| View previous topic :: View next topic |
| Author |
Message |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
Posted: Sat Jun 21, 2008 10:50 am Post subject: |
|
|
Backtrack...
- http://atlas.arbor.net/briefs/index#-51119944
Severity: High Severity
Published: Friday, June 20, 2008 20:31
ClamAV vuln... now marked as "Unpatched"
- http://secunia.com/advisories/30657/
Last Update: 2008-06-20
Critical: Moderately critical
Impact: DoS
Where: From remote
Solution Status: Unpatched ...
The vulnerability is confirmed in versions 0.93 and 0.93.1. Other versions may also be affected.
Solution: Disable the scanning of PE files.
NOTE: Version 0.93.1 only fixes a particular exploitation vector...
Changelog:
2008-06-20: Updated "Solution" section and marked the advisory as unpatched...
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
Posted: Mon Jul 07, 2008 12:18 pm Post subject: |
|
|
FYI...
Panda ActiveScan vulns - update available
- http://secunia.com/advisories/30841/
Release Date: 2008-07-07
Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch
Software: Panda ActiveScan 2.0 1.x
...Successful exploitation allows execution of arbitrary code. According to the vendor, the vulnerabilities affect versions prior to version 1.02.00.
Solution: Update to version 1.02.00 or later.
http://www.pandasecurity.com/activescan
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
Posted: Mon Aug 25, 2008 11:32 am Post subject: |
|
|
FYI...
Trend Micro Web Mgmt authentication bypass...
- http://secunia.com/advisories/31373/
Release Date: 2008-08-22
Critical: Moderately critical
Impact: Security Bypass, Brute force
Where: From local network
Solution Status: Partial Fix
Software:
Trend Micro Client Server Messaging Security for SMB 3.x
Trend Micro OfficeScan Corporate Edition 7.x
Trend Micro OfficeScan Corporate Edition 8.x
Trend Micro Worry-Free Business Security 5.x ...
Solution: Apply patches...
(See the URL above for links to patches.)
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
Posted: Fri Sep 12, 2008 2:45 pm Post subject: |
|
|
FYI...
Trend Micro OfficeScan Server - updates available
- http://secunia.com/advisories/31342/
Release Date: 2008-09-12
Critical: Moderately critical
Impact: System access
Where: From local network
Solution Status: Partial Fix
...Successful exploitation allows execution of arbitrary code. The vulnerability is confirmed in version 7.3 with Patch 4 build 1362 applied and also affects OfficeScan version 7.0 and 8.0, and Client Server Messaging Security version 3.6, 3.5, 3.0, and 2.0.
Solution: Apply patches...
(Links to patches/updates available at the URL above.)
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
Posted: Tue Oct 21, 2008 4:57 pm Post subject: AV "false positive" system killers |
|
|
FYI...
McAfee update classifies Vista component as a Trojan
- http://www.theregister.co.uk/2008/10/21/mcafee_vista_trojan_false_alert/
21 October 2008 - "McAfee has fixed an update glitch that wrongly slapped a Trojan classification on components of Microsoft Vista. As a result of a misfiring update, published on Monday, the Windows Vista console IME executable was treated as a password-stealing Trojan. Depending on their setup, McAfee users applying would have typically found the component either quarantined or deleted. The antivirus firm fixed the glitch with a definition update on Tuesday that recognised the difference between the Vista component and malware, as explained in a write-up by McAfee here*. False positives with virus signature updates are a perennial problem for antivirus vendors, and the latest glitch is far from the first such occurrence to befall McAfee. Only two months ago in August McAfee wrongly categorised a plug-in for Microsoft Office Live Meeting as a Trojan."
* http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100683
AVG flags ZoneAlarm as malware
- http://news.cnet.com/8301-1009_3-10067148-83.html
October 15, 2008 - "Grisoft, makers of AVG antivirus, on Wednesday released a new update addressing a false positive in another security product. On Tuesday, AVG users reported desktops warnings that their desktop was infected with something called Trojan Agent r.CX... The ZoneAlarm user forum soon filled with concerned users... Laura Yecies, vice president and general manager of Check Point's ZoneAlarm consumer division said, "as soon as Check Point learned that AVG's recent antivirus update was mistakenly flagging a ZoneAlarm file as a virus, we contacted AVG and they issued an update within hours that corrected the problem. AVG users will automatically get the update that corrects the issue." In July, Grisoft modified its free AVG 8 due to complaints about a proactive scanning of a Web site feature. The feature that had been enabled in the paid version of the product did not scale with the free release causing spikes in Web traffic."
 _________________ AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
AplusWebMaster
General

 Joined: Mar 14, 2004 Posts: 4806 Location: USA
|
|
| Back to top |
|
 |
|
|