Report an Incident

If you are a CNI organisation and you have encountered or suspect a cyber threat, please complete and return an Incident Reporting Form.

All incident reports provided to the CCIP are treated in the strictest of confidence. Please see our Confidentiality Charter for more details. Read More


New at CCIP

Current e-Bulletin The CCIP e-Bulletin provides a snapshot of security related news
Read More


New Zealand Government Website

November 2009

The following table includes the Vulnerability Alerts for the month.

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
Canonical Ltd.
Ubuntu update for qemu-kvm
05/12/09
Red Hat
Red Hat update for kernel
05/12/09
Debian
Debian update for gforge
05/12/09
Sun Microsystems
Sun Management Center XML Library Multiple Vulnerabilities
04/12/09
Sun Microsystems
Sun Solaris GNU tar Archive Parsing Vulnerabilities
04/12/09
Debian
Debian update for request-tracker
04/12/09
Apple
Apple Mac OS X update for Java
04/12/09
Sun Microsystems
Sun Solaris libexpat Library XML Parsing Denial of Service
04/12/09
Sun Microsystems
Sun Solaris wget SSL Certificate NULL Character Processing Vulnerability
04/12/09
Blue Coat Systems
Blue Coat ProxySG TCP Implementation Denial of Service Vulnerabilities
04/12/09
Adobe Systems
Adobe Illustrator Encapsulated Postscript Parsing Vulnerability
04/12/09
FreeBSD Project
FreeBSD Dynamic Linker Privilege Escalation Vulnerability
04/12/09
FreeBSD Project
FreeBSD freebsd-update Insecure Directory Permissions
04/12/09
FreeBSD Project
FreeBSD OpenSSL TLS Session Renegotiation Plaintext Injection Vulnerability
04/12/09
Novell
SUSE update for kernel
03/12/09
Slackware Linux
Slackware update for bind
03/12/09
Debian
Debian update for openldap
03/12/09
Sun Microsystems
Sun Products NSS TLS Session Renegotiation Plaintext Injection Vulnerability
03/12/09
Sun Microsystems
Sun Java System Portal Server Gateway Cross-Site Scripting Vulnerabilities
03/12/09
IBM
IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
03/12/09
Red Hat
Fedora update for wget
03/12/09
Red Hat
Fedora update for libsndfile
03/12/09
Novell
SUSE update for bind
03/12/09
Novell
Novell eDirectory NDS Verb 0x1 Request Integer Overflow Vulnerability
03/12/09
HP
HP NonStop Server Privilege Escalation
02/12/09
Sun Microsystems
Sun Solaris Adobe Reader Multiple Vulnerabilities
02/12/09
Red Hat
Fedora update for cups
02/12/09
Research In Motion
BlackBerry Products PDF Distiller Unspecified Vulnerabilities
02/12/09
Red Hat
Fedora update for roundcubemail
02/12/09
Gentoo
Gentoo update for openssl
02/12/09
Red Hat
Red Hat update for bind
02/12/09
Red Hat
Red Hat update for dstat
02/12/09
IBM
IBM WebSphere Portal Unspecified Security Issue and Cross-Site Scripting
02/12/09
Red Hat
Fedora update for php-pear-Mail
02/12/09
FreeBSD Project
FreeBSD Dynamic Linker Privilege Escalation Vulnerability
02/12/09
Red Hat
Fedora update for cups
01/12/09
Red Hat
Red Hat update for mod_jk
01/12/09
Red Hat
Red Hat update for tomcat
01/12/09
Red Hat
Red Hat update for xerces-j2
01/12/09
Debian
Debian update for wireshark
30/11/09
Red Hat
Fedora update for bind
30/11/09
Red Hat
Fedora update for tomcat6
30/11/09
Canonical Ltd.
Ubuntu update for php5
28/11/09
Gentoo
Gentoo update for PEAR-Net_Traceroute
27/11/09
SugarCRM
SugarCRM Multiple Vulnerabilities
27/11/09
Debian
Debian update for poppler
27/11/09
Debian
Debian update for php5
27/11/09
Red Hat
Fedora update for php-pear-Net-Traceroute
27/11/09
Sun Microsystems
Sun Solaris 8 LDAP Client Configuration Cache Daemon Denial of Service
27/11/09
Sun Microsystems
Sun Solaris LDAP Client Configuration Cache Daemon Denial of Service
27/11/09
HP
HP-UX update for OpenSSL
27/11/09
IBM
IBM DB2 "DASAUTO" Command Privilege Escalation
27/11/09
Gentoo
Gentoo update for dstat
27/11/09
Sun Microsystems
Sun Solaris BIND DNS Cache Poisoning Vulnerability
27/11/09
Gentoo
Gentoo update for wireshark
26/11/09
Red Hat
Fedora update for php-pear-Net-Ping
26/11/09
Gentoo
Gentoo update for uw-imap and c-client
26/11/09
GNU Project
libtool libltdl Library Search Path Privilege Escalation Security Issue
26/11/09
GNU Project
libtool libltdl Library Search Path Privilege Escalation Security Issue
26/11/09
Microsoft
Internet Explorer PDF Export Information Disclosure
26/11/09
Canonical Ltd.
Ubuntu update for libvorbis
26/11/09
Red Hat
Red Hat update for kdelibs
26/11/09
Sun Microsystems
Sun Solaris sshd Timeout Mechanism Denial of Service
25/11/09
Microsoft
Microsoft Windows Media Products Two Vulnerabilities
25/11/09
Internet Software Consortium (ISC)
ISC BIND DNSSEC Cache Poisoning Vulnerability
25/11/09
Debian
Debian update for libvorbis
25/11/09
SuSE
SUSE Update for Multiple Packages
25/11/09
Debian
Debian update for php-mail
25/11/09
Red Hat
Fedora update for snort
24/11/09
Red Hat
Fedora update for asterisk
24/11/09
Sun Microsystems
Sun Solaris OpenSSL TLS Session Renegotiation Plaintext Injection Vulnerability
24/11/09
Opera Software
Opera Multiple Vulnerabilities
24/11/09
MySQL
MySQL Denial of Service and Client Certificate Verification Vulnerabilities
24/11/09
Opera Software
Opera Floating Point Number Processing Memory Corruption
24/11/09
MySQL
MySQL Denial of Service and Client Certificate Verification Vulnerabilities
24/11/09
MySQL
MySQL Denial of Service and Client Certificate Verification Vulnerabilities
24/11/09
VMware
VMware ESXi update for ntp
24/11/09
MySQL
MySQL MyISAM Table Privilege Check Bypass
24/11/09
Debian
Debian update for gforge
24/11/09
Microsoft
Internet Explorer Layout Handling Memory Corruption Vulnerability
23/11/09
HP
HP Operations Manager Undocumented Account
23/11/09
HP
HP Operations Manager Unauthorised Access
21/11/09
IBM
IBM Rational Products Cross-Site Scripting Vulnerabilities
21/11/09
Opera Software
Opera Floating Point Number Processing Memory Corruption
21/11/09
Novell
SUSE update for java-1_6_0-sun
20/11/09
Cisco
Cisco VPN Client "cvpnd" Service Local Denial of Service
20/11/09
Canonical Ltd.
Ubuntu update for apache2
20/11/09
HP
HP Color LaserJet Printers Security Bypass and Denial of Service
20/11/09
Sun Microsystems
Sun Solaris Samba Information Disclosure and Denial of Service
19/11/09
Sun Microsystems
Sun Solaris 9 Samba Information Disclosure and Denial of Service
19/11/09
IBM
IBM solidDB Database Service Denial of Service
19/11/09
Nortel Networks
Nortel Alteon OS Script Insertion and Cross-Site Request Forgery
19/11/09
Mozilla Organization
Bugzilla Alias Information Leak Weakness
19/11/09
Red Hat
Red Hat update for cups
19/11/09
Red Hat
Red Hat update for kernel
19/11/09
Red Hat
Fedora update for proftpd
19/11/09
Red Hat
Red Hat update for kernel
19/11/09
Red Hat
Fedora update for wordpress
19/11/09
SuSE
SUSE update for openssl
19/11/09
Kaspersky Labs
Kaspersky Anti-Virus 2010 kl1.sys Denial of Service Vulnerability
18/11/09
Debian
Debian update for libgd2
18/11/09
Gentoo
Gentoo updates for sun-jre-bin, sun-jdk, blackdown-jre, blackdown-jdk, and emul-linux-x86-java
18/11/09
HP
HP OpenView Network Node Manager Database Service Denial of Service
18/11/09
Debian
Debian update for gnutls13 and gnutls26
18/11/09
HP
HP-UX update for BIND
18/11/09
Debian
Debian update for apache2
17/11/09
Red Hat
Red Hat update for samba3x
17/11/09
Red Hat
Red Hat update for java-1.6.0-openjdk
17/11/09
HP
HP Discovery & Dependency Mapping Inventory Arbitrary Code Execution
17/11/09
Slackware Linux
Slackware update for openssl
17/11/09
SuSE
SUSE update for kernel
17/11/09
Red Hat
Fedora update for qt
17/11/09
Canonical Ltd.
Ubuntu update for openjdk-6
16/11/09
Red Hat
Fedora update for java-1.6.0-openjdk
16/11/09
IBM
IBM OS/400 HTTP Server Cross-Site Scripting and Denial of Service
16/11/09
Red Hat
Fedora update for asterisk
16/11/09
Sun Microsystems
Sun VirtualBox Guest Additions Denial of Service Vulnerability
16/11/09
Microsoft
Microsoft Windows SMB Response Denial of Service Vulnerability
14/11/09
IBM
IBM AIX "syscall" Buffer Overflow Vulnerability
14/11/09
Cisco
Linksys WAP4400N Association Request Denial of Service
14/11/09
IBM
IBM WebSphere Application Server Cross-Site Scripting Vulnerability
14/11/09
IBM
IBM HTTP Server Apache Portable Runtime Integer Overflows
14/11/09
IBM
IBM HTTP Server Multiple Vulnerabilities
14/11/09
IBM
IBM WebSphere Application Server Multiple Vulnerabilities
14/11/09
Canonical Ltd.
Ubuntu update for openldap
13/11/09
SuSE
SUSE update for kernel
13/11/09
Red Hat
Fedora update for texlive
13/11/09
Red Hat
Red Hat update for java-1.6.0-ibm
13/11/09
Google
Google Chrome Cross-Origin Resource Sharing Security Bypass
13/11/09
Avaya
Avaya Products Linux Kernel Multiple Vulnerabilities
13/11/09
McAfee
McAfee Network Security Manager Cross-Site Scripting Vulnerabilities
13/11/09
Sun Microsystems
Sun Solaris 8 IP Module and STREAMS Framework Denial of Service
12/11/09
Sun Microsystems
Sun Solaris Pidgin ICQ Message Denial of Service Weakness
12/11/09
Sun Microsystems
Sun Solaris libpng Interlaced Images Information Disclosure
12/11/09
SuSE
SUSE update for kernel
12/11/09
Red Hat
Red Hat update for httpd
12/11/09
Red Hat
Red Hat update for httpd
12/11/09
Apple
Apple Safari Multiple Vulnerabilities
12/11/09
Red Hat
Fedora update for dhcp
12/11/09
Red Hat
Fedora update for libvorbis
12/11/09
Red Hat
Fedora update for wordpress-mu
12/11/09
Red Hat
Fedora update for ocaml-camlimages
12/11/09
Red Hat
Red Hat update for java-1.5.0-sun
11/11/09
NetGear
Netgear WNDAP330 Management Frame Denial of Service
11/11/09
Red Hat
Fedora update for ocaml-mysql
11/11/09
Red Hat
Fedora update for ocaml-postgresql
11/11/09
Citrix Systems
Citrix XenApp Online Plug-in / Receiver Certificate Spoofing Vulnerability
11/11/09
Citrix Systems
Citrix Secure Gateway TLS Session Renegotiation Plaintext Injection
11/11/09
HP
HP NonStop Server Unauthorised Data Access
11/11/09
Canonical Ltd.
Ubuntu update for qt
11/11/09
Adobe Systems
Adobe Photoshop Elements Active File Monitor Service Privilege Escalation
11/11/09
Red Hat
Red Hat update for 4Suite
11/11/09
Canonical Ltd.
Ubuntu update for cups
11/11/09
IBM
IBM BladeCenter Advanced Management Module Unspecified Vulnerabilities
11/11/09
Microsoft
Microsoft Windows Win32k Kernel-Mode Driver Multiple Vulnerabilities
11/11/09
Microsoft
Microsoft Windows Win32k Kernel-Mode Driver Privilege Escalation
11/11/09
Microsoft
Windows Web Services on Devices API Memory Corruption Vulnerability
11/11/09
Microsoft
Microsoft Office Word File Information Memory Corruption Vulnerability
11/11/09
Microsoft
Microsoft Excel Multiple Vulnerabilities
11/11/09
Microsoft
Microsoft Windows Active Directory Denial of Service
11/11/09
Microsoft
Microsoft Windows License Logging Server Buffer Overflow
11/11/09
Red Hat
Red Hat update for java-1.6.0-sun
11/11/09
SuSE
SUSE Update for Multiple Packages
11/11/09
Debian
Debian update for cups
11/11/09
Oracle
Oracle Document Capture EasyMail ActiveX Control Vulnerabilities
11/11/09
Apple
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
11/11/09
Red Hat
Red Hat update for tomcat
10/11/09
HP
HP-UX update for JRE / JDK
10/11/09
Red Hat
Red Hat update for libvorbis
10/11/09
IBM
IBM Lotus Domino Web Access Cross-Site Scripting Vulnerability
10/11/09
IBM
IBM Java 6 Multiple Vulnerabilities
10/11/09
Debian
Debian update for pidgin
10/11/09
Sun Microsystems
Sun Solaris mod_perl Two Vulnerabilities
10/11/09
Debian
Debian update for linux-2.6
10/11/09
Debian
Debian update for nspr
10/11/09
Debian
Debian update for drupal6
10/11/09
Debian
Debian update for linux-2.6
07/11/09
Debian
Debian update for linux-2.6.24
07/11/09
Gentoo
Gentoo update for horde
07/11/09
Red Hat
Fedora update for kernel
07/11/09
Red Hat
Fedora update for kernel
07/11/09
Canonical Ltd.
Ubuntu update for libgd2
07/11/09
Red Hat
Fedora update for alienarena-data
07/11/09
Canonical Ltd.
Ubuntu update for libgd2
07/11/09
GNU Project
GnuTLS TLS Session Renegotiation Plaintext Injection Vulnerability
07/11/09
Red Hat
Fedora update for alienarena
07/11/09
Debian
Debian update for linux-2.6
07/11/09
Canonical Ltd.
Ubuntu update for libhtml-parser-perl
07/11/09
Apple
Apple Mac OS X "ptrace()" Denial of Service Vulnerability
07/11/09
Citrix Systems
Citrix NetScaler / Access Gateway Denial of Service Vulnerability
06/11/09
Google
Google Chrome Two Vulnerabilities
06/11/09
IBM
IBM AIX PowerHA Cluster Management Data Manipulation
06/11/09
Red Hat
Fedora update for python-4Suite-XML
06/11/09
IBM
IBM OS/400 HTTP Server mod_proxy Denial of Service
05/11/09
Sun Microsystems
Sun Virtual Desktop Infrastructure VirtualBox Security Bypass
05/11/09
Red Hat
Fedora update for rt3
05/11/09
Debian
Debian update for typo3-src
05/11/09
HP
HP Power Manager Arbitrary Code Execution Vulnerability
05/11/09
Novell
SUSE update for MozillaFirefox
05/11/09
Red Hat
Fedora update for firefox
05/11/09
Red Hat
Fedora update for xulrunner
05/11/09
Red Hat
Fedora update for mimetex
05/11/09
Red Hat
Fedora update for wireshark
05/11/09
Red Hat
Fedora update for squidGuard
05/11/09
Red Hat
Fedora update for PyXML
05/11/09
Red Hat
Red Hat update for kernel-rt
05/11/09
Red Hat
Fedora update for expat
05/11/09
Red Hat
Red Hat update for kernel
05/11/09
Red Hat
Red Hat update for kernel
05/11/09
Red Hat
Red Hat update for kernel
05/11/09
IBM
IBM Tivoli Storage Manager Client Multiple Vulnerabilities
05/11/09
Research In Motion
BlackBerry Desktop Software Lotus Notes Intellisync Arbitrary Code Execution
05/11/09
Sun Microsystems
Sun Solaris PostgreSQL Privilege Escalation and Denial of Service
04/11/09
Sun Microsystems
Sun Solaris XScreenSaver Pop-up Windows Security Bypass
04/11/09
Sun Microsystems
Sun Solaris Sockets Direct Protocol Driver Denial of Service
04/11/09
Sun Microsystems
Sun Solaris 8 "w" Utility Privilege Escalation
04/11/09
Sun Microsystems
Sun Solaris FreeType Multiple Vulnerabilities
04/11/09
Sun Microsystems
Sun Solaris Adobe Reader Multiple Vulnerabilities
04/11/09
Red Hat
Red Hat update for wget
04/11/09
Sun Microsystems
Sun Solaris Trusted Extensions XScreenSaver Security Bypass
04/11/09
Sun Microsystems
Sun Java JDK / JRE Multiple Vulnerabilities
04/11/09
Adobe Systems
Adobe Shockwave Player Multiple Vulnerabilities
04/11/09