<?xml version="1.0"?>
<rss version="2.0" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:yt="http://gdata.youtube.com/schemas/2007">
   <channel>
      <title>cyber security - U.S. CERT</title>
      <description>Security alerts and bulletins (unfiltered) produced by the U.S. Computer Emergency Readiness Team, a government organization. US-CERT feeds aggregated here: 
Technical Cyber Alerts, 
Cyber Security Alerts,
Cyber Security Bulletins,
Recently Published Vulnerability Notes</description>
      <link>http://pipes.yahoo.com/pipes/pipe.info?_id=FJ3awlK33BGj_41qj9zu1g</link>
      <pubDate>Fri, 27 Nov 2009 16:35:57 -0800</pubDate>
      <generator>http://pipes.yahoo.com/pipes/</generator>
      <item>
         <title>VU#515749: Microsoft Internet Explorer CSS style element vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/515749</link>
         <description>2009-11-24T14:09:31-04:00&lt;h1&gt;Vulnerability Note VU#515749&lt;/h1&gt;
&lt;h2&gt;Microsoft Internet Explorer CSS style element vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Microsoft Internet Explorer (IE) does not safely reference CSS style elements. Using a specially crafted HTML page, an attacker can cause IE to crash and potentially execute arbitrary code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;IE contains a vulnerability in the way it references CSS style elements. Processing a specially crafted HTML page could cause IE to access an invalid memory location and crash. Using heap-spraying techniques, an attacker could leverage the crash to execute arbitrary code.
&lt;p&gt;Please see Microsoft Security Advisory (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;977981&lt;/a&gt;).
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message), an attacker could execute arbitrary code with the privileges of the user.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;A complete solution is not available.
&lt;p&gt;&lt;b&gt;Disable Active scripting&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
As noted in Microsoft Security Advisory (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;977981&lt;/a&gt;), consider disabling Active Scripting. Instructions for disabling Active scripting can be found in Microsoft Security Advisory (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;977981&lt;/a&gt; and &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&quot;&gt;Securing Your Web Browser.&quot;&lt;/a&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&quot;&gt;&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Enable DEP&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
As noted in Microsoft Security Advisory (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;977981&lt;/a&gt;), consider enabling Data Execution Prevention (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx&quot;&gt;DEP&lt;/a&gt;).&lt;br&gt;
&lt;br&gt;
Disabling scripting and enabling DEP do not resolve the vulnerability, but they greatly lower the chances of an attacker being able to execute arbitrary code.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Use Internet Explorer 8&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
According to Microsoft Security Advisory (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;977981&lt;/a&gt;), Internet Explorer 8 is not affected.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-23&lt;/td&gt;&lt;td&gt;2009-11-24&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/977981.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/977981.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/507984/30/0/threaded&quot;&gt;http://www.securityfocus.com/archive/1/507984/30/0/threaded&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/connect/blogs/zero-day-internet-explorer-exploit-published&quot;&gt;http://www.symantec.com/connect/blogs/zero-day-internet-explorer-exploit-published&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.computerworld.com/s/article/9141278/New_attack_fells_Internet_Explorer&quot;&gt;http://www.computerworld.com/s/article/9141278/New_attack_fells_Internet_Explorer&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/bugtraq/2009/Nov/148&quot;&gt;http://seclists.org/bugtraq/2009/Nov/148&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx&quot;&gt;http://blogs.msdn.com/ie/archive/2008/04/08/ie8-security-part-I_3A00_-dep-nx-memory-protection.aspx&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was publicly disclosed by info@securitylab.ir and/or K4mr4n_st@yahoo.com.
&lt;p&gt;This document was written by Art Manion. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-11-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-11-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-11-27&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3672&quot;&gt;CVE-2009-3672&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3672&quot;&gt;CVE-2009-3672&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;29.25&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;15&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/515749</guid>
         <pubDate>Tue, 24 Nov 2009 06:09:31 -0800</pubDate>
      </item>
      <item>
         <title>VU#723308: TCP may keep its offered receive window closed indefinitely (RFC 1122)</title>
         <link>http://www.kb.cert.org/vuls/id/723308</link>
         <description>&lt;h1&gt;Vulnerability Note VU#723308&lt;/h1&gt;
&lt;h2&gt;TCP may keep its offered receive window closed indefinitely (RFC 1122)&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Part of the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc1122#page-92&quot;&gt;&lt;/a&gt;Transmission Control Protocol (TCP) specification (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc1122#page-92&quot;&gt;RFC 1122&lt;/a&gt;) allows a receiver to advertise a zero byte window, instructing the sender to maintain the connection but not send additional TCP payload data. The sender should then probe the receiver to check if the receiver is ready to accept data. Narrow interpretation of this part of the specification can create a denial-of-service vulnerability. By advertising a zero receive window and acknowledging probes, a malicious receiver can cause a sender to consume resources (TCP state, buffers, and application memory), preventing the targeted service or system from handling legitimate connections.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;TCP implementations from multiple vendors are vulnerable to malicious or misbehaving connections that indefinitely advertize a zero receive window. &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc1122#page-92&quot;&gt;RFC 1122&lt;/a&gt; section 4.2.2.17 states that &quot;A TCP MAY keep its offered receive window closed indefinitely. As long as the receiving TCP continues to send acknowledgments in response to the probe segments, the sending TCP MUST allow the connection to stay open.&quot; The TCP connection is open however no data is being transmitted. This &quot;stalled&quot; state is generally referred to as the TCP persist condition.
&lt;p&gt;The intent of RFC 1122 section 4.2.2.17 is that TCP must not terminate connections in the persist condition &lt;i&gt;under normal operating conditions&lt;/i&gt;. It is possible to interpret the language narrowly to mean that TCP must not terminate connections in the persist condition &lt;i&gt;under any circumstances&lt;/i&gt;, and this interpretation is likely to cause denial-of-services vulnerabilities. An attacker can asymmetrically consume server resources by making TCP connections, optionally requesting data, then setting the receive window to zero and repeatedly acknowledging window probes from the server.&lt;br&gt;
&lt;br&gt;
General consensus of the IETF TCP Maintenance and Minor Extensions (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/dyn/wg/charter/tcpm-charter.html&quot;&gt;TCPM&lt;/a&gt;) working group is that an operating system or application can abort TCP connections for any reason, including resource exhaustion. TCP itself cannot reliably decide to abort connections, and doing so would violate protocol standards, however there is no guidance against an operating system or application from aborting connections to recover memory resources.&lt;br&gt;
&lt;br&gt;
This vulnerability, one specific attack (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/draft-ananth-tcpm-persist-01#section-3&quot;&gt;section 3&lt;/a&gt;), and a proposed defense (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/draft-ananth-tcpm-persist-01#section-7&quot;&gt;section 7&lt;/a&gt;) are further described in the individual IETF Internet-Draft &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/draft-ananth-tcpm-persist-01&quot;&gt;Clarification of sender behaviour in persist condition.&lt;/a&gt;&quot; A more comprehensive review of TCP state vulnerabilities is presented in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf&quot;&gt;CPNI Technical Note 3/2009: Security Assessment of the Transmission Control Protocol (TCP)&lt;/a&gt;. The CPNI document describes the persist condition in section 3.7.2 and suggests countermeasures in section 7.1.2.&lt;br&gt;
&lt;br&gt;
Persist condition attacks are implemented in the sockstress and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.phrack.org/issues.html?issue=66&amp;amp;id=9&quot;&gt;Nkiller2&lt;/a&gt; tools. Typically, these tools leverage a lightweight userland connection framework to generate many attacking connections without the overhead of full TCP state. There are different variants of attacks that exploit the persist condition, and some attack tools exploit other timers and states in TCP. Please see the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html&quot;&gt;CERT-FI Advisory on the Outpost24 TCP Issues&lt;/a&gt; for further information about sockstress including vendor responses.&lt;br&gt;
&lt;br&gt;
The security aspects of the TCP persist condition has been discussed on the TCPM working group mailing list since at least &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tcpm/current/msg02189.html&quot;&gt;2006&lt;/a&gt;.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote, unauthenticated attacker can cause a denial of service. The attacker may be able to cause the operating system or network application to be unresponsive for the duration of the attack.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;Modifications can be made to TCP implementations, interfaces, operating systems, and network applications, however any changes should consider the balance between improved resiliency and decreased interoperability. The IETF TCPM is considering the problem and any potential changes to TCP or guidance to implementors. As of the publication of this vulnerability note, the IETF has not yet decided whether additional clarifications of the TCP specifications are necessary. Some vendors have implemented changes to improve resiliency against zero window and other TCP state attacks.
&lt;p&gt;Consider the analysis and advice provided in the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf&quot;&gt;CPNI assessment&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Abort misbehaving TCP connections under resource exhaustion conditions&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The consensus of the TCPM discussion seems to be that an operating system or application that faces resource exhaustion can selectively abort TCP connections that appear to be malicious (i.e., in persist condition and consuming relatively large amounts of memory). TCP must implement the persist behavior in RFC 1122, but a higher protocol layer can decide to abort a connection for any reason, including resource exhaustion. How and when to abort connections are open questions, and beyond the scope of the TCP protocol specification.&lt;br&gt;
&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/draft-ananth-tcpm-persist-01#section-7&quot;&gt;Section 7&lt;/a&gt; of the &quot;Clarification...&quot; I-D describes an approach in which an application can limit how long the underlying TCP socket should tolerate connections in the persist condition. However, section 7.1.2 of the CPNI assessment warns that &quot;...an attacker could simply open the window (i.e., advertise a TCP window larger than zero) from time to time to prevent this enforced limit from causing his malicious connections to be aborted.&quot;&lt;br&gt;
&lt;br&gt;
A system that aborts TCP connections too aggressively is likely to drop legitimate connections. Carefully consider the likelihood of attack, the cost of dropping legitimate connections, and the benefit of dropping malicious connections before making design or configuration changes to TCP components of operating systems and applications. It is unlikely that one setting will work well for every TCP system.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Restrict Access&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Restricting access or limiting connections to TCP services using firewalls can mitigate zero window attacks, at the cost of potentially blocking legitimate connections.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt;
&lt;br&gt;
Generally, any system or product that implements or uses TCP could be affected by this vulnerability, depending on how the product handles resource exhaustion and TCP connections in persist. By design, TCP does not inherently defend against denial-of-service attacks based on resource exhaustion. Decisions about how to detect and respond to such attacks are the responsibility of individual systems or products.&lt;br&gt;
&lt;br&gt;
Please see the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html&quot;&gt;CERT-FI Advisory on the Outpost24 TCP Issues&lt;/a&gt; for further vendor information.&lt;br&gt;&lt;br&gt;
&lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;3com, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ACCESS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Alcatel-Lucent&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;AT&amp;T&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Avaya, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Barracuda Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Belkin, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Borderware Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Charlotte's Web Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Check Point Software Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cisco Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-11-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Clavister&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates eTrust Security Management&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;D-Link Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Enterasys Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ericsson&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;eSoft, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Extreme Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-10-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Force10 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fortinet, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Foundry Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Global Technology Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-11-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation (zseries)&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-23&lt;/td&gt;&lt;td&gt;2009-11-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infoblox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intel Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Security Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intoto&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Filter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Infusion, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-10-14&lt;/td&gt;&lt;td&gt;2009-10-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Linux Kernel Archives&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-11-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Luminous Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;m0n0wall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;McAfee&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-11-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Multitech, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetApp&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-10-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;netfilter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nortel Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OpenBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;PePLink&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Process Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Q1 Labs&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX, Software Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Quagga&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;RadWare, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Redback Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Secureworx, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SmoothWall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Snort&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Soapstone Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sourcefire&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Stonesoft&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Symantec&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;TippingPoint, Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;U4EA Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;VMware&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-10-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Vyatta&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Watchguard Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc1122#page-92&quot;&gt;http://tools.ietf.org/html/rfc1122#page-92&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/draft-ananth-tcpm-persist-01&quot;&gt;http://tools.ietf.org/html/draft-ananth-tcpm-persist-01&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/draft-mahesh-persist-timeout-02&quot;&gt;http://tools.ietf.org/html/draft-mahesh-persist-timeout-02&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf&quot;&gt;http://www.cpni.gov.uk/Docs/tn-03-09-security-assessment-TCP.pdf&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html&quot;&gt;https://www.cert.fi/haavoittuvuudet/2008/tcp-vulnerabilities.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://shlang.com/netkill/&quot;&gt;http://shlang.com/netkill/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.phrack.org/issues.html?issue=66&amp;id=9#article&quot;&gt;http://www.phrack.org/issues.html?issue=66&amp;amp;id=9#article&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://isc.sans.org/diary.html?storyid=5104&quot;&gt;http://isc.sans.org/diary.html?storyid=5104&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.t2.fi/2008/08/27/jack-c-louis-and-robert-e-lee-to-talk-about-new-dos-attack-vectors/&quot;&gt;http://www.t2.fi/2008/08/27/jack-c-louis-and-robert-e-lee-to-talk-about-new-dos-attack-vectors/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.darkreading.com/blog.asp?blog_sectionid=403&amp;doc_id=164939&amp;WT.svl=tease2_2&quot;&gt;http://www.darkreading.com/blog.asp?blog_sectionid=403&amp;amp;doc_id=164939&amp;amp;WT.svl=tease2_2&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tcpm/current/msg04040.html&quot;&gt;http://www.ietf.org/mail-archive/web/tcpm/current/msg04040.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tcpm/current/msg03826.html&quot;&gt;http://www.ietf.org/mail-archive/web/tcpm/current/msg03826.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tcpm/current/msg03503.html&quot;&gt;http://www.ietf.org/mail-archive/web/tcpm/current/msg03503.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tcpm/current/msg02870.html&quot;&gt;http://www.ietf.org/mail-archive/web/tcpm/current/msg02870.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tcpm/current/msg02557.html&quot;&gt;http://www.ietf.org/mail-archive/web/tcpm/current/msg02557.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tcpm/current/msg02189.html&quot;&gt;http://www.ietf.org/mail-archive/web/tcpm/current/msg02189.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git;a=blob;f=net/ipv4/tcp_timer.c;h=b144a26359bcf34a4b0606e171f97dc709afdfbb;hb=120f68c426e746771e8c09736c0f753822ff3f52#l233&quot;&gt;http://git.kernel.org/?p=linux/kernel/git/stable/linux-2.6.31.y.git;a=blob;f=net/ipv4/tcp_timer.c;h=b144a26359bcf34a4b0606e171f97dc709afdfbb;hb=120f68c426e746771e8c09736c0f753822ff3f52#l233&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://sla.ckers.org/forum/read.php?14,27324&quot;&gt;http://sla.ckers.org/forum/read.php?14,27324&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.checkpoint.com/defense/advisories/public/announcement/090809-tcpip-dos-sockstress.html&quot;&gt;http://www.checkpoint.com/defense/advisories/public/announcement/090809-tcpip-dos-sockstress.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/archive/1/archive/1/506331/100/0/&quot;&gt;http://www.securityfocus.com/archive/1/archive/1/506331/100/0/&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Mahesh Jethanandani and CERT-FI for their efforts researching and coordinating vendor responses to this vulnerability. Thanks also to Barry Greene, Lars Eggert, Wesley Eddy, and David Borman for their review and comments.
&lt;p&gt;This document was written by David Warren and Art Manion. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2006-07-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-11-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-11-25&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1926&quot;&gt;CVE-2009-1926&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4609&quot;&gt;CVE-2008-4609&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1926&quot;&gt;CVE-2009-1926&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-4609&quot;&gt;CVE-2008-4609&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;15.59&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;116&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/723308</guid>
         <pubDate>Mon, 23 Nov 2009 07:43:31 -0800</pubDate>
      </item>
      <item>
         <title>VU#632633: Wyse Simple Imager (WSI) includes vulnerable versions of TFTPD32</title>
         <link>http://www.kb.cert.org/vuls/id/632633</link>
         <description>2009-11-19T15:07:10-04:00&lt;h1&gt;Vulnerability Note VU#632633&lt;/h1&gt;
&lt;h2&gt;Wyse Simple Imager (WSI) includes vulnerable versions of TFTPD32&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Wyse Simple Imager (WSI) includes older versions version of TFTPD32 that contains publicly known vulnerabilities. An attacker could exploit these vulnerabilities to potentially execute arbitrary code on the system running WSI and TFTPD32.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Wyse Simple Imager (WSI) is a component of Wyse Device Manager (WDM, formerly known as Wyse Rapport). WSI includes TFTPD32 as the TFTP service to load firmware images on client devices. The versions of TFTPD32 contains several known vulnerabilities. The following list of TFTPD32 vulnerabilities is based on public information:
&lt;ol type=&quot;1&quot;&gt;
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-2226&quot;&gt;CVE-2002-2226&lt;/a&gt; Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filename argument.
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-2237&quot;&gt;CVE-2002-2237&lt;/a&gt; tftp32 TFTP server 2.21 and earlier allows remote attackers to cause a denial of service via a GET request with a DOS device name such as &lt;tt&gt;com1&lt;/tt&gt; or &lt;tt&gt;aux&lt;/tt&gt;.
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-2353&quot;&gt;CVE-2002-2353&lt;/a&gt; tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-0328&quot;&gt;CVE-2006-0328&lt;/a&gt; Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.
&lt;li&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6141&quot;&gt;CVE-2006-6141&lt;/a&gt; Buffer overflow in Tftpd32 3.01 allows remote attackers to cause a denial of service via a long GET or PUT request, which is not properly handled when the request is displayed in the title of the gauge window.
&lt;li&gt;OSVDB ID: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://osvdb.org/show/osvdb/12898&quot;&gt;12898&lt;/a&gt; Tftpd32 contains a flaw that may allow a remote denial of service. The issue is triggered when the server receives a TFTP request with a long filename, and will result in loss of availability for the service.&lt;/ol&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;An attacker with network access to TFTPD32 could execute arbitrary code or cause a denial of service on a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Use Wyse WDM and USB Imaging Tool&lt;/b&gt;
&lt;p&gt;&lt;br&gt;
According to Wyse, WSI 1.3.x is a legacy product and its functionality is included in Wyse WDM 4.7.2 and Wyse USB Imaging Tool. Customers are strongly advised to migrate to WDM and USB Imaging Tool. Customers who are unable to migrate promptly, can refer to Wyse Knowledge Base article 18555 for remedial action. Wyse Knowledge Base is accessible through &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://suppport.wyse.com/&quot;&gt;http://suppport.wyse.com/&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Upgrade TFTPD32&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Upgrade TFTPD32 by &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tftpd32.jounin.net/tftpd32_download.html&quot;&gt;downloading&lt;/a&gt; the latest version.&lt;br&gt;
&lt;br&gt;
WSI 1.3.6 provides TFTPD32 version 2.0 in the directory &lt;tt&gt;ftproot&amp;#92;Rapport&amp;#92;Tools&amp;#92;saTil&amp;#92;&lt;/tt&gt; and TFTPD32 version 2.80 in &lt;tt&gt;ftproot&amp;#92;Rapport&amp;#92;Tools&amp;#92;saTil&amp;#92;TFTPD280&amp;#92;&lt;/tt&gt;. Consider using TFTPD32 version 2.80 or downloading the most current version of TFTPD32.&lt;br&gt;
&lt;br&gt;
This table is based on public information, a brief exchange with the author of TFTPD32, and limited testing. This information may not be completely accurate, please send corrections to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;mailto:cert@cert.org&amp;amp;subject=VU%23632633%20Feedback&quot;&gt;cert@cert.org&lt;/a&gt;.&lt;br&gt;
&lt;div align=&quot;center&quot;&gt;&lt;br&gt; &lt;table border=&quot;1&quot;&gt;
&lt;tr valign=&quot;top&quot;&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;&lt;b&gt;Vulnerability&lt;/b&gt;&lt;/td&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;&lt;b&gt;Fixed Version&lt;/b&gt;&lt;/td&gt;&lt;td width=&quot;384&quot; valign=&quot;middle&quot;&gt;&lt;b&gt;Wyse Resolution&lt;/b&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr valign=&quot;top&quot;&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-2226&quot;&gt;CVE-2002-2226&lt;/a&gt;&lt;/td&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;2.50.2&lt;/td&gt;&lt;td width=&quot;384&quot; valign=&quot;middle&quot;&gt;Addressed by WSB09-01 (using TFTPD32 version 2.80).&lt;/td&gt;&lt;/tr&gt; &lt;tr valign=&quot;top&quot;&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-2237&quot;&gt;CVE-2002-2237&lt;/a&gt;&lt;/td&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;2.51&lt;/td&gt;&lt;td width=&quot;384&quot; valign=&quot;middle&quot;&gt;Addressed by WSB09-01 (using TFTPD32 version 2.80).&lt;/td&gt;&lt;/tr&gt; &lt;tr valign=&quot;top&quot;&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;&lt;font color=&quot;#0000FF&quot;&gt;CVE-2002-2353&lt;/font&gt;&lt;/td&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;2.51&lt;/td&gt;&lt;td width=&quot;384&quot; valign=&quot;middle&quot;&gt;Addressed by WSB09-01 (using TFTPD32 version 2.80).&lt;/td&gt;&lt;/tr&gt; &lt;tr valign=&quot;top&quot;&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=2006-0328&quot;&gt;CVE-2006-0328&lt;/a&gt;&lt;/td&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;2.8.2&lt;/td&gt;&lt;td width=&quot;384&quot; valign=&quot;middle&quot;&gt;?&lt;/td&gt;&lt;/tr&gt; &lt;tr valign=&quot;top&quot;&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6141&quot;&gt;CVE-2006-6141&lt;/a&gt;&lt;/td&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;3.10b&lt;/td&gt;&lt;td width=&quot;384&quot; valign=&quot;middle&quot;&gt;?&lt;/td&gt;&lt;/tr&gt; &lt;tr valign=&quot;top&quot;&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;OSVDB ID: &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://osvdb.org/show/osvdb/12898&quot;&gt;12898&lt;/a&gt;&lt;/td&gt;&lt;td width=&quot;192&quot; valign=&quot;middle&quot;&gt;2.80&lt;/td&gt;&lt;td width=&quot;384&quot; valign=&quot;middle&quot;&gt;Addressed by WSB09-01 (using TFTPD32 version 2.80).&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;
&lt;/div&gt;&lt;br&gt;
&lt;b&gt;Restrict Access to WSI&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
To limit the exposure of TFTPD32, run WSI systems on a physically isolated network, such as a staging network where client devices are imaged before production deployment..
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;TFTPD32&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wyse&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-04&lt;/td&gt;&lt;td&gt;2009-11-19&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tftpd32.jounin.net/tftpd32_news.html&quot;&gt;http://tftpd32.jounin.net/tftpd32_news.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tftpd32.jounin.net/tftpd32.html&quot;&gt;http://tftpd32.jounin.net/tftpd32.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://osvdb.org/show/osvdb/12898&quot;&gt;http://osvdb.org/show/osvdb/12898&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://secway.org/advisory/ad20050108.txt&quot;&gt;http://secway.org/advisory/ad20050108.txt&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wyse.com/serviceandsupport/support/WSB09-01.zip&quot;&gt;http://www.wyse.com/serviceandsupport/support/WSB09-01.zip&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf&quot;&gt;http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/&quot;&gt;http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html&quot;&gt;http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;These vulnerabilities were analyzed and reported by Kevin Finisterre of Netragard/SNOsoft and Art Manion.
&lt;p&gt;This document was written by Art Manion. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-11-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-11-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2226&quot;&gt;CVE-2002-2226&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2237&quot;&gt;CVE-2002-2237&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-2353&quot;&gt;CVE-2002-2353&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0328&quot;&gt;CVE-2006-0328&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-6141&quot;&gt;CVE-2003-6141&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-2226&quot;&gt;CVE-2002-2226&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-2237&quot;&gt;CVE-2002-2237&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-2353&quot;&gt;CVE-2002-2353&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-0328&quot;&gt;CVE-2006-0328&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2003-6141&quot;&gt;CVE-2003-6141&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;13.51&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;54&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/632633</guid>
         <pubDate>Thu, 19 Nov 2009 07:07:10 -0800</pubDate>
      </item>
      <item>
         <title>VU#120541: SSL and TLS protocols renegotiation vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/120541</link>
         <description>2009-11-11T10:31:10-04:00&lt;h1&gt;Vulnerability Note VU#120541&lt;/h1&gt;
&lt;h2&gt;SSL and TLS protocols renegotiation vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;A vulnerability exists in SSL and TLS protocols that may allow attackers to execute an arbitrary HTTP transaction.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols are commonly used to provide authentication, encryption, integrity, and non-repudiation services to network applications such as HTTP, IMAP, POP3, LDAP. A vulnerability in the way SSL and TLS protocols allow renegotiation requests may allow an attacker to inject plaintext into an application protocol stream. This could result in a situation where the attacker may be able to issue commands to the server that appear to be coming from a legitimate source. According to the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&quot;&gt;Network Working Group&lt;/a&gt;:
&lt;p&gt;&lt;i&gt;The server treats the client's initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data.&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
This issue affects SSL version 3.0 and newer and TLS version 1.0 and newer.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote, unauthenticated attacker may be able to inject an arbitrary amount of chosen plaintext into the beginning of the application protocol stream. This could allow and attacker to issue HTTP requests, or take action impersonating the user, among other consequences&lt;font size=&quot;4&quot;&gt;.&lt;/font&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;Users should contact vendors for specific patch information.
&lt;p&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;3com Inc&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ACCESS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Alcatel-Lucent&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apache-SSL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apache HTTP Server Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Aruba Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Attachmate&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;AT&amp;T&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Avaya, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Barracuda Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Belkin, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Borderware Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Certicom&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Charlotte's Web Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Check Point Software Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cisco Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Clavister&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cryptlib&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Crypto++ Library&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;D-Link Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Enterasys Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ericsson&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;eSoft, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Extreme Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Force10 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fortinet, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Foundry Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Global Technology Associates, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;GnuTLS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infoblox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intel Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Security Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intoto&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Filter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Infusion, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;libgcrypt&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Lotus Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Luminous Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;m0n0wall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;McAfee&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Internet Explorer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mirapoint, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;mod_ssl&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mozilla - Network Security Services&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Multitech, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;National Center for Supercomputing Applications&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetApp&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;netfilter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Netscape NSS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nortel Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OpenBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OpenSSL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;PePLink&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Process Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Q1 Labs&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX Software Systems Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Quagga&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;RadWare, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Redback Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Secureworx, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SmoothWall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Snort&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Soapstone Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sourcefire&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Spyrus&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Stonesoft&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Stunnel&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Symantec&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;TippingPoint Technologies Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;VMware&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Vyatta&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Watchguard Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://extendedsubset.com/?p=8&quot;&gt;http://extendedsubset.com/?p=8&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.links.org/?p=780&quot;&gt;http://www.links.org/?p=780&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.links.org/?p=786&quot;&gt;http://www.links.org/?p=786&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.links.org/?p=789&quot;&gt;http://www.links.org/?p=789&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.iss.net/archive/sslmitmiscsrf.html&quot;&gt;http://blogs.iss.net/archive/sslmitmiscsrf.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ietf.org/mail-archive/web/tls/current/msg03948.html&quot;&gt;http://www.ietf.org/mail-archive/web/tls/current/msg03948.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.redhat.com/show_bug.cgi?id=533125&quot;&gt;https://bugzilla.redhat.com/show_bug.cgi?id=533125&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00014.html&quot;&gt;http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00014.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cvs.openssl.org/chngview?cn=18790&quot;&gt;http://cvs.openssl.org/chngview?cn=18790&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.links.org/files/no-renegotiation-2.patch&quot;&gt;http://www.links.org/files/no-renegotiation-2.patch&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.zoller.lu/2009/11/new-sslv3-tls-vulnerability-mitm.html&quot;&gt;http://blog.zoller.lu/2009/11/new-sslv3-tls-vulnerability-mitm.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&quot;&gt;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html&quot;&gt;http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Marsh Ray of PhoneFactor for reporting this vulnerability. This issue was also independently discovered and publicly disclosed by Martin Rex of SAP.
&lt;p&gt;This document was written by Chris Taschner. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-11-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-11-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-11-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555&quot;&gt;CVE-2009-3555&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3555&quot;&gt;CVE-2009-3555&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;0.00&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;31&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/120541</guid>
         <pubDate>Wed, 11 Nov 2009 02:31:10 -0800</pubDate>
      </item>
      <item>
         <title>VU#257117: Adobe Acrobat and Reader contain vulnerabilities in multiple Document Object JavaScript methods</title>
         <link>http://www.kb.cert.org/vuls/id/257117</link>
         <description>2009-10-13T15:10:22-04:00&lt;h1&gt;Vulnerability Note VU#257117&lt;/h1&gt;
&lt;h2&gt;Adobe Acrobat and Reader contain vulnerabilities in multiple Document Object JavaScript methods&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;A vulnerability in the way Adobe Acrobat and Reader enforce privileges on JavaScript in PDF files could allow arbitrary files to be written to the local file system of an affected system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Adobe Reader and the Adobe Acrobat family of software are designed to create, view, and edit Portable Document Format (PDF) files. Adobe Reader is widely deployed, and the Acrobat Reader Plug-In displays PDF inside a web browser.
&lt;p&gt;Adobe Reader and Acrobat support JavaScript. According to the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://livedocs.adobe.com/acrobat_sdk/9.1/Acrobat9_1_HTMLHelp/JS_API_AcroJSPreface.87.1.html&quot;&gt;JavaScript for Acrobat API reference&lt;/a&gt;, certain methods are designed to be unavailable or have security restrictions in a non-privileged context. As a result, it should not be possible to call these methods from non-privileged events, such as &lt;i&gt;page open&lt;/i&gt; or &lt;i&gt;mouse-up&lt;/i&gt;.&lt;br&gt;
&lt;br&gt;
Adobe Acrobat and Reader fail to enforce the &lt;i&gt;Privileged Context&lt;/i&gt; and &lt;i&gt;Safe Path&lt;/i&gt; restrictions on certain JavaScript methods. This failure results in a vulnerability that allows methods that accept a &lt;i&gt;cPath&lt;/i&gt; parameter to write to an arbitrary file extension and arbitrary path rather than those intended to be limited by the &lt;i&gt;Safe Path&lt;/i&gt; restriction.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to open a specially crafted PDF file, an attacker may be able to execute certain privileged JavaScript methods that can be used to create arbitrary files and folders on an affected system, subject to the normal permissions of the victim user.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Update&lt;/b&gt;
&lt;p&gt;Adobe has released updates to address this issue. Users are encouraged to read Adobe Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-15.html&quot;&gt;APSB09-15&lt;/a&gt; and update vulnerable versions of Adobe Reader and Acrobat.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Enable Data Execution Prevention (DEP) in Microsoft Windows&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Consider enabling Data Execution Prevention (DEP) in supported versions of Windows. DEP should not be treated as a complete workaround, but it can mitigate the execution of attacker-supplied code in some cases. Microsoft has published detailed technical information about DEP in Security Research &amp;amp; Defense blog posts &quot;Understanding DEP as a mitigation technology&quot; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/06/05/understanding-dep-as-a-mitigation-technology-part-1.aspx&quot;&gt;part 1&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx&quot;&gt;part 2&lt;/a&gt;. Use of DEP should be considered in conjunction with the application of patches or other mitigations described in this document&lt;b&gt;.&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable JavaScript in Adobe Reader and Acrobat&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling JavaScript prevents these vulnerabilities from being exploited and reduces attack surface. If this workaround is applied to updated versions of Adobe Reader and Acrobat, it may protect against future vulnerabilities.&lt;br&gt;
&lt;br&gt;
To disable JavaScript in Adobe Reader:&lt;br&gt; &lt;ol type=&quot;1&quot;&gt;
&lt;li&gt;Open Adobe Acrobat Reader.
&lt;li&gt;Open the &lt;tt&gt;Edit&lt;/tt&gt; menu.
&lt;li&gt;Choose the &lt;tt&gt;Preferences...&lt;/tt&gt; option.
&lt;li&gt;Choose the &lt;tt&gt;JavaScrip&lt;/tt&gt;&lt;tt&gt;t&lt;/tt&gt; section.
&lt;li&gt;Uncheck the &lt;tt&gt;Enable Acrobat JavaScript&lt;/tt&gt; check box.&lt;/ol&gt;
Disabling JavaScript will not resolve the vulnerabilities, it will only disable the vulnerable JavaScript component. When JavaScript is disabled, Adobe Reader and Acrobat prompt to re-enable JavaScript when opening a PDF that contains JavaScript.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Prevent Internet Explorer from automatically opening PDF documents&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The installer for Adobe Reader and Acrobat configures Internet Explorer to automatically open PDF files without any user interaction. This behavior can be reverted to the safer option of prompting the user by importing the following as a .REG file:&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;Windows Registry Editor Version 5.00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_CLASSES_ROOT&amp;#92;AcroExch.Document.7]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;EditFlags&quot;=hex:00,00,00,00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable the displaying of PDF documents in the web browser&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Preventing PDF documents from opening inside a web browser reduces attack surface. If this workaround is applied to updated versions of Adobe Reader and Acrobat, it may protect against future vulnerabilities.&lt;br&gt;
&lt;br&gt;
To prevent PDF documents from automatically being opened in a web browser with Adobe Reader:&lt;br&gt; &lt;ol type=&quot;1&quot;&gt;
&lt;li&gt;Open Adobe Acrobat Reader.
&lt;li&gt;Open the &lt;tt&gt;Edit&lt;/tt&gt; menu.
&lt;li&gt;Choose the &lt;tt&gt;Preferences...&lt;/tt&gt; option.
&lt;li&gt;Choose the &lt;tt&gt;Internet&lt;/tt&gt; section.
&lt;li&gt;Uncheck the &lt;tt&gt;Display PDF in browser&lt;/tt&gt; check box.&lt;/ol&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Adobe&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-10-13&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-15.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb09-15.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Richard van Eeden of IOActive, for reporting this issue.
&lt;p&gt;This document was written by Chad R Dougherty. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-09-01&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-10-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-10-27&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2993&quot;&gt;CVE-2009-2993&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2993&quot;&gt;CVE-2009-2993&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;0.00&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;15&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/257117</guid>
         <pubDate>Tue, 13 Oct 2009 08:10:22 -0700</pubDate>
      </item>
      <item>
         <title>VU#654545: Wyse Device Manager (WDM) HServer and HAgent contain multiple vulnerabilities</title>
         <link>http://www.kb.cert.org/vuls/id/654545</link>
         <description>2009-10-13T00:20:50-04:00&lt;h1&gt;Vulnerability Note VU#654545&lt;/h1&gt;
&lt;h2&gt;Wyse Device Manager (WDM) HServer and HAgent contain multiple vulnerabilities&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Wyse Device Manager (WDM) Server and HAgent contain several vulnerabilities. An attacker with network access to WDM components could execute arbitrary code on vulnerable systems.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Wyse Device Manager (WDM, formerly known as Wyse Rapport) manages thin clients. Part of the server component (HServer) is implemented as an ISAPI filter on the Microsoft Windows Internet Information Server (IIS) platform. The client component (HAgent) runs as a service on Microsoft Windows systems.
&lt;p&gt;WDM components contain several vulnerabilities:&lt;br&gt; &lt;ol type=&quot;1&quot;&gt;
&lt;li&gt;HServer (&lt;tt&gt;hserver.dll&lt;/tt&gt;) User-Agent header stack buffer overflow and
&lt;li&gt;HAgent (&lt;tt&gt;hagent.exe&lt;/tt&gt;) heap overflow (both overflows are CVE-2009-0693)
&lt;li&gt;HAgent does not authenticate commands (CVE-2009-0695)&lt;/ol&gt;
The first two issues are implementation defects. The third issue is caused by the lack of adequate cryptographic authentication and authorization.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;An attacker with network access to WDM components could execute arbitrary code on a vulnerable system. The attacker could also execute unauthenticated management commands on a system running HAgent.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;Please see Wyse Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf&quot;&gt;WSB09-01&lt;/a&gt;.
&lt;p&gt;&lt;b&gt;Enable HTTPS&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Enabling HTTPS provides authentication between Hserver and HAgent nodes. HTTPS authenticates communication from an HServer host to an HAgent host. Depending on key distribution and PKI architecture, HTTPS should prevent an unauthenticated attacker from running management commands on an HAgent host.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wyse&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-04&lt;/td&gt;&lt;td&gt;2009-07-23&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://osvdb.org/show/osvdb/55808&quot;&gt;http://osvdb.org/show/osvdb/55808&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wyse.com/serviceandsupport/support/WSB09-01.zip&quot;&gt;http://www.wyse.com/serviceandsupport/support/WSB09-01.zip&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf&quot;&gt;http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/&quot;&gt;http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html&quot;&gt;http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;These vulnerabilities were analyzed and reported by Kevin Finisterre of Netragard/SNOsoft.
&lt;p&gt;This document was written by Art Manion. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-10-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-10-16&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0693&quot;&gt;CVE-2009-0693&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0695&quot;&gt;CVE-2009-0695&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0693&quot;&gt;CVE-2009-0693&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0695&quot;&gt;CVE-2009-0695&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;13.51&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;23&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/654545</guid>
         <pubDate>Mon, 12 Oct 2009 17:20:50 -0700</pubDate>
      </item>
      <item>
         <title>VU#676492: Wireshark Endace ERF unsigned integer wrap vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/676492</link>
         <description>2009-10-05T19:16:44-04:00&lt;h1&gt;Vulnerability Note VU#676492&lt;/h1&gt;
&lt;h2&gt;Wireshark Endace ERF unsigned integer wrap vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Wireshark contains an unsigned integer wrap vulnerability that may occur when parsing Endace Extensible Record Format (ERF) files.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Wireshark is a protocol analyzer that can open or import previously saved files. When processing an Endace &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ethereal.com/lists/ethereal-dev/200308/msg00399.html&quot;&gt;ERF&lt;/a&gt; file an unsigned integer wrap vulnerability may cause Wireshark to allocate a very large buffer. To exploit this issue, an attacker would have to convince a user to open a crafted ERF file using Wireshark.
&lt;p&gt;This issue also affects Tshark, the console version of Wireshark.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote attacker can cause Wireshark to crash. It may be possible, although unlikely, for an attacker to execute arbitrary code. Exploiting the vulnerability could result in a NULL pointer dereference, which can lead to code execution on &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.juniper.net/solutions/literature/white_papers/Vector-Rewrite-Attack.pdf&quot;&gt;certain platforms&lt;/a&gt;.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Update&lt;/b&gt;
&lt;p&gt;Wireshark &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wireshark.org/docs/relnotes/wireshark-1.2.2.html&quot;&gt;1.2.2&lt;/a&gt; has been released to address this and other issues.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Do not run Wireshark with root or administrator privileges&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Running Wireshark with a limited user account will reduce the impact of this and other vulnerabilities. &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wireshark&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-10-05&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.wireshark.org/docs/relnotes/wireshark-1.2.2.html&quot;&gt;http://www.wireshark.org/docs/relnotes/wireshark-1.2.2.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://anonsvn.wireshark.org/viewvc/trunk/wiretap/erf.c?view=markup&amp;pathrev=29364&quot;&gt;http://anonsvn.wireshark.org/viewvc/trunk/wiretap/erf.c?view=markup&amp;amp;pathrev=29364&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.securecoding.cert.org/confluence/display/cplusplus/INT30-CPP.+Ensure+that+unsigned+integer+operations+do+not+wrap&quot;&gt;https://www.securecoding.cert.org/confluence/display/cplusplus/INT30-CPP.+Ensure+that+unsigned+integer+operations+do+not+wrap&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://wiki.wireshark.org/Security#head-ac69042aeeb98cdaed2ec2ff1bd2c983fa03cffd&quot;&gt;http://wiki.wireshark.org/Security#head-ac69042aeeb98cdaed2ec2ff1bd2c983fa03cffd&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://xorl.wordpress.com/2009/11/10/cve-2009-3829-wireshark-endace-erf-protocol-integer-underflow/&quot;&gt;http://xorl.wordpress.com/2009/11/10/cve-2009-3829-wireshark-endace-erf-protocol-integer-underflow/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.juniper.net/solutions/literature/white_papers/Vector-Rewrite-Attack.pdf&quot;&gt;http://www.juniper.net/solutions/literature/white_papers/Vector-Rewrite-Attack.pdf&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This issue was discovered by Ryan Giobbi.
&lt;p&gt;This document was written by Ryan Giobbi and Art Manion. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-09-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-10-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-11-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;1.28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;27&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/676492</guid>
         <pubDate>Mon, 05 Oct 2009 12:16:44 -0700</pubDate>
      </item>
      <item>
         <title>VU#180065: Nginx ngx_http_parse_complex_uri() buffer underflow vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/180065</link>
         <description>2009-09-15T14:50:49-04:00&lt;h1&gt;Vulnerability Note VU#180065&lt;/h1&gt;
&lt;h2&gt;Nginx ngx_http_parse_complex_uri() buffer underflow vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;A vulnerability in the nginx web server may allow remote attackers to execute arbitrary code on an affected system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://nginx.net/&quot;&gt;nginx&lt;/a&gt; is an HTTP server and mail proxy server that is available for a number of different platforms. A buffer underflow vulnerability exists in the &lt;tt&gt;ngx_http_parse_complex_uri()&lt;/tt&gt; function when handling specially crafted URIs. Exploitation of this vulnerability would cause the nginx server to write data contained in the URI to heap memory before the allocated buffer.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;As with a number of other web servers, nginx is designed to operate with a single privileged master process and multiple unprivileged worker processes handling specific requests. A remote, unauthenticated attacker may be able to execute arbitrary code in the context of the worker process or cause the worker process to crash, resulting in a denial of service.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Upgrade or apply a patch&lt;/b&gt;
&lt;p&gt;Updated versions of the nginx package have been released to address this issue. Users should consult the Systems Affected section of this document for information about specific vendors.&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infoblox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;nginx&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-09-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OpenBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX Software Systems Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-08&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-08&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;td&gt;2009-09-06&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Chris Ries of the Carnegie Mellon University Information Security Office for reporting this vulnerability.
&lt;p&gt;This document was written by Chad R Dougherty. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-09-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-09-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-09-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2629&quot;&gt;CVE-2009-2629&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2629&quot;&gt;CVE-2009-2629&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;4.22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;8&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/180065</guid>
         <pubDate>Tue, 15 Sep 2009 07:50:49 -0700</pubDate>
      </item>
      <item>
         <title>VU#135940: Windows SMB version 2 vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/135940</link>
         <description>2009-09-10T11:35:30-04:00&lt;h1&gt;Vulnerability Note VU#135940&lt;/h1&gt;
&lt;h2&gt;Windows SMB version 2 vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Microsoft Windows Vista and Server 2008 do not correctly parse SMB version 2 messages.This vulnerability could allow an attacker to execute arbitrary code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The Server Message Block version 2 (SMBv2) protocol is the successor to the original SMB protocol. SMBv2 is available in Windows Vista, Server 2008 and Windows 7 release candidates. &lt;p&gt;Windows Vista and Server 2008 fail to properly process fails to properly parse the headers for the Negotiate Protocol Request portion of an SMBv2 message. &lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;An attacker may be able to execute arbitrary code or cause a vulnerable system to crash.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;There is currently no solution to this problem. Until patches are available, users and administrators are encouraged to review the below workarounds.
&lt;p&gt;&lt;br&gt;
&lt;b&gt;Restrict access&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Blocking access to ports &lt;tt&gt;139/tcp&lt;/tt&gt; and &lt;tt&gt;445/tcp&lt;/tt&gt; on vulnerable systems will mitigate this vulnerability. Administrators can configure mobile systems that use the Windows Firewall to open these ports when only when authenticated to a domain controller by using the firewall's &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technet.microsoft.com/en-us/library/dd734783(WS.10).aspx&quot;&gt;profile&lt;/a&gt;&quot; feature.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable SMBv2&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling SMBv2 will mitigate this issue. The below steps to disable SMBv2 are provided in Microsoft Security Advisory &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/975497.mspx&quot;&gt;975497&lt;/a&gt;.
&lt;ol type=&quot;1&quot;&gt;
&lt;li&gt;Click Start, click Run, type Regedit in the Open box, and then click OK.
&lt;li&gt;Locate and then click the following registry subkey:
&lt;li&gt;HKEY_LOCAL_MACHINE&amp;#92;System&amp;#92;CurrentControlSet&amp;#92;Services
&lt;li&gt;Click LanmanServer.
&lt;li&gt;Click Parameters.
&lt;li&gt;Right-click to add a new DWORD (32 bit) Value.
&lt;li&gt;Enter smb2 in the Name data field, and change the Value data field to 0.
&lt;li&gt;Exit.
&lt;li&gt;From a command prompt and with administrator privileges, type &lt;tt&gt;net stop server&lt;/tt&gt; and then &lt;tt&gt;net start server&lt;/tt&gt;.&lt;/ol&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-09-10&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/975497.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/975497.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://technet.microsoft.com/en-us/library/dd734783(WS.10).aspx&quot;&gt;http://technet.microsoft.com/en-us/library/dd734783(WS.10).aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html&quot;&gt;http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Microsoft and Laurent Gaffié for information that was used in this report.
&lt;p&gt;This document was written by Ryan Giobbi. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-09-07&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-09-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-09-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3103&quot;&gt;CVE-2009-3103&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3103&quot;&gt;CVE-2009-3103&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;62.70&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;14&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/135940</guid>
         <pubDate>Thu, 10 Sep 2009 04:35:30 -0700</pubDate>
      </item>
      <item>
         <title>VU#336053: Cyrus IMAPd buffer overflow vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/336053</link>
         <description>2009-09-09T09:31:30-04:00&lt;h1&gt;Vulnerability Note VU#336053&lt;/h1&gt;
&lt;h2&gt;Cyrus IMAPd buffer overflow vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Cyrus IMAP server contains a vulnerability that may allow an authenticated attacker to execute code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The Cyrus IMAP mail server supports the SIEVE mail filtering language. Cyrus IMAP versions 2.2 through 2.3.14 contain a buffer overflow vulnerability that may be triggered by a specially crafted SIEVE script. To install this type of script, the attacker would need to have direct access to a mail account on the server.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;An attacker with the ability to install SIEVE scripts may be able to gain elevated privileges and use the new permissions to execute code, read other user's mail, or send spoofed email messages.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Update&lt;/b&gt;
&lt;p&gt;The Cyrus IMAP team has released an update to address this issue. See &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.andrew.cmu.edu/pipermail/cyrus-announce/2009-September/000068.html&quot;&gt;http://lists.andrew.cmu.edu/pipermail/cyrus-announce/2009-September/000068.html&lt;/a&gt; for more information.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable SIEVE&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Administrators who compile Cyrus IMAP from source can use the &lt;tt&gt;--disable-sieve&lt;/tt&gt; option to mitigate this issue.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infoblox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OpenBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX Software Systems Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-08&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.andrew.cmu.edu/pipermail/cyrus-announce/2009-September/000068.html&quot;&gt;http://lists.andrew.cmu.edu/pipermail/cyrus-announce/2009-September/000068.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://cyrusimap.web.cmu.edu/imapd/install-compile.html&quot;&gt;http://cyrusimap.web.cmu.edu/imapd/install-compile.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://en.wikipedia.org/wiki/Sieve_(mail_filtering_language)&quot;&gt;http://en.wikipedia.org/wiki/Sieve_(mail_filtering_language)&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to the Cyrus IMAP development team and Bron Gondwana for information that was used in this report.
&lt;p&gt;This document was written by Ryan Giobbi. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-09-07&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-09-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-09-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2632&quot;&gt;CVE-2009-2632&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2632&quot;&gt;CVE-2009-2632&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;0.56&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;18&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/336053</guid>
         <pubDate>Wed, 09 Sep 2009 02:31:30 -0700</pubDate>
      </item>
      <item>
         <title>VU#444513: VMware VMnc AVI video codec image height heap overflow</title>
         <link>http://www.kb.cert.org/vuls/id/444513</link>
         <description>2009-09-05T09:42:30-04:00&lt;h1&gt;Vulnerability Note VU#444513&lt;/h1&gt;
&lt;h2&gt;VMware VMnc AVI video codec image height heap overflow&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The VMware VMnc video codec fails to properly handle the image height value in AVI files, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Several VMware products include the ability to create and play movies of running virtual machines. The codec used in these movies is called VMnc, which is based on the VNC RFB protocol. The VMnc decoder is provided by the file &lt;tt&gt;vmnc.dll&lt;/tt&gt;. The VMnc codec fails to properly handle video content with a specified height of less than 8 pixels. This flaw can lead to heap memory corruption. The vulnerable code in vmnc.dll may be reached via Windows applications that supports the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/dd375454(VS.85).aspx&quot;&gt;DirectShow&lt;/a&gt; API.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to parse a specially crafted VMnc codec AVI file, a remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system. This may occur as the result of several actions, including playing an AVI file with Windows Media Player, viewing a web page that uses the Windows Media Player ActiveX control or plug-in, or even simply by selecting an AVI file in Windows Explorer.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This issue is addressed in VMware Movie Decoder 6.5.3, Workstation 6.5.3, Player 6.5.3, and ACE 2.5.3. Details for obtaining these versions are available in VMware Security Advisory &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.vmware.com/pipermail/security-announce/2009/000065.html&quot;&gt;VMSA-2009-0012&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Remove the VMnc codec&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
If you are unable to apply an update, this vulnerability can be mitigated by removing the &lt;tt&gt;vmnc.dll&lt;/tt&gt; file. Note that this will prevent a system from being able to play VMnc codec AVI files.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;VMware&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-22&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://lists.vmware.com/pipermail/security-announce/2009/000065.html&quot;&gt;http://lists.vmware.com/pipermail/security-announce/2009/000065.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was reported by Will Dormann of the CERT/CC.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-09-04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-09-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2628&quot;&gt;CVE-2009-2628&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2628&quot;&gt;CVE-2009-2628&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;4.05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;17&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/444513</guid>
         <pubDate>Sat, 05 Sep 2009 02:42:30 -0700</pubDate>
      </item>
      <item>
         <title>VU#276653: Microsoft Internet Information Server (IIS) FTP server NLST stack buffer overflow</title>
         <link>http://www.kb.cert.org/vuls/id/276653</link>
         <description>2009-08-31T08:57:19-04:00&lt;h1&gt;Vulnerability Note VU#276653&lt;/h1&gt;
&lt;h2&gt;Microsoft Internet Information Server (IIS) FTP server NLST stack buffer overflow&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Microsoft IIS FTP server contains a stack buffer overflow in the handling of directory names, which may allow a remote attacker to execute arbitrary code on a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;IIS is a web server that comes with Microsoft Windows. IIS also includes FTP server functionality. The IIS FTP server fails to properly parse specially-crafted directory names. By issuing an FTP NLST (NAME LIST) command on a specially-named directory, an attacker may cause a stack buffer overflow. The attacker can create the specially-named directory if FTP is configured to allow write access using Anonymous account or another account that is available to the attacker.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote attacker may be able to execute arbitrary code on a vulnerable server. For servers that allow anonymous file uploads, the attacker would typically be unauthenticated.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;We are currently unaware of a practical solution to this problem. Please consider the workarounds listed in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/975191.mspx&quot;&gt;Microsoft Security Advisory (975191)&lt;/a&gt;, which include:
&lt;p&gt;&lt;b&gt;Disable anonymous FTP write access&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Configuring IIS to disallow write access to anonymous FTP users will limit the ability of the attacker to create a directory that can trigger this vulnerability.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-09-02&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/975191.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/975191.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.g-sec.lu/2009/09/iis-5-iis-6-ftp-vulnerability.html&quot;&gt;http://blog.g-sec.lu/2009/09/iis-5-iis-6-ftp-vulnerability.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://milw0rm.com/exploits/9541&quot;&gt;http://milw0rm.com/exploits/9541&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was publicly disclosed by Kingcope.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-08-31&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-08-31&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-09-02&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;20.81&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;23&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/276653</guid>
         <pubDate>Mon, 31 Aug 2009 01:57:19 -0700</pubDate>
      </item>
      <item>
         <title>VU#582244: Libpurple buffer overflow vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/582244</link>
         <description>2009-08-21T15:06:32-04:00&lt;h1&gt;Vulnerability Note VU#582244&lt;/h1&gt;
&lt;h2&gt;Libpurple buffer overflow vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Libpurple instant messenger library contains a vulnerability that may allow an attacker to execute arbitrary code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://developer.pidgin.im/wiki/WhatIsLibpurple&quot;&gt;Libpurple&lt;/a&gt; is an instant messenger (IM) library that is used by various programs to connect to multiple networks. Libpurple contains a buffer overflow vulnerability that can be triggered by sending specially crafted &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msnpiki.msnfanatic.com/index.php/MSNC:MSNSLP&quot;&gt;MSNSLP&lt;/a&gt; messages to a program that is using an affected version of the library.
&lt;p&gt;For more technical details, see CORE Advisory &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.coresecurity.com/content/libpurple-arbitrary-write#lref.4&quot;&gt;CORE-2009-0727&lt;/a&gt;.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;An attacker may be able to execute arbitrary code or cause an IM program to crash.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Upgrade&lt;/b&gt;
&lt;p&gt;Instant messenger programs may distribute Libpurple and will provide an updated version to their users as a security update. See the systems affected portion of this document for a partial list of affected IM clients. Users who compile Libpurple or IM programs should see the Libpurple &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://developer.pidgin.im/&quot;&gt;site&lt;/a&gt; or their operating system vendor for updated software.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Restrict Access&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The most likely attack vector for this issue would be via the MSN IM network. Administrators may be able to temporarily mitigate this issue by blocking access to the MSN IM network. This workaround is not likely to be totally effective.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Pidgin&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-08-21&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://pidgin.im/news/security/?id=34&quot;&gt;http://pidgin.im/news/security/?id=34&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://developer.pidgin.im/wiki/WhatIsLibpurple&quot;&gt;http://developer.pidgin.im/wiki/WhatIsLibpurple&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.coresecurity.com/content/libpurple-arbitrary-write#lref.4&quot;&gt;http://www.coresecurity.com/content/libpurple-arbitrary-write#lref.4&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msnpiki.msnfanatic.com/index.php/MSNC:MSNSLP&quot;&gt;http://msnpiki.msnfanatic.com/index.php/MSNC:MSNSLP&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://supportwiki.cisco.com/ViewWiki/index.php/How_to_configure_the_PIX_500_Series_Firewall_with_software_version_6.x_in_order_to_block_the_MSN_messenger_with_the_access-list_command&quot;&gt;http://supportwiki.cisco.com/ViewWiki/index.php/How_to_configure_the_PIX_500_Series_Firewall_with_software_version_6.x_in_order_to_block_the_MSN_messenger_with_the_access-list_command&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Information from CORE Advisory &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.coresecurity.com/content/libpurple-arbitrary-write#lref.4&quot;&gt;CORE-2009-0727&lt;/a&gt; was used in this report. &lt;p&gt;This document was written by Ryan Giobbi. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-08-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-08-21&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-08-21&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694&quot;&gt;CVE-2009-2694&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2694&quot;&gt;CVE-2009-2694&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;10.19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;12&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/582244</guid>
         <pubDate>Fri, 21 Aug 2009 08:06:32 -0700</pubDate>
      </item>
      <item>
         <title>VU#485961: Acer AcerCtrls.APlunch ActiveX Control fails to properly restrict access to methods</title>
         <link>http://www.kb.cert.org/vuls/id/485961</link>
         <description>2009-08-18T16:39:05-04:00&lt;h1&gt;Vulnerability Note VU#485961&lt;/h1&gt;
&lt;h2&gt;Acer AcerCtrls.APlunch ActiveX Control fails to properly restrict access to methods&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Acer AcerCtrls.APlunch ActiveX control contains methods that can allow a remote, unauthenticated attacker to run arbitrary commands on a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The Acer AcerCtrls.APlunch ActiveX control is provided by &lt;tt&gt;acerctrl.ocx&lt;/tt&gt;. It contains a method called &lt;tt&gt;Run()&lt;/tt&gt;, which takes two parameters: &lt;tt&gt;Drive&lt;/tt&gt; &lt;tt&gt;and FileName&lt;/tt&gt;. Although the control is not inherently marked as safe for scripting via the &lt;tt&gt;IObjectSafety&lt;/tt&gt; interface, it may be distributed with the appropriate &lt;tt&gt;Implemented Categories&lt;/tt&gt; registry key to make it safe for scripting. This means that a web page in Internet Explorer can call the &lt;tt&gt;Run()&lt;/tt&gt; method of the control.
&lt;p&gt;Note that this vulnerability is similar to but not the same issue as &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/221700&quot;&gt;VU#221700&lt;/a&gt;. This control has different parameters and uses a different CLSID that is not included in the killbits provided with Microsoft Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/Bulletin/MS07-027.mspx&quot;&gt;MS07-027&lt;/a&gt;.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a victim to view an HTML document (web page, HTML email, or email attachment), an attacker could run arbitrary commands with the privileges of the user running IE.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;We are currently unaware of a practical solution to this problem. Please consider the following workarounds:
&lt;p&gt;&lt;br&gt;
&lt;b&gt;Disable the Acer &lt;/b&gt;&lt;b&gt;AcerCtrls.APlunch&lt;/b&gt;&lt;b&gt; ActiveX control in Internet Explorer&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The Acer AcerCtrls.APlunch ActiveX control can be disabled in Internet Explorer by setting the kill bit for the following CLSID:&lt;br&gt; &lt;ul&gt;&lt;tt&gt;{&lt;/tt&gt;&lt;tt&gt;3895DD35-7573-11D2-8FED-00606730D3AA&lt;/tt&gt;&lt;tt&gt;}&lt;/tt&gt;&lt;/ul&gt;
More information about how to set the kill bit is available in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;&lt;font color=&quot;#0000FF&quot;&gt;Microsoft Support Document 240797&lt;/font&gt;&lt;/a&gt;. Alternatively, the following text can be saved as a &lt;tt&gt;.REG&lt;/tt&gt; file and imported to set the kill bit for this control:&lt;br&gt; &lt;ul&gt;&lt;tt&gt;Windows Registry Editor Version 5.00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;{&lt;/tt&gt;&lt;tt&gt;3895DD35-7573-11D2-8FED-00606730D3AA&lt;/tt&gt;&lt;tt&gt;}]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&lt;/tt&gt;&lt;tt&gt;&amp;#92;Wow6432Node&lt;/tt&gt;&lt;tt&gt;&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;{&lt;/tt&gt;&lt;tt&gt;3895DD35-7573-11D2-8FED-00606730D3AA&lt;/tt&gt;&lt;tt&gt;}]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;/ul&gt;
&lt;b&gt;Disable ActiveX&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&quot;&gt;&lt;font color=&quot;#0000FF&quot;&gt;Securing Your Web Browser&quot;&lt;/font&gt;&lt;/a&gt; document. &lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Acer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2007-05-09&lt;/td&gt;&lt;td&gt;2009-08-17&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/221700&quot;&gt;http://www.kb.cert.org/vuls/id/221700&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://vuln.sg/acerlunchapp-en.html&quot;&gt;http://vuln.sg/acerlunchapp-en.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;http://support.microsoft.com/kb/240797&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Michael Costa of Crosshair Information Technology &amp;amp; Security LLC for reporting this vulnerability.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-08-16&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-08-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-08-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2627&quot;&gt;CVE-2009-2627&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2627&quot;&gt;CVE-2009-2627&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;5.06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;13&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/485961</guid>
         <pubDate>Tue, 18 Aug 2009 09:39:05 -0700</pubDate>
      </item>
      <item>
         <title>VU#456745: ActiveX controls built with Microsoft ATL fail to properly handle initialization data</title>
         <link>http://www.kb.cert.org/vuls/id/456745</link>
         <description>2009-07-28T15:42:54-04:00&lt;h1&gt;Vulnerability Note VU#456745&lt;/h1&gt;
&lt;h2&gt;ActiveX controls built with Microsoft ATL fail to properly handle initialization data&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;ActiveX controls that are built using a Microsoft ATL template may fail to properly handle initialization data, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Microsoft Active Template Library (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/t9adwcde(VS.80).aspx&quot;&gt;ATL&lt;/a&gt;) is a set of C++ classes that are designed to simplify the creation of COM objects and ActiveX controls. An ActiveX control can be designated as &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/aa751977(VS.85).aspx#ov_script&quot;&gt;safe for scripting&lt;/a&gt;,&quot; which means that it can be used by an untrusted caller such as JavaScript in a web page, and/or it may be designated as &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/aa751977(VS.85).aspx#ov_init&quot;&gt;safe for initialization&lt;/a&gt;,&quot; which means that it can accept untrusted initialization data. ActiveX controls that are developed using the Microsoft ATL technology may fail to properly handle initialization data. The specific vulnerabilities include the use of uninitialized objects, unsafe usage of &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/ms680103(VS.85).aspx&quot;&gt;&lt;tt&gt;OleLoadFromStream&lt;/tt&gt;&lt;/a&gt;, and the failure to check for a terminating NULL character. This may result in memory corruption that can be leveraged to execute code, or it may bypass Internet Explorer &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;kill bit&lt;/a&gt; restrictions on unsafe controls.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code. &lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This vulnerability has been addressed in the update for Internet Explorer provided in Microsoft Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx&quot;&gt;MS09-034&lt;/a&gt;. This update helps prevent ActiveX controls that were built with the vulnerable ATL versions from being initialized with unsafe data patterns in Internet Explorer. This also includes techniques that can be used to bypass the kill bit in Internet Explorer.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Update and recompile ActiveX controls&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Developers who have created ActiveX controls using Microsoft ATL should install the update for Microsoft Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx&quot;&gt;MS09-035&lt;/a&gt; and recompile the ActiveX controls. This will cause the controls to use an updated ATL version that addresses these vulnerabilities.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable ActiveX&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&quot;&gt;&lt;font color=&quot;#001FE2&quot;&gt;Securing Your Web Browser&lt;/font&gt;&lt;/a&gt;&quot; document.&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Adobe&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-30&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Alcatel-Lucent&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;America Online, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-31&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Attachmate&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Aurigma Inc. &lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Axis&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;BT&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Business Objects&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Callisto Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cisco Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates eTrust Security Management&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Emergency Response Team Brazil&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Corel Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;E-Book Systems Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;eBay&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Electronic Arts&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ESET, LLC.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;GameTap-Turner Broadcasting subsidiary&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;GOVCERT-NL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gracenote&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Husdawg&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Iconics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IncrediMail Ltd.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infotriever, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;InterActual Technologies, Inc. &lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intuit, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Kodak Easy Share Gallery&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Lenovo&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;LizardTech, Inc&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;LogicNP&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-30&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Lotus Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Media Technology Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Motive&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Move Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Namzak Labs Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OSISoft&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-08-04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Panda Software Ltd.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;PNI Digital Media&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Radiant Systems&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;RealNetworks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Research in Motion (RIM)&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SAP&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ScriptLogic&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Siemens&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Simba Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SoftArtisans, Inc&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SonicWall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-10-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-08-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SupportSoft, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SwiftView&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Symantec&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Trend Micro&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unigraphics Solutions&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;VanDyke Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-08-04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;View22&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;WeOnlyDo! Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;WinZip Computing, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Worldspan&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Xerox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Yahoo, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/180513&quot;&gt;http://www.kb.cert.org/vuls/id/180513&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms09-034.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms09-035.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/security/atl.aspx&quot;&gt;http://www.microsoft.com/security/atl.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/msrc/archive/2009/07/28/microsoft-security-advisory-973882-microsoft-security-bulletins-ms09-034-and-ms09-035-released.aspx&quot;&gt;http://blogs.technet.com/msrc/archive/2009/07/28/microsoft-security-advisory-973882-microsoft-security-bulletins-ms09-034-and-ms09-035-released.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx&quot;&gt;http://blogs.msdn.com/sdl/archive/2009/07/28/atl-ms09-035-and-the-sdl.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/ecostrat/archive/2009/07/27/threat-complexity-requires-new-levels-of-collaboration.aspx&quot;&gt;http://blogs.technet.com/ecostrat/archive/2009/07/27/threat-complexity-requires-new-levels-of-collaboration.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/973882.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/973882.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/ms680103(VS.85).aspx&quot;&gt;http://msdn.microsoft.com/en-us/library/ms680103(VS.85).aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/aa751977(VS.85).aspx&quot;&gt;http://msdn.microsoft.com/en-us/library/aa751977(VS.85).aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/t9adwcde(VS.80).aspx&quot;&gt;http://msdn.microsoft.com/en-us/library/t9adwcde(VS.80).aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/168371&quot;&gt;http://support.microsoft.com/kb/168371&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;http://support.microsoft.com/kb/240797&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.adobe.com/psirt/2009/07/impact_of_microsoft_atl_vulner.html&quot;&gt;http://blogs.adobe.com/psirt/2009/07/impact_of_microsoft_atl_vulner.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/advisories/apsa09-04.html&quot;&gt;http://www.adobe.com/support/security/advisories/apsa09-04.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-10.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb09-10.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-11.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb09-11.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://addxorrol.blogspot.com/2009/07/poking-around-msvidctldll.html&quot;&gt;http://addxorrol.blogspot.com/2009/07/poking-around-msvidctldll.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/07/28/msvidctl-ms09-032-and-the-atl-vulnerability.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/07/28/atl-vulnerability-developer-deep-dive.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/07/28/atl-vulnerability-developer-deep-dive.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/07/28/internet-explorer-mitigations-for-atl-data-stream-vulnerabilities.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/07/28/internet-explorer-mitigations-for-atl-data-stream-vulnerabilities.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/07/28/overview-of-the-out-of-band-release.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/bluehat/archive/2009/07/27/black-hat-usa-atl-killbit-bypass.aspx&quot;&gt;http://blogs.technet.com/bluehat/archive/2009/07/27/black-hat-usa-atl-killbit-bypass.aspx&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Microsoft for reporting this vulnerability, who in turn credit David Dewey of IBM ISS X-Force and Ryan Smith of Verisign iDefense labs.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-10-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0901&quot;&gt;CVE-2009-0901&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2493&quot;&gt;CVE-2009-2493&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2495&quot;&gt;CVE-2009-2495&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0901&quot;&gt;CVE-2009-0901&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2493&quot;&gt;CVE-2009-2493&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2495&quot;&gt;CVE-2009-2495&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://www.us-cert.gov/cas/techalerts/TA09-209A.html&quot;&gt;TA09-209A&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;47.08&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;41&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/456745</guid>
         <pubDate>Tue, 28 Jul 2009 08:42:54 -0700</pubDate>
      </item>
      <item>
         <title>VU#725188: ISC BIND 9 vulnerable to denial of service via dynamic update request</title>
         <link>http://www.kb.cert.org/vuls/id/725188</link>
         <description>2009-07-28T08:28:08-04:00&lt;h1&gt;Vulnerability Note VU#725188&lt;/h1&gt;
&lt;h2&gt;ISC BIND 9 vulnerable to denial of service via dynamic update request&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;ISC BIND 9 contains a vulnerability that may allow a remote, unauthenticated attacker to create a denial-of-service condition.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.isc.org/software/bind&quot;&gt;Berkeley Internet Name Domain&lt;/a&gt; (BIND) is a popular Domain Name System (DNS) implementation from &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.isc.org/&quot;&gt;Internet Systems Consortium&lt;/a&gt; (ISC). It includes support for dynamic DNS updates as specified in IETF &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc2136&quot;&gt;RFC 2136&lt;/a&gt;. BIND 9 can crash when processing a specially-crafted dynamic update packet.
&lt;p&gt;ISC notes that this vulnerability affects all servers that are masters for one or more zones and is not limited to those that are configured to allow dynamic updates. ISC also indicates that the attack packet has to be constructed for a zone for which the target system is configured as a master; launching the attack against slave zones does not trigger the vulnerability.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By sending a specially-crafted dynamic update packet to a BIND 9 server, a remote, unauthenticated attacker can cause a denial of service by causing BIND to crash.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;Users who obtain BIND from a third-party vendor, such as their operating system vendor, should see the systems affected portion of this document for a partial list of affected vendors.&lt;br&gt;
&lt;br&gt;
This vulnerability is addressed in ISC BIND versions 9.4.3-P3, 9.5.1-P3, and BIND 9.6.1-P1. Users of BIND from the original source distribution should upgrade to one of these versions, as appropriate.&lt;br&gt;
&lt;br&gt;
See also &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.isc.org/node/474&quot;&gt;https://www.isc.org/node/474&lt;/a&gt;.&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Alcatel-Lucent&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;BlueCat Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Check Point Software Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ericsson&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gnu ADNS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;GNU glibc&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infoblox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Systems Consortium&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;McAfee&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Men &amp; Mice&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Metasolv Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nixu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nominum&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nortel Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OpenBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX, Software Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Shadowsupport&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.isc.org/node/474&quot;&gt;https://www.isc.org/node/474&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc2136&quot;&gt;http://tools.ietf.org/html/rfc2136&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://oldwww.isc.org/sw/bind/view?release=9.4.3-P3&amp;noframes=1&quot;&gt;http://oldwww.isc.org/sw/bind/view?release=9.4.3-P3&amp;amp;noframes=1&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://oldwww.isc.org/sw/bind/view?release=9.5.1-P3&amp;noframes=1&quot;&gt;http://oldwww.isc.org/sw/bind/view?release=9.5.1-P3&amp;amp;noframes=1&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://oldwww.isc.org/sw/bind/view?release=9.6.1-P1&amp;noframes=1&quot;&gt;http://oldwww.isc.org/sw/bind/view?release=9.6.1-P1&amp;amp;noframes=1&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975&quot;&gt;http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=538975&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to ISC for reporting this vulnerability.
&lt;p&gt;This document was written by Will Dormann and Chad Dougherty. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-07-30&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0696&quot;&gt;CVE-2009-0696&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0696&quot;&gt;CVE-2009-0696&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;26.32&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;32&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/725188</guid>
         <pubDate>Tue, 28 Jul 2009 01:28:08 -0700</pubDate>
      </item>
      <item>
         <title>VU#259425: Adobe Flash vulnerability affects Flash Player and other Adobe products</title>
         <link>http://www.kb.cert.org/vuls/id/259425</link>
         <description>2009-07-22T10:54:34-04:00&lt;h1&gt;Vulnerability Note VU#259425&lt;/h1&gt;
&lt;h2&gt;Adobe Flash vulnerability affects Flash Player and other Adobe products&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Adobe Flash contains a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system. Adobe Flash Player, Reader, Acrobat, and other products that include Flash support are affected.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Adobe Flash is a widely deployed multimedia platform typically used to provide content in web sites. Adobe Flash Player, Reader, Acrobat, and other Adobe products include Flash support.
&lt;p&gt;Adobe Flash Player contains a code execution vulnerability. An attacker may be able to trigger this vulnerability by convincing a user to open a specially crafted Flash (SWF) file. The SWF file could be hosted or embedded in a web page or contained in a Portable Document Format (PDF) file. If an attacker can take control of a website or web server, trusted sites may exploit this vulnerability.&lt;br&gt;
&lt;br&gt;
This vulnerability affects Adobe Flash versions 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions. Adobe Reader 9, Acrobat 9, and other Adobe products (including Photoshop CS3, PhotoShop Lightroom, Freehand MX, Fireworks) provide Flash support independent of Flash Player. As of 2009-07-22, Adobe Reader 9.1.2 includes Flash 9.0.155.0, which is likely vulnerable to issues addressed by Flash 9.0.159.0 (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-01.html&quot;&gt;APSB09-01&lt;/a&gt;).&lt;br&gt;
&lt;br&gt;
This vulnerability is being actively exploited.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), PDF file, Microsoft Office document, or any other document that supports embedded SWF content, an attacker may be able to execute arbitrary code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This issue is addressed in Flash Player 10.0.32.18. Please see Adobe Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-10.html&quot;&gt;APSB09-10&lt;/a&gt; for more details. Note that Microsoft Windows users should update both the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://fpdownload.adobe.com/get/flashplayer/current/install_flash_player_ax.exe&quot;&gt;ActiveX&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://fpdownload.adobe.com/get/flashplayer/current/install_flash_player.exe&quot;&gt;Plug-in&lt;/a&gt; versions of Flash Player for increased protection.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable Flash in your web browser&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disable Flash or selectively enable Flash content as described in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/&quot;&gt;Securing Your Web Browser&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable Flash and 3D &amp;amp; Multimedia support in Adobe Reader 9&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Flash and 3D &amp;amp; Multmedia support are implemented as plugin libraries in Adobe Reader. Disabling Flash in Adobe Reader will only mitigate attacks using a SWF embedded in a PDF file. Disabling 3D &amp;amp; Multimedia support does not directly address the vulnerability, but does provide additional mitigation and results in a more user-friendly error message instead of a crash.&lt;br&gt;
&lt;br&gt;
To disable Flash and 3D &amp;amp; Multimedia support in Adobe Reader 9 on Microsoft Windows, delete or rename these files:&lt;br&gt; &lt;ul&gt;&lt;tt&gt;&quot;%ProgramFiles%&amp;#92;Adobe&amp;#92;Reader 9.0&amp;#92;Reader&amp;#92;authplay.dll&quot;&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;%ProgramFiles%&amp;#92;Adobe&amp;#92;Reader 9.0&amp;#92;Reader&amp;#92;rt3d.dll&quot;&lt;/tt&gt;&lt;/ul&gt;
For Apple Mac OS X, delete or rename these files:&lt;br&gt; &lt;ul&gt;&lt;tt&gt;&quot;/Applications/Adobe Reader 9/Adobe Reader.app/Contents/Frameworks/AuthPlayLib.bundle&quot;&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;/Applications/Adobe Reader 9/Adobe Reader.app/Contents/Frameworks/Adobe3D.framework&quot;&lt;/tt&gt;&lt;/ul&gt;
For GNU/Linux delete or rename these files (locations may vary among distributions):&lt;br&gt; &lt;ul&gt;&lt;tt&gt;&quot;/opt/Adobe/Reader9/Reader/intellinux/lib/libauthplay.so&quot;&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;/opt/Adobe/Reader9/Reader/intellinux/lib/librt3d.so&quot;&lt;/tt&gt;&lt;/ul&gt;
File locations may be different for Adobe Acrobat or other Adobe products that include Flash and 3D &amp;amp; Multimedia support. Disabling these plugins will reduce functionality, and will not protect against SWF files hosted on web sites. Depending on the update schedule for products other than Flash Player, consider leaving Flash and 3D &amp;amp; Multimedia support disabled unless they are absolutely required.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Remove Flash&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Adobe has provided a &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://kb2.adobe.com/cps/141/tn_14157.html&quot;&gt;TechNote&lt;/a&gt; with utilities for uninstalling the Flash Player plug-in and ActiveX control on Windows and Mac OS X systems. Removing these components can mitigate the web browser attack vector for this vulnerability. Note that this will not remove the instances of Flash Player that is installed with Adobe Reader 9 or other Adobe products.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Enable DEP in Microsoft Windows&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Consider enabling Data Execution Prevention (DEP) in supported versions of Windows. DEP should not be treated as a complete workaround, but DEP can mitigate the execution of attacker-supplied code in some cases. Microsoft has published detailed technical information about DEP in Security Research &amp;amp; Defense blog posts &quot;Understanding DEP as a mitigation technology&quot; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/06/05/understanding-dep-as-a-mitigation-technology-part-1.aspx&quot;&gt;part 1&lt;/a&gt; and &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx&quot;&gt;part 2&lt;/a&gt;. Use of DEP should be considered in conjunction with the application of patches or other mitigations described in this document.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Adobe&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-23&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/&quot;&gt;http://www.us-cert.gov/reading_room/securing_browser/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-10.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb09-10.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html&quot;&gt;http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.adobe.com/psirt/2009/07/update_on_adobe_reader_acrobat.html&quot;&gt;http://blogs.adobe.com/psirt/2009/07/update_on_adobe_reader_acrobat.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/advisories/apsa09-03.html&quot;&gt;http://www.adobe.com/support/security/advisories/apsa09-03.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://bugs.adobe.com/jira/browse/FP-1265&quot;&gt;http://bugs.adobe.com/jira/browse/FP-1265&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability&quot;&gt;http://www.symantec.com/connect/blogs/next-generation-flash-vulnerability&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://kb2.adobe.com/cps/141/tn_14157.html&quot;&gt;http://kb2.adobe.com/cps/141/tn_14157.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.fireeye.com/research/2009/07/actionscript_heap_spray.html&quot;&gt;http://blog.fireeye.com/research/2009/07/actionscript_heap_spray.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/06/05/understanding-dep-as-a-mitigation-technology-part-1.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/06/05/understanding-dep-as-a-mitigation-technology-part-1.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/06/12/understanding-dep-as-a-mitigation-technology-part-2.aspx&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was reported on the Adobe PSIRT &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.adobe.com/psirt/2009/07/potential_adobe_reader_and_fla.html&quot;&gt;blog&lt;/a&gt;. Thanks to Department of Defense Cyber Crime Center/DCISE for information used in this document.
&lt;p&gt;This document was written by Chris Taschner, Will Dormann, Chad Dougherty, and Art Manion. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-08-07&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1862&quot;&gt;CVE-2009-1862&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1862&quot;&gt;CVE-2009-1862&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://www.us-cert.gov/cas/techalerts/TA09-204A.html&quot;&gt;TA09-204A&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;35.34&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;48&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/259425</guid>
         <pubDate>Wed, 22 Jul 2009 03:54:34 -0700</pubDate>
      </item>
      <item>
         <title>VU#545228: Microsoft Office Web Components Spreadsheet ActiveX control vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/545228</link>
         <description>2009-07-15T10:54:34-04:00&lt;h1&gt;Vulnerability Note VU#545228&lt;/h1&gt;
&lt;h2&gt;Microsoft Office Web Components Spreadsheet ActiveX control vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Microsoft Office Web Components Spreadsheet ActiveX controls (OWC10 and OWC11) contain a vulnerability that may allow an attacker to take control of a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The Office Web Components Spreadsheet ActiveX control contains a code execution vulnerability. Public reports indicate that this vulnerability is being actively exploited.
&lt;p&gt;Per the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx&quot;&gt;MSRC blog&lt;/a&gt;, the following products may install the affected control on a system:
&lt;ul&gt;&lt;i&gt;Microsoft Office XP Service Pack 3, Microsoft Office 2003 Service Pack 3, Microsoft Office XP Web Components Service Pack 3, Microsoft Office Web Components 2003 Service Pack 3, Microsoft Office 2003 Web Components for the 2007 Microsoft Office system Service Pack 1, Microsoft Internet Security and Acceleration Server 2004 Standard Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2004 Enterprise Edition Service Pack 3, Microsoft Internet Security and Acceleration Server 2006, Internet Security and Acceleration Server 2006 Supportability Update, Microsoft Internet Security and Acceleration Server 2006 Service Pack 1, Microsoft Office Small Business Accounting 2006.&lt;/i&gt;&lt;/ul&gt;
Further details are available from the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx&quot;&gt;Microsoft Security Research &amp;amp; Defense blog&lt;/a&gt;.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote attacker may be able to take control of a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;Until updates are available, the below workaround will mitigate this vulnerability.
&lt;p&gt;&lt;b&gt;Disable the Office Web Components Spreadsheet ActiveX controls in Internet Explorer&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The vulnerable controls can be disabled in Internet Explorer by setting the kill bit for the following CLSIDs:
&lt;ul&gt;&lt;tt&gt;{0002E541-0000-0000-C000-000000000046}&lt;/tt&gt; (OWC10)&lt;tt&gt;&lt;br&gt;
{0002E559-0000-0000-C000-000000000046}&lt;/tt&gt; (OWC11)&lt;/ul&gt;
More information about how to set the kill bit is available in Microsoft Support Document &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;240797&lt;/a&gt;. Alternatively, the following text can be saved as a .REG file and imported to set the kill bit for these controls:&lt;br&gt; &lt;ul&gt;&lt;tt&gt;Windows Registry Editor Version 5.00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;{0002E541-0000-0000-C000-000000000046}]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;&lt;/tt&gt;&lt;tt&gt;Wow6432Node&amp;#92;&lt;/tt&gt;&lt;tt&gt;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;{0002E541-0000-0000-C000-000000000046}]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;{0002E559-0000-0000-C000-000000000046}]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;&lt;/tt&gt;&lt;tt&gt;Wow6432Node&amp;#92;&lt;/tt&gt;&lt;tt&gt;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;{0002E559-0000-0000-C000-000000000046}]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;/ul&gt;
&lt;b&gt;Disable ActiveX&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&quot;&gt;&lt;font color=&quot;#001FE2&quot;&gt;Securing Your Web Browser&lt;/font&gt;&lt;/a&gt;&quot; document.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-15&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cert.org/tech_tips/securing_browser/&quot;&gt;http://www.cert.org/tech_tips/securing_browser/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/973472.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/973472.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx&quot;&gt;http://blogs.technet.com/msrc/archive/2009/07/13/microsoft-security-advisory-973472-released.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/07/13/more-information-about-the-office-web-components-activex-vulnerability.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;http://support.microsoft.com/kb/240797&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Microsoft for information that was used in this report.
&lt;p&gt;This document was written by Ryan Giobbi. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-08-07&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1136&quot;&gt;CVE-2009-1136&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1136&quot;&gt;CVE-2009-1136&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://www.us-cert.gov/cas/techalerts/TA09-195A.html&quot;&gt;TA09-195A&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;44.04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;17&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/545228</guid>
         <pubDate>Wed, 15 Jul 2009 03:54:34 -0700</pubDate>
      </item>
      <item>
         <title>VU#466161: XML signature HMAC truncation authentication bypass</title>
         <link>http://www.kb.cert.org/vuls/id/466161</link>
         <description>2009-07-14T15:26:34-04:00&lt;h1&gt;Vulnerability Note VU#466161&lt;/h1&gt;
&lt;h2&gt;XML signature HMAC truncation authentication bypass&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The XML Signature specification allows for HMAC truncation, which may allow a remote attacker to bypass authentication.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/TR/xmldsig-core/&quot;&gt;XML Signature Syntax and Processing&lt;/a&gt; (XMLDsig) is a W3C recommendation for providing integrity, message authentication, and/or signer authentication services for data. XMLDsig is commonly used by web services such as SOAP. The XMLDsig recommendation includes support for &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc2104#section-5&quot;&gt;HMAC truncation&lt;/a&gt;, as specified in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc2104&quot;&gt;RFC2104&lt;/a&gt;. However, the XMLDsig specification does not follow the RFC2104 recommendation to not allow truncation to less than half of the length of the hash output or less than 80 bits. When HMAC truncation is under the control of an attacker this can result in an effective authentication bypass. For example, by specifying an HMACOutputLength of &lt;tt&gt;1&lt;/tt&gt;, only one bit of the signature is verified. This can allow an attacker to forge an XML signature that will be accepted as valid.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;This vulnerability can allow an attacker to bypass the authentication mechanism provided by the XML Signature specification.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;Please check with your vendor for available updates. &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/2008/06/xmldsigcore-errata.html#e03&quot;&gt;Erratum E03&lt;/a&gt; for the XMLDsig recommendation has been added, which specifies minimum values for HMAC truncation.&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;3com, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ACCESS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Alcatel-Lucent&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apache XML Security&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;AT&amp;T&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Avaya, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Barracuda Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Belkin, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Borderware Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;CERT-Bund&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-22&lt;/td&gt;&lt;td&gt;2009-06-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Certicom&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-02-18&lt;/td&gt;&lt;td&gt;2009-02-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Charlotte's Web Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Check Point Software Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cisco Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Clavister&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates eTrust Security Management&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;D-Link Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Enterasys Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ericsson&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;eSoft, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Extreme Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Force10 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fortinet, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Foundry Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Global Technology Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infoblox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intel Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Security Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intoto&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Filter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Infusion, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Luminous Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;m0n0wall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;McAfee&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mono-Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Multitech, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetApp&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;netfilter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nortel Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Oracle Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;PePLink&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Process Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Q1 Labs&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX, Software Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Quagga&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;RadWare, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Redback Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;RSA Security, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Secureworx, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SmoothWall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Snort&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Soapstone Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sourcefire&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Stonesoft&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-08-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Symantec&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;TippingPoint, Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;U4EA Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;VMware&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Vyatta&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Watchguard Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;XML Security Library&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-10&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/2008/06/xmldsigcore-errata.html#e03&quot;&gt;http://www.w3.org/2008/06/xmldsigcore-errata.html#e03&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html&quot;&gt;http://www.w3.org/QA/2009/07/hmac_truncation_in_xml_signatu.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.rsa.com/blog/blog_entry.aspx?id=1492&quot;&gt;http://www.rsa.com/blog/blog_entry.aspx?id=1492&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/TR/xmldsig-core/&quot;&gt;http://www.w3.org/TR/xmldsig-core/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/TR/xmldsig-core/#sec-HMAC&quot;&gt;http://www.w3.org/TR/xmldsig-core/#sec-HMAC&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://tools.ietf.org/html/rfc2104#section-5&quot;&gt;http://tools.ietf.org/html/rfc2104#section-5&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.oasis-open.org/specs/index.php#wss&quot;&gt;http://www.oasis-open.org/specs/index.php#wss&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/2000/xp/Group/&quot;&gt;http://www.w3.org/2000/xp/Group/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/ms996502.aspx&quot;&gt;http://msdn.microsoft.com/en-us/library/ms996502.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ibm.com/support/docview.wss?rs=180&amp;uid=swg21384925&quot;&gt;http://www.ibm.com/support/docview.wss?rs=180&amp;amp;uid=swg21384925&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://santuario.apache.org/download.html&quot;&gt;http://santuario.apache.org/download.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mono-project.com/Vulnerabilities&quot;&gt;http://www.mono-project.com/Vulnerabilities&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html&quot;&gt;http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2009.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.aleksey.com/xmlsec/downloads.html&quot;&gt;http://www.aleksey.com/xmlsec/downloads.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161&quot;&gt;http://blogs.sun.com/security/entry/cert_vulnerability_note_vu_466161&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://rdist.root.org/2009/07/19/xmldsig-welcomes-all-signatures/&quot;&gt;http://rdist.root.org/2009/07/19/xmldsig-welcomes-all-signatures/&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Thomas Roessler of the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.w3.org/&quot;&gt;W3C&lt;/a&gt; for reporting this vulnerability.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-08-05&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0217&quot;&gt;CVE-2009-0217&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0217&quot;&gt;CVE-2009-0217&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;8.16&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;28&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/466161</guid>
         <pubDate>Tue, 14 Jul 2009 08:26:34 -0700</pubDate>
      </item>
      <item>
         <title>VU#410676: ISC DHCP dhclient stack buffer overflow</title>
         <link>http://www.kb.cert.org/vuls/id/410676</link>
         <description>2009-07-14T11:10:50-04:00&lt;h1&gt;Vulnerability Note VU#410676&lt;/h1&gt;
&lt;h2&gt;ISC DHCP dhclient stack buffer overflow&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The ISC DHCP dhclient application contains a stack buffer overflow, which may allow a remote, unauthenticated attacker to execute arbitrary code with root privileges.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;As described in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.faqs.org/rfcs/rfc2131.html&quot;&gt;RFC 2131&lt;/a&gt;, &quot;The Dynamic Host Configuration Protocol (DHCP) provides a framework for passing configuration information to hosts on a TCP/IP network.&quot; ISC DHCP is a reference implementation of the DHCP protocol, including a DHCP server, client, and relay agent.
&lt;p&gt;The ISC DHCP client code (dhclient) contains a stack buffer overflow in the &lt;tt&gt;script_write_params()&lt;/tt&gt; method. dhclient fails to check the length of the server-supplied subnet-mask option before copying it into a buffer. According to ISC, the following versions are affected:
&lt;ul&gt;DHCP 4.1 (all versions)&lt;br&gt;
DHCP 4.0 (all versions)&lt;br&gt;
DHCP 3.1 (all versions)&lt;br&gt;
DHCP 3.0 (all versions)&lt;br&gt;
DHCP 2.0 (all versions)&lt;/ul&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A rogue DHCP server may be able to execute arbitrary code with root privileges on a vulnerable client system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply a patch or update from your vendor&lt;/b&gt;
&lt;p&gt;For vendor-specific information regarding vulnerable status and patch availability, please see the Systems Affected section of this document.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Upgrade your version of DHCP&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Upgrade your system as specified by your vendor. If you need to upgrade DHCP manually, &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.isc.org/node/468&quot;&gt;according to ISC&lt;/a&gt;:
&lt;ul&gt;Upgrade to 4.1.0p1, 4.0.1p1, or 3.1.2p1&lt;br&gt;
&lt;br&gt;
There are no fixes planned for DHCP 3.0 or DHCP 2.0, as those release trains have reached End-Of-Life.&lt;/ul&gt;
&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;3com, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ACCESS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Alcatel-Lucent&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;AT&amp;T&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Avaya, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Barracuda Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Belkin, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Borderware Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Bro&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Charlotte's Web Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Check Point Software Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cisco Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Clavister&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates eTrust Security Management&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-25&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;D-Link Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Enterasys Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ericsson&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;eSoft, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Extreme Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Force10 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fortinet, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Foundry Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Global Technology Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Infoblox&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intel Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Security Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Systems Consortium&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Systems Consortium - DHCP&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intoto&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Filter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Luminous Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;m0n0wall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;McAfee&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Multitech, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetApp&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;netfilter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-25&lt;/td&gt;&lt;td&gt;2009-06-25&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nortel Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;PePLink&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-24&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Process Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Q1 Labs&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX, Software Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-07&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Quagga&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;RadWare, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-16&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Redback Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-03&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Secureworx, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SmoothWall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-25&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Snort&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Soapstone Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sourcefire&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Stonesoft&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-26&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Symantec&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-30&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;TippingPoint, Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;U4EA Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;VMware&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-29&lt;/td&gt;&lt;td&gt;2009-06-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Vyatta&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Watchguard Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-29&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;td&gt;2009-06-23&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://www.isc.org/node/468&quot;&gt;https://www.isc.org/node/468&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was reported by ISC, who in turn credit the Mandriva Linux Engineering Team with discovering and reporting the vulnerability.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-07-16&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0692&quot;&gt;CVE-2009-0692&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0692&quot;&gt;CVE-2009-0692&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;19.95&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;27&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/410676</guid>
         <pubDate>Tue, 14 Jul 2009 04:10:50 -0700</pubDate>
      </item>
      <item>
         <title>VU#443060: Mozilla Firefox 3.5 TraceMonkey JavaScript engine uninitialized memory vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/443060</link>
         <description>2009-07-14T08:09:51-04:00&lt;h1&gt;Vulnerability Note VU#443060&lt;/h1&gt;
&lt;h2&gt;Mozilla Firefox 3.5 TraceMonkey JavaScript engine uninitialized memory vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Mozilla Firefox's javascript engine contains a vulnerability that may allow an attacker to execute code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Mozilla Firefox version 3.5 contains a vulnerability in the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://wiki.mozilla.org/JavaScript:TraceMonkey&quot;&gt;TraceMonkey&lt;/a&gt; components of Firefox's JavaScript engine.
&lt;p&gt;Per Mozilla Bug Bug &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=503286#c14&quot;&gt;503286&lt;/a&gt;:&lt;br&gt;
&lt;i&gt;&quot;This is a JS engine bug dealing with deep bailing not properly restoring the return value from the result of the (fast native) escape function. We then try to do something with the uninitialized memory and crash in the interpreter.&quot;&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
Note that proof of concept code that demonstrates issue this is publicly available.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote, unauthenticated attacker may be able to execute arbitrary code or cause Firefox to crash.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;Firefox 3.5.1 has been released to address this issue. See Mozilla Foundation Security Advisory &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2009/mfsa2009-41.html&quot;&gt;2009-41&lt;/a&gt; for more information. Until updates can be applied, the below workarounds may mitigate this issue.
&lt;p&gt;&lt;b&gt;Disable &lt;/b&gt;&lt;b&gt;TraceMonkey&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
To disable the vulnerable components, use the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://kb.mozillazine.org/Firefox_:_FAQs_:_About:config_Entries&quot;&gt;about:config&lt;/a&gt; interface to set &lt;tt&gt;javascript.options.jit.content &lt;/tt&gt;and &lt;tt&gt;javascript.options.jit.chrome&lt;/tt&gt; to &lt;tt&gt;false&lt;/tt&gt;. This will still allow JavaScript to run, but it will disable the TraceMonkey performance enhancements.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Use NoScript&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Using the Mozilla Firefox &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://addons.mozilla.org/firefox/addon/722&quot;&gt;NoScript&lt;/a&gt; extension to whitelist web sites that can run scripts will help to mitigate this vulnerability. Further details for configuring NoScript are available in the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#noscript&quot;&gt;Securing Your Web Browser&lt;/a&gt; document.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable JavaScript&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
For instructions on how to disable JavaScript in Firefox, please refer to the Firefox section of the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Mozilla_Firefox&quot;&gt;Securing Your Web Browser&lt;/a&gt; document.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mozilla&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mozilla.org/security/announce/2009/mfsa2009-41.html&quot;&gt;http://www.mozilla.org/security/announce/2009/mfsa2009-41.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/&quot;&gt;http://blog.mozilla.com/security/2009/07/14/critical-javascript-vulnerability-in-firefox-35/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://bugzilla.mozilla.org/show_bug.cgi?id=503286&quot;&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=503286&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://milw0rm.com/exploits/9137&quot;&gt;http://milw0rm.com/exploits/9137&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://kb.mozillazine.org/Firefox_:_FAQs_:_About:config_Entries&quot;&gt;http://kb.mozillazine.org/Firefox_:_FAQs_:_About:config_Entries&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html?wprss=securityfix&quot;&gt;http://voices.washingtonpost.com/securityfix/2009/07/stopgap_fix_for_critical_firef.html?wprss=securityfix&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Information from zbyte, Mozilla, and other sources was used in this report.
&lt;p&gt;This document was written by Ryan Giobbi. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-07-17&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;40.50&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;21&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/443060</guid>
         <pubDate>Tue, 14 Jul 2009 01:09:51 -0700</pubDate>
      </item>
      <item>
         <title>VU#180513: Microsoft Video ActiveX control stack buffer overflow</title>
         <link>http://www.kb.cert.org/vuls/id/180513</link>
         <description>2009-07-06T17:16:50-04:00&lt;h1&gt;Vulnerability Note VU#180513&lt;/h1&gt;
&lt;h2&gt;Microsoft Video ActiveX control stack buffer overflow&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Microsoft Video ActiveX control contains a stack buffer overflow vulnerability, which can allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Microsoft Windows comes with an ActiveX component called &quot;ActiveX control for streaming video,&quot; which is provided by &lt;tt&gt;msvidctl.dll&lt;/tt&gt;. This component provides a number of Class Identifiers (CLSIDs) that are marked as Safe for Scripting and Safe for Initialization, which means that they can be used by Internet Explorer. The ActiveX controls provided by &lt;tt&gt;msvidctl.dll&lt;/tt&gt; fail to properly handle file input, which can result in stack memory corruption. This can allow the Structured Exception Handler (SEH) to be overwritten, thus allowing subversion of the program execution flow.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. &lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;Microsoft has released an update to address this issue. See Microsoft Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx&quot;&gt;MS09-032&lt;/a&gt; for more information.
&lt;p&gt;&lt;b&gt;Disable the vulnerable ActiveX controls&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Microsoft Security Advisory (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/972890.mspx&quot;&gt;972890&lt;/a&gt;) explains how to disable the 45 ActiveX controls provided by &lt;tt&gt;msvidctl.dll&lt;/tt&gt; to mitigate this vulnerability. A Microsoft Fix it application is provided in Microsoft Knowledgebase article &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/972890&quot;&gt;972890&lt;/a&gt; to disable these controls.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable ActiveX&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&quot;&gt;&lt;font color=&quot;#0000FF&quot;&gt;Securing Your Web Browser&lt;/font&gt;&lt;/a&gt;&quot; document. &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-07-15&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cert.org/tech_tips/securing_browser/&quot;&gt;http://www.cert.org/tech_tips/securing_browser/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/972890.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/972890.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/972890&quot;&gt;http://support.microsoft.com/kb/972890&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://dvlabs.tippingpoint.com/blog/2009/07/09/microsoft-video-activex-control-0day-technical-details&quot;&gt;http://dvlabs.tippingpoint.com/blog/2009/07/09/microsoft-video-activex-control-0day-technical-details&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://addxorrol.blogspot.com/2009/07/poking-around-msvidctldll.html&quot;&gt;http://addxorrol.blogspot.com/2009/07/poking-around-msvidctldll.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://isc.sans.org/diary.html?storyid=6733&quot;&gt;http://isc.sans.org/diary.html?storyid=6733&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799&quot;&gt;http://www.csis.dk/dk/nyheder/nyheder.asp?tekstID=799&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blogs.technet.com/srd/archive/2009/07/06/new-vulnerability-in-mpeg2tunerequest-activex-control-object-in-msvidctl-dll.aspx&quot;&gt;http://blogs.technet.com/srd/archive/2009/07/06/new-vulnerability-in-mpeg2tunerequest-activex-control-object-in-msvidctl-dll.aspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/techalerts/TA09-187A.html&quot;&gt;http://www.us-cert.gov/cas/techalerts/TA09-187A.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/techalerts/TA09-195A.html&quot;&gt;http://www.us-cert.gov/cas/techalerts/TA09-195A.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms09-032.mspx&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-07-04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-07-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-07-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0015&quot;&gt;CVE-2008-0015&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0015&quot;&gt;CVE-2008-0015&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://www.us-cert.gov/cas/techalerts/TA09-187A.html&quot;&gt;TA09-187A&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://www.us-cert.gov/cas/techalerts/TA09-195A.html&quot;&gt;TA09-195A&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;65.31&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;24&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/180513</guid>
         <pubDate>Mon, 06 Jul 2009 10:16:50 -0700</pubDate>
      </item>
      <item>
         <title>VU#251793: Foxit Reader contains multiple vulnerabilities in the processing of JPX data</title>
         <link>http://www.kb.cert.org/vuls/id/251793</link>
         <description>2009-06-19T10:12:47-04:00&lt;h1&gt;Vulnerability Note VU#251793&lt;/h1&gt;
&lt;h2&gt;Foxit Reader contains multiple vulnerabilities in the processing of JPX data&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Foxit Reader contains multiple vulnerabilities that may allow an attacker to execute arbitrary code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/pdf/reader/&quot;&gt;Foxit Reader&lt;/a&gt; is software designed to view Portable Document Format (PDF) files. Adobe also distributes the Adobe Acrobat Plug-In to allow users to view PDF files inside of a web browser. Foxit Reader contains multiple vulnerabilities in the handling of JPX (JPEG2000) streams. These vulnerabilities may result in memory corruption.
&lt;p&gt;Note: Foxit Reader does not contain the ability to decode JPEG2000 data by default. The &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/pdf/reader/addons.htm#cjkpack&quot;&gt;JPEG2000 / JBIG Decoder&lt;/a&gt; add-on must be installed for Foxit Reader to be vulnerable. When Foxit Reader encounters a PDF document that has JPEG2000 or JBIG data, the user will automatically be prompted to install the add-on, however.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to open a malicious PDF file, an attacker may be able to execute code or cause a vulnerable PDF viewer to crash. The PDF could be emailed as an attachment or hosted on a website.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This issue is addressed in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/downloads/&quot;&gt;Foxit Reader 3.0 Build 1817&lt;/a&gt;. Updating to this version should trigger the process to upgrade the JPEG2000 / JBIG Decoder component to be updated to version &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/downloads/addons/jpg_decoder2.0.20096.html&quot;&gt;2.0.2009.616&lt;/a&gt; if a vulnerable version is already installed. Additional details are available in the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/pdf/reader/security.htm#0602&quot;&gt;Foxit Reader security advisory&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable JavaScript in&lt;/b&gt;&lt;b&gt; Foxit Reader&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling JavaScript may help prevent this and other vulnerabilities from being exploited. Foxit Reader JavaScript can be disabled in the preferences dialog (&lt;tt&gt;Edit&lt;/tt&gt; -&amp;gt; &lt;tt&gt;Preferences&lt;/tt&gt; -&amp;gt; &lt;tt&gt;JavaScript&lt;/tt&gt; and uncheck &lt;tt&gt;Enable &lt;/tt&gt;JavaScript Actions). Note that this will not block the vulnerability. Foxit Reader still may crash when parsing specially crafted PDF documents.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Prevent Internet Explorer from automatically opening PDF documents&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The installer for Foxit Reader configures Internet Explorer to automatically open PDF files without any user interaction. This behavior can be reverted to the safer option of prompting the user by importing the following as a .REG file:
&lt;ul&gt;&lt;tt&gt;Windows Registry Editor Version 5.00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_CLASSES_ROOT&amp;#92;FoxitReader.Document]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;EditFlags&quot;=hex:00,00,00,00&lt;/tt&gt;&lt;/ul&gt;
&lt;b&gt;Disable the displaying of PDF documents in the web browser&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Preventing PDF documents from opening inside a web browser may help mitigate this vulnerability. If this workaround is applied to updated versions of the Foxit reader, it may help mitigate future vulnerabilities.&lt;br&gt;
&lt;br&gt;
To prevent PDF documents from automatically being opened in a web browser:&lt;br&gt; &lt;ol type=&quot;1&quot;&gt;
&lt;li&gt;Open Foxit Reader.
&lt;li&gt;Open the &lt;tt&gt;Edit&lt;/tt&gt; menu.
&lt;li&gt;Choose the &lt;tt&gt;Preferences&lt;/tt&gt; option.
&lt;li&gt;Choose the &lt;tt&gt;Internet&lt;/tt&gt; section.
&lt;li&gt;Uncheck the &lt;tt&gt;&lt;font size=&quot;4&quot;&gt;&quot;&lt;/font&gt;&lt;/tt&gt;&lt;tt&gt;Display PDF in browser&lt;/tt&gt;&lt;tt&gt;&lt;font size=&quot;4&quot;&gt;&quot;&lt;/font&gt;&lt;/tt&gt; check box.&lt;/ol&gt;
&lt;br&gt;
&lt;b&gt;Do not access PDF documents from untrusted sources&lt;br&gt;
&lt;br&gt;
&lt;/b&gt;Do not open unfamiliar or unexpected PDF documents, particularly those hosted on web sites or delivered as email attachments. Please see Cyber Security Tip &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-010.html&quot;&gt;ST04-010&lt;/a&gt;.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Foxit Software Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-06-02&lt;/td&gt;&lt;td&gt;2009-06-19&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/pdf/reader/&quot;&gt;http://www.foxitsoftware.com/pdf/reader/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/pdf/reader/security.htm#0602&quot;&gt;http://www.foxitsoftware.com/pdf/reader/security.htm#0602&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.foxitsoftware.com/downloads/addons/jpg_decoder2.0.20096.html&quot;&gt;http://www.foxitsoftware.com/downloads/addons/jpg_decoder2.0.20096.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was reported by Will Dormann of the CERT/CC.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-06-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-06-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-06-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0690&quot;&gt;CVE-2009-0690&lt;/a&gt;; &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0691&quot;&gt;CVE-2009-0691&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0690&quot;&gt;CVE-2009-0690&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0691&quot;&gt;CVE-2009-0691&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;1.02&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;10&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/251793</guid>
         <pubDate>Fri, 19 Jun 2009 03:12:47 -0700</pubDate>
      </item>
      <item>
         <title>VU#568153: Adobe Reader contains multiple vulnerabilities in the processing of JPX data</title>
         <link>http://www.kb.cert.org/vuls/id/568153</link>
         <description>2009-06-09T16:18:46-04:00&lt;h1&gt;Vulnerability Note VU#568153&lt;/h1&gt;
&lt;h2&gt;Adobe Reader contains multiple vulnerabilities in the processing of JPX data&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;Adobe Reader and Acrobat contain multiple vulnerabilities that may allow an attacker to execute arbitrary code.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/products/reader/&quot;&gt;Adobe Acrobat Reader&lt;/a&gt; is software designed to view Portable Document Format (PDF) files. Adobe also distributes the Adobe Acrobat Plug-In to allow users to view PDF files inside of a web browser. Adobe Reader and Acrobat contain multiple vulnerabilities in the handling of JPX (JPEG2000) streams. These vulnerabilities may result in heap memory corruption.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to open a malicious PDF file, an attacker may be able to execute code or cause a vulnerable PDF viewer to crash. The PDF could be emailed as an attachment or hosted on a website.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This issue is addressed in Adobe Reader and Acrobat versions 9.1.2, 8.1.6, and 7.1.3. More details are available in Adobe Security Bulletin &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-07.html&quot;&gt;APSB09-07&lt;/a&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-04.html&quot;&gt;&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable JavaScript in Adobe Reader and Acrobat&lt;/b&gt; &lt;br&gt;
&lt;br&gt;
Disabling JavaScript may prevent this vulnerability from being exploited. Acrobat JavaScript can be disabled in the preferences dialog (&lt;tt&gt;Edit&lt;/tt&gt; -&amp;gt; &lt;tt&gt;Preferences&lt;/tt&gt; -&amp;gt; &lt;tt&gt;JavaScript&lt;/tt&gt; and uncheck &lt;tt&gt;Enable Acrobat JavaScript&lt;/tt&gt;). Note that this will not block the vulnerability. Adobe products still may crash when parsing specially crafted PDF documents. Disabling JavaScript will mitigate a common method used to achieve code execution with this vulnerability. Also note that when JavaScript is disabled in Adobe Reader, the software will prompt the user to enable JavaScript when it opens a document that uses the feature. So although JavaScript is a single click away, setting this preference can help mitigate exploits that use JavaScript. &lt;br&gt;
&lt;br&gt;
Some vendors ship JavaScript support in a &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://packages.medibuntu.org/intrepid/acroread-escript.html&quot;&gt;separate package&lt;/a&gt;. Removing this package may remove JavaScript support in the Adobe PDF reader.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Prevent Internet Explorer from automatically opening PDF documents&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The installer for Adobe Reader and Acrobat configures Internet Explorer to automatically open PDF files without any user interaction. This behavior can be reverted to the safer option of prompting the user by importing the following as a .REG file:
&lt;ul&gt;&lt;tt&gt;Windows Registry Editor Version 5.00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_CLASSES_ROOT&amp;#92;AcroExch.Document.7]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;EditFlags&quot;=hex:00,00,00,00&lt;/tt&gt;&lt;/ul&gt;
&lt;b&gt;Disable the displaying of PDF documents in the web browser&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Preventing PDF documents from opening inside a web browser may mitigate this vulnerability. If this workaround is applied to updated versions of the Adobe reader, it may mitigate future vulnerabilities.&lt;br&gt;
&lt;br&gt;
To prevent PDF documents from automatically being opened in a web browser:&lt;br&gt; &lt;ol type=&quot;1&quot;&gt;
&lt;li&gt;Open Adobe Acrobat Reader.
&lt;li&gt;Open the &lt;tt&gt;Edit&lt;/tt&gt; menu.
&lt;li&gt;Choose the &lt;tt&gt;Preferences&lt;/tt&gt; option.
&lt;li&gt;Choose the &lt;tt&gt;Internet&lt;/tt&gt; section.
&lt;li&gt;Uncheck the &lt;tt&gt;&lt;font size=&quot;4&quot;&gt;&quot;&lt;/font&gt;&lt;/tt&gt;&lt;tt&gt;Display PDF in browser&lt;/tt&gt;&lt;tt&gt;&lt;font size=&quot;4&quot;&gt;&quot;&lt;/font&gt;&lt;/tt&gt; check box.&lt;br&gt;
&lt;/ol&gt;
&lt;b&gt;Disable Adobe Acrobat Windows Shell integration&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Adobe Acrobat and Reader integrate themselves with the Windows shell. The file &lt;tt&gt;pdfshell.dll&lt;/tt&gt; is used to configure Windows Explorer to launch Adobe components to render, preview, and obtain details from a PDF document, all without actually opening the PDF document itself. Windows shell integration for Adobe Acrobat and Reader can be disabled by unregistering the &lt;tt&gt;pdfshell.dll&lt;/tt&gt; by running the following command:
&lt;ul&gt;&lt;tt&gt;regsvr32 /u &quot;%CommonProgramFiles%&amp;#92;Adobe&amp;#92;Acrobat&amp;#92;ActiveX&amp;#92;pdfshell.dll&quot;&lt;/tt&gt;&lt;/ul&gt;
&lt;b&gt;Disable the Adobe Acrobat Indexing Service filter&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Adobe Reader and Adobe Acrobat install an &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/ms689718(VS.85).aspx&quot;&gt;Indexing Service&lt;/a&gt; filter that is used to parse PDF files. These filters are provided by &lt;tt&gt;AcroRdIF.dll&lt;/tt&gt; and &lt;tt&gt;AcroIF.dll&lt;/tt&gt;, respectively. When an application that uses the Adobe IFilters indexes a malicious PDF document, the vulnerability may be triggered. This attack vector can be mitigated by unregistering the Adobe IFilter files.&lt;br&gt;
Adobe Acrobat users should locate the Acrobat directory and run: &lt;tt&gt;regsvr32 /u AcroIF.dll&lt;/tt&gt;&lt;br&gt;
Adobe Reader users should locate the Adobe Reader directory and run: &lt;tt&gt;regsvr32 /u AcroRdIF.dll&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Note:&lt;/b&gt; After disabling the Windows shell integration or the Indexing Service filter by unregistering the appropriate DLL, the Windows Installer MSI &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/aa302344.aspx&quot;&gt;resiliency&lt;/a&gt; feature may trigger a &quot;repair&quot; of those features when an &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://msdn.microsoft.com/en-us/library/aa367548(VS.85).aspx&quot;&gt;advertised&lt;/a&gt; shortcut for Adobe Reader is clicked. To prevent this from occurring, delete the Adobe Reader icon from the Windows start menu and then re-create a normal, non-advertised shortcut. More details are available in the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cert.org/blogs/vuls/2009/03/windows_installer_application.html&quot;&gt;CERT/CC Vulnerability Analysis Blog&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Do not access PDF documents from untrusted sources&lt;br&gt;
&lt;br&gt;
&lt;/b&gt;Do not open unfamiliar or unexpected PDF documents, particularly those hosted on web sites or delivered as email attachments. Please see Cyber Security Tip &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-010.html&quot;&gt;ST04-010&lt;/a&gt;.&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Adobe&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-08&lt;/td&gt;&lt;td&gt;2009-06-09&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/cas/tips/ST04-010.html&quot;&gt;http://www.us-cert.gov/cas/tips/ST04-010.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cert.org/tech_tips/securing_browser/&quot;&gt;http://www.cert.org/tech_tips/securing_browser/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cert.org/blogs/vuls/2009/03/windows_installer_application.html&quot;&gt;http://www.cert.org/blogs/vuls/2009/03/windows_installer_application.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.adobe.com/support/security/bulletins/apsb09-07.html&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb09-07.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was reported by Will Dormann of the CERT/CC.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-06-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-06-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-06-17&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1861&quot;&gt;CVE-2009-1861&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1861&quot;&gt;CVE-2009-1861&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;2.89&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;13&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/568153</guid>
         <pubDate>Tue, 09 Jun 2009 09:18:46 -0700</pubDate>
      </item>
      <item>
         <title>VU#983731: eBay Enhanced Picture Uploader ActiveX control vulnerable to arbitrary command execution</title>
         <link>http://www.kb.cert.org/vuls/id/983731</link>
         <description>2009-06-09T14:01:52-04:00&lt;h1&gt;Vulnerability Note VU#983731&lt;/h1&gt;
&lt;h2&gt;eBay Enhanced Picture Uploader ActiveX control vulnerable to arbitrary command execution&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The eBay Enhanced Picture Uploader ActiveX control allows arbitrary commands to be executed.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The eBay Enhanced Picture Uploader ActiveX control is used by the eBay web site to give Internet Explorer users additional functionality when uploading pictures to an auction. This ActiveX control is provided by the file &lt;tt&gt;EPUWALcontrol.dll&lt;/tt&gt;. If an attacker provides a specially-crafted &lt;tt&gt;PictureUrls&lt;/tt&gt; property or initialization parameter, the ActiveX control will execute the commands that are specified.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary commands with the privileges of the user. &lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This update is addressed in version 1.0.27 of the Ebay Enhanced Picture Control software. This update can be obtained by visiting the eBay web site, creating a new auction and uploading images with the Internet Explorer web browser. This control is also disabled in Internet Explorer with the update for &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/969898.mspx&quot;&gt;Microsoft Security Advisory (969898)&lt;/a&gt;. Please see the eBay security center &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://pages.ebay.com/securitycenter/activex/index.html&quot;&gt;announcement&lt;/a&gt; for additional details.&lt;br&gt;
&lt;br&gt;
Please also consider the following workarounds:&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable the eBay Enhanced Picture Uploader ActiveX control in Internet Explorer&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The vulnerable ActiveX control can be disabled in Internet Explorer by setting the kill bit for the following CLSIDs:&lt;br&gt; &lt;ul&gt;&lt;tt&gt;{4C39376E-FA9D-4349-BACC-D305C1750EF3}&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;{C3EB1670-84E0-4EDA-B570-0B51AAE81679}&lt;/tt&gt;&lt;/ul&gt;
More information about how to set the kill bit is available in &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;&lt;font color=&quot;#0000FF&quot;&gt;Microsoft Support Document 240797&lt;/font&gt;&lt;/a&gt;. Alternatively, the following text can be saved as a &lt;tt&gt;.REG&lt;/tt&gt; file and imported to set the kill bit for this control:&lt;br&gt; &lt;ul&gt;&lt;tt&gt;Windows Registry Editor Version 5.00&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;&lt;/tt&gt;&lt;tt&gt;{4C39376E-FA9D-4349-BACC-D305C1750EF3}&lt;/tt&gt;&lt;tt&gt;]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;br&gt;
&lt;br&gt;
&lt;tt&gt;[HKEY_LOCAL_MACHINE&amp;#92;SOFTWARE&amp;#92;Microsoft&amp;#92;Internet Explorer&amp;#92;ActiveX Compatibility&amp;#92;&lt;/tt&gt;&lt;tt&gt;{C3EB1670-84E0-4EDA-B570-0B51AAE81679}&lt;/tt&gt;&lt;tt&gt;]&lt;/tt&gt;&lt;br&gt;
&lt;tt&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/tt&gt;&lt;/ul&gt;
&lt;b&gt;Disable ActiveX&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.us-cert.gov/reading_room/securing_browser/#Internet_Explorer&quot;&gt;&lt;font color=&quot;#0000FF&quot;&gt;Securing Your Web Browser&lt;/font&gt;&lt;/a&gt;&quot; document. &lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;eBay&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2008-08-27&lt;/td&gt;&lt;td&gt;2009-06-09&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.cert.org/tech_tips/securing_browser/#Internet_Explorer&quot;&gt;http://www.cert.org/tech_tips/securing_browser/#Internet_Explorer&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://pages.ebay.com/securitycenter/activex/index.html&quot;&gt;http://pages.ebay.com/securitycenter/activex/index.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/969898.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/969898.mspx&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;http://support.microsoft.com/kb/240797&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to Chris Weber of Casaba Security for reporting this vulnerability.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-06-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-06-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-06-09&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2475&quot;&gt;CVE-2008-2475&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-2475&quot;&gt;CVE-2008-2475&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;7.36&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;9&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/983731</guid>
         <pubDate>Tue, 09 Jun 2009 07:01:52 -0700</pubDate>
      </item>
      <item>
         <title>VU#710316: NSD vulnerable to one-byte overflow</title>
         <link>http://www.kb.cert.org/vuls/id/710316</link>
         <description>2009-05-20T16:06:16-04:00&lt;h1&gt;Vulnerability Note VU#710316&lt;/h1&gt;
&lt;h2&gt;NSD vulnerable to one-byte overflow&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;A vulnerability exists in the way NSD processes certain types of packets that may lead to a one-byte buffer overflow.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Name server daemon (NSD) is an open source name server developed by NLnet Labs. NSD contains an off-by-one error that can cause a one-byte buffer overflow when certain packets are processed. The vulnerability exits in the &lt;tt&gt;packet_read_query_section()&lt;/tt&gt; function in &lt;tt&gt;packet.c&lt;/tt&gt; in versions 3.x and in the &lt;tt&gt;process_query_section()&lt;/tt&gt; function in &lt;tt&gt;query.c&lt;/tt&gt; in versions 2.x.
&lt;p&gt;Note that this issue affects NSD versions 2.0.0 through 3.2.1.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote, unauthenticated attacker may be able to cause the DNS software to crash resulting in a denial-of-service condition.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply patch&lt;/b&gt;
&lt;p&gt;&lt;br&gt;
NLnet Labs has released NSD version 3.2.2 and patches for &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html&quot;&gt;&lt;/a&gt;versions 3.2.1 and 2.3.7. More information and links to these patches can be found in NLnet Labs &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html&quot;&gt;NSD Announcement&lt;/a&gt;.&lt;br&gt;
&lt;br&gt;
Users are encouraged to check with their vendor to determine the appropriate patch or update to apply.&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;3com, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ACCESS&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Alcatel-Lucent&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Computer, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;AT&amp;T&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Avaya, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Barracuda Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Belkin, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Borderware Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Bro&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Charlotte's Web Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Check Point Software Technologies&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cisco Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Clavister&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Computer Associates eTrust Security Management&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Enterasys Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ericsson&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;eSoft, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Extreme Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Force10 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fortinet, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Foundry Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Global Technology Associates&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Internet Security Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Intoto&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IP Filter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Luminous Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;m0n0wall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;McAfee&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Multitech, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetApp&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NetBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;netfilter&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NLnet Labs&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-28&lt;/td&gt;&lt;td&gt;2009-05-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nortel Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;OpenBSD&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;PePLink&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Process Software&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Q1 Labs&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-06-01&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX, Software Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Quagga&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;RadWare, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Redback Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-22&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Secureworx, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SmoothWall&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Snort&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Soapstone Networks&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sourcefire&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Stonesoft&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Symantec&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;TippingPoint, Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;U4EA Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Vyatta&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Watchguard Technologies, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;ZyXEL&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html&quot;&gt;http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This issue was reported in NLnet Labs &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.nlnetlabs.nl/publications/NSD_vulnerability_announcement.html&quot;&gt;NSD Announcement&lt;/a&gt;.
&lt;p&gt;This document was written by Chris Taschner. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-05-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-06-01&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;8.40&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;10&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/710316</guid>
         <pubDate>Wed, 20 May 2009 09:06:16 -0700</pubDate>
      </item>
      <item>
         <title>VU#787932: Microsoft IIS WebDAV Remote Authentication Bypass</title>
         <link>http://www.kb.cert.org/vuls/id/787932</link>
         <description>2009-05-19T17:00:53-04:00&lt;h1&gt;Vulnerability Note VU#787932&lt;/h1&gt;
&lt;h2&gt;Microsoft IIS WebDAV Remote Authentication Bypass&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;A vulnerability exists in the way Microsoft Internet Information Server (IIS) handles unicode tokens that may allow authentication bypass.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;Web-based Distributed Authoring and Versioning (WebDAV) is a set of HTTP extensions that allow collaborative management and editing of files collected on remote servers. The way that Microsoft IIS's implementation of WebDAV handles unicode tokens may allow authentication bypass. According to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2009/May/0134.html&quot;&gt;Nikolaos Rangos&lt;/a&gt;:
&lt;p&gt; &lt;i&gt;The specific flaw exists within the WebDAV functionality of IIS 6.0. The Web Server fails to properly handle unicode tokens when parsing the URI and sending back data.&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
According to &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.zoller.lu/2009/05/iis-6-webdac-auth-bypass-and-data.html&quot;&gt;Thierry Zoller&lt;/a&gt;:&lt;br&gt;
&lt;i&gt;The bug discovered by Rangos seems to suffer from a similar logic mistake when requesting source (translate:f) that has been introduced in the Webdav component. It appears that unicode characters are removed after the security checks.&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
Note that this issue affects IIS versions prior to 7.0
&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote attacker may be able to bypass the access restrictions and list, download, upload and modify protected files.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;We are currently unaware of a practical solution to this problem. Please consider the following workarounds: &lt;p&gt;&lt;br&gt;
&lt;b&gt;Disable WebDAV&lt;/b&gt;&lt;br&gt;
Disabling WebDAV prevents this vulnerability from being exploited and reduces attack surface. WebDAV functionality is disabled by default in IIS version 6.0 on systems that have not had services that utilize WebDAV installed. &lt;br&gt;
&lt;br&gt;
Please note that disabling WebDAV may affect the functionality of other applications such as SharePoint. &lt;br&gt;
&lt;br&gt;
&lt;b&gt;Filter external HTTP requests&lt;/b&gt;&lt;br&gt;
Administrators who are unable to disable WebDAV may be able to mitigate some risk by configuring their IDS to refuse external HTTP requests containing &quot;Translate: f&quot; HTTP headers.&lt;br&gt;
&lt;br&gt;
Please see Microsoft Security Advisory &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/971492.mspx&quot;&gt;971492&lt;/a&gt; for further mitigation information. &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://seclists.org/fulldisclosure/2009/May/0134.html&quot;&gt;http://seclists.org/fulldisclosure/2009/May/0134.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://blog.zoller.lu/2009/05/iis-6-webdac-auth-bypass-and-data.html&quot;&gt;http://blog.zoller.lu/2009/05/iis-6-webdac-auth-bypass-and-data.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://milw0rm.com/exploits/8704&quot;&gt;http://milw0rm.com/exploits/8704&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/technet/security/advisory/971492.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/971492.mspx&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was publicly disclosed by Nikolaos Rangos.
&lt;p&gt;This document was written by Chris Taschner. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-03-12&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-05-19&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1535&quot;&gt;CVE-2009-1535&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1535&quot;&gt;CVE-2009-1535&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;0.00&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;17&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/787932</guid>
         <pubDate>Tue, 19 May 2009 10:00:53 -0700</pubDate>
      </item>
      <item>
         <title>VU#853097: ntpd autokey stack buffer overflow</title>
         <link>http://www.kb.cert.org/vuls/id/853097</link>
         <description>2009-05-18T10:02:07-04:00&lt;h1&gt;Vulnerability Note VU#853097&lt;/h1&gt;
&lt;h2&gt;ntpd autokey stack buffer overflow&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;ntpd contains a stack buffer overflow, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system or create a denial of service.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;NTP (Network Time Protocol) is a method by which client machines can synchronize the local date and time with a reference server. ntpd, which is the NTP daemon, contains a stack buffer overflow when it is compiled with OpenSSL support. The vulnerability is caused by the use of &lt;tt&gt;sprintf()&lt;/tt&gt; in the &lt;tt&gt;crypto_recv()&lt;/tt&gt; function in &lt;tt&gt;ntpd/ntp_crypto.c&lt;/tt&gt;. The vulnerable code is reachable if ntpd is configured to use autokey. This vulnerable configuration is indicated by a &lt;tt&gt;crypto pw &lt;/tt&gt;&lt;tt&gt;&lt;i&gt;password&lt;/i&gt;&lt;/tt&gt; line in the &lt;tt&gt;ntp.conf&lt;/tt&gt; file, where &lt;tt&gt;&lt;i&gt;password&lt;/i&gt;&lt;/tt&gt;&lt;tt&gt;&amp;nbsp;&lt;/tt&gt;is the password that has been configured.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote, unauthenticated attacker may be able to execute arbitrary code with the privileges of the ntpd daemon.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Apply an update&lt;/b&gt;
&lt;p&gt;This issue is addressed in ntp 4.2.4p7 and 4.2.5p74.&lt;br&gt;
&lt;br&gt;
&lt;b&gt;Disable autokey&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
This vulnerability can be mitigated by removing the &lt;tt&gt;crypto pw &lt;/tt&gt;&lt;tt&gt;&lt;i&gt;password&lt;/i&gt;&lt;/tt&gt;line from the &lt;tt&gt;ntp.conf&lt;/tt&gt; file.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Apple Computer, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-08&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-11&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;DragonFly BSD Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-07&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;EMC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;F5 Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;FreeBSD, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fujitsu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-07&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hitachi&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation (zseries)&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ingrian Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Microsoft Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-07&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;NEC Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Nokia&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;QNX, Software Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-12&lt;/td&gt;&lt;td&gt;2009-05-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Silicon Graphics, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sony Corporation&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-07-31&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-12&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Unisys&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Wind River Systems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ntp.org/downloads.html&quot;&gt;http://www.ntp.org/downloads.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;https://rhn.redhat.com/errata/RHSA-2009-1039.html&quot;&gt;https://rhn.redhat.com/errata/RHSA-2009-1039.html&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.ubuntu.com/usn/usn-777-1&quot;&gt;http://www.ubuntu.com/usn/usn-777-1&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://bugs.gentoo.org/show_bug.cgi?id=268962&quot;&gt;http://bugs.gentoo.org/show_bug.cgi?id=268962&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://xorl.wordpress.com/2009/06/10/freebsd-sa-0911-ntpd-remote-stack-based-buffer-overflows/&quot;&gt;http://xorl.wordpress.com/2009/06/10/freebsd-sa-0911-ntpd-remote-stack-based-buffer-overflows/&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;This vulnerability was reported by Harlan Stenn of the NTP Forum at ISC (&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://ntpforum.isc.org&quot;&gt;ntpforum.isc.org&lt;/a&gt;), who in turn credits Chris Ries of CMU.
&lt;p&gt;This document was written by Will Dormann. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-05-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-05-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-07-31&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252&quot;&gt;CVE-2009-1252&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-1252&quot;&gt;CVE-2009-1252&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;9.45&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;31&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/853097</guid>
         <pubDate>Mon, 18 May 2009 03:02:07 -0700</pubDate>
      </item>
      <item>
         <title>VU#238019: Cyrus SASL library buffer overflow vulnerability</title>
         <link>http://www.kb.cert.org/vuls/id/238019</link>
         <description>2009-05-14T15:16:00-04:00&lt;h1&gt;Vulnerability Note VU#238019&lt;/h1&gt;
&lt;h2&gt;Cyrus SASL library buffer overflow vulnerability&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;The Cyrus SASL library contains a buffer overflow vulnerability that could allow an attacker to execute code or cause a vulnerable program to crash.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;SASL (Simple Authentication and Security Layer) is a method for adding authentication support to various protocols. SASL is commonly used by mail servers to request authentication from clients and by clients to authenticate to servers.
&lt;p&gt;The &lt;tt&gt;sasl_encode64()&lt;/tt&gt; function converts a string into base64. The Cyrus SASL library contains buffer overflows that occur because of unsafe use of the &lt;tt&gt;sasl_encode64()&lt;/tt&gt; function. &lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;A remote attacker might be able to execute code, or cause any programs relying on SASL to crash or be unavailable.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;&lt;b&gt;Upgrade&lt;/b&gt;
&lt;p&gt;Cyrus SASL &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.23.tar.gz&quot;&gt;2.1.23&lt;/a&gt; has been released to address this issue. Before releasing fixed binaries, maintainers are encouraged to review the Cyrus &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.kb.cert.org/vuls/id/RGII-7RYLZQ&quot;&gt;vendor statement&lt;/a&gt; associated with this note.&lt;br&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Conectiva Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cray Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Cyrus-IMAP&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;&lt;/td&gt;&lt;td&gt;2009-05-13&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Debian GNU/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Engarde Secure Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Fedora Project&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Gentoo Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-05-20&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Hewlett-Packard Company&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM Corporation (zseries)&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;IBM eServer&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ingrian Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Juniper Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-05-18&lt;/td&gt;&lt;td&gt;2009-05-18&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mandriva S. A.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;MontaVista Software, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Novell, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Openwall GNU/*/Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Red Hat, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-05-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SafeNet&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Not Vulnerable&lt;/td&gt;&lt;td&gt;2009-05-13&lt;/td&gt;&lt;td&gt;2009-06-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Slackware Linux Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Sun Microsystems, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-05-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;SUSE Linux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;The SCO Group&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-05-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Turbolinux&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Ubuntu&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Unknown&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;td&gt;2009-04-28&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.23.tar.gz&quot;&gt;ftp://ftp.andrew.cmu.edu/pub/cyrus-mail/cyrus-sasl-2.1.23.tar.gz&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://xorl.wordpress.com/2009/05/18/cve-2009-0688-cmu-cyrus-sasl-off-by-one-overflow/&quot;&gt;http://xorl.wordpress.com/2009/05/18/cve-2009-0688-cmu-cyrus-sasl-off-by-one-overflow/&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://en.wikipedia.org/w/index.php?title=Base64&amp;oldid=285664115&quot;&gt;http://en.wikipedia.org/w/index.php?title=Base64&amp;amp;oldid=285664115&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Thanks to James Ralston for reporting this issue and providing technical information.
&lt;p&gt;This document was written by Ryan Giobbi. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2009-04-08&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-05-14&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-06-15&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0688&quot;&gt;CVE-2009-0688&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; HREF=&quot;http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0688&quot;&gt;CVE-2009-0688&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;4.04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;24&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/238019</guid>
         <pubDate>Thu, 14 May 2009 08:16:00 -0700</pubDate>
      </item>
      <item>
         <title>VU#576996: NuPoint Messenger server transmits authentication credentials in plain text</title>
         <link>http://www.kb.cert.org/vuls/id/576996</link>
         <description>2009-05-06T06:31:31-04:00&lt;h1&gt;Vulnerability Note VU#576996&lt;/h1&gt;
&lt;h2&gt;NuPoint Messenger server transmits authentication credentials in plain text&lt;/h2&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;overview&quot;&gt;&lt;h3&gt;Overview&lt;/h3&gt;&lt;/a&gt;NuPoint Messenger is a unified communications product that connects to a Microsoft Exchange server. When communicating with the mail server the NuPoint Messenger server transmits Exchange usernames and passwords in cleartext.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;description&quot;&gt;&lt;h3&gt;I. Description&lt;/h3&gt;&lt;/a&gt;The NuPoint Messenger server can connect to a Microsoft Exchange server via the &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://en.wikipedia.org/w/index.php?title=Internet_Message_Access_Protocol&amp;amp;oldid=287045101&quot;&gt;IMAP&lt;/a&gt; or &lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://en.wikipedia.org/w/index.php?title=Messaging_Application_Programming_Interface&amp;amp;oldid=276195526&quot;&gt;MAPI&lt;/a&gt; protocols. During the authentication process, the NuPoint server will send user domain authentication credentials in cleartext to the Exchange server. Older versions of the NuPoint Messenger product may transmit the NuPoint server's root password without encryption instead of individual usernames and passwords. Administrators are encouraged review the &quot;&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mitel.com/resources/NuPoint_and_Exchange.pdf&quot;&gt;NuPoint communication with MS Exchange&lt;/a&gt;&quot; document for more information.&lt;a rel=&quot;nofollow&quot; NAME=&quot;impact&quot;&gt;&lt;h3&gt;II. Impact&lt;/h3&gt;&lt;/a&gt;An attacker with access to network data may be able to obtain domain (Exchange) usernames and passwords.&lt;a rel=&quot;nofollow&quot; NAME=&quot;solution&quot;&gt;&lt;h3&gt;III. Solution&lt;/h3&gt;&lt;/a&gt;There is no solution to this issue. Administrators are encourgaed to review the below workarounds to mitigate the impact of this vulnerability.
&lt;p&gt;&lt;b&gt;Encrypt connections between NuPoint and Exchange Servers&lt;/b&gt;&lt;br&gt; &lt;ul type=&quot;disc&quot;&gt;
&lt;li&gt;If the MAPI protocol is enabled, connections from the NuPoint server will be encrypted.
&lt;li&gt;Using IPSec or some other VPN technology to encrypt the connection between the NuPoint and Exchange server will mitigate this vulnerability.&lt;/ul&gt;
&lt;br&gt;
&lt;b&gt;Restrict access&lt;/b&gt;&lt;br&gt;
&lt;br&gt;
The NuPoint Messenger server should not use IMAP to connect to remote Exchange servers. If IMAP is enabled, the NuPoint server should be directly connected to the same isolated network as the Exchange server that it is communicating with.
&lt;a rel=&quot;nofollow&quot; NAME=&quot;systems&quot;&gt;&lt;h3&gt;Systems Affected&lt;/h3&gt;&lt;/a&gt;
&lt;table&gt;
&lt;tr&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Vendor&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Status&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Notified&lt;/th&gt;&lt;th ALIGN=&quot;LEFT&quot;&gt;Date Updated&lt;/th&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td&gt;&lt;a rel=&quot;nofollow&quot;&gt;Mitel Networks, Inc.&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Vulnerable&lt;/td&gt;&lt;td&gt;2009-04-30&lt;/td&gt;&lt;td&gt;2009-05-05&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt; &lt;a rel=&quot;nofollow&quot; NAME=&quot;references&quot;&gt;&lt;h3&gt;References&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://www.mitel.com/resources/NuPoint_and_Exchange.pdf&quot;&gt;http://www.mitel.com/resources/NuPoint_and_Exchange.pdf&lt;/a&gt;&lt;br&gt;
&lt;a rel=&quot;nofollow&quot; target=&quot;_blank&quot; href=&quot;http://en.wikipedia.org/w/index.php?title=Messaging_Application_Programming_Interface&amp;oldid=276195526&quot;&gt;http://en.wikipedia.org/w/index.php?title=Messaging_Application_Programming_Interface&amp;amp;oldid=276195526&lt;/a&gt;
&lt;a rel=&quot;nofollow&quot; NAME=&quot;credit&quot;&gt;&lt;h3&gt;Credit&lt;/h3&gt;&lt;/a&gt;
&lt;p&gt;Simon Laurin of Simon Laurin Services-Conseils inc. reported this issue and provided valuable feedback. Mitel provided technical information that was used in this report.
&lt;p&gt;This document was written by Ryan Giobbi. &lt;a rel=&quot;nofollow&quot; NAME=&quot;other&quot;&gt;&lt;h3&gt;Other Information&lt;/h3&gt;&lt;/a&gt; &lt;table&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Public:&lt;/td&gt;&lt;td&gt;2008-12-04&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date First Published:&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Date Last Updated:&lt;/td&gt;&lt;td&gt;2009-05-06&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CERT Advisory:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;CVE-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;NVD-ID(s):&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;US-CERT Technical Alerts:&lt;/td&gt;&lt;td&gt;&amp;nbsp;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Metric:&lt;/td&gt;&lt;td&gt;1.80&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td ALIGN=&quot;LEFT&quot;&gt;Document Revision:&lt;/td&gt;&lt;td&gt;23&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;</description>
         <author>US-CERT</author>
         <guid isPermaLink="false">http://www.kb.cert.org/vuls/id/576996</guid>
         <pubDate>Tue, 05 May 2009 23:31:31 -0700</pubDate>
      </item>
      <item>
         <title>TA09-195A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-195A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_0b8edafc5d6fd38b75333516be3ccef4</guid>
      </item>
      <item>
         <title>TA09-204A: Adobe Flash Vulnerability Affects Flash Player and Other Adobe Products</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-204A.html</link>
         <description>Adobe Flash Vulnerability Affects Flash Player and Other Adobe Products</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_f84219256aced53ec06484a7bdcc992e</guid>
      </item>
      <item>
         <title>TA09-209A: Microsoft Windows, Internet Explorer, and Active Template Library (ATL) Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-209A.html</link>
         <description>Microsoft Windows, Internet Explorer, and Active Template Library (ATL) Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_fdcf1c5ae794fe8a8751208a15ead029</guid>
      </item>
      <item>
         <title>TA09-218A: Apple Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-218A.html</link>
         <description>Apple Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_3d85f604b097900d2b7527f7a819e4f0</guid>
      </item>
      <item>
         <title>TA09-223A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-223A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_cb9cd099cd23db831068eaed01ba459e</guid>
      </item>
      <item>
         <title>TA09-251A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-251A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_186ca782405ec14b586cd174bb2dadc9</guid>
      </item>
      <item>
         <title>TA09-286A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-286A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_e955861d0e73bbaccb5d7a742d5c795c</guid>
      </item>
      <item>
         <title>TA09-286B: Adobe Reader and Acrobat Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-286B.html</link>
         <description>Adobe Reader and Acrobat Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_4d0b475a1d913d441d37b07e784d6805</guid>
      </item>
      <item>
         <title>TA09-294A: Oracle Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-294A.html</link>
         <description>Oracle Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_68dc7f927688d7ea1678254b98abf2c7</guid>
      </item>
      <item>
         <title>TA09-314A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/techalerts/TA09-314A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_4ea556c89160e16d8cd0dd0799639c91</guid>
      </item>
      <item>
         <title>SA09-160A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-160A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_3f53d773564dde38efaf33ca84808080</guid>
      </item>
      <item>
         <title>SA09-187A: Microsoft Video ActiveX Control Vulnerability</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-187A.html</link>
         <description>Microsoft Video ActiveX Control Vulnerability</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_bd3e49d75ead501ddbf4b08238bc7ca8</guid>
      </item>
      <item>
         <title>SA09-195A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-195A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_cd40d3f972715f8e1a371522bb4242b5</guid>
      </item>
      <item>
         <title>SA09-209A: Microsoft Windows and Internet Explorer Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-209A.html</link>
         <description>Microsoft Windows and Internet Explorer Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_127e94a65fa483ea7f2fc32d35b3f1cd</guid>
      </item>
      <item>
         <title>SA09-218A: Apple Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-218A.html</link>
         <description>Apple Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_d62feadf23af8ef2650c902f80ff9085</guid>
      </item>
      <item>
         <title>SA09-223A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-223A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_01c2e639d81e0b88c76d416ea2496941</guid>
      </item>
      <item>
         <title>SA09-251A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-251A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_9b4dd40f443c3d3a6c194ac726e14400</guid>
      </item>
      <item>
         <title>SA09-286A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-286A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_00c5819c2df3798790e851d4d1b533bb</guid>
      </item>
      <item>
         <title>SA09-286B: Multiple Vulnerabilities Affect Adobe Reader and Acrobat</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-286B.html</link>
         <description>Multiple Vulnerabilities Affect Adobe Reader and Acrobat</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_0025ff21d9c92e492ff958e4bbff111a</guid>
      </item>
      <item>
         <title>SA09-314A: Microsoft Updates for Multiple Vulnerabilities</title>
         <link>http://www.us-cert.gov/cas/alerts/SA09-314A.html</link>
         <description>Microsoft Updates for Multiple Vulnerabilities</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_bd49354351b445d49d96264c7384f16a</guid>
      </item>
      <item>
         <title>SB09-264: Vulnerability Summary for the Week of September 14, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-264.html</link>
         <description>Vulnerability Summary for the Week of September 14, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_de9a8f70179e1ede2353acda395adfb4</guid>
      </item>
      <item>
         <title>SB09-271: Vulnerability Summary for the Week of September 21, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-271.html</link>
         <description>Vulnerability Summary for the Week of September 21, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_0216d0db37f3f0e989da4f535d1f043f</guid>
      </item>
      <item>
         <title>SB09-278: Vulnerability Summary for the Week of September 28, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-278.html</link>
         <description>Vulnerability Summary for the Week of September 28, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_cb4cbbe365e390bb6aa95ebdccc53f75</guid>
      </item>
      <item>
         <title>SB09-285: Vulnerability Summary for the Week of October 5, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-285.html</link>
         <description>Vulnerability Summary for the Week of October 5, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_8b7e087be24e7c35fe7d3298c29bac1f</guid>
      </item>
      <item>
         <title>SB09-292: Vulnerability Summary for the Week of October 12, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-292.html</link>
         <description>Vulnerability Summary for the Week of October 12, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_11ccdb6ad8e5f7c50fe86a478421a710</guid>
      </item>
      <item>
         <title>SB09-299: Vulnerability Summary for the Week of October 19, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-299.html</link>
         <description>Vulnerability Summary for the Week of October 19, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_6bc8231ce72e0b952102b926c5135dc6</guid>
      </item>
      <item>
         <title>SB09-306: Vulnerability Summary for the Week of October 26, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-306.html</link>
         <description>Vulnerability Summary for the Week of October 26, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_cdfbbb810647d947d964f5ef29e503b2</guid>
      </item>
      <item>
         <title>SB09-313: Vulnerability Summary for the Week of November 2, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-313.html</link>
         <description>Vulnerability Summary for the Week of November 2, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_2f6e89a0f03e83bc9901f7124fa62e0c</guid>
      </item>
      <item>
         <title>SB09-320: Vulnerability Summary for the Week of November 9, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-320.html</link>
         <description>Vulnerability Summary for the Week of November 9, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_31f42011334dbadd55ff732a0b97895a</guid>
      </item>
      <item>
         <title>SB09-327: Vulnerability Summary for the Week of November 16, 2009</title>
         <link>http://www.us-cert.gov/cas/bulletins/SB09-327.html</link>
         <description>Vulnerability Summary for the Week of November 16, 2009</description>
         <guid isPermaLink="false">FJ3awlK33BGj_41qj9zu1g_aec9a49f707344101fdced195b9718be</guid>
      </item>
   </channel>
</rss>
<!-- fe9.pipes.sp1.yahoo.com uncompressed/chunked Fri Nov 27 16:35:55 PST 2009 -->
