You are here

JC3 Medium Impact Assessment Bulletins

August 9, 2012
U-231: Cisco ASA SIP and WebVPN Bugs Let Remote Users Deny Service

Two vulnerabilities were reported in Cisco ASA. A remote or remote authenticated user can cause denial of service conditions.

August 8, 2012
U-230: Sudo on Red Hat Enterprise Linux %postun Symlink Flaw Lets Local Users Gain Elevated Privileges

An updated sudo package that fixes one security issue and several bugs is now available for Red Hat Enterprise Linux 5.

August 7, 2012
U-229: HP Network Node Manager i Input Validation Flaw Permits Cross-Site Scripting Attacks

Potential security vulnerabilities have been identified with HP Network Node Manager i (NNMi) for HP-UX, Linux, Solaris, and Windows. The vulnerabilities could be remotely exploited resulting in cross site scripting (XSS).

August 3, 2012
U-227: bind-dyndb-ldap DN Escaping Flaw Lets Remote Users Deny Service

A vulnerability has been reported in bind-dyndb-ldap, which can be exploited by malicious people to cause a DoS (Denial of Service).

August 2, 2012
U-226: Linux Kernel SFC Driver TCP MSS Option Handling Denial of Service Vulnerability

The Linux kernel is prone to a remote denial-of-service vulnerability.

July 31, 2012
U-224: ISC DHCP Multiple Denial of Service Vulnerabilities

ISC DHCP is prone to multiple denial-of-service vulnerabilities.

July 23, 2012
U-218: Cisco Linksys WMB54G TFTP Command Injection Vulnerability

System access from local network

July 20, 2012
U-217: Red Hat Certificate System Bugs Let Remote Users Conduct Cross-Site Scripting and Denial of Service Attacks

Two vulnerabilities were reported in Red Hat Certificate System. A remote user can conduct cross-site scripting attacks. A remote authenticated user can revoke the CA certificate.

July 13, 2012
U-212: RSA Authentication Manager Flaws Permit Cross-Site and Cross-Frame Scripting and URL Redirection Attacks

RSA Authentication Manager is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input. Attackers can exploit these issues to execute arbitrary script or HTML code, steal cookie-based authentication credentials, and conduct phishing attacks. Other attacks may also be possible.