New User, Welcome!     Login

<< Previous Next >>

version

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances

Affected Products
=================

Cisco ASA 5500 Series Adaptive Security Appliances are affected by
multiple vulnerabilities. Affected versions of Cisco ASA Software
vary depending on the specific vulnerability.

Vulnerable Products
+------------------


Cisco Security Advisory: Multiple Vulnerabilities in Cisco Firewall Services Module

Vulnerable Products
+------------------

The Cisco FWSM for the Cisco Catalyst 6500 Series switches and Cisco
7600 Series routers is affected by multiple vulnerabilities. Affected
versions of Cisco FWSM Software vary depending on the specific
vulnerability. Refer to the "Software Version and Fixes" section for
specific information on vulnerable versions.

Syslog Message Memory Corruption Denial of Service Vulnerability
+---------------------------------------------------------------

Cisco Security Advisory: Cisco Unified Contact Center Express Directory Traversal Vulnerability

=================

Vulnerable Products
+------------------

The following Cisco UCCX versions are vulnerable:

  * Cisco UCCX version 6.0(x)
  * Cisco UCCX version 7.0(x)
  * Cisco UCCX version 8.0(x)
  * Cisco UCCX version 8.5(x)

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unity Connection

Vulnerable Products
+------------------

Cisco Unity Connection Privilege Escalation Vulnerability

The following versions of Cisco Unity Connection are vulnerable:

+---------------------------------------+
|       Version        |    Affected    |
|----------------------+----------------|
| Prior to 7.1         | Yes            |

[security bulletin] HPSBMA02491 SSRT100060 rev.1 - HP Operations Manager for Windows, Remote Execution of Arbitrary Code

Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c02078800
Version: 1

HPSBMA02491 SSRT100060 rev.1 - HP Operations Manager for Windows, Remote Execution of Arbitrary Code

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.


Cisco Security Advisory: Firewall Services Module Crafted ICMP Message Vulnerability

=================

Vulnerable Products
- -------------------

All non-fixed 2.x, 3.x and 4.x versions of the FWSM software are
affected by this vulnerability.

To determine the version of the FWSM software that is running, issue
the "show module" command-line interface (CLI) command from Cisco IOS
Software or Cisco Catalyst Operating System Software to identify what

VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues

    - The VMware Descheduled Time Accounting Service is not running
      in the virtual machine

    The VMware Descheduled Time Accounting Service is no longer provided
    in newer versions of VMware Tools, starting with the versions
    released in Fusion 2.0.2 and ESX 4.0.

    However, virtual machines migrated from vulnerable releases will
    still be vulnerable if the three conditions listed above are met,
    until their tools are upgraded.

[security bulletin] HPSBMA02363 SSRT080106 rev.1 - HP Enterprise Discovery Running on Windows, Remote Authorized User, Gain Extended Privileges

Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01508161
Version: 1

HPSBMA02363 SSRT080106 rev.1 - HP Enterprise Discovery Running on Windows, Remote Authorized User, Gain Extended Privileges

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.


Cisco Security Advisory: Cisco IOS Secure Shell Denial of Service

The IOS secure shell server is disabled by default. To determine if
SSH is enabled, use the show ip ssh command.

    Router#show ip ssh
    SSH Enabled - version 2.0
    Authentication timeout: 120 secs; Authentication retries: 3

The previous output shows that SSH is enabled on this device and that
the SSH protocol major version that is being supported is 2.0. If the
text "SSH Disabled" is displayed, the device is not vulnerable.

Cisco Security Advisory: Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities

  * 7940
  * 7940G
  * 7960
  * 7960G

The version of firmware running on an IP Phone can be determined via
the Settings menu on the phone or via the phone HTTP interface.

Products Confirmed Not Vulnerable
+--------------------------------


Cisco Security Advisory: Default Passwords in the Application Velocity System

+---------------------------------------------------------------------

Summary
=======

Versions of the Cisco Application Velocity System (AVS) prior to
software version AVS 5.1.0 do not prompt users to modify system account
passwords during the initial configuration process. Because there is no
requirement to change these credentials during the initial configuration
process, an attacker may be able to leverage the accounts that have
default credentials, some of which have root privileges, to take full

Cisco Security Advisory: Local Privilege Escalation Vulnerabilities in Cisco VPN Client

Vulnerable Products
+------------------

The vulnerabilities described in this document apply to the Cisco VPN
Client on the Microsoft Windows platform. The affected versions are
included in the following table:

+----------------------------------------------------------------+
|     Vulnerability Name      |     Versions     | Cisco Bug ID  |
|                             |     affected     |               |

VMSA-2010-0015 VMware ESX third party updates for Service Console

   Notes:
   Effective May 2010, VMware's patch and update release program during
   Extended Support will be continued with the condition that all
   subsequent patch and update releases will be based on the latest
   baseline release version as of May 2010 (i.e. ESX 3.0.3 Update 1,
   ESX 3.5 Update 5, and VirtualCenter 2.5 Update 6). Refer to section
   "End of Product Availability FAQs" at
   http://www.vmware.com/support/policies/lifecycle/vi/faq.html for
   details.


Cisco Security Advisory: Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability

=================

Vulnerable Products
+------------------

All non-fixed 4.x versions of Cisco FWSM Software are affected by this
vulnerability if SCCP inspection is enabled. SCCP inspection is enabled
by default.

To check if SCCP inspection is enabled, issue the "show service-policy
| include skinny" command and confirm that the command returns output.

[security bulletin] HPSBMA02438 SSRT090092 rev.1 - HP ProLiant DL/ML 100 Series G5/G6 Servers with ProLiant Onboard Administrator Powered by LO100i, Remote Denial of Service (DoS)

Hash: SHA1

SUPPORT COMMUNICATION - SECURITY BULLETIN

Document ID: c01767394
Version: 1

HPSBMA02438 SSRT090092 rev.1 - HP ProLiant DL/ML 100 Series G5/G6 Servers with ProLiant Onboard Administrator Powered by LO100i, Remote Denial of Service (DoS)

NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.


Cisco Security Advisory: Cisco Content Switching Module Memory Leak Vulnerability

Vulnerable Products
+------------------

The Cisco CSM and Cisco CSM-S are affected by the vulnerability
described in this document if they are running an affected software
version and are configured for layer 7 load balancing.

The following versions of the Cisco CSM software are affected by this
vulnerability: 4.2(3), 4.2(3a), 4.2(4), 4.2(5), 4.2(6), 4.2(7), and
4.2(8).


Cisco Security Advisory: Cisco Content Switching Module Memory Leak Vulnerability

Vulnerable Products
+------------------

The Cisco CSM and Cisco CSM-S are affected by the vulnerability
described in this document if they are running an affected software
version and are configured for layer 7 load balancing.

The following versions of the Cisco CSM software are affected by this
vulnerability: 4.2(3), 4.2(3a), 4.2(4), 4.2(5), 4.2(6), 4.2(7), and
4.2(8).


Cisco Security Advisory: Multiple Vulnerabilities in Firewall Services Module

Vulnerable Products
+------------------

The FWSM is affected by a crafted HTTPS request vulnerability if the
HTTPS server on the FWSM is enabled and is running software versions
3.1(5) and prior or 3.2(1). Version 2.3.x is not affected. The HTTPS
server is not enabled by default.

The FWSM is affected by a crafted MGCP packet vulnerability if MGCP
application layer protocol inspection is enabled and the device is

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Firewall Services Module

Vulnerable Products
+------------------

The Cisco Firewall Services Module (FWSM) for the Cisco Catalyst 6500
Series Switches and Cisco 7600 Series Routers is affected by multiple
vulnerabilities. Affected versions of Cisco FWSM Software vary
depending on the specific vulnerability.

SunRPC Inspection Denial of Service Vulnerabilities
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

Vulnerable Products
+------------------

The Cisco ACE Application Control Engine Module and Cisco ACE 4710
Application Control Engine are affected by multiple vulnerabilities.
Affected versions vary depending on the specific vulnerability. For
specific version information, refer to the Software Versions and
Fixes section of this advisory.

RTSP Inspection DoS Vulnerability
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Recording Server

Vulnerable Products
+------------------

Cisco TelePresence Recording Server devices that are running an
affected version of software are affected.

To determine the current version of software that is running on the
Cisco TelePresence Recording Server, SSH into the device and issue the
show version active and the show version inactive commands. The
output should resemble the following example:

Cisco Security Advisory: Cisco Firewall Services Module Skinny Client Control Protocol Inspection Denial of Service Vulnerability

=================

Vulnerable Products
+------------------

Versions 3.1.x, 3.2.x, 4.0.x, and 4.1.x of Cisco FWSM software are
affected by this vulnerability if SCCP inspection is enabled. SCCP
inspection is enabled by default.

To determine whether SCCP inspection is enabled, issue the "show
service-policy | include skinny" command and confirm that the command

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch

Vulnerable Products
+------------------

Cisco TelePresence Multipoint Switch devices running an affected
version of software are affected.

To determine the current version of software running on the Cisco 
TelePresence Multipoint Switch, SSH into the device and issue the
show version active and the show version inactive commands. The 
output should resemble the following example:

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Manager

Vulnerable Products
+------------------

Cisco TelePresence Manager devices that are running an affected
version of software are affected.

To determine the current version of software that is running on the
Cisco TelePresence Manager, establish an SSH connection to the device
and issue the show version active and the show version inactive
commands. The output should resemble the following example:

Cisco Security Advisory: Jabber Extensible Communications Platform and Cisco Unified Presence XML Denial of Service Vulnerability

=================

Vulnerable Products
+------------------

The following versions of Cisco Unified Presence and Jabber
Extensible Communications Platform (Jabber XCP) are affected by the
vulnerability in this advisory. JabberNow appliances are also
affected if they are running a vulnerable version of Jabber XCP
software.


VMSA-2009-0006 VMware Hosted products and patches for ESX and ESXi resolve a critical security vulnerability

   VMware ESX 3.0.3 without patch ESX303-200904403-SG,

   VMware ESX 3.0.2 without patch ESX-1008421.
 
   NOTE: General Support for Workstation version 5.x ended on 2009-03-19.
         Users should plan to upgrade to the latest Workstation version
         6.x release.

         Extended support for ESX 3.0.2 Update 1 ends on 2009-08-08.
         Users should plan to upgrade to ESX 3.0.3 and preferably to the

VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.

                                       ESX-1005117.

      NOTE: Hosted products VMware Workstation 5.x, VMware Player 1.x,
            and VMware ACE 1.x will reach end of general support
            2008-11-09. Customers should plan to upgrade to the latest
            version of their respective products.

            Extended support (Security and Bug fixes) for ESX 3.0.2 ends
            on 10/29/2008 and Extended support for ESX 3.0.2 Update 1
            ends on 8/8/2009.  Users should plan to upgrade to ESX 3.0.3
            and preferably to the newest release available.

VMSA-2010-0013

   Notes:
   Effective May 2010, VMware's patch and update release program during
   Extended Support will be continued with the condition that all
   subsequent patch and update releases will be based on the latest
   baseline release version as of May 2010 (i.e. ESX 3.0.3 Update 1,
   ESX 3.5 Update 5, and VirtualCenter 2.5 Update 6). Refer to section
   "End of Product Availability FAQs" at
   http://www.vmware.com/support/policies/lifecycle/vi/faq.html for
   details.


VMSA-2010-0013 VMware ESX third party updates for Service Console

   Notes:
   Effective May 2010, VMware's patch and update release program during
   Extended Support will be continued with the condition that all
   subsequent patch and update releases will be based on the latest
   baseline release version as of May 2010 (i.e. ESX 3.0.3 Update 1,
   ESX 3.5 Update 5, and VirtualCenter 2.5 Update 6). Refer to section
   "End of Product Availability FAQs" at
   http://www.vmware.com/support/policies/lifecycle/vi/faq.html for
   details.


[CORE-2010-1001] Cisco WebEx .atp and .wrf Overflow Vulnerabilities

trivially overwritten.


4. *Vulnerable packages*

   . Contact Cisco for a list of vulnerable versions.


5. *Non-vulnerable packages*

   . Contact Cisco.

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!