Report an Incident

If you are a CNI organisation and you have encountered or suspect a cyber threat, please complete and return an Incident Reporting Form.

All incident reports provided to the CCIP are treated in the strictest of confidence. Please see our Confidentiality Charter for more details. Read More


New at CCIP

Current e-Bulletin The CCIP e-Bulletin provides a snapshot of security related news
Read More


New Zealand Government Website

July 2005

The following table includes the Vulnerability Alerts for the month

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
FreeBSD
Incorrect key usage in AES-XCBC-MAC
29/07/05
Opera
Opera Download Dialog Spoofing Vulnerability
29/07/05
MySQL
Eventum PEAR XML_RPC PHP Code Execution Vulnerability
29/07/05
Gentoo
Ethereal: Multiple vulnerabilities
29/07/05
Mandriva
Updated clamav packages fix more vulnerabilities
29/07/05
Debian
ekg -- integer overflows
29/07/05
Sophos
Buffer overflow vulnerability
28/07/05
NISCC
Directory Traversal Issues with the SAP Internet Graphics Server Product
28/07/05
Novell
Buffer overflow in Groupwise client
28/07/05
Secunia
FtpLocate Arbitrary Code Execution Vulnerability
28/07/05
MDaemon
MDaemon Content Filter Directory Traversal Vulnerability
28/07/05
Gentoo
GNU Gadu, CenterICQ, Kadu, EKG, libgadu: Remote code execution in Gadu library
28/07/05
Ethereal
Multiple problems in Ethereal versions 0.8.5 to 0.10.10
28/07/05
Gentoo
Mozilla Suite: Multiple vulnerabilities
28/07/05
Gentoo
Clam AntiVirus: Integer overflows
28/07/05
Sybase
EAServer Buffer Overflow
27/07/05
Gentoo
Kopete: Vulnerability in included Gadu library
27/07/05
Slackware
New kdenetwork packages are available for Slackware 10.0, 10.1, and -current
26/07/05
Secunia
Fedora update for kdenetwork
26/07/05
Slackware
New Mozilla packages are available for Slackware 10.0, 10.1, and -current
26/07/05
ClamAV
ClamAV Library Remte Heap Overflows
26/07/05
Corsaire
SAP Internet Graphics Server traversal issue
26/07/05
Debian
heimdal -- buffer overflow
25/07/05
MySQL
MySQL Multiple Vulnerabilities
25/07/05
Xerox
Xerox MicroServer Web Server Multiple Vulnerabilities
25/07/05
redhat
mozilla security update
25/07/05
Fetchmail
Remote code injection vulnerability in fetchmail
25/07/05
Secunia
Fedora update for mozilla
25/07/05
redhat
kdenetwork security update
25/07/05
redhat
Thunderbird security update
25/07/05
Cisco
Security Agent Vulnerable to Crafted IP Attack
22/07/05
Cisco
CallManager memory handling vulnerabilities
20/07/05
Microsoft
Vulnerability in Remote Desktop Protocol
19/07/05
Debian
Update for krb5
19/07/05
SGI
Advanced Linux Environment Multiple Updates
19/07/05
Debian
New squirrelmail packages fix several vulnerabilities
15/07/05
Debian
New tiff packages fix arbitrary code execution
15/07/05
Debian
New centericq packages fix insecure temporary file creation
15/07/05
CoreLabs
MailEnable Buffer Overflow Vulnerability
15/07/05
Debian
New packages fix remote command execution in phpgroupware
15/07/05
US-CERT
zlib inflate() routine vulnerable to buffer overflow
14/07/05
Cisco
Cisco Security Agent Vulnerable to Crafted IP Attack
14/07/05
Cisco
Cisco ONS 15216 OADM Telnet Denial-of-Service Vulnerability
14/07/05
Debian
New gedit packages fix denial of service
14/07/05
Suse
Update for multiple packages
14/07/05
Sun
Sun Solaris / SEAM Kerberos "krb5_recvauth()" Vulnerability
14/07/05
Sun
Sun Solaris / SEAM Kerberos KDC Vulnerabilities
14/07/05
Secunia
Mozilla Multiple Vulnerabilities
14/07/05
Secunia
Firefox Multiple Vulnerabilities
14/07/05
Oracle
Critical Patch Update July 2005
14/07/05
redhat
krb5 security update - Enterprise Linux 4
14/07/05
redhat
krb5 security update - Enterprise Linux 2.1 and 3
14/07/05
MIT
Double-free in krb5_recvauth
14/07/05
MIT
Buffer overflow, heap corruption in KDC
14/07/05
Apple
Mac OS X 10.4.2 Update
14/07/05
Symantec
Technical Advisory for Veritas NetBackup
13/07/05
Cisco
Cisco CallManager Memory Handling Vulnerabilities
13/07/05
Microsoft
Vulnerability in JView Profiler Could Allow Remote Code Execution
13/07/05
Microsoft
Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution
13/07/05
Microsoft
Vulnerability in Microsoft Word Could Allow Remote Code Execution
13/07/05
Mandriva
Mandriva update for mplayer
13/07/05
Slackware
Slackware update for php
13/07/05
redhat
php security update
11/07/05
redhat
Adobe Acrobat Reader security update
11/07/05
Debian
New ettercap packages fix arbitrary code execution
11/07/05
Debian
New egroupware packages fix remote command execution
11/07/05
Debian
New drupal package fixes multiple vulnerabilities
11/07/05
Debian
New ht packages fix arbitrary code execution
11/07/05
Conectiva
Conectiva update for cacti
08/07/05
Secunia
MailWatch for MailScanner XML-RPC PHP Code Execution
08/07/05
Debian
Update for zlib
08/07/05
Adobe
Adobe Acrobat Reader Buffer Overflow Vulnerability
07/07/05
Gentoo
RealPlayer: Heap overflow vulnerability
07/07/05
Sun
Security Vulnerability in JRE Plug-in
07/07/05
Ubuntu
Update for libapache2-mod-php4/php4-pear
06/07/05
Secunia
PhpWiki XML-RPC PHP Code Execution Vulnerability
05/07/05
Gentoo
Update for PEAR XML_RPC
05/07/05
Trustix
Update for multiple packages
05/07/05
Debian
Spamassassin udpate to fix potential DOS
04/07/05
Microsoft
Internet Explorer "javaprxy.dll" Memory Corruption Vulnerability
04/07/05