Here is a report on sonicwall.  I do not see this as a big problem though
but keep an eye on it.

Date Reported:      10/29/2002
Brief Description:  SonicWALL Content Filtering IP addresses can bypass
                    URL filtering
Risk Factor:        Medium
Attack Type:        Network Based
Platforms:          Windows Any version, Sonicwall Content Filtering
                    Any Version
Vulnerability:      sonicwall-content-ip-bypass
X-Force URL:        http://www.iss.net/security_center/static/10531.php
_____________________________________________________________________
Scott Fosseen - Systems Engineer - Arrowhead AEA
www.aea5.k12.ia.us/aeaphone.nsf/web/fosseenscott -
_____________________________________________________________________
Tech Support: "What does the screen say now?"
Person: "It says, 'Hit ENTER when ready.'"
Tech Support: "Well?"
Person: "How do I know when it's ready?"
_____________________________________________________________________

----- Original Message -----
From: "X-Force" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Monday, November 11, 2002 1:18 PM
Subject: ISS Security Alert Summary AS02-45


> -----BEGIN PGP SIGNED MESSAGE-----
>
> Internet Security Systems Security Alert Summary AS02-45
> November 11, 2002
>
> X-Force Vulnerability and Threat Database:
> http://www.iss.net/security_center
>
> To receive these Alert Summaries, as well as other Alerts and
> Advisories, subscribe to the Internet Security Systems Alert
> mailing list at:
> http://www.iss.net/security_center/maillists
>
> This summary is available at the following address:
> http://www.iss.net/security_center/alerts/AS02-45.php
> _____
> Contents:
> * 36 Reported Vulnerabilities
> * Risk Factor Key
> _____
>
>
> Date Reported:      10/29/2002
> Brief Description:  SonicWALL Content Filtering IP addresses can bypass
>                     URL filtering
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows Any version, Sonicwall Content Filtering
>                     Any Version
> Vulnerability:      sonicwall-content-ip-bypass
> X-Force URL:        http://www.iss.net/security_center/static/10531.php
>
> Date Reported:      10/31/2002
> Brief Description:  SmartMail Server unexpected connection termination
>                     denial of service attack
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Windows Any version, SmartMail Server 2.0 Interim
>                     Build 83
> Vulnerability:      smartmail-terminate-connection-dos
> X-Force URL:        http://www.iss.net/security_center/static/10533.php
>
> Date Reported:      11/01/2002
> Brief Description:  Iomega NAS A300U FTP service could allow
>                     unauthorized access to shared directories
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Unix Any version, Iomega NAS A300U Any version
> Vulnerability:      iomega-ftp-shared-directories
> X-Force URL:        http://www.iss.net/security_center/static/10530.php
>
> Date Reported:      11/01/2002
> Brief Description:  Multiple vendor access point Embedded HTTP Server
>                     denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Linksys Access Points Any version, D-Link Access
>                     Points Any version
> Vulnerability:      ap-embedded-http-dos
> X-Force URL:        http://www.iss.net/security_center/static/10537.php
>
> Date Reported:      11/02/2002
> Brief Description:  EventSave and EventSave+ could allow event loss
>                     from the Windows NT log
> Risk Factor:        Low
> Attack Type:        Host Based
> Platforms:          Windows NT Any version, EventSave prior to 5.3
> Vulnerability:      eventsave-event-log-loss
> X-Force URL:        http://www.iss.net/security_center/static/10535.php
>
> Date Reported:      11/02/2002
> Brief Description:  Microsoft SQL Server login accounts use weak
>                     encryption algorithm
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows NT Any version, Microsoft SQL Server Any
>                     version, Windows 2000 Any version
> Vulnerability:      mssql-weak-password-encryption
> X-Force URL:        http://www.iss.net/security_center/static/10542.php
>
> Date Reported:      11/03/2002
> Brief Description:  AstroCam astrocam.cgi could allow remote command
>                     execution
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Linux Any version, NetBSD Any version, OpenBSD Any
>                     version, AstroCam prior to 2.1.3
> Vulnerability:      astrocam-cgi-command-execution
> X-Force URL:        http://www.iss.net/security_center/static/10538.php
>
> Date Reported:      11/04/2002
> Brief Description:  Pablo FTP Server malformed username format string
>                     denial of service
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows 2000 Any version, Pablo FTP Server 1.2,
>                     Pablo FTP Server 1.3, Pablo FTP Server 1.5
> Vulnerability:      pablo-ftp-username-dos
> X-Force URL:        http://www.iss.net/security_center/static/10532.php
>
> Date Reported:      11/04/2002
> Brief Description:  Xeneo Web Server PHP version malformed HTTP request
>                     denial of service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Windows Any version, Xeneo Web Server 2.1.0.0,
>                     Xeneo Web Server 2.0.759.6
> Vulnerability:      xeneo-php-dos
> X-Force URL:        http://www.iss.net/security_center/static/10534.php
>
> Date Reported:      11/04/2002
> Brief Description:  Global Sun Technology IEEE802.11b+ access points
>                     could disclose sensitive information
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Wisecom GL2422AP-0T Any version, Linksys WAP11 2.2
> Vulnerability:      ieee80211b-ap-information-disclosure
> X-Force URL:        http://www.iss.net/security_center/static/10536.php
>
> Date Reported:      11/04/2002
> Brief Description:  Sun RPC libc no time-out mechanism denial of
>                     service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          MacOS X 10.0 to 10.2.1, MacOS X Server 10.0 to
>                     10.2.1, glibc 2.3.1 and earlier
> Vulnerability:      sun-rpc-libc-dos
> X-Force URL:        http://www.iss.net/security_center/static/10539.php
>
> Date Reported:      11/04/2002
> Brief Description:  Com21 DOXport 1100 series cable modems allow an
>                     attacker to load a malicious configuration file
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Com21 DOXport 1100 series 2.1.1.106
> Vulnerability:      com21-doxport-config-file
> X-Force URL:        http://www.iss.net/security_center/static/10543.php
>
> Date Reported:      11/04/2002
> Brief Description:  The Magic Notebook invalid username denial of
>                     service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, The Magic
>                     Notebook prior to 1.2
> Vulnerability:      magic-book-username-dos
> X-Force URL:        http://www.iss.net/security_center/static/10562.php
>
> Date Reported:      11/05/2002
> Brief Description:  SnortCenter creates an insecure temporary file
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Linux Any version, Unix Any version, SnortCenter
>                     0.9.5
> Vulnerability:      snortcenter-tmp-file-insecure
> X-Force URL:        http://www.iss.net/security_center/static/10540.php
>
> Date Reported:      11/05/2002
> Brief Description:  networking_utils.php ping command could be used to
>                     read files
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Windows Any version, Unix Any
>                     version, networking_utils 1.0
> Vulnerability:      networkingutils-ping-read-files
> X-Force URL:        http://www.iss.net/security_center/static/10541.php
>
> Date Reported:      11/05/2002
> Brief Description:  HP TruCluster Server Interconnect denial of service
> Risk Factor:        Low
> Attack Type:        Host Based / Network Based
> Platforms:          HP TruCluster Server 5.1A, HP TruCluster Server
>                     5.0A
> Vulnerability:      hp-trucluster-interconnect-dos
> X-Force URL:        http://www.iss.net/security_center/static/10551.php
>
> Date Reported:      11/05/2002
> Brief Description:  pp_powerSwitch could allow an attacker to control
>                     any port
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, pp_powerSwitch prior to 0.1.1
> Vulnerability:      pp-powerswitch-port-access
> X-Force URL:        http://www.iss.net/security_center/static/10552.php
>
> Date Reported:      11/05/2002
> Brief Description:  PortalApp users could gain elevated privileges on
>                     the Web portal
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          PortalApp 2.2, Windows Any version
> Vulnerability:      portalapp-user-privilege-elevation
> X-Force URL:        http://www.iss.net/security_center/static/10558.php
>
> Date Reported:      11/05/2002
> Brief Description:  Cisco PIX Firewall TCP SYN packets denial of
>                     service
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Linux Any version, Windows Any version, Unix Any
>                     version, Cisco PIX Firewall 6.2.2
> Vulnerability:      cisco-pix-packet-dos
> X-Force URL:        http://www.iss.net/security_center/static/10566.php
>
> Date Reported:      11/06/2002
> Brief Description:  perl-MailTools Mail::Mailer module command
>                     execution
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          SuSE Linux 7.1, SuSE Linux 7.2, SuSE Linux 7.3,
>                     SuSE eMail Server III Any version, SuSE Linux 8.0,
>                     Gentoo Linux Any version, SuSE eMail Server 3.1,
>                     SuSE Linux 8.1, perl-MailTools Any version
> Vulnerability:      mail-mailer-command-execution
> X-Force URL:        http://www.iss.net/security_center/static/10548.php
>
> Date Reported:      11/06/2002
> Brief Description:  LuxMan maped binary file could be used to read memory
> Risk Factor:        Medium
> Attack Type:        Host Based
> Platforms:          Debian Linux 3.0, LuxMan 0.41
> Vulnerability:      luxman-maped-read-memory
> X-Force URL:        http://www.iss.net/security_center/static/10549.php
>
> Date Reported:      11/06/2002
> Brief Description:  QNX RTP timer denial of service
> Risk Factor:        Low
> Attack Type:        Host Based
> Platforms:          QNX RTP 6.1
> Vulnerability:      qnx-rtp-timer-dos
> X-Force URL:        http://www.iss.net/security_center/static/10550.php
>
> Date Reported:      11/06/2002
> Brief Description:  Linuxconf sendmail.cf file allows mail relaying
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          Linux Any version, Linuxconf prior to 1.28
> Vulnerability:      linuxconf-sendmail-mail-relay
> X-Force URL:        http://www.iss.net/security_center/static/10554.php
>
> Date Reported:      11/06/2002
> Brief Description:  Macromedia ColdFusion MX could allow an attacker to
>                     view CFML source
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, Windows NT Any
>                     version, Windows 2000 Any version, ColdFusion MX
> Vulnerability:      coldfusion-mx-file-disclosure
> X-Force URL:        http://www.iss.net/security_center/static/10565.php
>
> Date Reported:      11/06/2002
> Brief Description:  Macromedia JRun long URL buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Windows NT Any version, Windows 2000 Any version,
>                     JRun 3.0, JRun 3.1, JRun 4.0
> Vulnerability:      jrun-long-url-bo
> X-Force URL:        http://www.iss.net/security_center/static/10568.php
>
> Date Reported:      11/06/2002
> Brief Description:  Macromedia JRun Unicode encoded JSP file source
>                     disclosure
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, JRun 3.0, JRun
>                     3.1, JRun 4.0
> Vulnerability:      jrun-unicode-source-disclosure
> X-Force URL:        http://www.iss.net/security_center/static/10570.php
>
> Date Reported:      11/06/2002
> Brief Description:  Macromedia JRun log file and jrun.ini file
>                     disclosure
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows NT Any version, Windows 2000 Any version,
>                     JRun 3.0, JRun 3.1, JRun 4.0
> Vulnerability:      jrun-log-file-disclosure
> X-Force URL:        http://www.iss.net/security_center/static/10571.php
>
> Date Reported:      11/06/2002
> Brief Description:  OpenBSD getrlimit(2) denial of service
> Risk Factor:        Low
> Attack Type:        Host Based
> Platforms:          OpenBSD 3.0, OpenBSD 3.1
> Vulnerability:      openbsd-getrlimit-dos
> X-Force URL:        http://www.iss.net/security_center/static/10572.php
>
> Date Reported:      11/07/2002
> Brief Description:  Pine "From:" message header denial of service
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, Pine 4.44
> Vulnerability:      pine-from-header-dos
> X-Force URL:        http://www.iss.net/security_center/static/10555.php
>
> Date Reported:      11/07/2002
> Brief Description:  CuteCast Forum stores passwords in plain text
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Windows Any version, Unix Any
>                     version, CuteCast Forum 1.2
> Vulnerability:      cutecast-forum-plaintext-passwords
> X-Force URL:        http://www.iss.net/security_center/static/10556.php
>
> Date Reported:      11/07/2002
> Brief Description:  Lotus Domino non-existent .nsf request could
>                     disclose version information
> Risk Factor:        Low
> Attack Type:        Network Based
> Platforms:          HP-UX Any version, Linux Any version, Solaris Any
>                     version, Windows NT Any version, OS/2 Any version,
>                     Windows 2000 Any version, Lotus Domino 5.0.8, Lotus
>                     Domino 5.0.9, Lotus Domino 5.0.9a
> Vulnerability:      lotus-domino-version-disclosure
> X-Force URL:        http://www.iss.net/security_center/static/10557.php
>
> Date Reported:      11/07/2002
> Brief Description:  Window Maker image file buffer overflow
> Risk Factor:        High
> Attack Type:        Network Based
> Platforms:          Debian Linux 3.0, Window Maker Any version
> Vulnerability:      window-maker-image-bo
> X-Force URL:        http://www.iss.net/security_center/static/10560.php
>
> Date Reported:      11/07/2002
> Brief Description:  Perception LiteServe directory index cross-site
>                     scripting
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Windows Any version, LiteServe 2.01
> Vulnerability:      liteserve-directory-index-xss
> X-Force URL:        http://www.iss.net/security_center/static/10561.php
>
> Date Reported:      11/08/2002
> Brief Description:  Simple Web Server could allow an attacker to access
>                     password protected files
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Simple Web Server 0.5.1
> Vulnerability:      simple-server-file-access
> X-Force URL:        http://www.iss.net/security_center/static/10563.php
>
> Date Reported:      11/08/2002
> Brief Description:  QNX RTOS could allow an attacker to gain local root
>                     privileges
> Risk Factor:        High
> Attack Type:        Host Based
> Platforms:          QNX RTOS 6.2.0
> Vulnerability:      qnx-rtos-gain-privileges
> X-Force URL:        http://www.iss.net/security_center/static/10564.php
>
> Date Reported:      11/08/2002
> Brief Description:  Zeus Admin Server index.fcgi script cross-site
>                     scripting
> Risk Factor:        Medium
> Attack Type:        Network Based
> Platforms:          Linux Any version, Unix Any version, Zeus Web
>                     Server 4.1r2
> Vulnerability:      zeus-admin-index-xss
> X-Force URL:        http://www.iss.net/security_center/static/10567.php
>
> _____
>
> Risk Factor Key:
>
>      High     Any vulnerability that provides an attacker with immediate
>               access into a machine, gains superuser access, or bypasses
>               a firewall. Example: A vulnerable Sendmail 8.6.5 version
>               that allows an intruder to execute commands on mail server.
>      Medium   Any vulnerability that provides information that has a high
>               potential of giving system access to an intruder. Example:
>               A misconfigured TFTP or vulnerable NIS server that allows
>               an intruder to get the password file that could contain an
>               account with a guessable password.
>      Low      Any vulnerability that provides information that could
>               potentially lead to a compromise. Example: A finger that
>               allows an intruder to find out who is online and potential
>               accounts to attempt to crack passwords via brute force
>               methods.
>
> ______
>
> About Internet Security Systems (ISS)
> Founded in 1994, Internet Security Systems (ISS) (Nasdaq: ISSX) is a
> pioneer and world leader in software and services that protect critical
> online resources from an ever-changing spectrum of threats and misuse.
> Internet Security Systems is headquartered in Atlanta, GA, with
> additional operations throughout the Americas, Asia, Australia, Europe
> and the Middle East.
>
> Copyright (c) 2002 Internet Security Systems, Inc. All rights reserved
> worldwide.
>
> Permission is hereby granted for the electronic redistribution of this
> document. It is not to be edited or altered in any way without the
> express written consent of the Internet Security Systems X-Force. If you
> wish to reprint the whole or any part of this document in any other
> medium excluding electronic media, please email [EMAIL PROTECTED] for
> permission.
>
> Disclaimer: The information within this paper may change without notice.
Internet
> Security Systems provides this information on an AS IS basis with NO
warranties,
> implied or otherwise. Any use of this information is at the user's risk.
In no event
> shall Internet Security Systems be held liable for any damages whatsoever
arising
> out of or in connection with the use or dissemination of this information.
>
> X-Force PGP Key available on MIT's PGP key server and PGP.com's key
server,
> as well as at http://www.iss.net/security_center/sensitive.php
>
> Please send suggestions, updates, and comments to: X-Force
> [EMAIL PROTECTED] of Internet Security Systems, Inc.
>
> -----BEGIN PGP SIGNATURE-----
> Version: 2.6.2
>
> iQCVAwUBPdACHzRfJiV99eG9AQHnNAP+NwkvwSZO63wCVC3/D/Nbd9b8xYOwISZH
> YumfuFtptUML41sO/ZGPH0LSsOZD+7ykP7eSuC6M6SLy95mb8zxQ7AueawYAMiDu
> JE3SGjfmg3u2TFSaLOO33GyidcYuFxdJm4SNo4AysxWl0ygeDiqv4TWUZClhayCl
> 7llqIa12ODU=
> =u/Om
> -----END PGP SIGNATURE-----
> ---
> [This E-mail scanned for viruses by Declude Virus]
>
>

---
[This E-mail scanned for viruses by Declude Virus]

---------------------------------------------------------
Archived messages from this list can be found at:
http://www.mail-archive.com/info-tech@;aea8.k12.ia.us/
---------------------------------------------------------

Reply via email to