[AusNOG] AusCERT Week in Review - Week Ending 26/05/2006

matthew at auscert.org.au matthew at auscert.org.au
Sat May 27 08:07:55 EST 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi all,

This is a summary of what we have pushed to our subscribers for the past
week.  Sorry for the delay - just got back from our conference which went
pretty well.  At the conference we also released the 2006 Australian
Computer Crime and Security Survey:

  http://www.auscert.org.au/2001

I hope this is of some use.  

Best regards,

- -- Matthew McGlashan --
Coordination Centre Team Leader             | Hotline: +61 7 3365 4417
Australian Computer Emergency Response Team | Direct:  +61 7 3365 7924
(AusCERT)                                   | Fax:     +61 7 3365 7031
The University of Queensland                | WWW:     www.auscert.org.au
Qld 4072 Australia                          | Email: auscert at auscert.org.au

AusCERT Week in Review
26 May 2006


Papers, Articles and other documents:
- -------------------------------------
Title: Media coverage of AusCERT 2006 
Date:  26 May 2006
URL:   http://www.auscert.org.au/6335

Title: AusCERT Member Survey 2006 - Welcome 
Date:  22 May 2006
URL:   http://www.auscert.org.au/6311

Title: 2006 Australian Computer Crime and Security Survey 
Date:  22 May 2006
URL:   http://www.auscert.org.au/2001


Alerts, Advisories and Updates:
- -------------------------------
Title: AU-2006.0017 -- AusCERT Update - [Win] - Microsoft releases bulletin
       regarding unpatched Word buffer overflow vulnerability 
Date:  23 May 2006
URL:   http://www.auscert.org.au/6329

Title: AL-2006.0041 -- [Win] -- Unpatched Microsoft Word buffer overflow
       vulnerability 
Date:  20 May 2006
URL:   http://www.auscert.org.au/6316


External Security Bulletins:
- ----------------------------
Title: ESB-2006.0359 -- [Linux][RedHat] -- Important: kernel security update 
Date:  26 May 2006
OS:    Debian GNU/Linux, Other Linux Variants, Red Hat Linux 
URL:   http://www.auscert.org.au/6336

Title: ESB-2006.0358 -- [Win] -- Windows VPN Client Local Privilege Escalation
       Vulnerability 
Date:  26 May 2006
OS:    Windows 2003, Windows 2000, Windows XP 
URL:   http://www.auscert.org.au/6334

Title: ESB-2006.0357 -- [RedHat] -- Moderate: php security update 
Date:  24 May 2006
OS:    Red Hat Linux 
URL:   http://www.auscert.org.au/6333

Title: ESB-2006.0356 -- [Win][UNIX/Linux][RedHat][OSX] -- Important:
       postgresql security update 
Date:  24 May 2006
OS:    Solaris, HP Tru64 UNIX, Windows 98/98SE, Debian GNU/Linux, Other BSD
       Variants, IRIX, Windows 2003, OpenBSD, Windows 2000, FreeBSD, Other
       Linux Variants, Windows XP, Red Hat Linux, Windows NT 4, Mac OS X,
       HP-UX, AIX, Windows ME 
URL:   http://www.auscert.org.au/6332

Title: ESB-2006.0355 -- [UNIX/Linux][RedHat] -- Moderate: xscreensaver
       security update 
Date:  24 May 2006
OS:    Solaris, HP Tru64 UNIX, Debian GNU/Linux, Other BSD Variants, IRIX,
       OpenBSD, FreeBSD, Other Linux Variants, Red Hat Linux, HP-UX, AIX 
URL:   http://www.auscert.org.au/6331

Title: ESB-2006.0354 -- [Mac][OSX] -- Xcode Tools 2.3 
Date:  24 May 2006
OS:    Mac OS X 
URL:   http://www.auscert.org.au/6330

Title: ESB-2006.0353 -- [Debian] -- New Nagios packages fix arbitrary code
       execution 
Date:  23 May 2006
OS:    Debian GNU/Linux 
URL:   http://www.auscert.org.au/6328

Title: ESB-2006.0352 -- [Win][UNIX/Linux][Debian] -- New MySQL 3.23 packages
       fix several vulnerabilities 
Date:  23 May 2006
OS:    Solaris, HP Tru64 UNIX, Windows 98/98SE, Debian GNU/Linux, Other BSD
       Variants, IRIX, Windows 2003, OpenBSD, Windows 2000, FreeBSD, Other
       Linux Variants, Windows XP, Red Hat Linux, Windows NT 4, HP-UX, AIX,
       Windows ME 
URL:   http://www.auscert.org.au/6327

Title: ESB-2006.0351 -- [Win][UNIX/Linux][Debian] -- New phpbb2 packages fix
       execution of arbitrary web script code 
Date:  23 May 2006
OS:    Solaris, HP Tru64 UNIX, Windows 98/98SE, Debian GNU/Linux, Other BSD
       Variants, IRIX, Windows 2003, OpenBSD, Windows 2000, FreeBSD, Other
       Linux Variants, Windows XP, Red Hat Linux, Windows NT 4, HP-UX, AIX,
       Windows ME 
URL:   http://www.auscert.org.au/6326

Title: ESB-2006.0350 -- [Linux][Debian][FreeBSD] -- New hostapd packages fix
       denial of service 
Date:  23 May 2006
OS:    Debian GNU/Linux, FreeBSD, Other Linux Variants, Red Hat Linux 
URL:   http://www.auscert.org.au/6325

Title: ESB-2006.0349 -- [UNIX/Linux][Debian] -- New cscope packages fix
       arbitrary code execution 
Date:  23 May 2006
OS:    Solaris, HP Tru64 UNIX, Debian GNU/Linux, Other BSD Variants, IRIX,
       OpenBSD, FreeBSD, Other Linux Variants, Red Hat Linux, HP-UX, AIX 
URL:   http://www.auscert.org.au/6324

Title: ESB-2006.0348 -- [Win][UNIX/Linux][Debian] -- New phpgroupware packages
       fix execution of arbitrary web script code 
Date:  23 May 2006
OS:    Solaris, HP Tru64 UNIX, Windows 98/98SE, Debian GNU/Linux, Other BSD
       Variants, IRIX, Windows 2003, OpenBSD, Windows 2000, FreeBSD, Other
       Linux Variants, Windows XP, Red Hat Linux, Windows NT 4, HP-UX, AIX,
       Windows ME 
URL:   http://www.auscert.org.au/6323

Title: ESB-2006.0347 -- [UNIX/Linux][Debian] -- New kphone packages fix
       information disclosure 
Date:  23 May 2006
OS:    Solaris, HP Tru64 UNIX, Debian GNU/Linux, Other BSD Variants, IRIX,
       OpenBSD, FreeBSD, Other Linux Variants, Red Hat Linux, HP-UX, AIX 
URL:   http://www.auscert.org.au/6322

Title: ESB-2006.0346 -- [Win][UNIX/Linux][Debian] -- New popfile packages fix
       denial of service 
Date:  23 May 2006
OS:    Solaris, HP Tru64 UNIX, Windows 98/98SE, Debian GNU/Linux, Other BSD
       Variants, IRIX, Windows 2003, OpenBSD, Windows 2000, FreeBSD, Other
       Linux Variants, Windows XP, Red Hat Linux, Windows NT 4, HP-UX, AIX,
       Windows ME 
URL:   http://www.auscert.org.au/6321

Title: ESB-2006.0345 -- [UNIX/Linux][Debian] -- New kernel-patch-vserver
       packages fix privilege escalation 
Date:  23 May 2006
OS:    Debian GNU/Linux, Other BSD Variants, OpenBSD, FreeBSD, Other Linux
       Variants, Red Hat Linux 
URL:   http://www.auscert.org.au/6320

Title: ESB-2006.0344 -- [UNIX/Linux][Debian] -- New quagga packages fix
       several vulnerabilities 
Date:  23 May 2006
OS:    Solaris, HP Tru64 UNIX, Debian GNU/Linux, Other BSD Variants, IRIX,
       OpenBSD, FreeBSD, Other Linux Variants, Red Hat Linux, HP-UX, AIX 
URL:   http://www.auscert.org.au/6319

Title: ESB-2006.0343 -- [UNIX/Linux][Debian] -- New fbi packages fix denial of
       service 
Date:  22 May 2006
OS:    Solaris, HP Tru64 UNIX, Debian GNU/Linux, Other BSD Variants, IRIX,
       OpenBSD, FreeBSD, Other Linux Variants, Red Hat Linux, HP-UX, AIX 
URL:   http://www.auscert.org.au/6318

Title: ESB-2006.0342 -- [Linux][Debian] -- New Linux kernel 2.4.16, 2.4.18 and
       2.4.19 packages fix several vulnerabilities 
Date:  22 May 2006
OS:    Debian GNU/Linux, Other Linux Variants, Red Hat Linux 
URL:   http://www.auscert.org.au/6317

Title: ESB-2006.0320 -- [Solaris] -- Security Vulnerability in the Xorg(1)
       Version of the Render Extension 
Date:  25 May 2006
OS:    Solaris 
URL:   http://www.auscert.org.au/6271


===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert at auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (FreeBSD)
Comment: http://www.auscert.org.au/render.html?it=1967
Comment: http://www.auscert.org.au/render.html?it=1967

iQCVAwUBRHd8Oih9+71yA2DNAQIY1AP/cd0Mp2NHumJQhEI3pFkX/1YG3U2w2+Uo
uWVu19VeDLpUtmgqeyDihG3jcV6qnzulG/dZs5IyfN4hYAJE59386EKAZEVlMjCf
aUKlaP0foUomA3y5pQlE5VYYVrk1qgN0EVivcuERS7XY4JUK0KlUD3XhFHSs7Xlr
ZHE7IIO/7/w=
=QCXF
-----END PGP SIGNATURE-----




More information about the AusNOG mailing list