New User, Welcome!     Login

Next Page >>

analysis

[security bulletin] HPSBST02379 SSRT080143 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-056 to MS08-066

Note: Patch installation instructions are shown at the end of this table. 

 -------------------------------------------------  
MS Patch - MS08-056 Vulnerability in Microsoft Office Could Allow Information Disclosure (957699)
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue
 ------------------------------------------------- 
MS Patch - MS08-057 Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (956416)
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue

[security bulletin] HPSBST02360 SSRT080117 rev.2 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-041 to MS08-051

Note: Patch installation instructions are shown at the end of this table. 

 -------------------------------------------------  
MS Patch - MS08-041 Vulnerability in the ActiveX Control for the Snapshot Viewer for Microsoft Access 
Could Allow Remote Code Execution (955617)
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue
 -------------------------------------------------  
MS Patch - MS08-042 Vulnerability in Microsoft Word Could Allow Remote Code Execution (955048)
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue

[security bulletin] HPSBST02314 SSRT080016 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-003 to MS08-013

NOTE: Patch installation instructions are shown at the end of this table.

 -------------------------------------------------
MS Patch - MS08-003 Vulnerability in Active Directory Could Allow Denial of Service (946538) 
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue
 ------------------------------------------------- 
MS Patch - MS08-004 Vulnerability in Windows TCP/IP Could Allow Denial of Service (946456) 
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue

[security bulletin] HPSBST02314 SSRT080016 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-003 to MS08-013

NOTE: Patch installation instructions are shown at the end of this table.

 -------------------------------------------------
MS Patch - MS08-003 Vulnerability in Active Directory Could Allow Denial of Service (946538) 
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue
 ------------------------------------------------- 
MS Patch - MS08-004 Vulnerability in Windows TCP/IP Could Allow Denial of Service (946456) 
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue

CA20090107-01: CA Service Metric Analysis and CA Service Level Management smmsnmpd Arbitrary Command Execution Vulnerability

Title: CA20090107-01: CA Service Metric Analysis and CA Service 
Level Management smmsnmpd Arbitrary Command Execution 
Vulnerability


CA Advisory Reference: CA20090107-01


CA Advisory Date: 2009-01-07

Update+Errata: Re: A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability"

> much like my earlier attacks on BIND 9, BIND 8 and Microsoft
> Windows DNS server.
>
> Interestingly enough, OpenBSD uses a flavor of this PRNG for
> another field, this time the IP fragmentation ID, part of the
> OpenBSD kernel network stack. The analysis carries out quite
> similarly to show that OpenBSD's IP ID is predictable as well,
> which gives way to O/S fingerprinting, idle-scanning, host alias
> detection, traffic analysis, and in some cases, even to TCP blind
> data injection.
>

A paper by Amit Klein (Trusteer): "OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability"

much like my earlier attacks on BIND 9, BIND 8 and Microsoft
Windows DNS server.

Interestingly enough, OpenBSD uses a flavor of this PRNG for
another field, this time the IP fragmentation ID, part of the
OpenBSD kernel network stack. The analysis carries out quite
similarly to show that OpenBSD's IP ID is predictable as well,
which gives way to O/S fingerprinting, idle-scanning, host alias
detection, traffic analysis, and in some cases, even to TCP blind
data injection.


HPSBST02255 SSRT071456 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-042 to MS07-050

NOTE: Patch installation instructions are shown at the end of this table.

 ------------------------------------------------- 
MS Patch - MS07-042 Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (936227) 
Analysis - Possible security issue exists. Patch will run successfully.
Action -  For SMA v2.1, customers should download patch from Microsoft and install.
 ------------------------------------------------- 
MS Patch - MS07-043 Vulnerability in OLE Automation Could Allow Remote Code Execution (921503)  
Analysis - Possible security issue exists. Patch will run successfully.
Action -  For SMA v2.1, customers should download patch from Microsoft and install.

[security bulletin] HPSBST02394 SSRT080183 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-070 to MS08-077

Note: Patch installation instructions are shown at the end of this table. 

 ------------------------------------------------- 
MS Patch - MS08-070 Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution (932349)
Analysis - SMA does not have this component. Patch will not run successfully
Action - Customers should not be concerned with this issue.
 ------------------------------------------------- 
MS Patch - MS08-071 Vulnerabilities in GDI Could Allow Remote Code Execution (956802)
Analysis - Possible security issue exists. Patch will run successfully.
Action - For SMA v2.1, customers should download patch from Microsoft and install.

[oCERT-2008-008] multiple heap overflows in xine-lib

the real, qt, and matroska demuxers which result in process termination
or memory corruption that may have wider implications.

The oCERT team was contacted by the Xine project requesting a review of
some code changes relating to memory allocations. These vulnerabilities
were the findings of this requested analysis. The full analysis text can
be found in the references below.

Affected version:

xine-lib <= 1.1.14

[security bulletin] HPSBST02329 SSRT080048 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-018 to MS08-025

NOTE: Patch installation instructions are shown at the end of this table.

 -------------------------------------------------
MS Patch - MS08-018 Vulnerability in Microsoft Project Could Allow Remote Code Execution (950183)
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue
 -------------------------------------------------
MS Patch - MS08-019 Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (949032) 
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue 

XCon 2010 XFocus Information Security Conference Call for Paper

      - Protocol security & exploitation
      - Advanced Trojans, worms and backdoor technique
      - Encryption & decryption technique
      - Routing device

   --- Intrusion detection/forensics analysis
      - File system analysis & recovery
      - Real-time data structure recovery
      - Reverse engineering (malicious code analysis technique, vulnerability research)
      - Intrusion detection and anti-detection technique
      - Traffic analysis

CORE-2009-0827: Microsoft Office Excel / Word OfficeArtSpgr Container Pointer Overwrite Vulnerability

Core acknowledges receipt of the previous mail from the Microsoft team
and reminds them that the publication date proposed by Core is November
24th, 2009.

. 2009-09-14:
Core requests Microsoft's analysis of the second reported bug.

. 2009-09-14:
Microsoft confirms that the first bug reported on Excel is exploitable
and that they are working on defining a ship date. Microsoft also states
that the bug reported as MSRC case 9154 / CORE-2009-0504 is not

The XCon2010 is coming

      - Protocol security & exploitation
      - Advanced Trojans, worms and backdoor technique
      - Encryption & decryption technique
      - Routing device

   --- Intrusion detection/forensics analysis
      - File system analysis & recovery
      - Real-time data structure recovery
      - Reverse engineering (malicious code analysis technique, vulnerability research)
      - Intrusion detection and anti-detection technique
      - Traffic analysis

xcon2009 is coming

      - Protocol security & exploitation
      - Advanced Trojans, worms and backdoor technique
      - Encryption & decryption technique
      - Routing device

   --- Intrusion detection/forensics analysis
      - File system analysis & recovery
      - Real-time data structure recovery
      - Reverse engineering (malicious code analysis technique, vulnerability research)
      - Intrusion detection and anti-detection technique
      - Traffic analysis

XCon 2008 Call for Paper

      - Database security & attacks
      - Protocol security & exploitation
      - Advanced Trojans, worms and backdoor technique
      - Encryption & decryption technique

   --- Intrusion detection/forensics analysis
      - File system analysis & recovery
      - Real-time data structure recovery
      - Reverse engineering (malicious code analysis technique,
vulnerability research)
      - Traffic analysis

Re: XCon 2008 Call for Paper

>       - Database security & attacks
>       - Protocol security & exploitation
>       - Advanced Trojans, worms and backdoor technique
>       - Encryption & decryption technique
>
>    --- Intrusion detection/forensics analysis
>       - File system analysis & recovery
>       - Real-time data structure recovery
>       - Reverse engineering (malicious code analysis technique,
> vulnerability research)
>       - Traffic analysis

Re: XCon 2008 Call for Paper

>>       - Database security & attacks
>>       - Protocol security & exploitation
>>       - Advanced Trojans, worms and backdoor technique
>>       - Encryption & decryption technique
>>
>>    --- Intrusion detection/forensics analysis
>>       - File system analysis & recovery
>>       - Real-time data structure recovery
>>       - Reverse engineering (malicious code analysis technique,
>> vulnerability research)
>>       - Traffic analysis

[security bulletin] HPSBST02344 SSRT080087 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-030 to MS08-036

NOTE: Patch installation instructions are shown at the end of this table.

 ------------------------------------------------- 
MS Patch - MS08-030 Vulnerability in Bluetooth Stack Could Allow Remote Code Execution (951376) 
Analysis - SMA does not have this component. Patch will not run successfully.
Action - Customers should not be concerned with this issue
 ------------------------------------------------- 
MS Patch - MS08-031 Cumulative Security Update for Internet Explorer (950759)
Analysis -  Possible security issue exists. Patch will run successfully.
Action - For SMA v2.1, customers should download patch from Microsoft and install. 

[security bulletin] HPSBST02299 SSRT071506 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-063 to MS07-069

NOTE: Patch installation instructions are shown at the end of this table.

 -------------------------------------------------
MS Patch - MS07-063 Vulnerability in SMBv2 Could Allow Remote Code Execution (942624) 
Analysis -  SMA does not have this component. Patch will not run successfully.
Action -  Customers should not be concerned with this issue.
 ------------------------------------------------- 
MS Patch - MS07-064 Vulnerabilities in DirectX Could Allow Remote Code Execution (941568) 
Analysis -  Possible security issue exists. Patch will run successfully.
Action -  For SMA v2.1, customers should download patch from Microsoft and install.

XCon 2011 XFocus Information Security Conference Call for Paper

   - Protocol security & exploitation
   - Advanced Trojans, worms and backdoor technique
   - Encryption & decryption technique
   - Routing device

--- Intrusion detection/forensics analysis
   - File system analysis & recovery
   - Real-time data structure recovery
   - Reverse engineering (malicious code analysis technique, vulnerability research)
   - Intrusion detection and anti-detection technique
   - Traffic analysis

VUPEN Security Research - 7T Interactive Graphical SCADA System (IGSS) Remote Memory Corruption

---------------------------

7T Interactive Graphical SCADA System (IGSS) versions prior to 9.0.0.11143


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Oracle Java ICC Profile "bfd" Tag Integer Overflow Code Execution Vulnerability

---------------------------

Oracle Java JDK and JRE 6 Update 25 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Oracle Java ICC Profile "ncl2" Tag Integer Overflow Code Execution Vulnerability

---------------------------

Oracle Java JDK and JRE 6 Update 25 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Oracle Java ICC Profile "pseq" Tag Integer Overflow Code Execution Vulnerability

---------------------------

Oracle Java JDK and JRE 6 Update 25 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Oracle Java ICC Profile "clrt" Tag Integer Overflow Code Execution Vulnerability

---------------------------

Oracle Java JDK and JRE 6 Update 25 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Oracle Java ICC Profile "scrn" Tag Integer Overflow Code Execution Vulnerability

---------------------------

Oracle Java JDK and JRE 6 Update 25 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Oracle Java ICC Profile "mluc" Tag Integer Overflow Code Execution Vulnerability

---------------------------

Oracle Java JDK and JRE 6 Update 25 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Microsoft Windows OLE Automation Integer Underflow Vulnerability (MS11-038)

Microsoft Windows Vista x64 Edition Service Pack 2
Microsoft Windows XP Professional x64 Edition Service Pack 2
Microsoft Windows XP Service Pack 3


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a proof-of-concept code
are available through the VUPEN Binary Analysis & Exploits Service :


VUPEN Security Research - Adobe Shockwave rcsL Record Array Indexing Vulnerability (APSB11-19)

---------------------------

Adobe Shockwave Player v11.6.0.626 and prior


IV. Binary Analysis & Exploits/PoCs
---------------------------------------

In-depth binary analysis of the vulnerability and a code execution exploit
are available through the VUPEN Binary Analysis & Exploits Service :


Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!