Report an Incident

If you are a CNI organisation and you have encountered or suspect a cyber threat, please complete and return an Incident Reporting Form.

All incident reports provided to the CCIP are treated in the strictest of confidence. Please see our Confidentiality Charter for more details. Read More


New at CCIP

Current e-Bulletin The CCIP e-Bulletin provides a snapshot of security related news
Read More


New Zealand Government Website

December 2009

The following table includes the Vulnerability Alerts for the month.

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
Sun Microsystems
Sun Java System Web Server Multiple Vulnerabilities
05/01/10
Red Hat
Fedora update for slim
05/01/10
Red Hat
Fedora update for automake
05/01/10
Red Hat
Fedora update for cacti
05/01/10
Gentoo
Gentoo update for adobe-flash
05/01/10
Debian
Debian update for expat
05/01/10
F5 Networks
F5 BIG-IP DNSSEC Cache Poisoning Vulnerability
31/12/09
Microsoft
Microsoft IIS ASP Multiple Extensions Security Bypass
30/12/09
Red Hat
Fedora update for gcc
30/12/09
GNU Project
GNU GCC libtool Search Path Privilege Escalation Security Issue
30/12/09
Debian
Debian update for libtool
30/12/09
Red Hat
Fedora update for libtool
30/12/09
Adobe Systems
Adobe Reader/Acrobat Memory Corruption Vulnerabilities
30/12/09
Debian
Debian update for aria2
29/12/09
Red Hat
Fedora update for proftpd
29/12/09
Red Hat
Fedora update for cacti
29/12/09
IBM
IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
28/12/09
Sun Microsystems
Sun Java System Directory Server Multiple Vulnerabilities
28/12/09
Sun Microsystems
Sun Solaris PostgreSQL Two Vulnerabilities
28/12/09
Microsoft
Microsoft IIS ASP Multiple Extensions Security Bypass
25/12/09
Red Hat
Red Hat update for java-1.6.0-ibm
24/12/09
Red Hat
Fedora update for wireshark
24/12/09
Debian
Debian update for unbound
24/12/09
F5 Networks
F5 BIG-IP ASM / PSM Buffer Overflow Vulnerability
24/12/09
Debian
Debian update for kvm
24/12/09
SuSE
SUSE update for kernel
23/12/09
SuSE
SUSE update for MozillaFirefox
23/12/09
Novell
SUSE update for flash-player
23/12/09
Debian
Debian update for bind9
23/12/09
IBM
IBM SDK for Java TLS Session Renegotiation Plaintext Injection
21/12/09
Canonical Ltd.
Ubuntu update for Firefox and Xulrunner
21/12/09
Canonical Ltd.
Ubuntu update for Firefox and Xulrunner
21/12/09
Adobe Systems
Adobe Flash Media Server Two Vulnerabilities
21/12/09
Gentoo
Gentoo update for rails
21/12/09
Canonical Ltd.
Ubuntu update for redhat-cluster
21/12/09
Debian
Debian update for ganeti
21/12/09
Debian
Debian update for acpid
21/12/09
Nortel Networks
Nortel CS1000 NTP Mode 7 Request Denial of Service
21/12/09
D-Link Systems
D-Link DIR-615 "apply.cgi" Security Bypass Vulnerability
19/12/09
IBM
IBM AIX "qosmod" and "qoslist" Buffer Overflow Vulnerabilities
19/12/09
IBM
IBM WebSphere Application Server Feature Pack for CEA Hijacking Vulnerability
19/12/09
Red Hat
Fedora update for rubygem-actionpack
18/12/09
Red Hat
Fedora update for postgresql
18/12/09
Red Hat
Fedora update for drupal
18/12/09
Red Hat
Fedora update for gtk2
18/12/09
Red Hat
Fedora update for httpd
18/12/09
Red Hat
Fedora update for firefox
18/12/09
Red Hat
Fedora update for seamonkey
18/12/09
Red Hat
Fedora update for xulrunner
18/12/09
HP
HP Storage Data Protector Buffer Overflow Vulnerabilities
18/12/09
Red Hat
Fedora update for coreutils
18/12/09
Red Hat
Fedora update for tomcat-native
18/12/09
Cisco
Cisco ASA WebVPN Bookmark URLs Security Bypass
18/12/09
IBM
IBM Rational ClearQuest CQWeb Information Disclosure Vulnerability
18/12/09
Novell
Novell eDirectory Cross-Site Scripting Vulnerability
18/12/09
Debian
Debian update for network-manager
17/12/09
Debian
Debian update for cacti
17/12/09
Kaspersky Labs
Kaspersky Products Insecure Default Directory Permissions
17/12/09
GNU Project
GNU Automake "make dist" / "make distcheck" Insecure Directory Permissions
17/12/09
Debian
Debian update for xulrunner
17/12/09
Citrix Systems
Citrix NetScaler / Access Gateway TCP Implementation Denial of Service
17/12/09
IBM
IBM WebSphere Application Server JAAS-J2C Authentication Data Disclosure
17/12/09
Red Hat
Red Hat update for xpdf
17/12/09
Red Hat
Red Hat update for gpdf
17/12/09
Sun Microsystems
Sun Solaris Adobe Flash Player Multiple Vulnerabilities
17/12/09
Mozilla Organization
Mozilla Thunderbird JavaScript Engine Memory Corruption
17/12/09
Sun Microsystems
Sun Solaris 10 "mod_perl" Cross-Site Scripting Vulnerability
17/12/09
Sun Microsystems
Sun Solaris "mod_perl" Cross-Site Scripting Vulnerability
17/12/09
Sun Microsystems
Sun Solaris Gimp BMP Image Parsing Integer Overflow Vulnerability
17/12/09
Red Hat
Red Hat update for Sun Java Runtime
17/12/09
HP
HP OpenView Network Node Manager Buffer Overflow Vulnerabilities
17/12/09
17/12/09
VMware
VMware Products Update for Multiple Packages
17/12/09
IBM
IBM WebSphere Application Server Multiple Vulnerabilities
17/12/09
VMware
VMware vCenter Lab Manager WebWorks Help Cross-Site Scripting
17/12/09
Red Hat
Red Hat update for kdegraphics
17/12/09
Debian
Debian update for expat
17/12/09
Debian
Debian update for asterisk
17/12/09
Juniper Networks
Juniper Networks Secure Access Web VPN Same Origin Policy Bypass
17/12/09
Nortel Networks
Nortel CallPilot Web VPN Same Origin Policy Bypass
17/12/09
Citrix Systems
Citrix Access Gateway Web VPN Same Origin Policy Bypass
17/12/09
Research In Motion
BlackBerry Products PDF Distiller Unspecified Vulnerabilities
17/12/09
Red Hat
Red Hat update for seamonkey
16/12/09
Debian
Debian update for firefox-sage
16/12/09
Red Hat
Red Hat update for firefox
16/12/09
IBM
IBM WebSphere Application Server Cross-Site Request Forgery
16/12/09
Red Hat
Fedora update for merkaartor
16/12/09
Red Hat
Red Hat update for kernel
16/12/09
Red Hat
Red Hat update for kernel
16/12/09
Red Hat
Red Hat update for kernel
16/12/09
Mozilla Organization
Mozilla Firefox Multiple Vulnerabilities
16/12/09
Mozilla Organization
Mozilla SeaMonkey Multiple Vulnerabilities
16/12/09
Adobe Systems
Adobe Reader/Acrobat "Doc.media.newPlayer()" Memory Corruption
16/12/09
Sun Microsystems
Sun Ray Server Software Desktop Session Handling Security Issue
15/12/09
Sun Microsystems
Sun Multiple Products XML Parsing Denial of Service
15/12/09
F5 Networks
F5 Products TLS Session Renegotiation Plaintext Injection Vulnerability
15/12/09
F5 Networks
F5 Products TLS Session Renegotiation Plaintext Injection Vulnerability
15/12/09
Sun Microsystems
Sun Solaris Gnome PDF Viewer Multiple Vulnerabilities
15/12/09
Red Hat
Fedora update for memcached
15/12/09
Red Hat
Fedora update for asterisk
15/12/09
Red Hat
Fedora update for rt3
15/12/09
Red Hat
Fedora update for ruby
15/12/09
Red Hat
Fedora update for moodle
15/12/09
GNU Project
GNU Core Utilities "distcheck" Insecure Temporary Directory Security Issue
15/12/09
Red Hat
Fedora update for mysql
15/12/09
Debian
Debian update for webkit
14/12/09
Red Hat
Fedora update for ntp
14/12/09
Red Hat
Fedora update for kernel
14/12/09
Debian
Debian update for php-net-ping
14/12/09
Mozilla Organization
Sunbird Floating Point Parsing Memory Corruption Vulnerability
14/12/09
Mozilla Organization
Mozilla Thunderbird Floating Point Parsing Memory Corruption
14/12/09
SAP
SAP Products "sapstartsrv" Denial of Service
14/12/09
Canonical Ltd.
Ubuntu update for kdebase-runtime
14/12/09
Red Hat
Red Hat update for JBoss Enterprise Application Platform
14/12/09
Sun Microsystems
Sun Ray Server Software Multiple Vulnerabilities
14/12/09
Canonical Ltd.
Ubuntu update for kde4libs
14/12/09
Canonical Ltd.
Ubuntu update for kdelibs
14/12/09
HP
HP-UX update for VRTSweb
14/12/09
Canonical Ltd.
Ubuntu update for pygresql
14/12/09
Red Hat
Fedora update for kernel
14/12/09
HP
HP OpenView Network Node Manager Multiple Vulnerabilities
11/12/09
Red Hat
Fedora update for rubygem-actionpack
11/12/09
Canonical Ltd.
Ubuntu update for kernel
11/12/09
Apache Software Foundation
Apache Tomcat Multiple Vulnerabilities
11/12/09
Slackware Linux
Slackware update for ntp
11/12/09
Red Hat
Fedora update for httpd
10/12/09
Red Hat
Fedora update for nss-util
10/12/09
Red Hat
Red Hat update for flash-plugin
10/12/09
Red Hat
Red Hat update for flash-plugin
10/12/09
IBM
IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
10/12/09
IBM
IBM Java 6 Denial of Service Vulnerabilities
10/12/09
IBM
IBM Java Denial of Service Vulnerabilities
10/12/09
Canonical Ltd.
Ubuntu update for grub2
10/12/09
Microsoft
Microsoft Windows DNS Spoofing Vulnerabilities
10/12/09
Debian
Debian update for ntp
10/12/09
Computer Associates (CA)
CA Service Desk Unspecified Cross-Site Scripting Vulnerability
10/12/09
Red Hat
Red Hat update for ntp
10/12/09
Red Hat
Red Hat update for ntp
10/12/09
Canonical Ltd.
Ubuntu update for ntp
09/12/09
HP
HP Application Recovery Manager "MSG_PROTOCOL" Buffer Overflow
09/12/09
Adobe Systems
Adobe Flash Player Multiple Vulnerabilities
09/12/09
GNU Project
GNU Core Utilities "distcheck" Insecure Temporary Directory Security Issue
09/12/09
Red Hat
Red Hat update for libtool
09/12/09
Red Hat
Red Hat update for java-1.5.0-ibm
09/12/09
Microsoft
Microsoft Windows Indeo Codec Multiple Vulnerabilities
09/12/09
Microsoft
Microsoft Windows Internet Authentication Service Vulnerability
09/12/09
Microsoft
Microsoft Windows MS-CHAP Authentication Bypass
09/12/09
Microsoft
Windows Active Directory Federation Services Two Vulnerabilities
09/12/09
Microsoft
Internet Explorer Multiple Vulnerabilities
09/12/09
Microsoft
Microsoft Windows Local Security Authority Subsystem Denial of Service
09/12/09
Microsoft
Microsoft WordPad / Office Text Converters Memory Corruption Vulnerability
09/12/09
Microsoft
Microsoft Office Project Memory Validation Vulnerability
09/12/09
Red Hat
Fedora update for kernel
09/12/09
IBM
IBM InfoSphere Information Server Multiple Vulnerabilities
09/12/09
Canonical Ltd.
Ubuntu update for gnome-screensaver
09/12/09
Red Hat
Red Hat update for acpid
08/12/09
Novell
Novell iPrint Client Two Buffer Overflow Vulnerabilities
08/12/09
Novell
Novell iPrint Client Date/Time Parsing Buffer Overflow
08/12/09
Red Hat
Red Hat update for java-1.4.2-ibm
08/12/09
Debian
Debian update for shibboleth-sp, shibboleth-sp2, and opensaml2
08/12/09
Red Hat
Red Hat update for expat
08/12/09
Canonical Ltd.
Ubuntu update for bind9
08/12/09
Sun Microsystems
Sun Solaris Python Multiple Vulnerabilities
08/12/09
Red Hat
Fedora update for expat
08/12/09
Red Hat
Fedora update for dstat
08/12/09
Red Hat
Fedora update for nginx
08/12/09
Red Hat
Fedora update for php
08/12/09
Red Hat
Fedora update for cups
08/12/09
Red Hat
Fedora update for wireshark
08/12/09
Debian
Debian update for belpic
07/12/09
IBM
IBM HTTP Server TLS Session Renegotiation Plaintext Injection
07/12/09
Canonical Ltd.
Ubuntu update for kernel
07/12/09
Canonical Ltd.
Ubuntu update for qemu-kvm
05/12/09
Red Hat
Red Hat update for kernel
05/12/09
Debian
Debian update for gforge
05/12/09
Sun Microsystems
Sun Management Center XML Library Multiple Vulnerabilities
04/12/09
Sun Microsystems
Sun Solaris GNU tar Archive Parsing Vulnerabilities
04/12/09
Debian
Debian update for request-tracker
04/12/09
Apple
Apple Mac OS X update for Java
04/12/09
Sun Microsystems
Sun Solaris libexpat Library XML Parsing Denial of Service
04/12/09
Sun Microsystems
Sun Solaris wget SSL Certificate NULL Character Processing Vulnerability
04/12/09
Blue Coat Systems
Blue Coat ProxySG TCP Implementation Denial of Service Vulnerabilities
04/12/09
Adobe Systems
Adobe Illustrator Encapsulated Postscript Parsing Vulnerability
04/12/09
FreeBSD Project
FreeBSD Dynamic Linker Privilege Escalation Vulnerability
04/12/09
FreeBSD Project
FreeBSD freebsd-update Insecure Directory Permissions
04/12/09
FreeBSD Project
FreeBSD OpenSSL TLS Session Renegotiation Plaintext Injection Vulnerability
04/12/09
Novell
SUSE update for kernel
03/12/09
Slackware Linux
Slackware update for bind
03/12/09
Debian
Debian update for openldap
03/12/09
Sun Microsystems
Sun Products NSS TLS Session Renegotiation Plaintext Injection Vulnerability
03/12/09
Sun Microsystems
Sun Java System Portal Server Gateway Cross-Site Scripting Vulnerabilities
03/12/09
IBM
IBM WebSphere Application Server for z/OS Multiple Vulnerabilities
03/12/09
Red Hat
Fedora update for wget
03/12/09
Red Hat
Fedora update for libsndfile
03/12/09
Novell
SUSE update for bind
03/12/09
Novell
Novell eDirectory NDS Verb 0x1 Request Integer Overflow Vulnerability
03/12/09
HP
HP NonStop Server Privilege Escalation
02/12/09
Sun Microsystems
Sun Solaris Adobe Reader Multiple Vulnerabilities
02/12/09
Red Hat
Fedora update for cups
02/12/09
Research In Motion
BlackBerry Products PDF Distiller Unspecified Vulnerabilities
02/12/09
Red Hat
Fedora update for roundcubemail
02/12/09
Gentoo
Gentoo update for openssl
02/12/09