Here is a report on sonicwall. I do not see this as a big problem though
but keep an eye on it.
Date Reported: 10/29/2002
Brief Description: SonicWALL Content Filtering IP addresses can bypass
URL filtering
Risk Factor: Medium
Attack Type: Network Based
Platforms: Windows Any version, Sonicwall Content Filtering
Any Version
Vulnerability: sonicwall-content-ip-bypass
X-Force URL: http://www.iss.net/security_center/static/10531.php
_____________________________________________________________________
Scott Fosseen - Systems Engineer - Arrowhead AEA
www.aea5.k12.ia.us/aeaphone.nsf/web/fosseenscott -
_____________________________________________________________________
Tech Support: "What does the screen say now?"
Person: "It says, 'Hit ENTER when ready.'"
Tech Support: "Well?"
Person: "How do I know when it's ready?"
_____________________________________________________________________
----- Original Message -----
From: "X-Force" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, November 11, 2002 1:18 PM
Subject: ISS Security Alert Summary AS02-45
> -----BEGIN PGP SIGNED MESSAGE-----
>
> Internet Security Systems Security Alert Summary AS02-45
> November 11, 2002
>
> X-Force Vulnerability and Threat Database:
> http://www.iss.net/security_center
>
> To receive these Alert Summaries, as well as other Alerts and
> Advisories, subscribe to the Internet Security Systems Alert
> mailing list at:
> http://www.iss.net/security_center/maillists
>
> This summary is available at the following address:
> http://www.iss.net/security_center/alerts/AS02-45.php
> _____
> Contents:
> * 36 Reported Vulnerabilities
> * Risk Factor Key
> _____
>
>
> Date Reported: 10/29/2002
> Brief Description: SonicWALL Content Filtering IP addresses can bypass
> URL filtering
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Windows Any version, Sonicwall Content Filtering
> Any Version
> Vulnerability: sonicwall-content-ip-bypass
> X-Force URL: http://www.iss.net/security_center/static/10531.php
>
> Date Reported: 10/31/2002
> Brief Description: SmartMail Server unexpected connection termination
> denial of service attack
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: Windows Any version, SmartMail Server 2.0 Interim
> Build 83
> Vulnerability: smartmail-terminate-connection-dos
> X-Force URL: http://www.iss.net/security_center/static/10533.php
>
> Date Reported: 11/01/2002
> Brief Description: Iomega NAS A300U FTP service could allow
> unauthorized access to shared directories
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Unix Any version, Iomega NAS A300U Any version
> Vulnerability: iomega-ftp-shared-directories
> X-Force URL: http://www.iss.net/security_center/static/10530.php
>
> Date Reported: 11/01/2002
> Brief Description: Multiple vendor access point Embedded HTTP Server
> denial of service
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: Linksys Access Points Any version, D-Link Access
> Points Any version
> Vulnerability: ap-embedded-http-dos
> X-Force URL: http://www.iss.net/security_center/static/10537.php
>
> Date Reported: 11/02/2002
> Brief Description: EventSave and EventSave+ could allow event loss
> from the Windows NT log
> Risk Factor: Low
> Attack Type: Host Based
> Platforms: Windows NT Any version, EventSave prior to 5.3
> Vulnerability: eventsave-event-log-loss
> X-Force URL: http://www.iss.net/security_center/static/10535.php
>
> Date Reported: 11/02/2002
> Brief Description: Microsoft SQL Server login accounts use weak
> encryption algorithm
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Windows NT Any version, Microsoft SQL Server Any
> version, Windows 2000 Any version
> Vulnerability: mssql-weak-password-encryption
> X-Force URL: http://www.iss.net/security_center/static/10542.php
>
> Date Reported: 11/03/2002
> Brief Description: AstroCam astrocam.cgi could allow remote command
> execution
> Risk Factor: High
> Attack Type: Network Based
> Platforms: Linux Any version, NetBSD Any version, OpenBSD Any
> version, AstroCam prior to 2.1.3
> Vulnerability: astrocam-cgi-command-execution
> X-Force URL: http://www.iss.net/security_center/static/10538.php
>
> Date Reported: 11/04/2002
> Brief Description: Pablo FTP Server malformed username format string
> denial of service
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Windows 2000 Any version, Pablo FTP Server 1.2,
> Pablo FTP Server 1.3, Pablo FTP Server 1.5
> Vulnerability: pablo-ftp-username-dos
> X-Force URL: http://www.iss.net/security_center/static/10532.php
>
> Date Reported: 11/04/2002
> Brief Description: Xeneo Web Server PHP version malformed HTTP request
> denial of service
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: Windows Any version, Xeneo Web Server 2.1.0.0,
> Xeneo Web Server 2.0.759.6
> Vulnerability: xeneo-php-dos
> X-Force URL: http://www.iss.net/security_center/static/10534.php
>
> Date Reported: 11/04/2002
> Brief Description: Global Sun Technology IEEE802.11b+ access points
> could disclose sensitive information
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: Wisecom GL2422AP-0T Any version, Linksys WAP11 2.2
> Vulnerability: ieee80211b-ap-information-disclosure
> X-Force URL: http://www.iss.net/security_center/static/10536.php
>
> Date Reported: 11/04/2002
> Brief Description: Sun RPC libc no time-out mechanism denial of
> service
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: MacOS X 10.0 to 10.2.1, MacOS X Server 10.0 to
> 10.2.1, glibc 2.3.1 and earlier
> Vulnerability: sun-rpc-libc-dos
> X-Force URL: http://www.iss.net/security_center/static/10539.php
>
> Date Reported: 11/04/2002
> Brief Description: Com21 DOXport 1100 series cable modems allow an
> attacker to load a malicious configuration file
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Com21 DOXport 1100 series 2.1.1.106
> Vulnerability: com21-doxport-config-file
> X-Force URL: http://www.iss.net/security_center/static/10543.php
>
> Date Reported: 11/04/2002
> Brief Description: The Magic Notebook invalid username denial of
> service
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: Linux Any version, Unix Any version, The Magic
> Notebook prior to 1.2
> Vulnerability: magic-book-username-dos
> X-Force URL: http://www.iss.net/security_center/static/10562.php
>
> Date Reported: 11/05/2002
> Brief Description: SnortCenter creates an insecure temporary file
> Risk Factor: Medium
> Attack Type: Host Based
> Platforms: Linux Any version, Unix Any version, SnortCenter
> 0.9.5
> Vulnerability: snortcenter-tmp-file-insecure
> X-Force URL: http://www.iss.net/security_center/static/10540.php
>
> Date Reported: 11/05/2002
> Brief Description: networking_utils.php ping command could be used to
> read files
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, Windows Any version, Unix Any
> version, networking_utils 1.0
> Vulnerability: networkingutils-ping-read-files
> X-Force URL: http://www.iss.net/security_center/static/10541.php
>
> Date Reported: 11/05/2002
> Brief Description: HP TruCluster Server Interconnect denial of service
> Risk Factor: Low
> Attack Type: Host Based / Network Based
> Platforms: HP TruCluster Server 5.1A, HP TruCluster Server
> 5.0A
> Vulnerability: hp-trucluster-interconnect-dos
> X-Force URL: http://www.iss.net/security_center/static/10551.php
>
> Date Reported: 11/05/2002
> Brief Description: pp_powerSwitch could allow an attacker to control
> any port
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, pp_powerSwitch prior to 0.1.1
> Vulnerability: pp-powerswitch-port-access
> X-Force URL: http://www.iss.net/security_center/static/10552.php
>
> Date Reported: 11/05/2002
> Brief Description: PortalApp users could gain elevated privileges on
> the Web portal
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: PortalApp 2.2, Windows Any version
> Vulnerability: portalapp-user-privilege-elevation
> X-Force URL: http://www.iss.net/security_center/static/10558.php
>
> Date Reported: 11/05/2002
> Brief Description: Cisco PIX Firewall TCP SYN packets denial of
> service
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: Linux Any version, Windows Any version, Unix Any
> version, Cisco PIX Firewall 6.2.2
> Vulnerability: cisco-pix-packet-dos
> X-Force URL: http://www.iss.net/security_center/static/10566.php
>
> Date Reported: 11/06/2002
> Brief Description: perl-MailTools Mail::Mailer module command
> execution
> Risk Factor: High
> Attack Type: Network Based
> Platforms: SuSE Linux 7.1, SuSE Linux 7.2, SuSE Linux 7.3,
> SuSE eMail Server III Any version, SuSE Linux 8.0,
> Gentoo Linux Any version, SuSE eMail Server 3.1,
> SuSE Linux 8.1, perl-MailTools Any version
> Vulnerability: mail-mailer-command-execution
> X-Force URL: http://www.iss.net/security_center/static/10548.php
>
> Date Reported: 11/06/2002
> Brief Description: LuxMan maped binary file could be used to read memory
> Risk Factor: Medium
> Attack Type: Host Based
> Platforms: Debian Linux 3.0, LuxMan 0.41
> Vulnerability: luxman-maped-read-memory
> X-Force URL: http://www.iss.net/security_center/static/10549.php
>
> Date Reported: 11/06/2002
> Brief Description: QNX RTP timer denial of service
> Risk Factor: Low
> Attack Type: Host Based
> Platforms: QNX RTP 6.1
> Vulnerability: qnx-rtp-timer-dos
> X-Force URL: http://www.iss.net/security_center/static/10550.php
>
> Date Reported: 11/06/2002
> Brief Description: Linuxconf sendmail.cf file allows mail relaying
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: Linux Any version, Linuxconf prior to 1.28
> Vulnerability: linuxconf-sendmail-mail-relay
> X-Force URL: http://www.iss.net/security_center/static/10554.php
>
> Date Reported: 11/06/2002
> Brief Description: Macromedia ColdFusion MX could allow an attacker to
> view CFML source
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, Unix Any version, Windows NT Any
> version, Windows 2000 Any version, ColdFusion MX
> Vulnerability: coldfusion-mx-file-disclosure
> X-Force URL: http://www.iss.net/security_center/static/10565.php
>
> Date Reported: 11/06/2002
> Brief Description: Macromedia JRun long URL buffer overflow
> Risk Factor: High
> Attack Type: Network Based
> Platforms: Windows NT Any version, Windows 2000 Any version,
> JRun 3.0, JRun 3.1, JRun 4.0
> Vulnerability: jrun-long-url-bo
> X-Force URL: http://www.iss.net/security_center/static/10568.php
>
> Date Reported: 11/06/2002
> Brief Description: Macromedia JRun Unicode encoded JSP file source
> disclosure
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, Unix Any version, JRun 3.0, JRun
> 3.1, JRun 4.0
> Vulnerability: jrun-unicode-source-disclosure
> X-Force URL: http://www.iss.net/security_center/static/10570.php
>
> Date Reported: 11/06/2002
> Brief Description: Macromedia JRun log file and jrun.ini file
> disclosure
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Windows NT Any version, Windows 2000 Any version,
> JRun 3.0, JRun 3.1, JRun 4.0
> Vulnerability: jrun-log-file-disclosure
> X-Force URL: http://www.iss.net/security_center/static/10571.php
>
> Date Reported: 11/06/2002
> Brief Description: OpenBSD getrlimit(2) denial of service
> Risk Factor: Low
> Attack Type: Host Based
> Platforms: OpenBSD 3.0, OpenBSD 3.1
> Vulnerability: openbsd-getrlimit-dos
> X-Force URL: http://www.iss.net/security_center/static/10572.php
>
> Date Reported: 11/07/2002
> Brief Description: Pine "From:" message header denial of service
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, Unix Any version, Pine 4.44
> Vulnerability: pine-from-header-dos
> X-Force URL: http://www.iss.net/security_center/static/10555.php
>
> Date Reported: 11/07/2002
> Brief Description: CuteCast Forum stores passwords in plain text
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, Windows Any version, Unix Any
> version, CuteCast Forum 1.2
> Vulnerability: cutecast-forum-plaintext-passwords
> X-Force URL: http://www.iss.net/security_center/static/10556.php
>
> Date Reported: 11/07/2002
> Brief Description: Lotus Domino non-existent .nsf request could
> disclose version information
> Risk Factor: Low
> Attack Type: Network Based
> Platforms: HP-UX Any version, Linux Any version, Solaris Any
> version, Windows NT Any version, OS/2 Any version,
> Windows 2000 Any version, Lotus Domino 5.0.8, Lotus
> Domino 5.0.9, Lotus Domino 5.0.9a
> Vulnerability: lotus-domino-version-disclosure
> X-Force URL: http://www.iss.net/security_center/static/10557.php
>
> Date Reported: 11/07/2002
> Brief Description: Window Maker image file buffer overflow
> Risk Factor: High
> Attack Type: Network Based
> Platforms: Debian Linux 3.0, Window Maker Any version
> Vulnerability: window-maker-image-bo
> X-Force URL: http://www.iss.net/security_center/static/10560.php
>
> Date Reported: 11/07/2002
> Brief Description: Perception LiteServe directory index cross-site
> scripting
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Windows Any version, LiteServe 2.01
> Vulnerability: liteserve-directory-index-xss
> X-Force URL: http://www.iss.net/security_center/static/10561.php
>
> Date Reported: 11/08/2002
> Brief Description: Simple Web Server could allow an attacker to access
> password protected files
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, Simple Web Server 0.5.1
> Vulnerability: simple-server-file-access
> X-Force URL: http://www.iss.net/security_center/static/10563.php
>
> Date Reported: 11/08/2002
> Brief Description: QNX RTOS could allow an attacker to gain local root
> privileges
> Risk Factor: High
> Attack Type: Host Based
> Platforms: QNX RTOS 6.2.0
> Vulnerability: qnx-rtos-gain-privileges
> X-Force URL: http://www.iss.net/security_center/static/10564.php
>
> Date Reported: 11/08/2002
> Brief Description: Zeus Admin Server index.fcgi script cross-site
> scripting
> Risk Factor: Medium
> Attack Type: Network Based
> Platforms: Linux Any version, Unix Any version, Zeus Web
> Server 4.1r2
> Vulnerability: zeus-admin-index-xss
> X-Force URL: http://www.iss.net/security_center/static/10567.php
>
> _____
>
> Risk Factor Key:
>
> High Any vulnerability that provides an attacker with immediate
> access into a machine, gains superuser access, or bypasses
> a firewall. Example: A vulnerable Sendmail 8.6.5 version
> that allows an intruder to execute commands on mail server.
> Medium Any vulnerability that provides information that has a high
> potential of giving system access to an intruder. Example:
> A misconfigured TFTP or vulnerable NIS server that allows
> an intruder to get the password file that could contain an
> account with a guessable password.
> Low Any vulnerability that provides information that could
> potentially lead to a compromise. Example: A finger that
> allows an intruder to find out who is online and potential
> accounts to attempt to crack passwords via brute force
> methods.
>
> ______
>
> About Internet Security Systems (ISS)
> Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a
> pioneer and world leader in software and services that protect critical
> online resources from an ever-changing spectrum of threats and misuse.
> Internet Security Systems is headquartered in Atlanta, GA, with
> additional operations throughout the Americas, Asia, Australia, Europe
> and the Middle East.
>
> Copyright (c) 2002 Internet Security Systems, Inc. All rights reserved
> worldwide.
>
> Permission is hereby granted for the electronic redistribution of this
> document. It is not to be edited or altered in any way without the
> express written consent of the Internet Security Systems X-Force. If you
> wish to reprint the whole or any part of this document in any other
> medium excluding electronic media, please email [EMAIL PROTECTED] for
> permission.
>
> Disclaimer: The information within this paper may change without notice.
Internet
> Security Systems provides this information on an AS IS basis with NO
warranties,
> implied or otherwise. Any use of this information is at the user's risk.
In no event
> shall Internet Security Systems be held liable for any damages whatsoever
arising
> out of or in connection with the use or dissemination of this information.
>
> X-Force PGP Key available on MIT's PGP key server and PGP.com's key
server,
> as well as at http://www.iss.net/security_center/sensitive.php
>
> Please send suggestions, updates, and comments to: X-Force
> [EMAIL PROTECTED] of Internet Security Systems, Inc.
>
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2
>
> iQCVAwUBPdACHzRfJiV99eG9AQHnNAP+NwkvwSZO63wCVC3/D/Nbd9b8xYOwISZH
> YumfuFtptUML41sO/ZGPH0LSsOZD+7ykP7eSuC6M6SLy95mb8zxQ7AueawYAMiDu
> JE3SGjfmg3u2TFSaLOO33GyidcYuFxdJm4SNo4AysxWl0ygeDiqv4TWUZClhayCl
> 7llqIa12ODU=
> =u/Om
> -----END PGP SIGNATURE-----
> ---
> [This E-mail scanned for viruses by Declude Virus]
>
>
---
[This E-mail scanned for viruses by Declude Virus]
---------------------------------------------------------
Archived messages from this list can be found at:
http://www.mail-archive.com/info-tech@;aea8.k12.ia.us/
---------------------------------------------------------