<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.nessus.org/">
<title>Nessus.org Plugins</title>
<link>http://www.nessus.org/scripts.php</link>
<description>All the newest security checks for the Nessus scanner</description>

<items>
<rdf:Seq>
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34055" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34054" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34053" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34052" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34051" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34050" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34049" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34048" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34047" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34046" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34045" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34044" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34043" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34042" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34041" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34040" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34039" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34038" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34037" />
<rdf:li rdf:resource="http://www.nessus.org/plugins/index.php?view=single&amp;id=34036" />
</rdf:Seq>
</items>
</channel>

<image rdf:about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus Plugins</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>

<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34055">
<title>awstatstotals.php remote command execution</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote web server contains a PHP script that is prone to arbitrary<br />
code execution. <br />
<br />
Description :<br />
<br />
The remote web server is running a version of awstatstotals.php which<br />
does not properly sanitize its 'sort' argument.<br />
An attacker can run arbitrary commands on the remote host within the <br />
context of the web server.<br />
<br />
See also :<br />
<br />
<a href="http://www.securityfocus.com/archive/1/20080826165439.GQ10038@dx4.org" target="_blank">http://www.securityfocus.com/archive/1/20080826165439.GQ10038@dx4.org</a><br />
<a href="http://www.telartis.nl/xcms/awstats/" target="_blank">http://www.telartis.nl/xcms/awstats/</a><br />
<br />
Solution :<br />
<br />
Upgrade to Telartis AWStats Totals 1.15<br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 7.5<br />
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34055</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34054">
<title>RHSA-2008-0849: ipsec</title>
<description><![CDATA[<br />
<br />
  An updated ipsec-tools package that fixes two security issues is now<br />
  available for Red Hat Enterprise Linux 3, 4, and 5.<br />
<br />
  This update has been rated as having important security impact by the Red<br />
  Hat Security Response Team.<br />
<br />
  The ipsec-tools package is used in conjunction with the IPsec functionality<br />
  in the Linux kernel and includes racoon, an IKEv1 keying daemon.<br />
<br />
  Two denial of service flaws were found in the ipsec-tools racoon daemon. It<br />
  was possible for a remote attacker to cause the racoon daemon to consume<br />
  all available memory. (CVE-2008-3651, CVE-2008-3652)<br />
<br />
  Users of ipsec-tools should upgrade to this updated package, which contains<br />
  backported patches that resolve these issues.<br />
<br />
<br />
<br />
<br />
Solution : <a href="http://rhn.redhat.com/errata/RHSA-2008-0849.html" target="_blank">http://rhn.redhat.com/errata/RHSA-2008-0849.html</a><br />
Risk factor : High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34054</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34053">
<title>[DSA1632] DSA-1632-1 tiff</title>
<description><![CDATA[<br />
Drew Yao discovered that libTIFF, a library for handling the Tagged Image<br />
File Format, is vulnerable to a programming error allowing malformed<br />
tiff files to lead to a crash or execution of arbitrary code.<br />
For the stable distribution (etch), this problem has been fixed in<br />
version 3.8.2-7+etch1.<br />
<br />
<br />
Solution : <a href="http://www.debian.org/security/2008/dsa-1632" target="_blank">http://www.debian.org/security/2008/dsa-1632</a><br />
Risk factor : High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34053</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34052">
<title>CentOS : RHSA-2008-0849</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote host is missing a security update.<br />
<br />
Description :<br />
<br />
The remote CentOS system is missing a security update which has been <br />
documented in Red Hat advisory RHSA-2008-0849.<br />
<br />
See also :<br />
<br />
<a href="https://rhn.redhat.com/errata/RHSA-2008-0849.html" target="_blank">https://rhn.redhat.com/errata/RHSA-2008-0849.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to the newest packages by doing :<br />
<br />
  yum update<br />
<br />
Risk factor :<br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34052</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34051">
<title>CentOS : RHSA-2008-0836</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote host is missing a security update.<br />
<br />
Description :<br />
<br />
The remote CentOS system is missing a security update which has been <br />
documented in Red Hat advisory RHSA-2008-0836.<br />
<br />
See also :<br />
<br />
<a href="https://rhn.redhat.com/errata/RHSA-2008-0836.html" target="_blank">https://rhn.redhat.com/errata/RHSA-2008-0836.html</a><br />
<br />
Solution :<br />
<br />
Upgrade to the newest packages by doing :<br />
<br />
  yum update<br />
<br />
Risk factor :<br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34051</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34050">
<title>Trend Micro Multiple Products Security Bypass Vulnerability</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Windows host contains an application that is affected by a<br />
security bypass vulnerability. <br />
<br />
Description :<br />
<br />
The remote host is either running Trend Micro OfficeScan or Worry-Free <br />
Business Security. The installed version is affected by a security <br />
bypass vulnerability, because it reportedly implements a weak algorithm <br />
to generate random session token typically assigned to a successful <br />
authentication request. An attacker can easily brute force the <br />
authentication token and gain access to the web console. <br />
<br />
In some cases it may be possible to execute arbitrary code on the remote <br />
system.<br />
<br />
See also :<br />
<br />
<a href="http://www.securityfocus.com/archive/1/495670" target="_blank">http://www.securityfocus.com/archive/1/495670</a><br />
<a href="http://www.nessus.org/u?c33a341a" target="_blank">http://www.nessus.org/u?c33a341a</a><br />
<a href="http://www.nessus.org/u?84d581da" target="_blank">http://www.nessus.org/u?84d581da</a><br />
<a href="http://www.nessus.org/u?7a1c665c" target="_blank">http://www.nessus.org/u?7a1c665c</a><br />
<a href="http://www.nessus.org/u?12e41037" target="_blank">http://www.nessus.org/u?12e41037</a><br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
<br />
 - Trend Micro OfficeScan 8.0 Build 1351 or 2402 or 3307 <br />
   depending on the current OfficeScan patch level.<br />
 - Worry-Free Business Security 5.0 Build 1404.<br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34050</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34049">
<title>Novell iPrint Client ActiveX Control Multiple Vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote Windows host has an ActiveX control that is affected by<br />
multiple vulnerabilities.<br />
<br />
Description :<br />
<br />
Novell iPrint Client is installed on the remote host.<br />
<br />
An ActiveX control included with Novell iPrint Client is affected<br />
by multiple vulnerabilities.<br />
<br />
- Vulnerabilities affecting GetDriverFile(), GetDriverSettings()<br />
  GetPrinterURLList(), GetFileList(), GetServerVersion(), <br />
  UploadResource(), ExecuteRequest(), UploadResource(), and<br />
  UploadResourceToRMS() methods in 'ienipp.ocx' could be exploited to <br />
  perform stack based buffer overflows and execute arbitrary code on<br />
  the remote system.<br />
<br />
- A vulnerability in IppGetDriverSettings() method in nipplib.dll<br />
  could be exploited to perform a stack based buffer overflow.  <br />
<br />
- A vulnerability in GetFileList() method may disclose sensitive <br />
  information.<br />
<br />
See also :<br />
<br />
<a href="http://secunia.com/secunia_research/2008-27/advisory/" target="_blank">http://secunia.com/secunia_research/2008-27/advisory/</a><br />
<a href="http://secunia.com/secunia_research/2008-30/advisory/" target="_blank">http://secunia.com/secunia_research/2008-30/advisory/</a><br />
<a href="http://download.novell.com/Download?buildid=_BILqzyqc2g~" target="_blank">http://download.novell.com/Download?buildid=_BILqzyqc2g~</a><br />
<br />
Solution :<br />
<br />
Upgrade to Novell iPrint Client for Vista 5.06<br />
<br />
Risk factor :<br />
<br />
Critical / CVSS Base Score : 10.0<br />
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34049</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34048">
<title>USN637-1 : Linux kernel vulnerabilities</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
These remote packages are missing security patches :<br />
- linux-doc-2.6.15 <br />
- linux-doc-2.6.20 <br />
- linux-doc-2.6.22 <br />
- linux-doc-2.6.24 <br />
- linux-headers-2.6.15-52 <br />
- linux-headers-2.6.15-52-386 <br />
- linux-headers-2.6.15-52-686 <br />
- linux-headers-2.6.15-52-amd64-generic <br />
- linux-headers-2.6.15-52-amd64-k8 <br />
- linux-headers-2.6.15-52-amd64-server <br />
- linux-headers-2.6.15-52-amd64-xeon <br />
- linux-headers-2.6.15-52-k7 <br />
- linux-headers-2.6.15-52-powerpc <br />
- linux-headers-2.6.15-52-powerpc-smp <br />
- linux-headers-2.6.15-52-powe<br />
[...]<br />
<br />
Description :<br />
<br />
It was discovered that there were multiple NULL-pointer function<br />
dereferences in the Linux kernel terminal handling code. A local attacker<br />
could exploit this to execute arbitrary code as root, or crash the system,<br />
leading to a denial of service. (CVE-2008-2812)<br />
<br />
The do_change_type routine did not correctly validation administrative<br />
users. A local attacker could exploit this to block mount points or cause<br />
private mounts to be shared, leading to denial of service or a possible<br />
loss of privacy. (CVE-2008-2931)<br />
<br />
Tobias Klein discovered that the OSS interface through ALSA did not<br />
correctly validate the device number. A local attacker could exploit this<br />
to access sensitive kernel memory, leading to a denial of service or a loss<br />
of privacy. (CVE-2008-3272)<br />
<br />
Zoltan Sogor discovered that new directory entries could be added to<br />
already deleted directories. A local attacker could exploit this, filling<br />
up available memory and disk space, leading to a denial of service.<br />
(CVE-2008-3275)<br />
<br />
In certain situations, the fix for<br />
[...]<br />
<br />
Solution :<br />
<br />
Upgrade to : <br />
- linux-doc-2.6.15-2.6.15-52.71 (Ubuntu 6.06)<br />
- linux-doc-2.6.20-2.6.20-17.39 (Ubuntu 7.04)<br />
- linux-doc-2.6.22-2.6.22-15.58 (Ubuntu 7.10)<br />
- linux-doc-2.6.24-2.6.24-19.41 (Ubuntu 8.04)<br />
- linux-headers-2.6.15-52-2.6.15-52.71 (Ubuntu 6.06)<br />
- linux-headers-2.6.15-52-386-2.6.15-52.71 (Ubuntu 6.06)<br />
- linux-headers-2.6.15-52-686-2.6.15-52.71 (Ubuntu 6.06)<br />
- linux-headers-2.6.15-52-amd64-generic-2.6.15-52.71 (Ubuntu 6.06)<br />
- linux-headers-2.6.15-52-amd64-k8-2.6.15-52.71 (Ubuntu 6.06)<br />
- linux-headers-2<br />
[...]<br />
<br />
<br />
Risk factor : High<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34048</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34047">
<title>SuSE Security Update: wireshark: various vulnerabilities (wireshark-5515)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch wireshark-5515.<br />
<br />
Description :<br />
<br />
Various vulnerabilities have been fixed in wireshark:<br />
CVE-2008-3137, CVE-2008-3138, CVE-2008-3139, CVE-2008-3140,<br />
CVE-2008-3141, CVE-2008-3145 and CVE-2008-3146.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch wireshark-5515.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34047</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34046">
<title>SuSE Security Update: Security update for ethereal (ethereal-5520)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch ethereal-5520.<br />
<br />
Description :<br />
<br />
Various vulnerabilities have been fixed in wireshark:<br />
CVE-2008-3137, CVE-2008-3138, CVE-2008-3139, CVE-2008-3140,<br />
CVE-2008-3141, CVE-2008-3145 and CVE-2008-3146.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch ethereal-5520.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34046</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34045">
<title>FreeBSD : opera -- multiple vulnerabilities (1153)</title>
<description><![CDATA[<br />
The remote host is missing an update to the system<br />
<br />
The following package is affected: linux-opera<br />
<br />
Solution : Update the package on the remote host<br />
See also : <br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34045</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34044">
<title>PowerDNS recursor cache poisoning</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote DNS recursor is vulnerable to cache poisoning.<br />
<br />
Description :<br />
<br />
The remote PowerDNS recursor is vulnerable to a cache poisoning<br />
attack although it uses random source ports for the UDP queries.<br />
Version below 3.1.6 rely upon the random() library function, which is<br />
often implemented as a Linear Feedback Shift Register.<br />
Such generators have good statistical properties and long cycle but<br />
their internal state can be computed from few samples, so an attacker <br />
would thus be able to predict the next values.<br />
<br />
Solution :<br />
<br />
Update to PowerDNS recursor 3.1.6.<br />
<br />
Risk factor :<br />
<br />
High / CVSS Base Score : 9.3 <br />
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34044</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34043">
<title>Version of PowerDNS</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
It is possible to obtain the version number of the remote DNS server.<br />
<br />
Description :<br />
<br />
The remote host is running PowerDNS, an open-source DNS server. It is possible<br />
to extract the version number of the remote installation by sending<br />
a special DNS request for the text 'version.pdns' in the domain 'chaos'.<br />
<br />
Solution :<br />
<br />
It is possible to hide the version number of PowerDNS by setting the <br />
'version-string' option in pdns.conf or recursor.conf<br />
<br />
Risk factor : <br />
<br />
None]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34043</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34042">
<title>SuSE Security Update: rxvt-unicode security update (rxvt-unicode-5541)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch rxvt-unicode-5541.<br />
<br />
Description :<br />
<br />
It was possible to open a terminal on :0 when the<br />
environment variable was not set. This could be exploited<br />
by local users to hijack X11 connections (CVE-2008-1142).<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch rxvt-unicode-5541.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34042</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34041">
<title>SuSE Security Update: Security update for Perl (perl-5444)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch perl-5444.<br />
<br />
Description :<br />
<br />
Specially crafted regular expressions could crash perl<br />
(CVE-2008-1927).<br />
<br />
Additionally problem in the CGI module was fixed that could<br />
result in an endless loop if uploads were cancelled.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch perl-5444.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34041</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34040">
<title>SuSE Security Update: perl security update (perl-5443)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch perl-5443.<br />
<br />
Description :<br />
<br />
Specially crafted regular expressions could crash perl<br />
(CVE-2008-1927).<br />
<br />
Additionally problem in the CGI module was fixed that could<br />
result in an endless loop if uploads were cancelled.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch perl-5443.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34040</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34039">
<title>SuSE Security Update: opera: version upgrade to 9.52 (opera-5537)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch opera-5537.<br />
<br />
Description :<br />
<br />
This is a version upgrade for opera to version 9.52 to fix<br />
possible security vulnerabilities.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch opera-5537.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34039</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34038">
<title>SuSE Security Update: java-1_6_0-sun: Security update to 1.6.0 update 7 (java-1_6_0-sun-5435)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch java-1_6_0-sun-5435.<br />
<br />
Description :<br />
<br />
This update brings the SUN JDK 6 to update level 7.<br />
<br />
CVE-2008-3115: Secure Static Versioning in Sun Java JDK and<br />
JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15,<br />
does not properly prevent execution of applets on older JRE<br />
releases, which might allow remote attackers to exploit<br />
vulnerabilities in these older releases.<br />
<br />
CVE-2008-3114: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allows context-dependent attackers to obtain sensitive<br />
information (the cache location) via an untrusted<br />
application, aka CR 6704074. <br />
<br />
CVE-2008-3112: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allows remote attackers to create arbitrary files via an<br />
untrusted application, aka CR 6703909. <br />
<br />
CVE-2008-3111: Multiple buffer overflows in Sun Java Web<br />
Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allow context-dependent attackers to gain privileges via an<br />
untrusted application, as demonstrated by an application<br />
that grants itself privileges to (1) read local files, (2)<br />
write to local files, or (3) execute local programs, aka CR<br />
6557220.<br />
<br />
CVE-2008-3110:  Unspecified vulnerability in scripting<br />
language support in Sun Java Runtime Environment (JRE) in<br />
JDK and JRE 6 Update 6 and earlier allows remote attackers<br />
to obtain sensitive information by using an applet to read<br />
information from another applet. <br />
<br />
CVE-2008-3109:  Unspecified vulnerability in scripting<br />
language support in Sun Java Runtime Environment (JRE) in<br />
JDK and JRE 6 Update 6 and earlier allows context-dependent<br />
attackers to gain privileges via an untrusted (1)<br />
application or (2) applet, as demonstrated by an<br />
application or applet that grants itself privileges to (a)<br />
read local files, (b) write to local files, or (c) execute<br />
local programs. <br />
<br />
CVE-2008-3107: Unspecified vulnerability in the Virtual<br />
Machine in Sun Java Runtime Environment (JRE) in JDK and<br />
JRE 6 before Update 7, JDK and JRE 5.0 before Update 16,<br />
and SDK and JRE 1.4.x before 1.4.2_18 allows<br />
context-dependent attackers to gain privileges via an<br />
untrusted (1) application or (2) applet, as demonstrated by<br />
an application or applet that grants itself privileges to<br />
(a) read local files, (b) write to local files, or (c)<br />
execute local programs.<br />
<br />
CVE-2008-3106: Unspecified vulnerability in Sun Java<br />
Runtime Environment (JRE) in JDK and JRE 6 Update 6 and<br />
earlier and JDK and JRE 5.0 Update 15 and earlier allows<br />
remote attackers to access URLs via unknown vectors<br />
involving processing of XML data by an untrusted (1)<br />
application or (2) applet, a different vulnerability than<br />
CVE-2008-3105. <br />
<br />
CVE-2008-3105: Unspecified vulnerability in the JAX-WS<br />
client and service in Sun Java Runtime Environment (JRE) in<br />
JDK and JRE 6 Update 6 and earlier allows remote attackers<br />
to access URLs or cause a denial of service via unknown<br />
vectors involving 'processing of XML data' by a trusted<br />
application. <br />
<br />
CVE-2008-3104: Multiple unspecified vulnerabilities in Sun<br />
Java Runtime Environment (JRE) in JDK and JRE 6 before<br />
Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE<br />
1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before<br />
1.3.1_23 allow remote attackers to violate the security<br />
model for an applet's outbound connections by connecting to<br />
localhost services running on the machine that loaded the<br />
applet. <br />
<br />
CVE-2008-3103: Unspecified vulnerability in the Java<br />
Management Extensions (JMX) management agent in Sun Java<br />
Runtime Environment (JRE) in JDK and JRE 6 Update 6 and<br />
earlier and JDK and JRE 5.0 Update 15 and earlier, when<br />
local monitoring is enabled, allows remote attackers to<br />
'perform unauthorized operations' via unspecified vectors.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch java-1_6_0-sun-5435.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34038</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34037">
<title>SuSE Security Update: java-1_5_0-sun: Security update to 1.5.0 update 16 (java-1_5_0-sun-5434)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch java-1_5_0-sun-5434.<br />
<br />
Description :<br />
<br />
Sun Java was updated to 1.5.0u16 to fix following security<br />
vulnerabilities:<br />
<br />
CVE-2008-3115: Secure Static Versioning in Sun Java JDK and<br />
JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15,<br />
does not properly prevent execution of applets on older JRE<br />
releases, which might allow remote attackers to exploit<br />
vulnerabilities in these older releases.<br />
<br />
CVE-2008-3114: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allows context-dependent attackers to obtain sensitive<br />
information (the cache location) via an untrusted<br />
application, aka CR 6704074. <br />
<br />
CVE-2008-3113: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 5.0 before Update 16 and SDK and JRE<br />
1.4.x before 1.4.2_18 allows remote attackers to create or<br />
delete arbitrary files via an untrusted application, aka CR<br />
6704077. <br />
<br />
CVE-2008-3112: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allows remote attackers to create arbitrary files via an<br />
untrusted application, aka CR 6703909. <br />
<br />
CVE-2008-3111: Multiple buffer overflows in Sun Java Web<br />
Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allow context-dependent attackers to gain privileges via an<br />
untrusted application, as demonstrated by an application<br />
that grants itself privileges to (1) read local files, (2)<br />
write to local files, or (3) execute local programs, aka CR<br />
6557220.<br />
<br />
CVE-2008-3108:  Buffer overflow in Sun Java Runtime<br />
Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK<br />
and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before<br />
1.3.1_23 allows context-dependent attackers to gain<br />
privileges via unspecified vectors related to font<br />
processing. <br />
<br />
CVE-2008-3107: Unspecified vulnerability in the Virtual<br />
Machine in Sun Java Runtime Environment (JRE) in JDK and<br />
JRE 6 before Update 7, JDK and JRE 5.0 before Update 16,<br />
and SDK and JRE 1.4.x before 1.4.2_18 allows<br />
context-dependent attackers to gain privileges via an<br />
untrusted (1) application or (2) applet, as demonstrated by<br />
an application or applet that grants itself privileges to<br />
(a) read local files, (b) write to local files, or (c)<br />
execute local programs.<br />
<br />
CVE-2008-3106: Unspecified vulnerability in Sun Java<br />
Runtime Environment (JRE) in JDK and JRE 6 Update 6 and<br />
earlier and JDK and JRE 5.0 Update 15 and earlier allows<br />
remote attackers to access URLs via unknown vectors<br />
involving processing of XML data by an untrusted (1)<br />
application or (2) applet, a different vulnerability than<br />
CVE-2008-3105. <br />
<br />
CVE-2008-3104: Multiple unspecified vulnerabilities in Sun<br />
Java Runtime Environment (JRE) in JDK and JRE 6 before<br />
Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE<br />
1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before<br />
1.3.1_23 allow remote attackers to violate the security<br />
model for an applet's outbound connections by connecting to<br />
localhost services running on the machine that loaded the<br />
applet. <br />
<br />
CVE-2008-3103: Unspecified vulnerability in the Java<br />
Management Extensions (JMX) management agent in Sun Java<br />
Runtime Environment (JRE) in JDK and JRE 6 Update 6 and<br />
earlier and JDK and JRE 5.0 Update 15 and earlier, when<br />
local monitoring is enabled, allows remote attackers to<br />
'perform unauthorized operations' via unspecified vectors.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch java-1_5_0-sun-5434.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34037</link>
<dc:date>?</dc:date>
</item>
<item rdf:about="http://www.nessus.org/plugins/index.php?view=single&amp;id=34036">
<title>SuSE Security Update: Security update for Java 1.4.2 (java-1_4_2-sun-5431)</title>
<description><![CDATA[<br />
Synopsis :<br />
<br />
The remote SuSE system is missing the security patch java-1_4_2-sun-5431.<br />
<br />
Description :<br />
<br />
Sun Java was updated to 1.4.2u18 to fix following security<br />
vulnerabilities:<br />
<br />
CVE-2008-3114: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allows context-dependent attackers to obtain sensitive<br />
information (the cache location) via an untrusted<br />
application, aka CR 6704074. <br />
<br />
CVE-2008-3113: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 5.0 before Update 16 and SDK and JRE<br />
1.4.x before 1.4.2_18 allows remote attackers to create or<br />
delete arbitrary files via an untrusted application, aka CR<br />
6704077. <br />
<br />
CVE-2008-3112: Unspecified vulnerability in Sun Java Web<br />
Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allows remote attackers to create arbitrary files via an<br />
untrusted application, aka CR 6703909. <br />
<br />
CVE-2008-3111: Multiple buffer overflows in Sun Java Web<br />
Start in JDK and JRE 6 before Update 4, JDK and JRE 5.0<br />
before Update 16, and SDK and JRE 1.4.x before 1.4.2_18<br />
allow context-dependent attackers to gain privileges via an<br />
untrusted application, as demonstrated by an application<br />
that grants itself privileges to (1) read local files, (2)<br />
write to local files, or (3) execute local programs, aka CR<br />
6557220.<br />
<br />
CVE-2008-3108:  Buffer overflow in Sun Java Runtime<br />
Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK<br />
and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before<br />
1.3.1_23 allows context-dependent attackers to gain<br />
privileges via unspecified vectors related to font<br />
processing. <br />
<br />
CVE-2008-3107: Unspecified vulnerability in the Virtual<br />
Machine in Sun Java Runtime Environment (JRE) in JDK and<br />
JRE 6 before Update 7, JDK and JRE 5.0 before Update 16,<br />
and SDK and JRE 1.4.x before 1.4.2_18 allows<br />
context-dependent attackers to gain privileges via an<br />
untrusted (1) application or (2) applet, as demonstrated by<br />
an application or applet that grants itself privileges to<br />
(a) read local files, (b) write to local files, or (c)<br />
execute local programs.<br />
<br />
CVE-2008-3104: Multiple unspecified vulnerabilities in Sun<br />
Java Runtime Environment (JRE) in JDK and JRE 6 before<br />
Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE<br />
1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before<br />
1.3.1_23 allow remote attackers to violate the security<br />
model for an applet's outbound connections by connecting to<br />
localhost services running on the machine that loaded the<br />
applet.<br />
<br />
<br />
Solution : <br />
<br />
Install the security patch java-1_4_2-sun-5431.<br />
<br />
Risk factor : <br />
<br />
High]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=34036</link>
<dc:date>?</dc:date>
</item>
</rdf:RDF>
