm
 abfe548617969f619aec5b0e807f1f67  mnf/2.0/i586/libopenssl0.9.7-devel-0.9.7c-3.6.M20mdk.i586.rpm
 92e7515c9125367a79fdb490f5b39cd4  mnf/2.0/i586/libopenssl0.9.7-static-devel-0.9.7c-3.6.M20mdk.i586.rpm
 847eecb1d07e4cab3d1de1452103c3a0  mnf/2.0/i586/openssl-0.9.7c-3.6.M20mdk.i586.rpm 
 b6b67fa82d7119cde7ab7816aed17059  mnf/2.0/SRPMS/openssl-0.9.7c-3.6.M20mdk.src.rpm
 _______________________________________________________________________
 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you. 
 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:
  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
 You can view other update advisories for Mandriva Linux at:
  http://www.mandriva.com/security/advisories
 If you want to report vulnerabilities, please contact
  security_(at)_mandriva.com
 _______________________________________________________________________
 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFFHA4hmqjQ0CJFipgRApknAJ9Ybd8xjfkR+RL1fWEI2Fgn/KIuqACeOH/0
wB09L3fylyiHgrXvSV6VL7A=
=/+dm
-----END PGP SIGNATURE-----
                        
| VAR-200609-0823 | CVE-2006-3738 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 10.0 CVSS V3: - Severity: HIGH | 
                            Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. The Oracle SYS.DBMS_AQ package is vulnerable to PL/SQL injection. This vulnerability may allow a remote, authenticated attacker to execute arbitrary PL/SQL commands on a vulnerable Oracle installation. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. 
Successfully exploiting this issue may result in the execution of arbitrary machine code in the context of applications that use the affected library. Failed exploit attempts may crash applications, denying service to legitimate users. Oracle has released a Critical Patch Update advisory for January 2007 to address these vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by these issues as well. 
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to leverage some of the issues, but other issues do not require any authorization. The most severe of the vulnerabilities could possibly expose affected computers to complete compromise. OpenSSL Security Advisory [28th September 2006]
New OpenSSL releases are now available to correct four security
issues. 
ASN.1 Denial of Service Attacks (CVE-2006-2937, CVE-2006-2940)
==============================================================
Vulnerability
-------------
Dr. Henson recently developed an ASN.1 test suite for NISCC
(www.niscc.gov.uk). During the parsing of certain invalid ASN.1 structures an error
condition is mishandled.  This can result in an infinite loop which
consumes system memory (CVE-2006-2937).  (This issue did not affect
OpenSSL versions prior to 0.9.7)
2. Certain types of public key can take disproportionate amounts of
time to process. This could be used by an attacker in a denial of
service attack (CVE-2006-2940). 
Any code which uses OpenSSL to parse ASN.1 data from untrusted sources
is affected. This includes SSL servers which enable client
authentication and S/MIME applications. 
Acknowledgements
----------------
The OpenSSL team thank Dr S. Henson of Open Network Security and NISCC
for funding the ASN.1 test suite project.  An attacker could send a list of ciphers to an
application that uses this function and overrun a buffer
(CVE-2006-3738). 
Acknowledgements
----------------
The OpenSSL team thank Tavis Ormandy and Will Drewry of the Google
Security Team for reporting this issue. 
SSLv2 Client Crash (CVE-2006-4343)
==================================
Vulnerability
-------------
A flaw in the SSLv2 client code was discovered. 
Acknowledgements
----------------
The OpenSSL team thank Tavis Ormandy and Will Drewry of the Google
Security Team for reporting this issue. 
Recommendations
===============
These vulnerabilities are resolved in the following versions of OpenSSL:
   - in the 0.9.7 branch, version 0.9.7l (or later);
   - in the 0.9.8 branch, version 0.9.8d (or later). 
OpenSSL 0.9.8d and OpenSSL 0.9.7l are available for download via
HTTP and FTP from the following master locations (you can find the
various FTP mirrors under https://www.openssl.org/source/mirror.html):
    o https://www.openssl.org/source/
    o ftp://ftp.openssl.org/source/
The distribution file names are:
    o openssl-0.9.8d.tar.gz
      MD5 checksum: 8ed1853538e1d05a1f5ada61ebf8bffa
      SHA1 checksum: 4136fba00303a3d319d2052bfa8e1f09a2e12fc2
    o openssl-0.9.7l.tar.gz
      MD5 checksum: b21d6e10817ddeccf5fbe1379987333e
      SHA1 checksum: f0e4136639b10cbd1227c4f7350ff7ad406e575d
    
The checksums were calculated using the following commands:
    openssl md5 openssl-0.9*.tar.gz
    openssl sha1 openssl-0.9*.tar.gz
After upgrading make sure to recompile any applications statically
linked to OpenSSL libraries and restart all applications that use
OpenSSL. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------
                   VMware Security Advisory
Advisory ID:       VMSA-2007-0001
Synopsis:          VMware ESX server security updates
Issue date:        2007-01-08
Updated on:        2007-01-08
CVE:               CVE-2006-3589 CVE-2006-2937 CVE-2006-2940
                   CVE-2006-3738 CVE-2006-4339 CVE-2006-4343
                   CVE-2006-4980
- -------------------------------------------------------------------
1. Summary:
Updated ESX Patches address several security issues. 
2. Relevant releases:
VMware ESX 3.0.1 without patch ESX-9986131
VMware ESX 3.0.0 without patch ESX-3069097
VMware ESX 2.5.4 prior to upgrade patch 3
VMware ESX 2.5.3 prior to upgrade patch 6
VMware ESX 2.1.3 prior to upgrade patch 4
VMware ESX 2.0.2 prior to upgrade patch 4
3. Problem description:
Problems addressed by these patches:
a. Incorrect permissions on SSL key files generated  by vmware-config
(CVE-2006-3589):
    ESX 3.0.1: does not have this problem
    ESX 3.0.0: does not have this problem
    ESX 2.5.4: corrected by ESX 2.5.4 Upgrade Patch 3 (Build# 36502)
    ESX 2.5.3: corrected by ESX 2.5.3 Upgrade Patch 6 (Build# 35703)
    ESX 2.1.3: corrected by ESX 2.1.3 Upgrade Patch 4 (Build# 35803)
    ESX 2.0.2: corrected by ESX 2.0.2 Upgrade Patch 4 (Build# 35801)
    A possible security issue with the configuration program
    vmware-config which could set incorrect permissions on SSL key
    files. Local users may be able to obtain access to the SSL key
    files. The Common Vulnerabilities and Exposures project
    (cve.mitre.org) assigned the name CVE-2006-3589 to this issue. 
b. OpenSSL library vulnerabilities:
    ESX 3.0.1: corrected by ESX 3.0.1 Patch ESX-9986131
    ESX 3.0.0: corrected by ESX 3.0.0 Patch ESX-3069097
    ESX 2.5.4: corrected by ESX 2.5.4 Upgrade Patch 3 (Build# 36502)
    ESX 2.5.3: corrected by ESX 2.5.3 Upgrade Patch 6 (Build# 35703)
    ESX 2.1.3: corrected by ESX 2.1.3 Upgrade Patch 4 (Build# 35803)
    ESX 2.0.2: corrected by ESX 2.0.2 Upgrade Patch 4 (Build# 35801)
    (CVE-2006-2937) OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d
    allows remote attackers to cause a denial of service (infinite
    loop and memory consumption) via malformed ASN.1 structures that
    trigger an improperly handled error condition. 
    (CVE-2006-2940) OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d,
    and earlier versions allows attackers to cause a denial of service
    (CPU consumption) via parasitic public keys with large (1) "public
    exponent" or (2) "public modulus" values in X.509 certificates that
    require extra time to process when using RSA signature verification. 
    (CVE-2006-4339) OpenSSL before 0.9.7, 0.9.7 before 0.9.7k, and 0.9.8
    before 0.9.8c, when using an RSA key with exponent 3, removes PKCS-1
    padding before generating a hash, which allows remote attackers to
    forge a PKCS #1 v1.5 signature that is signed by that RSA key and
    prevents OpenSSL from correctly verifying X.509 and other
    certificates that use PKCS #1. 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    assigned the names CVE-2006-2937, CVE-2006-2940, CVE-2006-3738,
    CVE-2006-4339, and CVE-2006-4343 to these issues. 
c. Updated OpenSSH package addresses the following possible security issues:
    ESX 3.0.1: corrected by Patch ESX-9986131
    ESX 3.0.0: corrected by Patch ESX-3069097
    ESX 2.5.4: does not have these problems
    ESX 2.5.3: does not have these problems
    ESX 2.1.3: does not have these problems
    ESX 2.0.2: does not have these problems
    (CVE-2004-2069) sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly
    other versions, when using privilege separation, does not properly
    signal the non-privileged process when a session has been terminated
    after exceeding the LoginGraceTime setting, which leaves the
    connection open and allows remote attackers to cause a denial of
    service (connection consumption). 
    (CVE-2006-0225) scp in OpenSSH 4.2p1 allows attackers to execute
    arbitrary commands via filenames that contain shell metacharacters
    or spaces, which are expanded twice. 
    (CVE-2003-0386) OpenSSH 3.6.1 and earlier, when restricting host
    access by numeric IP addresses and with VerifyReverseMapping
    disabled, allows remote attackers to bypass "from=" and "user@host"
    address restrictions by connecting to a host from a system whose
    reverse DNS hostname contains the numeric IP address. 
    (CVE-2006-4924) sshd in OpenSSH before 4.4, when using the version 1
    SSH protocol, allows remote attackers to cause a denial of service
    (CPU consumption) via an SSH packet that contains duplicate blocks,
    which is not properly handled by the CRC compensation attack
    detector. 
    NOTE: ESX by default disables version 1 SSH protocol. 
    (CVE-2006-5051) Signal handler race condition in OpenSSH before 4.4
    allows remote attackers to cause a denial of service (crash), and
    possibly execute arbitrary code if GSSAPI authentication is enabled,
    via unspecified vectors that lead to a double-free. 
    NOTE: ESX doesn't use GSSAPI by default. 
    (CVE-2006-5794) Unspecified vulnerability in the sshd Privilege
    Separation Monitor in OpenSSH before 4.5 causes weaker verification
    that authentication has been successful, which might allow attackers
    to bypass authentication. 
    NOTE: as of 20061108, it is believed that this issue is only
    exploitable by leveraging vulnerabilities in the unprivileged
    process, which are not known to exist. 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    assigned the names CVE-2004-2069, CVE-2006-0225, CVE-2003-0386,
    CVE-2006-4924, CVE-2006-5051, and CVE-2006-5794 to these issues. 
d. Object reuse problems with newly created virtual disk (.vmdk or .dsk)
files:
    ESX 3.0.1: does not have this problem
    ESX 3.0.0: does not have this problem
    ESX 2.5.4: corrected by ESX 2.5.4 Upgrade Patch 3 (Build# 36502)
    ESX 2.5.3: corrected by ESX 2.5.3 Upgrade Patch 6 (Build# 35703)
    ESX 2.1.3: corrected by ESX 2.1.3 Upgrade Patch 4 (Build# 35803)
    ESX 2.0.2: corrected by ESX 2.0.2 Upgrade Patch 4 (Build# 35801)
    A possible security issue with virtual disk (.vmdk or .dsk) files
    that are newly created, but contain blocks from recently deleted
    virtual disk files.  Information belonging to the previously
    deleted virtual disk files could be revealed in newly created
    virtual disk files. 
    VMware recommends the following workaround: When creating new
    virtual machines on an ESX Server that may contain sensitive
    data, use vmkfstools with the -W option. This initializes the
    virtual disk with zeros.  NOTE: ESX 3.x defines this option as -w. 
e. Buffer overflow in Python function repr():
    ESX 3.0.1: corrected by Patch ESX-9986131
    ESX 3.0.0: corrected by ESX-3069097
    ESX 2.5.4: does not have this problem
    ESX 2.5.3: does not have this problem
    ESX 2.1.3: does not have this problem
    ESX 2.0.2: does not have this problem
    A possible security issue with how the Python function repr()
    function handles UTF-32/UCS-4 strings. 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    assigned the name CVE-2006-4980 to this issue. 
4. Solution:
Please review the Patch notes for your version of ESX and verify the md5sum. 
  ESX 3.0.1
  http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
  md5usm: 239375e107fd4c7af57663f023863fcb
  ESX 3.0.0
  http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
  md5sum: ca9947239fffda708f2c94f519df33dc
  ESX 2.5.4
  http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html
  md5sum: 239375e107fd4c7af57663f023863fcb
  ESX 2.5.3
  http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html
  md5sum: f90fcab28362edbf2311f3ca90cc7739
  ESX 2.1.3
  http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html
  md5sum: 7d7d0e40f4dccd5ca64b9c13a856da8f
  ESX 2.0.2
  http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html
  md5sum: 925e70f28d17714c53fdbd24de64329f
5. References:
ESX 3.0.0 Patch URL:
http://www.vmware.com/support/vi3/doc/esx-3069097-patch.html
Knowledge base URL:  http://kb.vmware.com/kb/3069097
ESX 3.0.1 Patch URL:
http://www.vmware.com/support/vi3/doc/esx-9986131-patch.html
Knowledge base URL:  http://kb.vmware.com/kb/9986131
ESX 2.5.4 Patch URL:
http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html
ESX 2.5.3 Patch URL:
http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html
ESX 2.1.3 Patch URL:
http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html
ESX 2.0.2 Patch URL:
http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3589
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4339
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4980
6. Contact:
http://www.vmware.com/security
VMware Security Response Policy
http://www.vmware.com/vmtn/technology/security/security_response.html
E-mail:  security@vmware.com
Copyright 2007 VMware Inc. All rights reserved. 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
iD8DBQFFovs16KjQhy2pPmkRCMfyAKCXhdGwZyXW5VzSwcOmu2NNXKN/OwCgo+CE
neFG0RikD74TCYeXKW6CBy4=
=9/6k
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it. 
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
. 
Corrected:      2007-10-03 21:39:43 UTC (RELENG_6, 6.2-STABLE)
                2007-10-03 21:40:35 UTC (RELENG_6_2, 6.2-RELEASE-p8)
                2007-10-03 21:41:22 UTC (RELENG_6_1, 6.1-RELEASE-p20)
                2007-10-03 21:42:00 UTC (RELENG_5, 5.5-STABLE)
                2007-10-03 21:42:32 UTC (RELENG_5_5, 5.5-RELEASE-p16)
CVE Name:       CVE-2007-5135
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit <URL:http://security.FreeBSD.org/>.   Background
FreeBSD includes software from the OpenSSL Project.  The OpenSSL Project is
a collaborative effort to develop a robust, commercial-grade, full-featured,
and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols as well as a full-strength
general purpose cryptography library. 
II. 
III. 
IV.  Workaround
No workaround is available, but only applications using the
SSL_get_shared_ciphers() function are affected.   Solution
Perform one of the following:
1) Upgrade your vulnerable system to 5-STABLE, or 6-STABLE, or to the
RELENG_6_2, RELENG_6_1, or RELENG_5_5 security branch dated after the
correction date. 
2) To patch your present system:
The following patch have been verified to apply to FreeBSD 5.5, 6.1,
and 6.2 systems. 
a) Download the relevant patch from the location below, and verify the
detached PGP signature using your PGP utility. 
# fetch http://security.FreeBSD.org/patches/SA-07:08/openssl.patch
# fetch http://security.FreeBSD.org/patches/SA-07:08/openssl.patch.asc
b) Execute the following commands as root:
# cd /usr/src
# patch < /path/to/patch
# cd /usr/src/secure/lib/libssl
# make obj && make depend && make && make install
VI.  Correction details
The following list contains the revision numbers of each file that was
corrected in FreeBSD. 
Branch                                                           Revision
  Path
- -------------------------------------------------------------------------
RELENG_5
  src/crypto/openssl/ssl/ssl_lib.c                           1.1.1.11.2.3
RELENG_5_5
  src/UPDATING                                            1.342.2.35.2.16
  src/sys/conf/newvers.sh                                  1.62.2.21.2.18
  src/crypto/openssl/ssl/ssl_lib.c                       1.1.1.11.2.1.4.2
RELENG_6
  src/crypto/openssl/ssl/ssl_lib.c                           1.1.1.12.2.2
RELENG_6_2
  src/UPDATING                                            1.416.2.29.2.11
  src/sys/conf/newvers.sh                                  1.69.2.13.2.11
  src/crypto/openssl/ssl/ssl_lib.c                       1.1.1.12.2.1.2.1
RELENG_6_1
  src/UPDATING                                            1.416.2.22.2.22
  src/sys/conf/newvers.sh                                  1.69.2.11.2.22
  src/crypto/openssl/ssl/ssl_lib.c                           1.1.1.12.6.2
- -------------------------------------------------------------------------
VII. 
________________________________________________________________________
References:
  [0] http://www.openssl.org/news/secadv_20060928.txt 
  [1] http://www.openssl.org/
  [2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
  [3] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
  [4] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
  [5] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
________________________________________________________________________
For security reasons, this advisory was digitally signed with the
OpenPGP public key "OpenPKG <openpkg@openpkg.org>" (ID 63C4CB9F) of the
OpenPKG project which you can retrieve from http://pgp.openpkg.org and
hkp://pgp.openpkg.org. Follow the instructions on http://pgp.openpkg.org
for details on how to verify the integrity of this advisory. 
--WfZ7S8PLGjBY9Voh
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200610-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
  Severity: High
     Title: OpenSSL: Multiple vulnerabilities
      Date: October 24, 2006
      Bugs: #145510
        ID: 200610-11
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
OpenSSL contains multiple vulnerabilities including the possible remote
execution of arbitrary code. Additionally Dr. 
Resolution
==========
All OpenSSL 0.9.8 users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-libs/openssl-0.9.8d"
All OpenSSL 0.9.7 users should upgrade to the latest version:
    # emerge --sync
    # emerge --ask --oneshot --verbose ">=dev-libs/openssl-0.9.7l"
References
==========
  [ 1 ] CVE-2006-2937
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
  [ 2 ] CVE-2006-2940
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
  [ 3 ] CVE-2006-3738
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
  [ 4 ] CVE-2006-4343
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
  http://security.gentoo.org/glsa/glsa-200610-11.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org. 
License
=======
Copyright 2006 Gentoo Foundation, Inc; referenced text
belongs to its owner(s). 
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license. 
 _______________________________________________________________________
 References:
 
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2937
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2940
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3738
 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4343
 _______________________________________________________________________
 
 Updated Packages:
 
 Mandriva Linux 2006.0:
 17e2d82c3f6c0afbf48eccbfbcc17b55  2006.0/i586/libopenssl0.9.7-0.9.7g-2.4.20060mdk.i586.rpm
 8c3f89e1900f069d4a4ad3162a9f7d78  2006.0/i586/libopenssl0.9.7-devel-0.9.7g-2.4.20060mdk.i586.rpm
 3a68c653ba0339ba99162459385c72e2  2006.0/i586/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mdk.i586.rpm
 8291bde3bd9aa95533aabc07280203b8  2006.0/i586/openssl-0.9.7g-2.4.20060mdk.i586.rpm 
 52b3fbfc1389bcd73e406d6ff741e9dc  2006.0/SRPMS/openssl-0.9.7g-2.4.20060mdk.src.rpm
 Mandriva Linux 2006.0/X86_64:
 b2ce6e6bb7e3114663d3a074d0cc7da5  2006.0/x86_64/lib64openssl0.9.7-0.9.7g-2.4.20060mdk.x86_64.rpm
 f7c8dbc2eda0c90547d43661454d1068  2006.0/x86_64/lib64openssl0.9.7-devel-0.9.7g-2.4.20060mdk.x86_64.rpm
 7c9ebd9f9179f4e93627dcf0f3442335  2006.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7g-2.4.20060mdk.x86_64.rpm
 17e2d82c3f6c0afbf48eccbfbcc17b55  2006.0/x86_64/libopenssl0.9.7-0.9.7g-2.4.20060mdk.i586.rpm
 8c3f89e1900f069d4a4ad3162a9f7d78  2006.0/x86_64/libopenssl0.9.7-devel-0.9.7g-2.4.20060mdk.i586.rpm
 3a68c653ba0339ba99162459385c72e2  2006.0/x86_64/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mdk.i586.rpm
 6ce5832a59b8b67425cb7026ea9dc876  2006.0/x86_64/openssl-0.9.7g-2.4.20060mdk.x86_64.rpm 
 52b3fbfc1389bcd73e406d6ff741e9dc  2006.0/SRPMS/openssl-0.9.7g-2.4.20060mdk.src.rpm
 Mandriva Linux 2007.0:
 1bfeff47c8d2f6c020c459881be68207  2007.0/i586/libopenssl0.9.8-0.9.8b-2.1mdv2007.0.i586.rpm
 1e1a4db54ddfaedb08a6d847422099ff  2007.0/i586/libopenssl0.9.8-devel-0.9.8b-2.1mdv2007.0.i586.rpm
 59c80405f33b2e61ffd3cef025635e21  2007.0/i586/libopenssl0.9.8-static-devel-0.9.8b-2.1mdv2007.0.i586.rpm
 3a6657970a2e7661bd869d221a69c8da  2007.0/i586/openssl-0.9.8b-2.1mdv2007.0.i586.rpm 
 aad29e57ddceb66105af5d6434de9a62  2007.0/SRPMS/openssl-0.9.8b-2.1mdv2007.0.src.rpm
 Mandriva Linux 2007.0/X86_64:
 af679c647d97214244a8423dc1a766b7  2007.0/x86_64/lib64openssl0.9.8-0.9.8b-2.1mdv2007.0.x86_64.rpm
 d7b1ed07df4115b3bcc3907e00d25a89  2007.0/x86_64/lib64openssl0.9.8-devel-0.9.8b-2.1mdv2007.0.x86_64.rpm
 5bd3ece2c0ec7a3201c29fa84e25a75a  2007.0/x86_64/lib64openssl0.9.8-static-devel-0.9.8b-2.1mdv2007.0.x86_64.rpm
 9b028020dba009eddbf06eeb8607b87f  2007.0/x86_64/openssl-0.9.8b-2.1mdv2007.0.x86_64.rpm 
 aad29e57ddceb66105af5d6434de9a62  2007.0/SRPMS/openssl-0.9.8b-2.1mdv2007.0.src.rpm
 Corporate 3.0:
 c99ea58f6f4959a4c36398cc6b2b4ee2  corporate/3.0/i586/libopenssl0.9.7-0.9.7c-3.6.C30mdk.i586.rpm
 98a925c5ba2ecc9d704b1e730035755e  corporate/3.0/i586/libopenssl0.9.7-devel-0.9.7c-3.6.C30mdk.i586.rpm
 151493a50693e3b9cc67bfafadb9ce42  corporate/3.0/i586/libopenssl0.9.7-static-devel-0.9.7c-3.6.C30mdk.i586.rpm
 82b4709bdbb9128746887013a724356a  corporate/3.0/i586/openssl-0.9.7c-3.6.C30mdk.i586.rpm 
 a5bdbe6afa52005a734dc18aa951677d  corporate/3.0/SRPMS/openssl-0.9.7c-3.6.C30mdk.src.rpm
 Corporate 3.0/X86_64:
 01a922d80d6fc9d1b36dde15ee27747e  corporate/3.0/x86_64/lib64openssl0.9.7-0.9.7c-3.6.C30mdk.x86_64.rpm
 30268f0b70862d1f5998694ac8b4addc  corporate/3.0/x86_64/lib64openssl0.9.7-devel-0.9.7c-3.6.C30mdk.x86_64.rpm
 e0388ff1efa34ea55d033e95b4e9bb63  corporate/3.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7c-3.6.C30mdk.x86_64.rpm
 c99ea58f6f4959a4c36398cc6b2b4ee2  corporate/3.0/x86_64/libopenssl0.9.7-0.9.7c-3.6.C30mdk.i586.rpm
 83759622f0cc8ea9c0f6d32671283354  corporate/3.0/x86_64/openssl-0.9.7c-3.6.C30mdk.x86_64.rpm 
 a5bdbe6afa52005a734dc18aa951677d  corporate/3.0/SRPMS/openssl-0.9.7c-3.6.C30mdk.src.rpm
 Corporate 4.0:
 6d71d2358738be9967b2dfe19d3642f1  corporate/4.0/i586/libopenssl0.9.7-0.9.7g-2.4.20060mlcs4.i586.rpm
 22890554d3096ce596eeec7393ee3fcf  corporate/4.0/i586/libopenssl0.9.7-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 679fe740859fa35b2bb77b19c4a0e787  corporate/4.0/i586/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 d8477333b67ec3a36ba46c50e6183993  corporate/4.0/i586/openssl-0.9.7g-2.4.20060mlcs4.i586.rpm 
 b65dbbd9fb3d74d302478640476a2cd2  corporate/4.0/SRPMS/openssl-0.9.7g-2.4.20060mlcs4.src.rpm
 Corporate 4.0/X86_64:
 746e5e916d1e05379373138a5db20923  corporate/4.0/x86_64/lib64openssl0.9.7-0.9.7g-2.4.20060mlcs4.x86_64.rpm
 a2b1d750075a32fe8badbdf1f7febafe  corporate/4.0/x86_64/lib64openssl0.9.7-devel-0.9.7g-2.4.20060mlcs4.x86_64.rpm
 47c464cf890a004f772c1db3e839fa12  corporate/4.0/x86_64/lib64openssl0.9.7-static-devel-0.9.7g-2.4.20060mlcs4.x86_64.rpm
 6d71d2358738be9967b2dfe19d3642f1  corporate/4.0/x86_64/libopenssl0.9.7-0.9.7g-2.4.20060mlcs4.i586.rpm
 22890554d3096ce596eeec7393ee3fcf  corporate/4.0/x86_64/libopenssl0.9.7-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 679fe740859fa35b2bb77b19c4a0e787  corporate/4.0/x86_64/libopenssl0.9.7-static-devel-0.9.7g-2.4.20060mlcs4.i586.rpm
 1030a6124a9fa4fd5a41bdff077301bf  corporate/4.0/x86_64/openssl-0.9.7g-2.4.20060mlcs4.x86_64.rpm 
 b65dbbd9fb3d74d302478640476a2cd2  corporate/4.0/SRPMS/openssl-0.9.7g-2.4.20060mlcs4.src.rpm
 Multi Network Firewall 2.0:
 19055eda58e1f75814e594ce7709a710  mnf/2.0/i586/libopenssl0.9.7-0.9.7c-3.6.M20mdk.i586.rpm
 abfe548617969f619aec5b0e807f1f67  mnf/2.0/i586/libopenssl0.9.7-devel-0.9.7c-3.6.M20mdk.i586.rpm
 92e7515c9125367a79fdb490f5b39cd4  mnf/2.0/i586/libopenssl0.9.7-static-devel-0.9.7c-3.6.M20mdk.i586.rpm
 847eecb1d07e4cab3d1de1452103c3a0  mnf/2.0/i586/openssl-0.9.7c-3.6.M20mdk.i586.rpm 
 b6b67fa82d7119cde7ab7816aed17059  mnf/2.0/SRPMS/openssl-0.9.7c-3.6.M20mdk.src.rpm
 _______________________________________________________________________
 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you. 
 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:
  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98
 You can view other update advisories for Mandriva Linux at:
  http://www.mandriva.com/security/advisories
 If you want to report vulnerabilities, please contact
  security_(at)_mandriva.com
 _______________________________________________________________________
 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)
iD8DBQFFHA4hmqjQ0CJFipgRApknAJ9Ybd8xjfkR+RL1fWEI2Fgn/KIuqACeOH/0
wB09L3fylyiHgrXvSV6VL7A=
=/+dm
-----END PGP SIGNATURE-----
                        
| VAR-200110-0214 | CVE-2006-4396 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 4.6 CVSS V3: - Severity: MEDIUM | 
                            The Apple Type Services (ATS) server in Mac OS X 10.4.8 and earlier does not securely create log files, which allows local users to create and modify arbitrary files via unspecified vectors, possibly relating to a symlink attack. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Apple Mac OS X is prone to multiple security vulnerabilities. 
These issue affect Mac OS X and various applications including Apple Type Services, CFNetwork, Finder, FTPD, Installer, PPP, Security Framework, VPN, and WebKit. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. 
Apple Mac OS X 10.4.8 and prior versions are vulnerable to these issues
                        
| VAR-200609-0932 | CVE-2006-5710 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 7.5 CVSS V3: - Severity: HIGH | 
                            The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Failed exploit attempts will likely result in denial-of-service conditions. 
This issue affects the eMac, iBook, iMac, PowerBook G3, PowerBook G4, and Power Mac G4 computers which were equipped with an original AirPort card.  Computers with an AirPort Extreme are not affected. An Apple AirPort device is a wireless access point that provides 802.11 services to network clients. There is a memory corruption vulnerability in Apple AirPort when processing malformed probe response packets
                        
| VAR-200609-0939 | CVE-2006-4402 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Heap-based buffer overflow in the Finder in Apple Mac OS X 10.4.8 and earlier allows user-assisted remote attackers to execute arbitrary code by browsing directories containing crafted .DS_Store files. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. Apple Finder fails to properly handle malformed .DS_Store files. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code. Multiple RSA implementations fail to properly handle RSA signatures. Apple Mac OS X is prone to multiple security vulnerabilities. 
These issue affect Mac OS X and various applications including Apple Type Services, CFNetwork, Finder, FTPD, Installer, PPP, Security Framework, VPN, and WebKit. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. 
Apple Mac OS X 10.4.8 and prior versions are vulnerable to these issues. Program crashes or executes arbitrary commands as the user running Finder
                        
| VAR-200609-0868 | CVE-2006-4404 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 10.0 CVSS V3: - Severity: HIGH | 
                            The Installer application in Apple Mac OS X 10.4.8 and earlier, when used by a user with Admin credentials, does not authenticate the user before installing certain software requiring system privileges. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Apple Mac OS X is prone to multiple security vulnerabilities. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. 
Apple Mac OS X 10.4.8 and prior versions are vulnerable to these issues
                        
| VAR-200609-0887 | CVE-2006-4407 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM | 
                            The Security Framework in Apple Mac OS X 10.3.x up to 10.3.9 does not properly prioritize encryption ciphers when negotiating the strongest shared cipher, which causes Secure Transport to user a weaker cipher that makes it easier for remote attackers to decrypt traffic. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application.  This vulnerability may allow traffic to be weakly encrypted. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. When making a connection, the best cipher supported by both parties should be used. Due to errors in the priority order of credentials, Secure Transport may use ciphers that do not provide encryption or authentication when better ciphers are available
                        
| VAR-200609-0855 | CVE-2006-4409 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM | 
                            The Online Certificate Status Protocol (OCSP) service in the Security Framework in Apple Mac OS X 10.4 through 10.4.8 retrieve certificate revocation lists (CRL) when an HTTP proxy is in use, which could cause the system to accept certificates that have been revoked. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application.  This vulnerability may result in the use of revoked certificates. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Apple Mac OS X is prone to multiple security vulnerabilities. 
These issue affect Mac OS X and various applications including Apple Type Services, CFNetwork, Finder, FTPD, Installer, PPP, Security Framework, VPN, and WebKit. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. 
Apple Mac OS X 10.4.8 and prior versions are vulnerable to these issues
                        
| VAR-200609-0852 | CVE-2006-4411 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 7.2 CVSS V3: - Severity: HIGH | 
                            The VPN service in Apple Mac OS X 10.3.x through 10.3.9 and 10.4.x through 10.4.8 does not properly clean the environment when executing commands, which allows local users to gain privileges via unspecified vectors. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Apple Mac OS X is prone to multiple security vulnerabilities. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. 
Apple Mac OS X 10.4.8 and prior versions are vulnerable to these issues
                        
| VAR-200609-0808 | CVE-2006-4396 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 4.6 CVSS V3: - Severity: MEDIUM | 
                            The Apple Type Services (ATS) server in Mac OS X 10.4.8 and earlier does not securely create log files, which allows local users to create and modify arbitrary files via unspecified vectors, possibly relating to a symlink attack. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Apple Mac OS X is prone to multiple security vulnerabilities. 
These issue affect Mac OS X and various applications including Apple Type Services, CFNetwork, Finder, FTPD, Installer, PPP, Security Framework, VPN, and WebKit. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. 
Apple Mac OS X 10.4.8 and prior versions are vulnerable to these issues
                        
| VAR-200609-0782 | CVE-2006-4398 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 7.2 CVSS V3: - Severity: HIGH | 
                            Multiple buffer overflows in the Apple Type Services (ATS) server in Mac OS X 10.4 through 10.4.8 allow local users to execute arbitrary code via crafted service requests. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application.  These vulnerabilities may allow a local attacker to execute arbitrary code with system privileges. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Both local and remote vulnerabilities are present. A local attacker can trigger these overflows by sending a specially crafted service request, causing a denial of service or executing arbitrary commands with system privileges
                        
| VAR-200609-0720 | CVE-2006-4400 | OpenSSL SSLv2 client code fails to properly check for NULL | CVSS V2: 5.1 CVSS V3: - Severity: MEDIUM | 
                            Stack-based buffer overflow in the Apple Type Services (ATS) server in Mac OS 10.4.8 and earlier allow user-assisted attackers to execute arbitrary code via crafted font files. A flaw in the OpenSSL library could allow a remote attacker to cause a denial of service on an affected application. Multiple RSA implementations fail to properly handle RSA signatures. This vulnerability may allow an attacker to forge RSA signatures. Apple Mac OS X is prone to multiple security vulnerabilities. 
These issue affect Mac OS X and various applications including Apple Type Services, CFNetwork, Finder, FTPD, Installer, PPP, Security Framework, VPN, and WebKit. Attackers may exploit these issues to execute arbitrary code, trigger denial-of-service conditions, escalate privileges, overwrite files, and access potentially sensitive information. Both local and remote vulnerabilities are present. 
Apple Mac OS X 10.4.8 and prior versions are vulnerable to these issues. A remote attacker could trigger this overflow by tricking a user into opening a specially crafted font file, causing a denial of service or executing arbitrary commands with system privileges
                        
