ID

VAR-201201-0259


CVE

CVE-2011-4858


TITLE

Hash table implementations vulnerable to algorithmic complexity attacks

Trust: 0.8

sources: CERT/CC: VU#903934

DESCRIPTION

Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. Some programming language implementations do not sufficiently randomize their hash functions or provide means to limit key collision attacks, which can be leveraged by an unauthenticated attacker to cause a denial-of-service (DoS) condition. Multiple Hitachi COBOL2002 products have security vulnerabilities that allow attackers to take control of target user systems. No detailed vulnerability details are provided at this time. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Apache Tomcat: Multiple vulnerabilities Date: June 24, 2012 Bugs: #272566, #273662, #303719, #320963, #329937, #373987, #374619, #382043, #386213, #396401, #399227 ID: 201206-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities were found in Apache Tomcat, the worst of which allowing to read, modify and overwrite arbitrary files. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/tomcat *< 5.5.34 *>= 6.0.35 *< 6.0.35 >= 7.0.23 < 7.0.23 Description =========== Multiple vulnerabilities have been discovered in Apache Tomcat. Please review the CVE identifiers referenced below for details. Impact ====== The vulnerabilities allow an attacker to cause a Denial of Service, to hijack a session, to bypass authentication, to inject webscript, to enumerate valid usernames, to read, modify and overwrite arbitrary files, to bypass intended access restrictions, to delete work-directory files, to discover the server's hostname or IP, to bypass read permissions for files or HTTP headers, to read or write files outside of the intended working directory, and to obtain sensitive information by reading a log file. Workaround ========== There is no known workaround at this time. Resolution ========== All Apache Tomcat 6.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-6.0.35" All Apache Tomcat 7.0.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-servers/tomcat-7.0.23" References ========== [ 1 ] CVE-2008-5515 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-5515 [ 2 ] CVE-2009-0033 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0033 [ 3 ] CVE-2009-0580 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0580 [ 4 ] CVE-2009-0781 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0781 [ 5 ] CVE-2009-0783 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-0783 [ 6 ] CVE-2009-2693 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2693 [ 7 ] CVE-2009-2901 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2901 [ 8 ] CVE-2009-2902 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-2902 [ 9 ] CVE-2010-1157 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-1157 [ 10 ] CVE-2010-2227 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2227 [ 11 ] CVE-2010-3718 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3718 [ 12 ] CVE-2010-4172 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4172 [ 13 ] CVE-2010-4312 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-4312 [ 14 ] CVE-2011-0013 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0013 [ 15 ] CVE-2011-0534 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0534 [ 16 ] CVE-2011-1088 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1088 [ 17 ] CVE-2011-1183 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1183 [ 18 ] CVE-2011-1184 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1184 [ 19 ] CVE-2011-1419 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1419 [ 20 ] CVE-2011-1475 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1475 [ 21 ] CVE-2011-1582 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-1582 [ 22 ] CVE-2011-2204 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2204 [ 23 ] CVE-2011-2481 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2481 [ 24 ] CVE-2011-2526 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2526 [ 25 ] CVE-2011-2729 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2729 [ 26 ] CVE-2011-3190 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3190 [ 27 ] CVE-2011-3375 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3375 [ 28 ] CVE-2011-4858 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-4858 [ 29 ] CVE-2011-5062 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5062 [ 30 ] CVE-2011-5063 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5063 [ 31 ] CVE-2011-5064 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-5064 [ 32 ] CVE-2012-0022 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0022 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201206-24.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . Description: JBoss Operations Network (JBoss ON) is a middleware management solution that provides a single point of control to deploy, manage, and monitor JBoss Enterprise Middleware, applications, and services. The Release Notes will be available shortly from https://docs.redhat.com/docs/en-US/index.html The following security issues are also fixed with this release: JBoss ON did not properly verify security tokens, allowing an unapproved agent to connect as an approved agent. As a result, the attacker could retrieve sensitive data about the server the hijacked agent was running on, including JMX credentials. (CVE-2012-0052) JBoss ON sometimes allowed agent registration to succeed when the registration request did not include a security token. This is a feature designed to add convenience. A remote attacker could use this flaw to spoof the identity of an approved agent and pass a null security token, allowing them to hijack the approved agent's session, and steal its security token. As a result, the attacker could retrieve sensitive data about the server the hijacked agent was running on, including JMX credentials. (CVE-2011-4858) Multiple cross-site scripting (XSS) flaws were found in the JBoss ON administration interface. If a remote attacker could trick a user, who was logged into the JBoss ON administration interface, into visiting a specially-crafted URL, it would lead to arbitrary web script execution in the context of the user's JBoss ON session. (CVE-2011-3206) JBoss ON did not verify that a user had the proper modify resource permissions when they attempted to delete a plug-in configuration update from the group connection properties history. This could allow such a user to delete a plug-in configuration update from the audit trail. Note that a user without modify resource permissions cannot use this flaw to make configuration changes. Warning: Before applying the update, back up your existing JBoss ON installation (including its databases, applications, configuration files, and so on). Solution: The References section of this erratum contains a download link (you must log in to download the update). Relevant releases/architectures: Red Hat Enterprise Linux Desktop Optional (v. 6) - noarch Red Hat Enterprise Linux HPC Node Optional (v. 6) - noarch Red Hat Enterprise Linux Workstation (v. 6) - noarch Red Hat Enterprise Linux Workstation Optional (v. 6) - noarch 3. Release Date: 2012-02-06 Last Updated: 2012-02-06 ------------------------------------------------------------------------------ Potential Security Impact: Remote Denial of Service (DoS), access restriction bypass Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY Potential security vulnerabilities have been identified with HP-UX Apache Running Tomcat Servlet Engine. These vulnerabilities could be exploited remotely to create a Denial of Service (DoS) or to perform an access restriction bypass. References: CVE-2006-7243, CVE-2011-4858, CVE-2011-4885, CVE-2012-0022 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP-UX B.11.23, B.11.31 running HP-UX Apache Web Server Suite v3.21 or earlier BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2006-7243 (AV:N/AC:L/Au:N/C:N/I:P/A:N) 5.0 CVE-2011-4858 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2011-4885 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2012-0022 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided the following software updates to resolve the vulnerability. The updates are available for download from ftp://srt10728:Secure12@ftp.usa.hp.com Note: HP-UX Web Server Suite v3.22 contains HP-UX Tomcat-based Servlet Engine v5.5.35.01 Web Server Suite Version Apache Depot Name HP-UX Web Server Suite v.3.22 HP-UX B.11.23 HPUXWS22ATW-B322-64.depot HP-UX B.11.23 HPUXWS22ATW-B322-32.depot HP-UX B.11.31 HPUXWS22ATW-B322-64.depot HP-UX B.11.31 HPUXWS22ATW-B322-32.depot MANUAL ACTIONS: Yes - Update Install HP-UX Web Server Suite v3.22 or subsequent. PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see https://www.hp.com/go/swa The following text is for use by the HP-UX Software Assistant. AFFECTED VERSIONS HP-UX Web Server Suite HP-UX B.11.23 HP-UX B.11.31 ================== hpuxws22TOMCAT.TOMCAT action: install revision B.5.5.35.01 or subsequent hpuxws22APCH32.APACHE hpuxws22APCH32.APACHE2 hpuxws22APCH32.AUTH_LDAP hpuxws22APCH32.AUTH_LDAP2 hpuxws22APCH32.MOD_JK hpuxws22APCH32.MOD_JK2 hpuxws22APCH32.MOD_PERL hpuxws22APCH32.MOD_PERL2 hpuxws22APCH32.PHP hpuxws22APCH32.PHP2 hpuxws22APCH32.WEBPROXY action: install revision B.2.2.15.11 or subsequent END AFFECTED VERSION HISTORY Version:1 (rev.1) - 06 February 2012 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin List: A list of HP Security Bulletins, updated periodically, is contained in HP Security Notice HPSN-2011-001: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay/?docId=emr_na-c02964430 Security Bulletin Archive: A list of recently released Security Bulletins is available here: http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2012 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits;damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: tomcat6 security and bug fix update Advisory ID: RHSA-2012:0682-01 Product: JBoss Enterprise Web Server Advisory URL: https://rhn.redhat.com/errata/RHSA-2012-0682.html Issue date: 2012-05-21 CVE Names: CVE-2011-1184 CVE-2011-2204 CVE-2011-2526 CVE-2011-3190 CVE-2011-3375 CVE-2011-4858 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 CVE-2012-0022 ===================================================================== 1. Summary: Updated tomcat6 packages that fix multiple security issues and three bugs are now available for JBoss Enterprise Web Server 1.0.2 for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: JBoss Enterprise Web Server 1.0 for RHEL 5 Server - noarch JBoss Enterprise Web Server 1.0 for RHEL 6 Server - noarch 3. Description: Apache Tomcat is a servlet container. JBoss Enterprise Web Server includes the Tomcat Native library, providing Apache Portable Runtime (APR) support for Tomcat. References in this text to APR refer to the Tomcat Native implementation, not any other apr package. This update fixes the JBPAPP-4873, JBPAPP-6133, and JBPAPP-6852 bugs. It also resolves the following security issues: Multiple flaws weakened the Tomcat HTTP DIGEST authentication implementation, subjecting it to some of the weaknesses of HTTP BASIC authentication, for example, allowing remote attackers to perform session replay attacks. (CVE-2011-1184, CVE-2011-5062, CVE-2011-5063, CVE-2011-5064) A flaw was found in the way the Coyote (org.apache.coyote.ajp.AjpProcessor) and APR (org.apache.coyote.ajp.AjpAprProcessor) Tomcat AJP (Apache JServ Protocol) connectors processed certain POST requests. An attacker could send a specially-crafted request that would cause the connector to treat the message body as a new request. This allows arbitrary AJP messages to be injected, possibly allowing an attacker to bypass a web application's authentication checks and gain access to information they would otherwise be unable to access. The JK (org.apache.jk.server.JkCoyoteHandler) connector is used by default when the APR libraries are not present. The JK connector is not affected by this flaw. (CVE-2011-3190) A flaw in the way Tomcat recycled objects that contain data from user requests (such as IP addresses and HTTP headers) when certain errors occurred. If a user sent a request that caused an error to be logged, Tomcat would return a reply to the next request (which could be sent by a different user) with data from the first user's request, leading to information disclosure. Under certain conditions, a remote attacker could leverage this flaw to hijack sessions. (CVE-2011-3375) The Java hashCode() method implementation was susceptible to predictable hash collisions. This update introduces a limit on the number of parameters processed per request to mitigate this issue. The default limit is 512 for parameters and 128 for headers. These defaults can be changed by setting the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2011-4858) Tomcat did not handle large numbers of parameters and large parameter values efficiently. A remote attacker could make Tomcat use an excessive amount of CPU time by sending an HTTP request containing a large number of parameters or large parameter values. This update introduces limits on the number of parameters and headers processed per request to address this issue. Refer to the CVE-2011-4858 description for information about the org.apache.tomcat.util.http.Parameters.MAX_COUNT and org.apache.tomcat.util.http.MimeHeaders.MAX_COUNT system properties. (CVE-2012-0022) A flaw in the Tomcat MemoryUserDatabase. If a runtime exception occurred when creating a new user with a JMX client, that user's password was logged to Tomcat log files. Note: By default, only administrators have access to such log files. (CVE-2011-2204) A flaw in the way Tomcat handled sendfile request attributes when using the HTTP APR or NIO (Non-Blocking I/O) connector. A malicious web application running on a Tomcat instance could use this flaw to bypass security manager restrictions and gain access to files it would otherwise be unable to access, or possibly terminate the Java Virtual Machine (JVM). The HTTP NIO connector is used by default in JBoss Enterprise Web Server. (CVE-2011-2526) Red Hat would like to thank oCERT for reporting CVE-2011-4858, and the Apache Tomcat project for reporting CVE-2011-2526. oCERT acknowledges Julian Wälde and Alexander Klink as the original reporters of CVE-2011-4858. 4. Solution: Users of Tomcat should upgrade to these updated packages, which resolve these issues. Tomcat must be restarted for this update to take effect. Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 717013 - CVE-2011-2204 tomcat: password disclosure vulnerability 720948 - CVE-2011-2526 tomcat: security manager restrictions bypass 734868 - CVE-2011-3190 tomcat: authentication bypass and information disclosure 741401 - CVE-2011-1184 CVE-2011-5062 CVE-2011-5063 CVE-2011-5064 tomcat: Multiple weaknesses in HTTP DIGEST authentication 750521 - CVE-2011-4858 tomcat: hash table collisions CPU usage DoS (oCERT-2011-003) 782624 - CVE-2011-3375 tomcat: information disclosure due to improper response and request object recycling 783359 - CVE-2012-0022 tomcat: large number of parameters DoS 6. Package List: JBoss Enterprise Web Server 1.0 for RHEL 5 Server: Source: tomcat6-6.0.32-24_patch_07.ep5.el5.src.rpm noarch: tomcat6-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-admin-webapps-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-docs-webapp-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-el-1.0-api-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-javadoc-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-jsp-2.1-api-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-lib-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-log4j-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-servlet-2.5-api-6.0.32-24_patch_07.ep5.el5.noarch.rpm tomcat6-webapps-6.0.32-24_patch_07.ep5.el5.noarch.rpm JBoss Enterprise Web Server 1.0 for RHEL 6 Server: Source: tomcat6-6.0.32-24_patch_07.ep5.el6.src.rpm noarch: tomcat6-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-admin-webapps-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-docs-webapp-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-el-1.0-api-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-javadoc-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-jsp-2.1-api-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-lib-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-log4j-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-servlet-2.5-api-6.0.32-24_patch_07.ep5.el6.noarch.rpm tomcat6-webapps-6.0.32-24_patch_07.ep5.el6.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.redhat.com/security/data/cve/CVE-2011-1184.html https://www.redhat.com/security/data/cve/CVE-2011-2204.html https://www.redhat.com/security/data/cve/CVE-2011-2526.html https://www.redhat.com/security/data/cve/CVE-2011-3190.html https://www.redhat.com/security/data/cve/CVE-2011-3375.html https://www.redhat.com/security/data/cve/CVE-2011-4858.html https://www.redhat.com/security/data/cve/CVE-2011-5062.html https://www.redhat.com/security/data/cve/CVE-2011-5063.html https://www.redhat.com/security/data/cve/CVE-2011-5064.html https://www.redhat.com/security/data/cve/CVE-2012-0022.html https://access.redhat.com/security/updates/classification/#moderate http://tomcat.apache.org/security-6.html https://issues.jboss.org/browse/JBPAPP-4873 https://issues.jboss.org/browse/JBPAPP-6133 https://issues.jboss.org/browse/JBPAPP-6852 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFPunmrXlSAg2UNWIIRAkA4AKCTaGA0dlkzcdXw8BMDz6i6Kk31iQCbBwk5 HGbJnvqJAVX57f9/Kpj3+R4= =pyZw -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce . CVE-2011-2204 In rare setups passwords were written into a logfile. CVE-2011-2526 Missing input sanisiting in the HTTP APR or HTTP NIO connectors could lead to denial of service. CVE-2011-3190 AJP requests could be spoofed in some setups. CVE-2011-3375 Incorrect request caching could lead to information disclosure. CVE-2011-4858 CVE-2012-0022 This update adds countermeasures against a collision denial of service vulnerability in the Java hashtable implementation and addresses denial of service potentials when processing large amounts of requests. Additional information can be found at http://tomcat.apache.org/security-6.html For the stable distribution (squeeze), this problem has been fixed in version 6.0.35-1+squeeze2. For the unstable distribution (sid), this problem has been fixed in version 6.0.35-1. We recommend that you upgrade your tomcat6 packages. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ . HP Network Node Manager I (NNMi) v9.0X and v9.1X for HP-UX, Linux, Solaris, and Windows. These hotfixes also apply to the following products and can be applied to all patch levels: HP NNM iSPI for IP QA HP NNM iSPI for IP Telephony HP NNM SPI for IP Multicast HP NNM SPI for MPLS NNMi Version Operating System Hotfix 9.00 HP-UX, Linux, Solaris, and Windows. HF-NNMi-9.0xP5-JBoss-20130417 9.10 HP-UX, Linux, Solaris, and Windows. 5 client) - i386, x86_64 3. Description: The JBoss Communications Platform (JBCP) is an open source VoIP platform certified for JAIN SLEE 1.1 and SIP Servlets 1.1 compliance. JBCP serves as a high performance core for Service Delivery Platforms (SDPs) and IP Multimedia Subsystems (IMSs) by leveraging J2EE to enable the convergence of data and video in Next-Generation Intelligent Network (NGIN) applications. If JBoss Web was hosting an application with UTF-8 character encoding enabled, or that included user-supplied UTF-8 strings in a response, a remote attacker could use this flaw to cause a denial of service (infinite loop) on the JBoss Web server. ---------------------------------------------------------------------- Secunia is hiring! Find your next job here: http://secunia.com/company/jobs/ ---------------------------------------------------------------------- TITLE: Hitachi COBOL2002 Products Unspecified Vulnerability SECUNIA ADVISORY ID: SA47612 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/47612/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=47612 RELEASE DATE: 2012-01-20 DISCUSS ADVISORY: http://secunia.com/advisories/47612/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/47612/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=47612 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Hitachi has reported a vulnerability in some COBOL2002 products, which can be exploited by malicious users to compromise a vulnerable system. The vulnerability is caused due to an unspecified error. No further information is currently available. PROVIDED AND/OR DISCOVERED BY: Reported by the vendor. ORIGINAL ADVISORY: http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS12-002/index.html OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 3.33

sources: NVD: CVE-2011-4858 // CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 114139 // PACKETSTORM: 109328 // PACKETSTORM: 111783 // PACKETSTORM: 109271 // PACKETSTORM: 109542 // PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 109363 // PACKETSTORM: 122552 // PACKETSTORM: 111782 // PACKETSTORM: 109274 // PACKETSTORM: 108859

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2012-0341

AFFECTED PRODUCTS

vendor:apachemodel:tomcatscope:eqversion:5.5.35

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.6

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.0

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.1

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.2

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.4

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.5

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.3

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.7

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:6.0.8

Trust: 1.6

vendor:apachemodel:tomcatscope:eqversion:7.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.28

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.29

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.0

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.1

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.7

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.12

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.20

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.31

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.16

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.9

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.2

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.25

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.26

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.20

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.19

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.3

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.13

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.32

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.17

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.15

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.10

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.34

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.5

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.23

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.8

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.27

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.30

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.33

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.11

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.21

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.22

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.4

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.18

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.6

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.24

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:7.0.14

Trust: 1.0

vendor:apachemodel:tomcatscope:eqversion:6.0.9

Trust: 1.0

vendor:apache tomcatmodel: - scope: - version: -

Trust: 0.8

vendor:microsoftmodel: - scope: - version: -

Trust: 0.8

vendor:oraclemodel: - scope: - version: -

Trust: 0.8

vendor:rubymodel: - scope: - version: -

Trust: 0.8

vendor:the php groupmodel: - scope: - version: -

Trust: 0.8

vendor:hitachimodel:cobol2002 net server suitescope:eqversion:2.x

Trust: 0.6

vendor:hitachimodel:cobol2002 net client suitescope:eqversion:2.x

Trust: 0.6

vendor:hitachimodel:cobol2002 net developerscope:eqversion:2.x

Trust: 0.6

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2011-4858
value: MEDIUM

Trust: 1.0

CARNEGIE MELLON: VU#903934
value: 10.80

Trust: 0.8

CNNVD: CNNVD-201201-056
value: MEDIUM

Trust: 0.6

VULMON: CVE-2011-4858
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2011-4858
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

sources: CERT/CC: VU#903934 // VULMON: CVE-2011-4858 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

PROBLEMTYPE DATA

problemtype:CWE-399

Trust: 1.0

sources: NVD: CVE-2011-4858

THREAT TYPE

remote

Trust: 1.0

sources: PACKETSTORM: 111783 // PACKETSTORM: 109271 // PACKETSTORM: 112906 // PACKETSTORM: 111782 // CNNVD: CNNVD-201201-056

TYPE

resource management error

Trust: 0.6

sources: CNNVD: CNNVD-201201-056

EXPLOIT AVAILABILITY

sources: VULMON: CVE-2011-4858

PATCH

title:Patch for Hitachi COBOL2002 product has an unknown vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/8212

Trust: 0.6

title:Red Hat: Moderate: tomcat6 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120475 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120474 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120074 - Security Advisory

Trust: 0.1

title:Red Hat: Important: jbossweb security updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120076 - Security Advisory

Trust: 0.1

title:Ubuntu Security Notice: tomcat6 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-1359-1

Trust: 0.1

title:Red Hat: Moderate: tomcat5 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120680 - Security Advisory

Trust: 0.1

title:Red Hat: Moderate: tomcat6 security and bug fix updateurl:https://vulmon.com/vendoradvisory?qidtp=red_hat_security_advisories&qid=RHSA-20120682 - Security Advisory

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2011-4084

Trust: 0.1

sources: CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858

EXTERNAL IDS

db:NVDid:CVE-2011-4858

Trust: 2.8

db:OCERTid:OCERT-2011-003

Trust: 2.5

db:CERT/CCid:VU#903934

Trust: 2.5

db:SECUNIAid:48791

Trust: 1.1

db:SECUNIAid:48790

Trust: 1.1

db:SECUNIAid:48549

Trust: 1.1

db:SECUNIAid:54971

Trust: 1.1

db:SECUNIAid:55115

Trust: 1.1

db:BIDid:51200

Trust: 1.1

db:SECUNIAid:47612

Trust: 0.8

db:CNVDid:CNVD-2012-0341

Trust: 0.6

db:MLISTid:[ANNOUNCE] 20111228 [SECURITY] APACHE TOMCAT AND THE HASHTABLE COLLISION DOS VULNERABILITY

Trust: 0.6

db:CNNVDid:CNNVD-201201-056

Trust: 0.6

db:EXPLOIT-DBid:2012

Trust: 0.1

db:VULMONid:CVE-2011-4858

Trust: 0.1

db:PACKETSTORMid:114139

Trust: 0.1

db:PACKETSTORMid:109328

Trust: 0.1

db:PACKETSTORMid:111783

Trust: 0.1

db:PACKETSTORMid:109271

Trust: 0.1

db:PACKETSTORMid:109542

Trust: 0.1

db:PACKETSTORMid:112906

Trust: 0.1

db:PACKETSTORMid:112904

Trust: 0.1

db:PACKETSTORMid:109363

Trust: 0.1

db:PACKETSTORMid:122552

Trust: 0.1

db:PACKETSTORMid:111782

Trust: 0.1

db:PACKETSTORMid:109274

Trust: 0.1

db:HITACHIid:HS12-002

Trust: 0.1

db:PACKETSTORMid:108859

Trust: 0.1

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 114139 // PACKETSTORM: 109328 // PACKETSTORM: 111783 // PACKETSTORM: 109271 // PACKETSTORM: 109542 // PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 109363 // PACKETSTORM: 122552 // PACKETSTORM: 111782 // PACKETSTORM: 109274 // PACKETSTORM: 108859 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

REFERENCES

url:http://www.ocert.org/advisories/ocert-2011-003.html

Trust: 2.5

url:http://www.nruns.com/_downloads/advisory28122011.pdf

Trust: 2.5

url:https://bugzilla.redhat.com/show_bug.cgi?id=750521

Trust: 1.7

url:http://tomcat.apache.org/tomcat-7.0-doc/changelog.html

Trust: 1.7

url:http://www.kb.cert.org/vuls/id/903934

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2012-0089.html

Trust: 1.2

url:http://rhn.redhat.com/errata/rhsa-2012-0075.html

Trust: 1.2

url:http://rhn.redhat.com/errata/rhsa-2012-0078.html

Trust: 1.2

url:https://github.com/firefart/hashcollision-dos-poc/blob/master/hashtablepoc.py

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=132871655717248&w=2

Trust: 1.1

url:http://www.debian.org/security/2012/dsa-2401

Trust: 1.1

url:http://secunia.com/advisories/48791

Trust: 1.1

url:http://secunia.com/advisories/48790

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=136485229118404&w=2

Trust: 1.1

url:http://secunia.com/advisories/54971

Trust: 1.1

url:http://secunia.com/advisories/55115

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0406.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0074.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0325.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0076.html

Trust: 1.1

url:http://rhn.redhat.com/errata/rhsa-2012-0077.html

Trust: 1.1

url:http://www.securityfocus.com/bid/51200

Trust: 1.1

url:https://oval.cisecurity.org/repository/search/definition/oval%3aorg.mitre.oval%3adef%3a18886

Trust: 1.1

url:http://secunia.com/advisories/48549

Trust: 1.1

url:http://marc.info/?l=bugtraq&m=133294394108746&w=2

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4858

Trust: 1.1

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106%40apache.org%3e

Trust: 1.0

url:http://www.cs.rice.edu/~scrosby/hash/crosbywallach_usenixsec2003.pdf

Trust: 0.8

url:http://technet.microsoft.com/en-us/security/bulletin/ms11-100.mspx

Trust: 0.8

url:http://blogs.technet.com/b/srd/archive/2011/12/27/more-information-about-the-december-2011-asp-net-vulnerability.aspx

Trust: 0.8

url:http://blade.nagaokaut.ac.jp/cgi-bin/scat.rb/ruby/ruby-talk/391606

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2012-0022

Trust: 0.8

url:http://secunia.com/advisories/47612/

Trust: 0.7

url:http://mail-archives.apache.org/mod_mbox/tomcat-announce/201112.mbox/%3c4efb9800.5010106@apache.org%3e

Trust: 0.7

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.7

url:https://www.redhat.com/security/data/cve/cve-2011-4858.html

Trust: 0.7

url:http://bugzilla.redhat.com/):

Trust: 0.7

url:https://access.redhat.com/security/team/contact/

Trust: 0.7

url:https://nvd.nist.gov/vuln/detail/cve-2011-2526

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-1184

Trust: 0.6

url:https://www.redhat.com/security/data/cve/cve-2012-0022.html

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2011-5063

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-5064

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-5062

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2011-2204

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2011-3190

Trust: 0.4

url:https://access.redhat.com/security/team/key/#package

Trust: 0.4

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2011-5063.html

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2011-2526.html

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2011-5064.html

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2011-1184.html

Trust: 0.4

url:https://www.redhat.com/security/data/cve/cve-2011-5062.html

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2011-3375

Trust: 0.3

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.3

url:http://tomcat.apache.org/security-6.html

Trust: 0.3

url:https://docs.redhat.com/docs/en-us/index.html

Trust: 0.2

url:https://access.redhat.com/kb/docs/doc-11259

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-4610.html

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-4610

Trust: 0.2

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-2204.html

Trust: 0.2

url:https://www.redhat.com/security/data/cve/cve-2011-3190.html

Trust: 0.2

url:https://issues.jboss.org/browse/jbpapp-6133

Trust: 0.2

url:https://issues.jboss.org/browse/jbpapp-4873

Trust: 0.2

url:https://access.redhat.com/knowledge/articles/11258

Trust: 0.2

url:http://tomcat.apache.org/security-5.html

Trust: 0.2

url:https://cwe.mitre.org/data/definitions/399.html

Trust: 0.1

url:https://access.redhat.com/errata/rhsa-2012:0475

Trust: 0.1

url:https://github.com/live-hack-cve/cve-2011-4084

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://usn.ubuntu.com/1359-1/

Trust: 0.1

url:https://www.exploit-db.com/exploits/2012/

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=24901

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0783

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0033

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0033

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0781

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2729

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2902

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5062

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2902

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0534

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1183

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-3718

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1475

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0534

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0013

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5063

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3718

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1582

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0580

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-4172

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-5064

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-4312

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2693

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1475

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0781

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-2227

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1088

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-0580

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2901

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2526

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1183

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1184

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2204

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2008-5515

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2012-0022

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2009-2693

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-1157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4172

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1088

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2481

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-0783

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-4312

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-4858

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-2227

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2481

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0013

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1157

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2729

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2008-5515

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-2901

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-3190

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1419

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-3375

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201206-24.xml

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-1582

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1419

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-4573.html

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-0052.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-0062

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-0052

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4573

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-3206.html

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?downloadtype=distributions&product=em&version=2.4.2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3206

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2012-0062.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0475.html

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=appplatform&downloadtype=securitypatches&version=5.1.2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4885

Trust: 0.1

url:http://h20566.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.1

url:https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docdisplay/?docid=emr_na-c02964430

Trust: 0.1

url:https://www.hp.com/go/swa

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2006-7243

Trust: 0.1

url:https://issues.jboss.org/browse/jbpapp-6852

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2011-3375.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0682.html

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0680.html

Trust: 0.1

url:http://secunia.com/

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:http://lists.grok.org.uk/full-disclosure-charter.html

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2007-5333

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-0738

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2009-3554

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1429

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-1483

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-1428

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2196

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3546

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-4605

Trust: 0.1

url:https://rhn.redhat.com/errata/rhsa-2012-0474.html

Trust: 0.1

url:https://access.redhat.com/jbossnetwork/restricted/listsoftware.html?product=communications.platform&downloadtype=distributions

Trust: 0.1

url:http://www.hitachi.co.jp/prod/comp/soft1/global/security/info/vuls/hs12-002/index.html

Trust: 0.1

url:http://secunia.com/company/jobs/

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/advisories/47612/#comments

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=47612

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: CERT/CC: VU#903934 // CNVD: CNVD-2012-0341 // VULMON: CVE-2011-4858 // PACKETSTORM: 114139 // PACKETSTORM: 109328 // PACKETSTORM: 111783 // PACKETSTORM: 109271 // PACKETSTORM: 109542 // PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 109363 // PACKETSTORM: 122552 // PACKETSTORM: 111782 // PACKETSTORM: 109274 // PACKETSTORM: 108859 // CNNVD: CNNVD-201201-056 // NVD: CVE-2011-4858

CREDITS

Red Hat

Trust: 0.7

sources: PACKETSTORM: 109328 // PACKETSTORM: 111783 // PACKETSTORM: 109271 // PACKETSTORM: 112906 // PACKETSTORM: 112904 // PACKETSTORM: 111782 // PACKETSTORM: 109274

SOURCES

db:CERT/CCid:VU#903934
db:CNVDid:CNVD-2012-0341
db:VULMONid:CVE-2011-4858
db:PACKETSTORMid:114139
db:PACKETSTORMid:109328
db:PACKETSTORMid:111783
db:PACKETSTORMid:109271
db:PACKETSTORMid:109542
db:PACKETSTORMid:112906
db:PACKETSTORMid:112904
db:PACKETSTORMid:109363
db:PACKETSTORMid:122552
db:PACKETSTORMid:111782
db:PACKETSTORMid:109274
db:PACKETSTORMid:108859
db:CNNVDid:CNNVD-201201-056
db:NVDid:CVE-2011-4858

LAST UPDATE DATE

2024-11-06T22:03:52.895000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#903934date:2016-02-15T00:00:00
db:CNVDid:CNVD-2012-0341date:2012-02-01T00:00:00
db:VULMONid:CVE-2011-4858date:2018-01-09T00:00:00
db:CNNVDid:CNNVD-201201-056date:2012-01-09T00:00:00
db:NVDid:CVE-2011-4858date:2023-11-07T02:09:38.600

SOURCES RELEASE DATE

db:CERT/CCid:VU#903934date:2011-12-28T00:00:00
db:CNVDid:CNVD-2012-0341date:2012-02-01T00:00:00
db:VULMONid:CVE-2011-4858date:2012-01-05T00:00:00
db:PACKETSTORMid:114139date:2012-06-24T23:54:31
db:PACKETSTORMid:109328date:2012-02-02T01:22:48
db:PACKETSTORMid:111783date:2012-04-12T03:14:12
db:PACKETSTORMid:109271date:2012-02-01T02:54:44
db:PACKETSTORMid:109542date:2012-02-08T16:07:24
db:PACKETSTORMid:112906date:2012-05-22T00:21:41
db:PACKETSTORMid:112904date:2012-05-22T00:20:13
db:PACKETSTORMid:109363date:2012-02-02T23:31:24
db:PACKETSTORMid:122552date:2013-07-25T18:22:00
db:PACKETSTORMid:111782date:2012-04-12T03:11:30
db:PACKETSTORMid:109274date:2012-02-01T02:55:27
db:PACKETSTORMid:108859date:2012-01-20T08:20:00
db:CNNVDid:CNNVD-201201-056date:2012-01-09T00:00:00
db:NVDid:CVE-2011-4858date:2012-01-05T19:55:01.033