Report an Incident

If you are a CNI organisation and you have encountered or suspect a cyber threat, please complete and return an Incident Reporting Form.

All incident reports provided to the CCIP are treated in the strictest of confidence. Please see our Confidentiality Charter for more details. Read More


New at CCIP

Current e-Bulletin The CCIP e-Bulletin provides a snapshot of security related news
Read More


New Zealand Government Website

September 2005

The following table includes the Vulnerability Alerts for the month

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
Debian
clamav -- infinite loop, buffer overflow
30/09/05
redhat
Updated kernel packages available for Red Hat Enterprise Linux 3 Update 6
30/09/05
Cisco
Update - Cisco IOS Firewall Authentication Proxy for FTP and Telnet Sessions Buffer Overflow
30/09/05
TWiki
TWiki INCLUDE function allows arbitrary shell command execution
29/09/05
Gentoo
PHP: Vulnerabilities in included PCRE and XML-RPC libraries
29/09/05
SGI
Advanced Linux Environment 3 Security Update #47
29/09/05
Mandriva
Updated mozilla packages fix multiple vulnerabilities
28/09/05
redhat
Update for HelixPlayer
28/09/05
Slackware
Update for mozilla
28/09/05
FrSIRT
Realplayer and Helix Player Remote Format String Vulnerability
28/09/05
SCO
OpenServer 6.0.0 : TCP Remote ICMP Denial Of Service Vulnerabilities
26/09/05
Hewlett-Packard
System Management Homepage (v2.0.x) Denial of Service (DoS) and XSS
26/09/05
Debian
python2.1 -- integer overflow
26/09/05
redhat
firefox security update
26/09/05
redhat
mozilla security update
26/09/05
Apple
Mac OS 10.X Security Updates
23/09/05
Mozilla
Firefox 1.0.7 is a security and stability release
22/09/05
Mandriva
Update for clamav
22/09/05
x.org
Multiple vulnerabilities have been reported in libXpm
22/09/05
Sun
Vulnerability in the Xsun and Xorg Servers
21/09/05
Secunia
Firefox Command Line URL Shell Command Injection
21/09/05
Altervista
CuteNews "Client-IP" PHP Code Injection Vulnerability
20/09/05
SourceForge
ClamAV UPX and FSG Handling Vulnerabilities
20/09/05
Gentoo
Mozilla Firefox: Buffer overflow
20/09/05
SUSE
Update for evolution
19/09/05
Sun
Vulnerability in Sun Java System Application Server
15/09/05
Apple
Apple Mac OS X update for Java
15/09/05
Debian
Squid - several vulnerabilities
14/09/05
Sun
DoS Vunerabilities in Sun Java Web Proxy Server
14/09/05
Ubuntu
Update for mozilla-browser/mozilla-firefox/mozilla-thunderbird
13/09/05
redhat
Update for mozilla
13/09/05
redhat
Update for firefox
13/09/05
Cisco
Cisco CSS SSL Authentication Bypass Vulnerability
12/09/05
Secunia
Netscape URL Domain Name Buffer Overflow
12/09/05
Secunia
Mozilla URL Domain Name Buffer Overflow
12/09/05
PBLang
Local File Inclusion and PHP Code Injection
09/09/05
Cisco
IOS Firewall Authentication Proxy for FTP and Telnet Sessions Buffer Overflow
09/09/05
SGI
Advanced Linux Environment Multiple Updates
09/09/05
Ubuntu
Updates for Multiple Packages
08/09/05
Hewlett-Packard
HP OpenView Event Correlation Services (OV ECS) Remote Unauthorized Privileged
07/09/05
Hewlett-Packard
HP OpenView Network Node Manager (OV NNM) Remote Unauthorized Privileged Access
07/09/05
Xforce
OpenSSH GatewayPorts security bypass
07/09/05
redhat
httpd security update
07/09/05
Gentoo
OpenTTD: Format string vulnerabilities
07/09/05
MAXdev
MD-Pro Multiple Vulnerabilities
07/09/05
SuSE
Kernel multiple security problems
02/09/05
Microsoft
Windows Firewall Exception May Not Display in the User Interface
02/09/05
Gentoo
phpWebSite: Arbitrary command execution through XML-RPC and SQL injection
02/09/05
phpWebSite
phpWebSite PEAR XML_RPC Nested XML Tags PHP Code Execution
02/09/05
Hewlett-Packard
HP-UX Java Web Start remote unauthorized privileged access
01/09/05
Hewlett-Packard
HP-UX Java Runtime Environment (JRE) may allow untrusted applet to elevate privileges
01/09/05
Slackware
Slackware update for gaim
01/09/05
Slackware
Slackware update for php
01/09/05
SuSE
SUSE update for php4/php5
01/09/05
Gentoo
phpGroupWare: Multiple vulnerabilities
01/09/05
Debian
php4 -- several vulnerabilities
01/09/05