securityadmin's blog

Poppler Embedded Fonts Processing Vulnerability - Poppler is a PDF rendering engine used by xpdf, evince and other tools. There is a system compromise vulnerability that can be exploited by processing malicious PDF files. RedHat has released poppler-0.5.4-4.4 to fix this vulnerability. It is suggested to test and update to this version during the next outage window.

Nagios Plugins Long Location Header Buffer Overflow Vulnerability - A vulnerability in the plugins for Nagios could lead to system compromise. Successful exploitation requires that a connection is made to a malicious web server. This affects versions prior to 1.4.10. Fedora just released updates for nagios-plugins for Fedora 7 and Fedora 8.

ClamAV Multiple Vulnerabilities - Some vulnerabilities have been reported in ClamAV, which can be exploited by malicious people to bypass certain security restrictions, to cause a DoS (Denial of Service), or to compromise a vulnerable system. This affects versions prior to 0.93 and have been fixed in v0.93. It is suggested to test and update to this version as soon as possible for systems scanning email, and during the next outage window for other systems not performing real time scanning.

WordPress PHP Code Execution and Cross-Site Scripting in v2.5 and prior - Two vulnerabilities have been discovered, one which can lead to authentication bypass (if account registration is enabled) and another which can lead to arbitrary HTML and code execution on the clients web browser. This could appear to be a defacement, but is executed locally on the users computer, not on the server itself. Test and update to v2.5.1 when possible.

Sun Solaris Apache Modules Cross-Site Scripting Vulnerabilities - Sun has acknowledged some vulnerabilities in Solaris, which can be exploited by malicious people to conduct cross-site scripting attacks. This affects Apache 1.3.x and 2.0.x running on Solaris 8, 9 and 10 on SPARC and x86. Some vendor patches are available. Please test and apply these patches when available.