Skip Navigation

  • Home
  • Contact us
  • FAQ
  • Glossary
  • Public key
  • Sitemap
  • Cymraeg
  • What's new
CPNI - Centre for the Protection of National Infastructure

Advanced search

  • About CPNI
  • The threats
  • Security planning
  • Methods of attack
  • Protecting your assets
  • Products and services
    • CSIRTUK advisories
      • Advisories archive
    • General protective security publications
    • InfoSec briefings
    • InfoSec technical notes
    • InfoSec vulnerability disclosures
    • Good practice guidelines
    • Viewpoints
    • Information exchanges
  • Research
Home > Products and services > CSIRTUK advisories > Advisories archive > July 2007

July 2007

July 2007

- 3299 - SUN Weekly Summary

The Sun(SM) Alert Weekly Summary Report, a newsletter that provides a weekly listing of newly released and updated Sun Alert Notifications

- 3287 - Red Hat Security Advisories

Description of a number of Red Hat Security advisories

- 3286 - Novell Groupwise Mobile Server

This patch is for a security issue found in GMS 1.0. This patch can update either GMS 1.0 and GMS 1.0 DST code.

- 3285 - IBM AIX Advisories

Details of several IBM AIX security advisories

- 3280 - Mandriva Security Advisories

Details of several Mandriva security advisories

- 3279 - Computer Associates Security Advisories

Description of a number of some vulnerabilities in CA products.

- 3276 - SUN(SM) ALERT WEEKLY SUMMARY REPORT - Week of 15-Jul-2007 - 21-Jul-2007

The Sun(SM) Alert Weekly Summary Report, a newsletter that provides a weekly listing of newly released and updated Sun Alert Notifications

- 3275 - OpenPKG Bind Security Advisory

The default access control lists (acls) are not being correctly set, as a result, anyone can make recursive queries and/or query the cache contents. In addition, the DNS query id generation is vulnerable to cryptographic analysis which provides a 1 in 8 chance of guessing the next query id for 50% of the query ids. This can be used to perform cache poisoning by an attacker.

- 3274 - Red Hat Security Advisories

Details of several Red Hat security advisories

- 3273 - Several Debian Security Advisories

Details of several Debian security advisories

- 3272 - Cisco Security Advisory: Denial of Service Vulnerability in Cisco Wide Area Application Services (WAAS) Software

The Cisco Wide Area Application Services (WAAS) software contains a denial of service (DoS) vulnerability that may cause some devices that run WAAS software (WAE appliance and NM-WAE-502 module) to stop processing all types of traffic, including data traffic and management traffic. This condition may occur if a device running WAAS software is configured for Edge Services, which utilizes Common Internet File System (CIFS) optimization and receives a flood of TCP SYN packets on port 139 or 445.

- 3271 - Cisco Security Response: Vulnerability in Java Secure Socket Extension

Some versions of Sun JSSE do not properly handle certain Transport Layer Security (TLS) or Secure Sockets Layer (SSL) handshake requests. A device running an affected JSSE version will experience excessive CPU usage, which may affect normal device operation and result in a denial of service (DoS) condition.

- 3268 - A new mechanism for advisory distribution and security incident reporting to CSIRTUK

This advisory describes the function of CSIRTUK (CPNI Combined Security Incident Response Team), how its community can report security incidents and the new method of distributing security advisories using RSS Feeds.  

- Mozilla Updates for Multiple Vulnerabilities

The Mozilla web browser and derived products contain several vulnerabilities, the most severe of which could allow a remote attacker to execute arbitrary code on an affected system.

- FreeBSD Security Advisory - libarchive

Errors handling corrupt tar files in libarchive

- iDefense Security Advisory concerning Computer Associates Alert Notification Server

Remote exploitation of multiple buffer overflow vulnerabilities in Computer Associates International Inc Threat Manager allows attackers to execute arbitrary code with SYSTEM privileges

- iDefense Security Advisory concerning IBM Tivoli Provisioning Manager

Remote exploitation of a denial of service vulnerability within version 5.1.0.2 of IBM Tivoli Provisioning Manager for OS Deployment allows attackers to deny service to all product functionality

- iDefense Security Advisories concerning Trend Micro OfficeScan

Details of security advisories: Trend Micro OfficeScan Management Console Authorization Bypass Vulnerability Trend Micro OfficeScan Session Cookie Buffer Overflow Vulnerability

- Mandriva Linux Security Advisories

Details of vulnerabilities in hdf5, openoffice, wireshark, perl-Net-DNS and x11-server

- SUN(SM) ALERT WEEKLY SUMMARY REPORT Week of 08-Jul-2007 - 14-Jul-2007

A newsletter that provides you with a weekly listing of newly released and updated Sun Alert Notifications

- Red Hat Security Advisories

Details of Red Hat security vulnerabilities in tomcat and httpd

- Oracle Critical Patch Update - July 2007

Oracle has released a Critical Patch Update for multiple security vulnerabilities and non-security fixes.

- Symantec Security Advisory - AntiVirus Malformed RAR and CAB Compression Type Bypass

Two vulnerabilities have been identified in the Symantec Decomposer component used to decompose some types of archive content while scanning for malicious content.

- iDefense Security Advisories concerning Trend Micro OfficeScan

Computer Associates Alert Notification Server is used by several CA products, including eTrust Integrated Threat Management, to provide notifications to console users.

164 - Red Hat Security Advisories

163 - Adobe Flash Player Updates for Multiple Vulnerabilities

162 - Symantec Security Advisory - SYMTDI.SYS Device Driver Local Elevation of Privilege

161 - Symantec Security Advisory - Backup Exec for Windows Server

160 - Cisco Security Advisories - Unified Communications Manager

159 - Sun Java WebStart JNLP Stack Buffer Overflow Vulnerability

158 - Hewlett Packard Security Bulletin: HP Tru64 UNIX Internet Express running Samba

157 - Microsoft Security Bulletin Summary for July 2007

156 - iDefense Security Advisory: GIMP

155 - iDefense Security Advisory: WinPcap

154 - Mandriva Security Advisories

153 - IBM AIX Security advisories

152 - Microsoft Security Bulletin Advance Notification for July 2007

151 - Several Debian Security Advisories

150 - SUSE Security Announcements

149 - Mandriva Security Advisories

148 - Gentoo Linux Security Advisories

147 - SUN(SM) ALERT WEEKLY SUMMARY REPORT - Week of 24-Jun-2007 - 30-Jun-2007

146 - Several Debian Security Advisories

  • Accessibility |
  • Terms and conditions |
  • Privacy statement |
  • Data protection act |
  • Freedom of information |