New User, Welcome!     Login

Next Page >>

affected

VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.

      CVE-2008-3696 to the security issues with VMware ActiveX controls.

      VMware         Product   Running  Replace with/
      Product        Version   on       Apply Patch
      =============  ========  =======  =================
      VirtualCenter  any       Windows  not affected

      Workstation    6.x       Windows  6.0.5 build 109488 or later
      Workstation    6.x       Linux    not affected
      Workstation    5.x       Windows  5.5.8 build 108000 or later
      Workstation    5.x       Linux    not affected

VMSA-2010-0004 ESX Service Console and vMA third party updates

    (column 4) if a solution is available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected


VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues

    (column 4) if a solution is available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    Workstation    6.5.x     any      6.5.1 build 126130 or later
    Workstation    6.0.x     any      upgrade to at least 6.5.1
    Workstation    5.5.x     any      5.5.9 build 126128 or later


VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    vCenter        4.0       Windows  Update 1
    VirtualCenter  2.5       Windows  affected, patch pending
    VirtualCenter  2.0.2     Windows  affected, patch pending

    Workstation    any       any      not affected

    Player         any       any      not affected

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    details.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    Workstation    7.x       any      not affected
    Workstation    6.5.x     any      6.5.4 build 246459 or later

    Player         3.x       any      not affected

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    details.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    Workstation    7.x       any      not affected
    Workstation    6.5.x     any      6.5.4 build 246459 or later

    Player         3.x       any      not affected

VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    vCenter        4.1       Windows  Update 1
    vCenter        4.0       Windows  affected, patch pending
    VirtualCenter  2.5       Windows  affected, no patch planned

    Update Manager 4.1       Windows  Update 1
    Update Manager 4.0       Windows  affected, patch pending
    Update Manager 1.0       Windows  affected, no patch planned

Evasion attacks expoliting file-parsing vulnerabilities in antivirus products

Multiple file-parsing vulnerabilities leading to evasion in different antivirus(AV) products. All 
affected products are command-line versions of 
the AVs.

----------------------------
Vulnerability Descriptions
----------------------------

1. Specially crafted infected POSIX TAR files with "[aliases]" as first 9 bytes 
   evades detection.

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances

+---------------------------------------------------------------------

Summary
=======

Cisco ASA 5500 Series Adaptive Security Appliances are affected by the
following vulnerabilities:

  * TCP Connection Exhaustion Denial of Service Vulnerability
  * Session Initiation Protocol (SIP) Inspection Denial of Service
    Vulnerabilities

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances and Cisco Catalyst 6500 Series ASA Services Module

Summary
=======

Cisco ASA 5500 Series Adaptive Security Appliances (ASA) and Cisco
Catalyst 6500 Series ASA Services Module (ASASM) are affected by the
following vulnerabilities:

  * Cisco ASA UDP Inspection Engine Denial of Service Vulnerability
  * Cisco ASA Threat Detection Denial of Service Vulnerability
  * Cisco ASA Syslog Message 305006 Denial of Service Vulnerability

VMSA-2010-0005 VMware products address vulnerabilities in WebAccess

    control of a server on the same network as the system where
    WebAccess is being used.

    Workaround
    By switching off WebAccess the issue can no longer be exploited.
    This can be accomplished on affected versions of Virtual Center and
    ESX as follows:
     
    Virtual Center 2.0.2 and Virtual Center 2.5:
      Go to the Windows Services overview on the system that runs
      Virtual Center.

VMSA-2010-0018 VMware hosted products and ESX patches resolve multiple security issues

    The way temporary files are handled by the mounting process could
    result in a race condition. This issue could allow a local user on
    the host to elevate their privileges.

    VMware Workstation and Player running on Microsoft Windows are not
    affected.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-4295 to this issue.

    VMware would like to thank Dan Rosenberg for reporting this issue.

VMSA-2010-0009 ESXi ntp and ESX Service Console third party updates

    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected


VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues

    is running, as this is a guest driver vulnerability and not a
    vulnerability on the host.

    The HGFS.sys driver is present in the guest operating system if the
    VMware Tools package is loaded.  Even if the host has HGFS disabled
    and has no shared folders, Windows-based guests may be affected. This
    is regardless if a host supports HGFS.

    This issue could be mitigated by removing the VMware Tools package
    from Windows based guests.  However this is not recommended as it
    would impact usability of the product.

Cisco Security Advisory: Cisco IOS Software IPS and Zone-Based Firewall Vulnerabilities

Cisco IOS Software Security Advisory Bundled Publication" at the
following link:

http://www.cisco.com/web/about/security/intelligence/Cisco_ERP_sep11.html

Affected Products
=================

Vulnerable Products
+------------------


Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities

=======

Multiple vulnerabilities exist in the Session Initiation Protocol
(SIP) implementation in Cisco IOS Software and Cisco IOS XE Software
that could allow an unauthenticated, remote attacker to cause a
reload of an affected device or trigger memory leaks that may result
in system instabilities. Affected devices would need to be configured
to process SIP messages for these vulnerabilities to be exploitable.

Cisco has released free software updates that address these
vulnerabilities. There are no workarounds for devices that must run

Cisco Security Advisory: Multiple Vulnerabilities in Cisco ASA 5500 Series Adaptive Security Appliances

+---------------------------------------------------------------------

Summary
=======

Cisco ASA 5500 Series Adaptive Security Appliances are affected by
multiple vulnerabilities as follows:

  * Three SunRPC Inspection Denial of Service Vulnerabilities
  * Three Transport Layer Security (TLS) Denial of Service
    Vulnerabilities

Cisco Security Advisory: Cisco IOS Software Border Gateway Protocol 4-Byte Autonomous System Number Vulnerabilities

Recent versions of Cisco IOS Software support RFC4893 ("BGP Support
for Four-octet AS Number Space") and contain two remote denial of
service (DoS) vulnerabilities when handling specific Border Gateway
Protocol (BGP) updates.

These vulnerabilities affect only devices running Cisco IOS Software
with support for four-octet AS number space (here after referred to as
4-byte AS number) and BGP routing configured.

The first vulnerability could cause an affected device to reload when
processing a BGP update that contains autonomous system (AS) path

Cisco Security Advisory: Cisco ASA 5500 Series Adaptive Security Appliance Clientless VPN ActiveX Control Remote Code Execution Vulnerability

The Cisco Clientless VPN solution as deployed by Cisco ASA 5500
Series Adaptive Security Appliances (Cisco ASA) uses an ActiveX
control on client systems to perform port forwarding operations.
Microsoft Windows-based systems that are running Internet Explorer or
another browser that supports Microsoft ActiveX technology may be
affected if the system has ever connected to a device that is running
the Cisco Clientless VPN solution. A remote, unauthenticated attacker
who could convince a user to connect to a malicious web page could
exploit this issue to execute arbitrary code on the affected machine
with the privileges of the web browser.


VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues

    this issue on the guest operating system does not lead to a
    compromise of the host system but could lead to a privilege
    escalation on guest operating system.  An attacker would need to
    have a user account on the guest operating system.

    Affected
    64-bit Windows and 64-bit FreeBSD guest operating systems and
    possibly other 64-bit operating systems. The issue does not
    affect the 64-bit versions of Linux guest operating systems.

    VMware would like to thank Derek Soeder for discovering

Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Recording Server

  * Unauthenticated XML-RPC Interface

Duplicate Issue Identification in Other Cisco TelePresence Advisories
+--------------------------------------------------------------------

The Unauthenticated Java Servlet Access vulnerability affects the
Cisco TelePresence Multipoint Switch and Recording Server. The defect
that is related to each component is covered in each associated
advisory. The Cisco Bug IDs for these defects are as follows:

  * Cisco TelePresence Multipoint Switch - CSCtf42008

Cisco Security Advisory: Cisco IOS Software Session Initiation Protocol Denial of Service Vulnerabilities

Summary
=======

Multiple vulnerabilities exist in the Session Initiation Protocol
(SIP) implementation in Cisco IOS^  Software that could allow an
unauthenticated, remote attacker to cause a reload of an affected
device when SIP operation is enabled.

Cisco has released free software updates that address these
vulnerabilities. There are no workarounds for devices that must run
SIP; however, mitigations are available to limit exposure to the

Cisco Security Advisory: Cisco IOS Software Multiple Features Crafted TCP Sequence Vulnerability

Summary
=======

Cisco IOS  Software contains a vulnerability in multiple features
that could allow an attacker to cause a denial of service (DoS)
condition on the affected device. A sequence of specially crafted TCP
packets can cause the vulnerable device to reload.

Cisco has released free software updates that address this
vulnerability.


Cisco Security Advisory: Cisco 10000 Series Denial of Service Vulnerability

+---------------------------------------------------------------------

Summary
=======

The Cisco 10000 Series Router is affected by a denial of service
(DoS) vulnerability that can allow an attacker to cause a device
reload by sending a series of ICMP packets.

Cisco has released free software updates that address this
vulnerability.

VMSA-2010-0013

    available.  

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected


VMSA-2010-0013 VMware ESX third party updates for Service Console

    available.  

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected


Cisco Security Advisory: Multiple Vulnerabilities in Cisco TelePresence Multipoint Switch

  * Real-Time Transport Control Protocol Denial of Service
  * XML-Remote Procedure Call (RPC) Denial of Service

Duplicate Issue Identification in Other Cisco TelePresence Advisories

The Unauthenticated Java Servlet Access vulnerability affects the
Cisco TelePresence Multipoint Switch and Recording Server. The defect
as related to each component is covered in each associated advisory.
The Cisco bug IDs for these defects are as follows:

  * Cisco TelePresence Multipoint Switch - CSCtf42008

Cisco Security Advisory: Cisco IOS Software Smart Install Remote Code Execution Vulnerability

=======

A vulnerability exists in the Smart Install feature of Cisco Catalyst
Switches running Cisco IOS Software that could allow an
unauthenticated, remote attacker to perform remote code execution on
the affected device.

Cisco has released free software updates that address this
vulnerability.

There are no workarounds available to mitigate this vulnerability

Cisco Security Advisory: Multiple Vulnerabilities in the Cisco ACE Application Control Engine Module and Cisco ACE 4710 Application Control Engine

  * HTTP, RTSP, and Session Initiation Protocol (SIP) inspection DoS
    vulnerability
  * Secure Socket Layer (SSL) DoS vulnerability
  * SIP inspection DoS vulnerability

Cisco has released free software updates for affected customers.
Workarounds that mitigate some of the vulnerabilities are available.

Note: These vulnerabilities are independent of each other. A device
may be affected by one vulnerability and not affected by another.


Cisco Security Advisory: Cisco Content Services Gateway Denial of Service Vulnerability

A denial of service (DoS) vulnerability exists in the Cisco Content
Services Gateway - Second Generation, that runs on the Cisco Service
and Application Module for IP (SAMI). An unauthenticated, remote
attacker could exploit this vulnerability by sending a series of
crafted ICMP packets to an affected device. Exploitation could cause
the device to reload.

There are no workarounds available to mitigate exploitation of this
vulnerability other than blocking ICMP traffic destined to the
affected device.

Next Page>>

Copyright © 1995-2013 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!