<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Vulnerability Managment Blog</title>
	<atom:link href="http://vulnerabilitymanagement.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://vulnerabilitymanagement.wordpress.com</link>
	<description></description>
	<lastBuildDate>Sat, 04 Dec 2010 13:03:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='vulnerabilitymanagement.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/2cb21caaf3fe6dc4a4be07ef00e109d9?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Vulnerability Managment Blog</title>
		<link>http://vulnerabilitymanagement.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://vulnerabilitymanagement.wordpress.com/osd.xml" title="Vulnerability Managment Blog" />
	<atom:link rel='hub' href='http://vulnerabilitymanagement.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Cisco IPSec VPN Implementation Group Name Enumeration: Patch Notification</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/04/cisco-ipsec-vpn-implementation-group-name-enumeration-patch-notification/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/04/cisco-ipsec-vpn-implementation-group-name-enumeration-patch-notification/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 13:03:50 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[gavin jones]]></category>
		<category><![CDATA[ngs secure]]></category>
		<category><![CDATA[patch notification]]></category>
		<category><![CDATA[security advisories]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/04/cisco-ipsec-vpn-implementation-group-name-enumeration-patch-notification/</guid>
		<description><![CDATA[Users of Cisco IPSec VPN Implementation Group Name Enumeration please be advised of a Patch Notification that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com NGS00014: [NGS00014] Patch Notification: Cisco IPSec VPN Implementation Group Name Enumeration Gavin Jones of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1018&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of Cisco IPSec VPN Implementation Group Name Enumeration please be advised of a Patch Notification that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34392" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34392">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34392">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">
<h1 id="AutoGeneratedID-0"><strong>NGS00014: [NGS00014] Patch Notification: Cisco IPSec VPN Implementation Group Name Enumeration</strong></h1>
</div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34392"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Gavin Jones of NGS Secure has discovered a vulnerability in (Cisco) Cisco VPN Concentrator, Cisco PIX and Cisco <br />Adaptive Security Appliance.</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34392" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34392">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/fbz1Bx">http://bit.ly/fbz1Bx</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1018/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1018/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1018/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1018/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1018/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1018/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1018/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1018/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1018/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1018/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1018/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1018/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1018/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1018/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1018&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/04/cisco-ipsec-vpn-implementation-group-name-enumeration-patch-notification/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>Winamp: NSV Table of Contents Parsing Integer Overflow Vulnerability</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/04/winamp-nsv-table-of-contents-parsing-integer-overflow-vulnerability/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/04/winamp-nsv-table-of-contents-parsing-integer-overflow-vulnerability/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 13:00:47 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[security advisories]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<category><![CDATA[winamp]]></category>
		<category><![CDATA[winamp nsv table]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/04/winamp-nsv-table-of-contents-parsing-integer-overflow-vulnerability/</guid>
		<description><![CDATA[Users of Winamp please be advised of a NSV Table of Contents Parsing Integer Overflow vulnerability that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com Winamp-SA-12/01/2010: Winamp NSV Table of Contents Parsing Integer Overflow Affected Software * Winamp 5.581* [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1017&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of Winamp please be advised of a NSV Table of Contents Parsing Integer Overflow vulnerability that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>Winamp-SA-12/01/2010: Winamp NSV Table of Contents Parsing Integer Overflow</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Affected Software </p>
<p>* Winamp 5.581<br />* Winamp 5.59 Beta Build 3033</p>
<p>NOTE: Other versions may also be affected.</p></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Description of Vulnerability</p>
<p>Secunia Research has discovered a vulnerability in Winamp, which can<br />be exploited by malicious people to compromise a user&#8217;s system.</p>
<p>The vulnerability is caused by an integer overflow error in the<br />&#8220;in_nsv.dll&#8221; plugin when parsing the Table of Contents. This can be<br />exploited to cause a heap-based buffer overflow via a specially <br />crafted NSV stream or file.</p>
<p>Successful exploitation allows execution of arbitrary code.</p></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">
<div></div>
<div id="leftCurve"></div>
<ul id="tabmenu">
<li><a rel="nofollow" href="http://www.criticalwatch.com/support/critical-watch-support.aspx"></a></li>
</ul>
</div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">
<div></div>
<p><span><br />
       					</span>
<div id="leftCurve"></div>
<p><span><br />
							</span>
<ul id="tabmenu"><span><br />
								</span><span><br />
								</span>
<li><a rel="nofollow" href="http://www.criticalwatch.com/support/critical-watch-support.aspx"></a></li>
</ul>
</div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">
<div></div>
<p><span><span><br />
       					</span></span>
<div id="leftCurve"></div>
<p><span><span><br />
							</span></span>
<ul id="tabmenu"><span><span><br />
								</span></span><span><span><br />
								</span></span>
<li><a rel="nofollow" href="http://www.criticalwatch.com/support/critical-watch-support.aspx"></a></li>
</ul>
</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34387">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/edeLcx">http://bit.ly/edeLcx</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1017/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1017/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1017/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1017&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/04/winamp-nsv-table-of-contents-parsing-integer-overflow-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>Bind: Denial of Service Vulnerabilities</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bind-denial-of-service-vulnerabilities/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bind-denial-of-service-vulnerabilities/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 12:46:33 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security advisories]]></category>
		<category><![CDATA[usn-1025-1]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/04/bind-denial-of-service-vulnerabilities/</guid>
		<description><![CDATA[Users of Bind please be advised of a denial of service vulnerabilities that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com USN-1025-1: [USN-1025-1] Bind vulnerabilities Details follow: It was discovered that Bind would incorrectly allow a ncache entry and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1016&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of Bind please be advised of a denial of service vulnerabilities that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34378" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34378">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34378">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>USN-1025-1: [USN-1025-1] Bind vulnerabilities</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34378"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Details follow:</p>
<p>It was discovered that Bind would incorrectly allow a ncache entry and a<br />
<br />rrsig for the same type. A remote attacker could exploit this to cause<br />
<br />Bind to crash, resulting in a denial of service. (CVE-2010-3613)</p>
<p>It was discovered that Bind would incorrectly mark zone data as insecure<br />
<br />when the zone is undergoing a key algorithm rollover. (CVE-2010-3614)
</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34378" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34378">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/hruLHb">http://bit.ly/hruLHb</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1016/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1016/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1016/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1016/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1016/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1016/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1016/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1016/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1016/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1016/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1016/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1016/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1016/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1016/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1016&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bind-denial-of-service-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>Apache Archiva: CSRF Vulnerability</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/04/apache-archiva-csrf-vulnerability/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/04/apache-archiva-csrf-vulnerability/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 12:37:02 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[apache archiva]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security advisories]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/04/apache-archiva-csrf-vulnerability/</guid>
		<description><![CDATA[Users of Apache Archiva please be advised of a CSRF vulnerability that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com CVE-2010-3449: Apache Archiva CSRF Vulnerability Description:Apache Archiva doesn&#8217;t check which form sends credentials. An attackercan create a specially crafted [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1015&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of Apache Archiva please be advised of a CSRF vulnerability that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34376" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34376">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34376">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>CVE-2010-3449: Apache Archiva CSRF Vulnerability</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34376"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Description:<br />Apache Archiva doesn&#8217;t check which form sends credentials. An attacker<br />can create a specially crafted page and force archiva administrators<br />to view it and change their credentials. To fix this, a referrer check<br />was added to the security interceptor for all secured actions. A<br />prompt for the administrator&#8217;s password when changing a user account<br />was also set in place.</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34376" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34376">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/gcg0s3">http://bit.ly/gcg0s3</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1015/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1015&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/04/apache-archiva-csrf-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>BugTracker.Net: Multiple Vulnerabilities</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-multiple-vulnerabilities/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-multiple-vulnerabilities/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 12:28:47 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[aspx]]></category>
		<category><![CDATA[bugtracker]]></category>
		<category><![CDATA[BugTracker.Net]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[sanitization]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-multiple-vulnerabilities/</guid>
		<description><![CDATA[Users of BugTracker.Net please be advised of Multiple vulnerabilities that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com CORE-2010-1109: [CORE-2010-1109] Multiple vulnerabilities in BugTracker.Net *Vulnerability Description* BugTracker.NET [1][2] is an open-source web-based bug tracker writtenusing ASP.NET, C#, and Microsoft [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1014&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of BugTracker.Net please be advised of Multiple vulnerabilities that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34377" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34377">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34377">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>CORE-2010-1109: [CORE-2010-1109] Multiple vulnerabilities in BugTracker.Net</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34377"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">*Vulnerability Description*</p>
<p>BugTracker.NET [1][2] is an open-source web-based bug tracker written<br />using ASP.NET, C#, and Microsoft SQL Server. Several cross-site<br />scripting and SQL-injection vulnerabilities were found in the following<br />files of the BugTracker.NET:</p>
<p>   . *bugs.aspx*. SQL injection in line 141.<br />   . *delete_query.aspx*. No sanitization for &#8216;row_id.Value&#8217; in line 30.<br />   . *edit_bug.aspx*. Variables without sanitization in lines 1846 and 1857.<br />   . *edit_bug.aspx*. No sanitization for variable &#8216;new_project&#8217;, line 2214.<br />   . *edit_bug.aspx*. XSS in line 2918.<br />   . *edit_comment.aspx*. XSS in line 233.<br />   . *edit_customfield.aspx*. Lines 165 and 172, no sanitization.<br />   . *edit_user_permissions2.aspx*. XSS in line 40.<br />   . *massedit.aspx*. SQL Injection in line 162.</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34377" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34377">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/gNT2lW">http://bit.ly/gNT2lW</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1014/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1014/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1014/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1014/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1014/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1014/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1014/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1014/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1014/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1014/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1014/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1014/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1014/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1014/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1014&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>BugTracker.Net: Several Cross-Site Scripting and SQL-Injection Vulnerabilities</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-several-cross-site-scripting-and-sql-injection-vulnerabilities/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-several-cross-site-scripting-and-sql-injection-vulnerabilities/#comments</comments>
		<pubDate>Sat, 04 Dec 2010 12:21:55 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[aspx]]></category>
		<category><![CDATA[bugtracker]]></category>
		<category><![CDATA[BugTraker.Net]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[sanitization]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-several-cross-site-scripting-and-sql-injection-vulnerabilities/</guid>
		<description><![CDATA[Users of BugTracker.Net please be advised of Several cross-site scripting and SQL-injection vulnerabilities that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com CORE-2010-1109: [CORE-2010-1109] Multiple vulnerabilities in BugTracker.Net *Vulnerability Description* BugTracker.NET [1][2] is an open-source web-based bug tracker writtenusing [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1013&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of BugTracker.Net please be advised of Several cross-site scripting and SQL-injection vulnerabilities that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34389" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34389">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34389">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>CORE-2010-1109: [CORE-2010-1109] Multiple vulnerabilities in BugTracker.Net</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34389"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">*Vulnerability Description*</p>
<p>BugTracker.NET [1][2] is an open-source web-based bug tracker written<br />using ASP.NET, C#, and Microsoft SQL Server. Several cross-site<br />scripting and SQL-injection vulnerabilities were found in the following<br />files of the BugTracker.NET:</p>
<p>   . *bugs.aspx*. SQL injection in line 141.<br />   . *delete_query.aspx*. No sanitization for &#8216;row_id.Value&#8217; in line 30.<br />   . *edit_bug.aspx*. Variables without sanitization in lines 1846 and 1857.<br />   . *edit_bug.aspx*. No sanitization for variable &#8216;new_project&#8217;, line 2214.<br />   . *edit_bug.aspx*. XSS in line 2918.<br />   . *edit_comment.aspx*. XSS in line 233.<br />   . *edit_customfield.aspx*. Lines 165 and 172, no sanitization.<br />   . *edit_user_permissions2.aspx*. XSS in line 40.<br />   . *massedit.aspx*. SQL Injection in line 162.</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34389" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34389">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/hjepQz">http://bit.ly/hjepQz</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1013/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1013/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1013/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1013/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1013/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1013/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1013/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1013&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/04/bugtracker-net-several-cross-site-scripting-and-sql-injection-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>Pandora FMS: Authentication Bypass and Multiple Input Validation Vulnerabilities</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/03/pandora-fms-authentication-bypass-and-multiple-input-validation-vulnerabilities/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/03/pandora-fms-authentication-bypass-and-multiple-input-validation-vulnerabilities/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 19:37:33 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[cve ids]]></category>
		<category><![CDATA[multiple input validation]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security advisories]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/03/pandora-fms-authentication-bypass-and-multiple-input-validation-vulnerabilities/</guid>
		<description><![CDATA[Users of Pandora FMS please be advised of an Authentication Bypass and Multiple Input Validation Vulnerabilities that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com Pandora-SA-11/30/2010: Pandora FMS Authentication Bypass and Multiple Input Validation Vulnerabilities Pandora FMS Authentication Bypass [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1012&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of Pandora FMS please be advised of an Authentication Bypass and Multiple Input Validation Vulnerabilities that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34361" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34361">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34361">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>Pandora-SA-11/30/2010: Pandora FMS Authentication Bypass and Multiple Input Validation Vulnerabilities</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34361"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Pandora FMS Authentication Bypass and Multiple Input Validation<br />Vulnerabilities</p>
<p>CVE IDs in this security advisory:</p>
<p>1) Authentication bypass &#8211; CVE-2010-4279<br />2) OS Command Injection &#8211; CVE-2010-4278<br />3) SQL Injection &#8211; CVE-2010-4280<br />4) Blind SQL Injection &#8211; CVE-2010-4280<br />5) Path Traversal &#8211; CVE-2010-4281 &#8211; CVE-2010-4282 &#8211; CVE-2010-4283</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34361" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34361">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/dYg6Y0">http://bit.ly/dYg6Y0</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1012/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1012/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1012/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1012&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/03/pandora-fms-authentication-bypass-and-multiple-input-validation-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>Phpmyadmin: Cross-Site-Scripting (XSS) Vulnerability</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/03/phpmyadmin-cross-site-scripting-xss-vulnerability/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/03/phpmyadmin-cross-site-scripting-xss-vulnerability/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 19:33:12 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[phpmyadmin]]></category>
		<category><![CDATA[problem description]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security advisories]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/03/phpmyadmin-cross-site-scripting-xss-vulnerability/</guid>
		<description><![CDATA[Users of phpmyadmin please be advised of a Cross-site-scripting (XSS) vulnerability that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com MDVSA-2010:244: [MDVSA-2010:244] phpmyadmin Cross-site-scripting Issue Package : phpmyadmin Problem Description: A vulnerability has been found and corrected in phpmyadmin: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1011&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of phpmyadmin please be advised of a Cross-site-scripting (XSS) vulnerability that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34342" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34342">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34342">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>MDVSA-2010:244: [MDVSA-2010:244] phpmyadmin Cross-site-scripting Issue</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34342"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"> Package : phpmyadmin
</div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34342"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Problem Description:</p>
<p> A vulnerability has been found and corrected in phpmyadmin:</p>
<p> It was possible to conduct a XSS attack using spoofed request on the<br />
<br /> db search script (CVE-2010-4329).</p>
<p> This upgrade provides the latest phpmyadmin versions which is not<br />
<br /> vulnerable to this security issue.
</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34342" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34342">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/hvlc89">http://bit.ly/hvlc89</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1011/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1011/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1011/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1011/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1011/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1011/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1011/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1011/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1011/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1011/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1011/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1011/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1011/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1011/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1011&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/03/phpmyadmin-cross-site-scripting-xss-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>MIT Kerberos (krb5): Multiple Checksum Handling Vulnerabilities</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/03/mit-kerberos-krb5-multiple-checksum-handling-vulnerabilities/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/03/mit-kerberos-krb5-multiple-checksum-handling-vulnerabilities/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 19:24:09 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[accepts]]></category>
		<category><![CDATA[checksum]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[incorrectly]]></category>
		<category><![CDATA[krb5]]></category>
		<category><![CDATA[releases]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/03/mit-kerberos-krb5-multiple-checksum-handling-vulnerabilities/</guid>
		<description><![CDATA[Users of MIT Kerberos (krb5) please be advised of a Multiple checksum handling vulnerabilities that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com MITKRB5-SA-2010-007: [MITKRB5-SA-2010-007] Multiple checksum handling vulnerabilities SUMMARY ======= These vulnerabilities are in the MIT implementation of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1010&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of MIT Kerberos (krb5) please be advised of a Multiple checksum handling vulnerabilities that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34373" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34373">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34373">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt"><strong>MITKRB5-SA-2010-007: [MITKRB5-SA-2010-007] Multiple checksum handling vulnerabilities</strong></div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34373"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">SUMMARY
<div>=======</div>
<p>These vulnerabilities are in the MIT implementation of Kerberos<br />(krb5), but because these vulnerabilities arise from flaws in protocol
<div>handling logic, other implementations may also be vulnerable.</div>
<p>
<div>CVE-2010-1324</div>
<p>MIT krb5 (releases krb-1.7 and newer) incorrectly accepts an unkeyed<br />checksum with DES session keys for version 2 (RFC 4121) of the GSS-API
<div>krb5 mechanism.</div>
<p>MIT krb5 (releases krb5-1.7 and newer) incorrectly accepts an unkeyed<br />checksum for PAC signatures.  Running exclusively krb5-1.8 or newer
<div>KDCs blocks the attack.</div>
<p>MIT krb5 KDC (releases krb5-1.7 and newer) incorrectly accepts RFC<br />3961 key-derivation checksums using RC4 keys when verifying the
<div>req-checksum in a KrbFastArmoredReq.</div>
</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34373" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34373">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/gC9Vkx">http://bit.ly/gC9Vkx</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1010/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1010/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1010/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1010/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1010/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1010/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1010/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1010/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1010/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1010/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1010/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1010/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1010/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1010/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1010&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/03/mit-kerberos-krb5-multiple-checksum-handling-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
		<item>
		<title>Red Hat Enterprise MRG Messaging and Grid: Important Security Update</title>
		<link>http://vulnerabilitymanagement.wordpress.com/2010/12/03/red-hat-enterprise-mrg-messaging-and-grid-important-security-update/</link>
		<comments>http://vulnerabilitymanagement.wordpress.com/2010/12/03/red-hat-enterprise-mrg-messaging-and-grid-important-security-update/#comments</comments>
		<pubDate>Fri, 03 Dec 2010 19:12:02 +0000</pubDate>
		<dc:creator>vulnerability management</dc:creator>
				<category><![CDATA[vulnerability-management-scanning-assessment]]></category>
		<category><![CDATA[critical watch]]></category>
		<category><![CDATA[red hat enterprise]]></category>
		<category><![CDATA[red hat enterprise mrg]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security advisories]]></category>
		<category><![CDATA[update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability management]]></category>

		<guid isPermaLink="false">http://vulnerabilitymanagement.wordpress.com/2010/12/03/red-hat-enterprise-mrg-messaging-and-grid-important-security-update/</guid>
		<description><![CDATA[Users of Red Hat Enterprise MRG Messaging and Grid please be advised of an Important security update that has been identified. To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx) Amplify&#8217;d from http://www.criticalwatch.com RHSA-2010:0921-01: [RHSA-2010:0921-01] Important: Red Hat Enterprise MRG Messaging and Grid security update Product: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1009&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="Amp_Commentary_Wrap">
<div class="Amp_Post_Text">
<p>Users of Red Hat Enterprise MRG Messaging and Grid please be advised of an Important security update that has been identified.<br />
To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (<a href="http://criticalwatch.com/support/security-advisories.aspx" rel="nofollow" target="_blank">http://criticalwatch.com/support/security-advisories.aspx</a>)</p>
</div>
</div>
<div class="">
<div class="Amp_Content_Outer">
<div class="Amp_Top_Wrap">
<div class="Amp_Source_First"><span>Amplify&rsquo;d from <a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365">http://www.criticalwatch.com</a></span></div>
</div>
<div class="Amp_Middle_Wrap">
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365">
<table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">
<h1 id="AutoGeneratedID-0"><strong>RHSA-2010:0921-01: [RHSA-2010:0921-01] Important: Red Hat Enterprise MRG Messaging and Grid security update</strong></h1>
</div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Product:           Red Hat Enterprise MRG for RHEL-5
</div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">Synopsis:          Important: Red Hat Enterprise MRG Messaging and Grid security update
</div>
</td>
</tr>
</table>
</blockquote>
<div class="Amp_Content_Hr"></div>
<blockquote class="Amp_Content_Item" cite="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365"><table cellpadding="0" cellspacing="0">
<tr>
<td>
<div class="TxtCntnt">
<div>Summary:
</div>
<p>Updated Red Hat Enterprise MRG Messaging and Grid packages that fix one<br />
<br />security issue and several bugs are now available for Red Hat Enterprise<br />

<div>Linux 5.
</div>
<p>The Red Hat Security Response Team has rated this update as having<br />
<br />important security impact. A Common Vulnerability Scoring System (CVSS)<br />
<br />base score, which gives a detailed severity rating, is available from the<br />

<div>CVE link in the References section.
</div>
</div>
<p><span class="Amp_Source_Button"><a rel="clipsource" target="_blank" title="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365" href="http://www.criticalwatch.com/support/security-advisories.aspx?AID=34365">Read more at <a href="http://www.criticalwatch.com" rel="nofollow">http://www.criticalwatch.com</a></a></span></td>
</tr>
</table>
</blockquote>
</div>
<div class="Amp_Bottom_Wrap">&nbsp;</div>
</div>
</div>
<div class="Amp_Link">See this Amp at <a href="http://bit.ly/eDgl8k">http://bit.ly/eDgl8k</a></div>
<p></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/vulnerabilitymanagement.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/vulnerabilitymanagement.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/vulnerabilitymanagement.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/vulnerabilitymanagement.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/vulnerabilitymanagement.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/vulnerabilitymanagement.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/vulnerabilitymanagement.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/vulnerabilitymanagement.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/vulnerabilitymanagement.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/vulnerabilitymanagement.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/vulnerabilitymanagement.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/vulnerabilitymanagement.wordpress.com/1009/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/vulnerabilitymanagement.wordpress.com/1009/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/vulnerabilitymanagement.wordpress.com/1009/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=vulnerabilitymanagement.wordpress.com&amp;blog=13446717&amp;post=1009&amp;subd=vulnerabilitymanagement&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://vulnerabilitymanagement.wordpress.com/2010/12/03/red-hat-enterprise-mrg-messaging-and-grid-important-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/f07cd7eccc3b0d61e3243dd6677a2001?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">vulnerabilitymanagement</media:title>
		</media:content>
	</item>
	</channel>
</rss>
