Report an Incident

If you are a CNI organisation and you have encountered or suspect a cyber threat, please complete and return an Incident Reporting Form.

All incident reports provided to the CCIP are treated in the strictest of confidence. Please see our Confidentiality Charter for more details. Read More


New at CCIP

Current e-Bulletin The CCIP e-Bulletin provides a snapshot of security related news
Read More


New Zealand Government Website

August 2008

The following table includes the Vulnerability Alerts for the month.

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
RedHat
update for ipsec-tools
29/08/08
Debian
Update for tiff
29/08/08
Million
Pixel Ad Script "id_cat" SQL Injection
29/08/08
RedHat
update for kernel
29/08/08
KM
Scanner File Utility Multiple Vulnerabilities
29/08/08
IBM
DB2 CLR Stored Procedures Unspecified Vulnerability
29/08/08
HP
Enterprise Discovery Unspecified Privilege Escalation
28/08/08
SUSE
Update for IBMJava2-JRE and IBMJava2-SDK
26/08/08
Debian
Update for libxml2
26/08/08
SUSE
Update for IBM Java
26/08/08
SUSE
Update for Sun Java
26/08/08
Ruby
REXML Denial of Service Vulnerability
26/08/08
RedHat
update for libxml2
25/08/08
Trend Micro Products
Web Management Authentication Bypass
25/08/08
RedHat
Update for Tampered OpenSSH Packages
25/08/08
Anzio
Web Print Object (WePO) ActiveX Component "mainurl" BufferOverflow
22/08/08
Opera
Multiple Vulnerabilities
22/08/08
Secunia
Programs Rating "id" SQL Injection Vulnerability
22/08/08
Avaya
CMS Solaris "snoop" Multiple Vulnerabilities
22/08/08
Secunia
Viral Marketing Script "id" SQL Injection Vulnerability
22/08/08
Secunia
Ad-Exchange Script "id" SQL Injection Vulnerability
22/08/08
Secunia
URL Rotator Script "id" SQL Injection Vulnerability
22/08/08
Secunia
Short Url & Url Tracker Script "id" SQL Injection Vulnerability
21/08/08
Secunia
Forced Matrix Script "id" SQL Injection Vulnerability
21/08/08
SUSE
Update for python
21/08/08
SFS
Affiliate Directory "id" SQL Injection Vulnerability
21/08/08
MailScan For Mail Servers
Web Administration Interface Multiple Vulnerabilities
21/08/08
IBM
WebSphere Portal Server Authentication Bypass
20/08/08
Symantec
Veritas Storage Foundation NULL NTLMSSP Authentication Security Bypass
20/08/08
Drupal
Multiple Vulnerabilities
20/08/08
Red Hat
update for Red Hat Network Satellite Server
20/08/08
VLC
Media Player TTA Processing Integer Overflow
20/08/08
Reflection
For Secure IT Multiple Vulnerabilities
20/08/08
E-Shop
Shopping Cart "cid" SQL Injection Vulnerability
18/08/08
xine-lib
Multiple Vulnerabilities
18/08/08
rPath
Update for freetype
18/08/08
rPath
Update for idle and python
18/08/08
Red Hat
Network Satellite Server Update for Solaris Client
18/08/08
Yelp
Invalid URI Format String Vulnerability
18/08/08
Red Hat
Network Satellite Server Update for Sun Java / IBM JavaRuntime
18/08/08
HP
Tru64 UNIX BIND Query Port DNS Cache Poisoning
18/08/08
HP
TCP/IP Services for OpenVMS BIND DNS Cache Poisoning
18/08/08
Secunia
Microsoft Visual Studio Masked Edit Control "Mask" Buffer Overflow
18/08/08
HP-UX
Ftpd Unspecified Privileged Access Vulnerability
15/08/08
HP-UX
Ftpd Unspecified Privileged Access Vulnerability
15/08/08
Sun
Java System Web Proxy Server FTP Subsystem Denial of Service
15/08/08
VMware
ESXi OpenSSL Vulnerabilities
15/08/08
VMware
Updates for OpenSSL, net-snmp, and perl
15/08/08
Joomla
"token" Password Change Vulnerability
15/08/08
Ventrilo
Server Denial of Service Vulnerability
14/08/08
PHP
Realty "docID" SQL Injection Vulnerability
14/08/08
RedHat
update for dnsmasq
14/08/08
CA Products
kmxfw.sys Privilege Escalation and Denial of Service
14/08/08
Yamaha
RT Series Routers DNS Cache Poisoning
13/08/08
PHP
Multiple Vulnerabilities
13/08/08
Microsoft
Windows Color Management System Buffer Overflow
13/08/08
Microsoft
Office Filters Multiple Vulnerabilities
13/08/08
Microsoft
Windows Messenger ActiveX Control Vulnerability
13/08/08
Microsoft
Office PowerPoint Multiple Vulnerabilities
13/08/08
Microsoft
Internet Explorer Multiple Vulnerabilities
13/08/08
Microsoft
Office Excel Multiple Vulnerabilities
13/08/08
Gentoo
Update for acroread
13/08/08
Gentoo
Update for clamav
13/08/08
Ruby
Multiple Vulnerabilities
13/08/08
Ubuntu
Update for xine-lib
12/08/08
TrendMicro Products
ObjRemoveCtrl Class Buffer Overflows
12/08/08
SUSE
Update for Multiple Packages
11/08/08
SUSE
Update for Multiple Packages
11/08/08
e107
Download.php "extract()" Vulnerability
11/08/08
Fedora
Update for poppler
11/08/08
Fedora
Update for thunderbird
11/08/08
Fedora
Update for libxslt
11/08/08
Gentoo
Update for libxslt
11/08/08
Free
Hosting Manager Insecure Cookie Handling Vulnerability
11/08/08
Contenido
Unspecified File Inclusion Vulnerabilities
08/08/08
Webex
Meeting Manager WebexUCFObject ActiveX Control Buffer Overflow
08/08/08
Gentoo
Update for wireshark
08/08/08
Gentoo
Update for Mozilla products
08/08/08
Gentoo
Update for xine-lib
08/08/08
rPath
Update for cups
08/08/08
Sun
Solaris "snoop" Command Execution Vulnerability
08/08/08
rPath
Update for gaim
08/08/08
Secunia
LoveCMS Multiple Vulnerabilities
08/08/08
Slackware
Update for python
07/08/08
Astaro
Security Gateway DNS Cache Poisoning
07/08/08
Winamp
"NowPlaying" Unspecified Vulnerability
07/08/08
E-Store
Kit "pid" SQL Injection Vulnerability
06/08/08
GIT
Pathname Processing Multiple Buffer Overflows
06/08/08
Ubuntu
Update for libxslt
06/08/08
Sun
Solaris Adobe Reader Multiple Vulnerabilities
06/08/08
Apache
Tomcat 6 Cross-Site Scripting and Security Bypass
06/08/08
Apache
Tomcat Cross-Site Scripting and Security Bypass
06/08/08
Gentoo
Update for python
05/08/08
Secunia
E.Z. Poll "Username" and "Password" SQL Injection Vulnerabilities
05/08/08
Ubuntu
Update for python
05/08/08
Python
Multiple Vulnerabilities
05/08/08
Gentoo
Update for pan
04/08/08
Debian
Update for dnsmasq
04/08/08
Red Hat
update for java-1.5.0-ibm
04/08/08
libxslt
"crypto:rc4_encrypt" and "crypto:rc4_decrypt" Buffer Overflow Vulnerabilities
04/08/08
CA
ARCserve Backup for Laptops and Desktops LGServer Service IntegerUnderflow
04/08/08
Avaya
Communication Manager Perl Regular Expressions Vulnerability
04/08/08
Red Hat
Extras and Supplementary RealPlayer Vulnerability
04/08/08
Debian
Update for libxslt
04/08/08
Red Hat
update for libxslt
04/08/08
Apple
Mac OS X Security Update Fixes Multiple Vulnerabilities
04/08/08
SUSE
Update for MozillaFirefox
04/08/08
Debian
Update for cupsys
04/08/08
Fedora
Update for pdns-recursor
04/08/08
rPath
Update for openssl
04/08/08
Debian
Update for newsx
04/08/08
Blue Coat
K9 Web Protection Multiple Buffer Overflow Vulnerabilities
01/08/08