Report an Incident

If you are a CNI organisation and you have encountered or suspect a cyber threat, please complete and return an Incident Reporting Form.

All incident reports provided to the CCIP are treated in the strictest of confidence. Please see our Confidentiality Charter for more details. Read More


New at CCIP

Current e-Bulletin The CCIP e-Bulletin provides a snapshot of security related news
Read More


New Zealand Government Website

January 2010

The following table includes the Vulnerability Alerts for the month.

Note: These links reference external sites. CCIP can not accept responsibility for outdated links or such links contents.
Reference Description Date
Canonical Ltd.
Ubuntu update for samba
30/01/10
Red Hat
Fedora update for samba
30/01/10
Red Hat
Feodra update for ncpfs
30/01/10
Samba Team
Samba "mount.cifs" Race Condition Security Issue
30/01/10
Canonical Ltd.
Ubuntu update for fuse
30/01/10
Red Hat
Fedora update for bltk
30/01/10
Debian
Debian update for ircd-hybrid and ircd-ratbox
30/01/10
IBM
IBM WebSphere Application Server TLS Session Renegotiation Plaintext Injection
30/01/10
Debian
Debian update for maildrop
29/01/10
Symantec
Symantec Altiris Notification Server Static Encryption Key
29/01/10
Debian
Debian update for pdns-recursor
29/01/10
Debian
Debian update for maildrop
29/01/10
HP
HP-UX update for CIFS Server
29/01/10
Canonical Ltd.
Ubuntu update for lintian
29/01/10
Debian
Debian update for lintian
29/01/10
Apache Software Foundation
Apache mod_proxy "ap_proxy_send_fb()" Integer Truncation Vulnerability
29/01/10
Canonical Ltd.
Ubuntu update for dhcp3
28/01/10
MySQL
MySQL yaSSL Certificate Processing Buffer Overflow Vulnerability
28/01/10
Red Hat
Fedora update for zabbix
28/01/10
Red Hat
Fedora update for wordpress-mu
28/01/10
Cisco
Cisco Unified MeetingPlace Multiple Vulnerabilities
28/01/10
IBM
IBM Tivoli Directory Server Denial of Service Vulnerabilities
28/01/10
HP
HP OpenView Storage Data Protector Unauthorised Access
28/01/10
IBM
IBM DataPower ICMP Packet Processing Denial of Service
28/01/10
SuSE
SUSE update for acroread
28/01/10
Sun Microsystems
Sun Java System Web Server Multiple Vulnerabilities
28/01/10
Sun Microsystems
Sun Java System Web Proxy Server Multiple Vulnerabilities
28/01/10
Sun Microsystems
Sun Solaris BIND Dynamic Update Denial of Service Vulnerability
28/01/10
HP
HP OpenView Network Node Manager Database Service Denial of Service
27/01/10
Canonical Ltd.
Ubuntu update for python-xml
27/01/10
Debian
Debian update for phpgroupware
27/01/10
Citrix Systems
XenServer Realtek 8169 Driver Large Packet Processing Vulnerability
27/01/10
Google
Google Chrome Stylesheet Redirection Information Disclosure
26/01/10
Debian
Debian update for python2.4 and python2.5
26/01/10
Google
Google Chrome Multiple Vulnerabilities
26/01/10
Oracle
Oracle WebLogic Server Node Manager Security Bypass
26/01/10
Red Hat
Fedora update for kernel
26/01/10
Apache Software Foundation
Apache Tomcat 5 WAR Deployment Directory Traversal Weaknesses and Security Issue
26/01/10
Apache Software Foundation
Apache Tomcat WAR Deployment Directory Traversal Weaknesses and Security Issue
26/01/10
Avaya
Avaya CMS Solaris libexpat Library XML Parsing Denial of Service
26/01/10
Avaya
Avaya Products Multiple Vulnerabilities
26/01/10
IBM
IBM WebSphere Application Server TLS Session Renegotiation Plaintext Injection
26/01/10
Red Hat
Red Hat update for bind
25/01/10
SuSE
SUSE update for kernel
25/01/10
Canonical Ltd.
Ubuntu update for python
25/01/10
Debian
Debian update for dokuwiki
25/01/10
Slackware Linux
Slackware update for php
25/01/10
Google
Google Chrome Stylesheet Redirection Information Disclosure
23/01/10
Apple
Apple Safari Stylesheet Redirection Information Disclosure
23/01/10
Sun Microsystems
Sun Solaris Thunderbird Network Security Services Vulnerabilities
23/01/10
Sun Microsystems
Sun Solaris BIND DNSSEC Cache Poisoning Vulnerabilities
22/01/10
Debian
Debian update for audiofile
22/01/10
Sun Microsystems
Sun Java System Directory Server LDAP Search Request Denial of Service
22/01/10
Canonical Ltd.
Ubuntu update for python
22/01/10
Red Hat
Red Hat update for kernel-rt
22/01/10
Microsoft
Microsoft Internet Explorer Multiple Vulnerabilities
22/01/10
Debian
Debian update for glibc and eglibc
22/01/10
IBM
IBM Lotus Domino Buffer Overflow Vulnerability
22/01/10
Red Hat
Fedora update for kernel
22/01/10
Canonical Ltd.
Ubuntu update for expat
22/01/10
Sun Microsystems
Sun Java System Web Server Multiple Vulnerabilities
22/01/10
Debian
Debian update for gzip
22/01/10
Canonical Ltd.
Ubuntu update for gzip
22/01/10
Research In Motion
BlackBerry Products PDF Distiller Unspecified Vulnerabilities
22/01/10
Red Hat
Red Hat update for gzip
21/01/10
Cisco
Cisco IOS XR SSH Denial of Service Vulnerability
21/01/10
Cisco
Cisco InternetWork Performance Monitor GIOP Request Buffer Overflow
21/01/10
Red Hat
Red Hat update for acroread
21/01/10
Canonical Ltd.
Ubuntu update for bind9
21/01/10
Mozilla Organization
Mozilla Thunderbird Multiple Vulnerabilities
21/01/10
Red Hat
Fedora update for bind
21/01/10
Red Hat
Red Hat update for bind
21/01/10
RealNetworks
RealPlayer IVR File Processing Two Vulnerabilities
21/01/10
RealNetworks
RealPlayer Multiple Vulnerabilities
21/01/10
IBM
IBM Java 6 Multiple Vulnerabilities
21/01/10
IBM
IBM Java Multiple Vulnerabilities
21/01/10
SuSE
SUSE Update for Multiple Packages
21/01/10
SAP
SAP Web Application Server Integrated ITS Buffer Overflow
21/01/10
Sun Microsystems
Sun Java System Web Server Two Vulnerabilities
21/01/10
Microsoft
Microsoft Windows "KiTrap0D" Privilege Escalation Vulnerability
21/01/10
Red Hat
Red Hat update for kernel
21/01/10
Internet Software Consortium (ISC)
ISC BIND DNSSEC CNAME / DNAME and NXDOMAIN Cache Poisoning Vulnerabilities
20/01/10
HP
HP Power Manager "formExportDataLogs" Two Vulnerabilities
20/01/10
Red Hat
Red Hat update for openssl
20/01/10
Canonical Ltd.
Ubuntu update for libthai
20/01/10
SuSE
SUSE update for krb5
20/01/10
Apple
Apple Mac OS X Security Update Fixes Multiple Vulnerabilities
20/01/10
Adobe Systems
Adobe Shockwave Player 3D Model Parsing Eight Vulnerabilities
20/01/10
D-Link Systems
D-Link DIR Routers HNAP Security Bypass Vulnerability
20/01/10
IBM
IBM WebSphere Application Server Two Vulnerabilities
19/01/10
IBM
IBM HTTP Server "mod_proxy_ftp" Two Vulnerabilities
19/01/10
Canonical Ltd.
Ubuntu update for pidgin
19/01/10
Red Hat
Fedora update for systemtap
19/01/10
IBM
IBM AIX update for sendmail
19/01/10
Novell
SUSE update for kernel
18/01/10
Red Hat
Fedora update for php-ZendFramework
18/01/10
Microsoft
Microsoft Internet Explorer Event Handling Use-After-Free Vulnerability
18/01/10
Debian
Debian update for audiofile
18/01/10
Debian
Debian update for audiofile
18/01/10
HP
HP-UX update for sendmail
16/01/10
Novell
Novell GroupWise Multiple Vulnerabilities
16/01/10
IBM
IBM Lotus Web Content Management Cross-Site Scripting Vulnerability
16/01/10
Debian
Debian update for libthai
16/01/10
D-Link Systems
D-Link Router DI-524 HNAP Security Bypass Vulnerability
16/01/10
D-Link Systems
D-Link Routers DIR-628 / DIR-655 HNAP Security Bypass Vulnerability
16/01/10
Gentoo
Gentoo update for ruby
15/01/10
Red Hat
Red Hat update for pidgin
15/01/10
Red Hat
Red Hat update for java-1.6.0-ibm
15/01/10
HP
HP Discovery & Dependency Mapping Inventory Arbitrary Code Execution
15/01/10
Sun Microsystems
Sun Solaris NTP Mode 7 Request Denial of Service
15/01/10
Canonical Ltd.
Ubuntu update for transmission
15/01/10
Red Hat
Fedora update for ruby
15/01/10
Microsoft
Microsoft Internet Explorer Arbitrary Code Execution
15/01/10
IBM
WebSphere DataPower TLS Session Renegotiation Vulnerability
15/01/10
Google
Google SketchUp 3DS and SKP Processing Vulnerabilities
15/01/10
Debian
Debian update for openssl
14/01/10
Gentoo
Gentoo update for VirtualBox
14/01/10
Gentoo
Gentoo update for net-snmp
14/01/10
Gentoo
Gentoo update for aria2
14/01/10
Gentoo
Gentoo update for squirrelmail
14/01/10
Canonical Ltd.
Ubuntu update for OpenSSL
14/01/10
Red Hat
Fedora update for krb5
14/01/10
Canonical Ltd.
Ubuntu update for network-manager-applet
14/01/10
Red Hat
Red Hat update for gcc and gcc4
14/01/10
Gentoo
Gentoo update for blender
14/01/10
IBM
IBM AIX update for OpenSSL
14/01/10
HP
HP Web Jetadmin SQL Server Connection Security Issue
14/01/10
Canonical Ltd.
Ubuntu update for php
14/01/10
Red Hat
Red Hat update for php
14/01/10
Red Hat
Red Hat update for acroread
14/01/10
Sun Microsystems
Sun Solaris Kerberos Integer Underflow Vulnerabilities
14/01/10
NetBSD
NetBSD update for openssl
14/01/10
Red Hat
Fedora update for GraphicsMagick
14/01/10
Red Hat
Fedora update for pidgin
14/01/10
Red Hat
Fedora update for openttd
14/01/10
Red Hat
Fedora update for sssd
14/01/10
IBM
IBM OS/400 TLS Session Renegotiation Plaintext Injection
14/01/10
MySQL
MaxDB Information Disclosure and Denial of Service
14/01/10
SuSE
SUSE update for java-1_4_2-ibm
14/01/10
Novell
Novell ZENWorks Asset Management SQL Injection Vulnerability
14/01/10
Red Hat
Red Hat update for krb5
14/01/10
Debian
Debian update for krb5
14/01/10
Red Hat
Fedora update for transmission
14/01/10
Red Hat
Fedora update for DevIL
14/01/10
Red Hat
Fedora update for trac
14/01/10
Sun Microsystems
Sun Solaris Trusted Extensions Privilege Escalation
14/01/10
Sun Microsystems
Sun Solaris Pidgin ICQ Message Denial of Service Weakness
14/01/10
Oracle
Oracle E-Business Suite Multiple Vulnerabilities
14/01/10
BEA
Oracle JRockit Multiple Vulnerabilities
14/01/10
Sun Microsystems
Sun Java System Identity Manager Security Bypass
14/01/10
Oracle
Oracle Secure Backup Buffer Overflow Vulnerability
14/01/10
Oracle
Oracle Primavera Products Denial of Service Vulnerability
13/01/10
Oracle
Oracle Database Multiple Vulnerabilities
13/01/10
Oracle
Oracle Application Server Multiple Vulnerabilities
13/01/10
Oracle
Oracle PeopleSoft Enterprise HCM eProfile Vulnerability
13/01/10
BEA
Oracle BEA WebLogic Server Multiple Vulnerabilities
13/01/10
Novell
SUSE update for java-1_6_0-ibm
13/01/10
Canonical Ltd.
Ubuntu update for krb5
13/01/10
Adobe Systems
Adobe Reader/Acrobat Multiple Vulnerabilities
13/01/10
Adobe Systems
Adobe Reader/Acrobat 7 Multiple Vulnerabilities
13/01/10
Microsoft
Microsoft Windows Flash Player Multiple Vulnerabilities
13/01/10
Microsoft
Microsoft Visual Studio Active Template Library Three Vulnerabilities
13/01/10
Microsoft
Microsoft Windows Embedded OpenType Font Engine Vulnerability
13/01/10
SuSE
SUSE Update for Multiple Packages
13/01/10
Apple
Apple Mac OS X "strtod()" Floating Point Parsing Memory Corruption
13/01/10
SuSE
SUSE update for java-1_5_0-ibm
13/01/10
IBM
IBM Lotus Domino Web Access Cross-Site Scripting Vulnerabilities
13/01/10
IBM
IBM Lotus Domino Web Access Cross-Site Scripting Vulnerabilities
12/01/10
D-Link Systems
D-Link DKVM-IP8 "auth.asp" Cross-Site Scripting
12/01/10
Sun Microsystems
Sun Java System Directory Server LDAP Search Request Denial of Service
12/01/10
Debian
Debian update for pdns-recursor
12/01/10
Debian
Debian update for pdns-recursor
12/01/10
Sun Microsystems
Sun Java System Products TLS Session Renegotiation Plaintext Injection
12/01/10
Juniper Networks
JUNOS TCP Packet Processing Denial of Service
09/01/10
Canonical Ltd.
Ubuntu update for Firefox and Xulrunner
09/01/10
Canonical Ltd.
Ubuntu update for Firefox and Xulrunner
09/01/10
Novell
SUSE update for kernel
08/01/10
Red Hat
Red Hat update for the kernel
08/01/10
Debian
Debian update for transmission
08/01/10
Red Hat
Red Hat update for the kernel
08/01/10
Red Hat
Red Hat update for dbus
08/01/10
IBM
IBM Lotus Domino Web Access Unspecified Vulnerabilities
08/01/10
Adobe Systems
Adobe Illustrator Encapsulated Postscript Parsing Vulnerabilities
08/01/10
Red Hat
Fedora update for ImageMagick
08/01/10
Canonical Ltd.
Ubuntu update for gimp
08/01/10
Novell
Novell iManager eDirectory Plugin Schema Processing Buffer Overflow
08/01/10
Debian
Debian update for horde3
08/01/10
Avaya
Avaya Products TLS Session Renegotiation Plaintext Injection Vulnerability
08/01/10
Avaya
Avaya Products Two Vulnerabilities
08/01/10
Avaya
Avaya CMS Multiple Vulnerabilities
08/01/10
Avaya
Avaya Products Mozilla Firefox Multiple Vulnerabilities
08/01/10
Debian
Debian update for phpldapadmin
08/01/10
VMware
VMware ESX / vMA update for nss and nspr
08/01/10
FreeBSD Project
FreeBSD ZFS Intent Log "setattr" Transaction Replay Weakness
08/01/10
FreeBSD Project
FreeBSD update for ntpd
08/01/10
Red Hat
JBoss Enterprise Web Server update for httpd and httpd22
08/01/10
FreeBSD Project
FreeBSD update for bind
08/01/10
Red Hat
Fedora update for pdns-recursor
07/01/10
Red Hat
Fedora update for condor
07/01/10
F5 Networks
F5 Products NTP Mode 7 Request Denial of Service
07/01/10
Gentoo
Gentoo update for php
07/01/10
Red Hat
Fedora update for krb5
07/01/10
Canonical Ltd.
Ubuntu update for krb5
07/01/10
Slackware Linux
Slackware update for mozilla-firefox
07/01/10
Novell
Novell NetWare AFP Implementation Denial of Service Vulnerability
07/01/10
F5 Networks
F5 Data Manager Directory Traversal Vulnerabilities
07/01/10
Red Hat
Fedora update for gimp
07/01/10
Red Hat
Red Hat update for PyXML
07/01/10
Red Hat
Red Hat update for gd
07/01/10