New User, Welcome!     Login

Next Page >>

man/in/the/middle attack

ERRATA - n.runs-SA-2008.001 - Jscape Secure FTP Applet

Vendor:             Jscape, http://www.jscape.com/
Affected Products:  Jscape Secure FTP Applet
                    http://www.jscape.com/sftpapplet/index.html
Vulnerability:      SSH Host key is not verified allowing 
                          man-in-the-middle attacks
Risk:               Medium
____________________________________________________________________________
____



VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

    A cURL is affected by the previously published "null prefix attack",
    caused by incorrect handling of NULL characters in X.509
    certificates. If an attacker is able to get a carefully-crafted
    certificate signed by a trusted Certificate Authority, the attacker
    could use the certificate during a man-in-the-middle attack and
    potentially confuse cURL into accepting it by mistake.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-2417 to this issue


Cisco Security Advisory: Transport Layer Security Renegotiation Vulnerability

=======

An industry-wide vulnerability exists in the Transport Layer Security
(TLS) protocol that could impact any Cisco product that uses any version
of TLS and SSL. The vulnerability exists in how the protocol handles
session renegotiation and exposes users to a potential man-in-the-middle
attack.

This advisory is posted at
http://www.cisco.com/warp/public/707/cisco-sa-20091109-tls.shtml.


n.runs-SA-2008.001 - Jscape Secure FTP Applet

Vendor:             Jscape, http://www.jscape.com/
Affected Products:  Jscape Secure FTP Applet
                    http://www.jscape.com/sftpapplet/index.html
Vulnerability:      SSH Host key is not verified allowing for Man in the
Middle 
                    attacks 
Risk:               High
____________________________________________________________________________
____


rPSA-2009-0154-1 httpd mod_ssl

    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1891

Description:
    Previous versions of httpd are vulnerable to a man-in-the-middle attack
    during TLS session renegotiation, sometimes referred to as the "Project
    Mogul" issue.  This vulnerability has been addressed in this update.
    Additionally, two denial of service vulnerabilities and an access
    restriction bypass in mod_proxy_ftp are resolved in this update.


[ MDVSA-2009:197 ] nss

 _______________________________________________________________________

 Problem Description:

 Security issues in nss prior to 3.12.3 could lead to a
 man-in-the-middle attack via a spoofed X.509 certificate
 (CVE-2009-2408) and md2 algorithm flaws (CVE-2009-2409), and also
 cause a denial-of-service and possible code execution via a long
 domain name in X.509 certificate (CVE-2009-2404).
 
 This update provides the latest versions of NSS and NSPR libraries

[ MDVSA-2009:217-2 ] mozilla-thunderbird

 Problem Description:

 A number of security vulnerabilities have been discovered in Mozilla
 Thunderbird:
 
 Security issues in thunderbird could lead to a man-in-the-middle
 attack via a spoofed X.509 certificate (CVE-2009-2408).
 
 A vulnerability was found in xmltok_impl.c (expat) that with
 specially crafted XML could be exploited and lead to a denial of
 service attack. Related to CVE-2009-2625.

Multiple vulnerabilities in several ATEN IP KVM Switches

have access to other similar devices and want to test whether they are
vulnerable as well, please contact me at jakob@cs.tu-berlin.de.


Impact: Arbitrary code execution on client system, Information
disclosure and man in the middle attacks.

Background:
Aten produces several IP KVM Switches. This devices can be used like a
normal kvm switch with an attached keyboard, mouse and monitor.
However, it is also possible to access the hosts connected to the kvm

rPSA-2009-0155-1 httpd mod_ssl

    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3094
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3095
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555

Description:
    Previous versions of httpd are vulnerable to a man-in-the-middle attack
    during TLS session renegotiation, sometimes referred to as the "Project
    Mogul" issue.  This vulnerability has been addressed in this update.
    Additionally, a denial of service vulnerability and an access
    restriction bypass in mod_proxy_ftp are resolved in this update.


[ MDVSA-2009:217-3 ] mozilla-thunderbird

 Problem Description:

 A number of security vulnerabilities have been discovered in Mozilla
 Thunderbird:
 
 Security issues in thunderbird could lead to a man-in-the-middle
 attack via a spoofed X.509 certificate (CVE-2009-2408).
 
 A vulnerability was found in xmltok_impl.c (expat) that with
 specially crafted XML could be exploited and lead to a denial of
 service attack. Related to CVE-2009-2625 (CVE-2009-3720).

[ GLSA 200910-01 ] Wget: Certificate validation error

Synopsis
========

An error in the X.509 certificate handling of Wget might enable remote
attackers to conduct man-in-the-middle attacks.

Background
==========

GNU Wget is a free software package for retrieving files using HTTP,

[ GLSA 200909-13 ] irssi: Execution of arbitrary code

Impact
======

A remote attacker might entice a user to connect to a malicious IRC
server, use a man-in-the-middle attack to redirect a user to such a
server or use ircop rights to send a specially crafted WALLOPS message,
which might result in the execution of arbitrary code with the
privileges of the user running irssi.

Workaround

[ GLSA 200909-20 ] cURL: Certificate validation error

Synopsis
========

An error in the X.509 certificate handling of cURL might enable remote
attackers to conduct man-in-the-middle attacks.

Background
==========

cURL is a command line tool for transferring files with URL syntax,

[ MDVSA-2009:216 ] mozilla-thunderbird

 A number of security vulnerabilities have been discovered in the NSS
 and NSPR libraries and in Mozilla Thunderbird:
 
 Security issues in nss prior to 3.12.3 could lead to a
 man-in-the-middle attack via a spoofed X.509 certificate
 (CVE-2009-2408) and md2 algorithm flaws (CVE-2009-2409), and also
 cause a denial-of-service and possible code execution via a long
 domain name in X.509 certificate (CVE-2009-2404).
 
 A vulnerability was found in xmltok_impl.c (expat) that with

[ MDVSA-2009:197 ] nss

 _______________________________________________________________________

 Problem Description:

 Security issues in nss prior to 3.12.3 could lead to a
 man-in-the-middle attack via a spoofed X.509 certificate
 (CVE-2009-2408) and md2 algorithm flaws (CVE-2009-2409), and also
 cause a denial-of-service and possible code execution via a long
 domain name in X.509 certificate (CVE-2009-2404).
 
 This update provides the latest versions of NSS and NSPR libraries

Remote Arbitrary Code Execution Vulnerability in UFO: Alien Invasion

The IRC client component of UFO: Alien Invasion 2.2.1 contains multiple
security vulnerabilities that allow a malicious IRC server to remotely execute
arbitrary code on the client's system. There are numerous ways that an attacker
could cause a player to connect to a malicious server, for example:

- Perform a man-in-the-middle attack to inject IRC server responses into the
  TCP stream.
- Use DNS poisoning to redirect the player's client from the real
  irc.freenode.org server to the attacker's malicious server.
- Use the in-game "rcon" functionality against a server to remotely issue the
  command "irc_connect <attacker's server>" (passwords for rcon can be

CVE-2009-4510: TANDBERG VCS Static SSH Host Keys

Vulnerability Overview
- ----------------------
On December 2nd, VSR identified a SSH service authentication weakness
vulnerability in the TANDBERG's Video Communication Server.  This issue would
allow an attacker with privileged network access to conduct server impersonation
and man-in-the-middle attacks on administrator SSH sessions.  Successful attacks
could yield shell access to vulnerable appliances.


Product Background
- ------------------

[ GLSA 201006-12 ] Fetchmail: Multiple vulnerabilities

Synopsis
========

Multiple vulnerabilities have been reported in Fetchmail, allowing
remote attackers to execute arbitrary code or to conduct
Man-in-the-Middle attacks.

Background
==========

Fetchmail is a remote mail retrieval and forwarding utility.

[ MDVSA-2009:197-3 ] nss

 _______________________________________________________________________

 Problem Description:

 Security issues in nss prior to 3.12.3 could lead to a
 man-in-the-middle attack via a spoofed X.509 certificate
 (CVE-2009-2408) and md2 algorithm flaws (CVE-2009-2409), and also
 cause a denial-of-service and possible code execution via a long
 domain name in X.509 certificate (CVE-2009-2404).
 
 This update provides the latest versions of NSS and NSPR libraries

New Paper: MitM Attacks against the chipTAN comfort Online Banking System

Abstract
========
ChipTAN comfort is a new system which is supposed to securely authorise online
banking transactions by means of a trusted device. It is assumed that chipTAN
comfort specifically protects against man-in-the-middle attacks. Such attacks are
currently putting bank customers who are using the iTAN system at risk. RedTeam
Pentesting examined chipTAN comfort and showed that even when using this sys-
tem, man-in-the-middle attacks can compromise online banking security.



[ MDVSA-2009:197-2 ] nss

 _______________________________________________________________________

 Problem Description:

 Security issues in nss prior to 3.12.3 could lead to a
 man-in-the-middle attack via a spoofed X.509 certificate
 (CVE-2009-2408) and md2 algorithm flaws (CVE-2009-2409), and also
 cause a denial-of-service and possible code execution via a long
 domain name in X.509 certificate (CVE-2009-2404).
 
 This update provides the latest versions of NSS and NSPR libraries

rPSA-2010-0036-1 openssl openssl-scripts

Description:
    Openssl has been patched to address multiple vulnerabilities;
    see the listed CVEs for details.  Most importantly, this update 
    adds support for the TLS Renegotiation Indication Extension as
    specified in RFC-5746, to address man-in-the-middle attack
    weaknesses in the TLS protocol.
    

http://wiki.rpath.com/Advisories:rPSA-2010-0036


[ MDVSA-2009:217 ] mozilla-thunderbird

 Problem Description:

 A number of security vulnerabilities have been discovered in Mozilla
 Thunderbird:
 
 Security issues in thunderbird could lead to a man-in-the-middle
 attack via a spoofed X.509 certificate (CVE-2009-2408).
 
 A vulnerability was found in xmltok_impl.c (expat) that with
 specially crafted XML could be exploited and lead to a denial of
 service attack. Related to CVE-2009-2625.

[ MDVSA-2009:217-1 ] mozilla-thunderbird

 Problem Description:

 A number of security vulnerabilities have been discovered in Mozilla
 Thunderbird:
 
 Security issues in thunderbird could lead to a man-in-the-middle
 attack via a spoofed X.509 certificate (CVE-2009-2408).
 
 A vulnerability was found in xmltok_impl.c (expat) that with
 specially crafted XML could be exploited and lead to a denial of
 service attack. Related to CVE-2009-2625.

[SECURITY] [DSA 1830-1] New icedove packages fix several vulnerabilities

(MFSA 2009-24)                                                          

CVE-2009-1836

Shuo Chen, Ziqing Mao, Yi-Min Wang and Ming Zhang reported a potential
man-in-the-middle attack, when using a proxy due to insufficient checks
on a certain proxy response. (MFSA 2009-27)

CVE-2009-1838

moz_bug_r_a4 discovered that it is possible to execute arbitrary

[ MDVSA-2009:134 ] firefox

 CVE-2009-1839: Firefox information disclosure flaw
 CVE-2009-1840: Firefox XUL scripts skip some security checks
 CVE-2009-1841: Firefox JavaScript arbitrary code execution
 CVE-2009-2043: firefox - remote TinyMCE denial of service
 CVE-2009-2044: firefox - remote GIF denial of service
 CVE-2009-2061: firefox - man-in-the-middle exploit
 CVE-2009-2065: firefox - man-in-the-middle exploit
 
 This update provides the latest Mozilla Firefox 3.x to correct
 these issues.
 

[SECURITY] [DSA 1820-1] New xulrunner packages fix several vulnerabilities

cookies via a crafted HTML document. (MFSA 2009-26)               

CVE-2009-1836

Shuo Chen, Ziqing Mao, Yi-Min Wang and Ming Zhang reported a potential
man-in-the-middle attack, when using a proxy due to insufficient checks
on a certain proxy response. (MFSA 2009-27)                            

CVE-2009-1837

Jakob Balle and Carsten Eiram reported a race condition in the

Serena Dimensions CM Desktop Client does not validate the server SSL certificate

Application: Serena Dimensions CM
Affected versions: 10.1 and later
Vulnerability: man-in-the-middle attacks
Problem type: remote

Problem description:
====================

The client/server connection can be SSL encrypted by setting "-ssl" in the listener.dat. The problem is that the Desktop client accepts any server certificates. They may be self signed or signed by a CA. But there is no user interaction required to accept the certificate. There is also no possibility to configure trusted certificates.


[USN-596-1] Ruby vulnerabilities

Details follow:

Chris Clark discovered that Ruby's HTTPS module did not check for
commonName mismatches early enough during SSL negotiation.  If a remote
attacker were able to perform man-in-the-middle attacks, this flaw could
be exploited to view sensitive information in HTTPS requests coming from
Ruby applications. (CVE-2007-5162)

It was discovered that Ruby's FTPTLS, telnets, and IMAPS modules
did not check the commonName when performing SSL certificate checks.

[ MDVSA-2008:029 ] - Updated ruby packages fix possible man-in-the-middle attack

 
 Problem Description:
 
 Ruby network libraries Net::HTTP, Net::IMAP, Net::FTPTLS, Net::Telnet,
 Net::POP3, and Net::SMTP, up to Ruby version 1.8.6 are affected by a
 possible man-in-the-middle attack, when using SSL, due to a missing
 check of the CN (common name) attribute in SSL certificates against
 the server's hostname.
 
 The updated packages have been patched to prevent the issue.
 _______________________________________________________________________

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!