<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wazi &#187; Security Team</title>
	<atom:link href="http://olex.openlogic.com/wazi/author/security-team/feed/" rel="self" type="application/rss+xml" />
	<link>http://olex.openlogic.com/wazi</link>
	<description>Thinking OPEN</description>
	<lastBuildDate>Fri, 06 Nov 2009 19:33:28 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>E-courirer Cms  [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium-2/</link>
		<comments>http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[e-courirer_cms]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium-2/</guid>
		<description><![CDATA[Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to (1) Wizard_tracking.asp, (2) wizard_oe2.asp, (3) your-register.asp, (4) main-whyregister.asp, and (5) your.asp in home/, and other unspecified vectors...

CVE Identifier: CVE-2009-3905
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>E-courirer Cms  [Medium]
</ul>
<h3>Description</h3>
<p>Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to (1) Wizard_tracking.asp, (2) wizard_oe2.asp, (3) your-register.asp, (4) main-whyregister.asp, and (5) your.asp in home/, and other unspecified vectors.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3905" target="_blank">CVE-2009-3905</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>E-courirer Cms  [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[e-courirer_cms]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium/</guid>
		<description><![CDATA[Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors....

CVE Identifier: CVE-2009-3901
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>E-courirer Cms  [Medium]
</ul>
<h3>Description</h3>
<p>Multiple cross-site scripting (XSS) vulnerabilities in e-Courier CMS allow remote attackers to inject arbitrary web script or HTML via the UserGUID parameter to home/index.asp and other unspecified vectors.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3901" target="_blank">CVE-2009-3901</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/e-courirer-cms-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blender 2.49b and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/blender-2-49b-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/blender-2-49b-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[blender]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/blender-2-49b-and-prior-high/</guid>
		<description><![CDATA[Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA....

CVE Identifier: CVE-2009-3850
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Blender 2.49b and prior [High]
</ul>
<h3>Description</h3>
<p>Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3850" target="_blank">CVE-2009-3850</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/blender-2-49b-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulndisco Pack 8.12 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/vulndisco-pack-8-12-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/vulndisco-pack-8-12-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[vulndisco_pack]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/vulndisco-pack-8-12-and-prior-high/</guid>
		<description><![CDATA[Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in VulnDisco Pack Professional 8.12...

CVE Identifier: CVE-2009-3878
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Vulndisco Pack 8.12 and prior [High]
</ul>
<h3>Description</h3>
<p>Buffer overflow in Sun Java System Web Server 7.0 Update 6 has unspecified impact and remote attack vectors, as demonstrated by the vd_sjws module in VulnDisco Pack Professional 8.12.  NOTE: as of 20091105, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3878" target="_blank">CVE-2009-3878</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/vulndisco-pack-8-12-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-3/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-3/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-3/</guid>
		<description><![CDATA[Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911....

CVE Identifier: CVE-2009-3877
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted HTTP headers, which are not properly parsed by the ASN.1 DER input stream parser, aka Bug Id 6864911.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3877" target="_blank">CVE-2009-3877</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-2/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-2/</guid>
		<description><![CDATA[Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911....

CVE Identifier: CVE-2009-3876
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Unspecified vulnerability in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to cause a denial of service (memory consumption) via crafted DER encoded data, which is not properly decoded by the ASN.1 DER input stream parser, aka Bug Id 6864911.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3876" target="_blank">CVE-2009-3876</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium/</guid>
		<description><![CDATA[The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to "timing attack vulnerabilities," aka Bug Id 6863503....

CVE Identifier: CVE-2009-3875
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [Medium]
</ul>
<h3>Description</h3>
<p>The MessageDigest.isEqual function in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to spoof HMAC-based digital signatures, and possibly bypass authentication, via unspecified vectors related to &#8220;timing attack vulnerabilities,&#8221; aka Bug Id 6863503.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3875" target="_blank">CVE-2009-3875</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-5/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-5/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-5/</guid>
		<description><![CDATA[Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643....

CVE Identifier: CVE-2009-3874
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [High]
</ul>
<h3>Description</h3>
<p>Integer overflow in the JPEGImageReader implementation in the ImageI/O component in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via large subsample dimensions in a JPEG file that triggers a heap-based buffer overflow, aka Bug Id 6874643.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3874" target="_blank">CVE-2009-3874</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [Low]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-low/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-low/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-low/</guid>
		<description><![CDATA[The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a "quantization problem," aka Bug Id 6862968....

CVE Identifier: CVE-2009-3873
Vulnerability Type(s): 
Severity: Low
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [Low]
</ul>
<h3>Description</h3>
<p>The JPEG Image Writer in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, related to a &#8220;quantization problem,&#8221; aka Bug Id 6862968.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3873" target="_blank">CVE-2009-3873</a><br />
Severity: Low
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-low/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [Unknown Severity]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-unknown-severity/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-unknown-severity/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-unknown-severity/</guid>
		<description><![CDATA[Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969....

CVE Identifier: CVE-2009-3872
Vulnerability Type(s): 
Severity: Unknown Severity
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [Unknown Severity]
</ul>
<h3>Description</h3>
<p>Unspecified vulnerability in the JPEG JFIF Decoder in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862969.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3872" target="_blank">CVE-2009-3872</a><br />
Severity: Unknown Severity
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-unknown-severity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-4/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-4/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-4/</guid>
		<description><![CDATA[Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358....

CVE Identifier: CVE-2009-3871
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [High]
</ul>
<h3>Description</h3>
<p>Heap-based buffer overflow in the setBytePixels function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via crafted arguments, aka Bug Id 6872358.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3871" target="_blank">CVE-2009-3871</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-3/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-3/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-3/</guid>
		<description><![CDATA[Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357....

CVE Identifier: CVE-2009-3869
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [High]
</ul>
<h3>Description</h3>
<p>Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a crafted argument, aka Bug Id 6872357.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3869" target="_blank">CVE-2009-3869</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-2/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-2/</guid>
		<description><![CDATA[Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970....

CVE Identifier: CVE-2009-3868
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [High]
</ul>
<h3>Description</h3>
<p>Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 does not properly parse color profiles, which allows remote attackers to gain privileges via a crafted image file, aka Bug Id 6862970.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3868" target="_blank">CVE-2009-3868</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high/</guid>
		<description><![CDATA[Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303....

CVE Identifier: CVE-2009-3867
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 and prior [High]
</ul>
<h3>Description</h3>
<p>Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, JDK and JRE 6 before Update 17, SDK and JRE 1.3.x before 1.3.1_27, and SDK and JRE 1.4.x before 1.4.2_24 allows remote attackers to execute arbitrary code via a long file: URL in an argument, aka Bug Id 6854303.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3867" target="_blank">CVE-2009-3867</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high-2/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high-2/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high-2/</guid>
		<description><![CDATA[The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824....

CVE Identifier: CVE-2009-3866
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 [High]
</ul>
<h3>Description</h3>
<p>The Java Web Start Installer in Sun Java SE in JDK and JRE 6 before Update 17 does not properly use security model permissions when removing installer extensions, which allows remote attackers to execute arbitrary code by modifying a certain JNLP file to have a URL field that points to an unintended trusted application, aka Bug Id 6872824.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3866" target="_blank">CVE-2009-3866</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jdk 1.6.0 [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jdk]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high/</guid>
		<description><![CDATA[The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752....

CVE Identifier: CVE-2009-3865
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jdk 1.6.0 [High]
</ul>
<h3>Description</h3>
<p>The launch method in the Deployment Toolkit plugin in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 6 before Update 17 allows remote attackers to execute arbitrary commands via a crafted web page, aka Bug Id 6869752.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3865" target="_blank">CVE-2009-3865</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jdk-1-6-0-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jre 1.6.0 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/jre-1-6-0-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/jre-1-6-0-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[jre]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/jre-1-6-0-and-prior-high/</guid>
		<description><![CDATA[The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694....

CVE Identifier: CVE-2009-3864
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Jre 1.6.0 and prior [High]
</ul>
<h3>Description</h3>
<p>The Java Update functionality in Java Runtime Environment (JRE) in Sun Java SE in JDK and JRE 5.0 before Update 22 and JDK and JRE 6 before Update 17, when a non-English version of Windows is used, does not retrieve available new JRE versions, which allows remote attackers to leverage vulnerabilities in older releases of this software, aka Bug Id 6869694.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3864" target="_blank">CVE-2009-3864</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/jre-1-6-0-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Groupwise 7.0.3.1294 [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/groupwise-7-0-3-1294-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2009/groupwise-7-0-3-1294-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[groupwise]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/groupwise-7-0-3-1294-medium/</guid>
		<description><![CDATA[Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method....

CVE Identifier: CVE-2009-3863
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Groupwise 7.0.3.1294 [Medium]
</ul>
<h3>Description</h3>
<p>Buffer overflow in the gxmim1.dll ActiveX control in Novell Groupwise Client 7.0.3.1294 allows remote attackers to cause a denial of service (application crash) via a long argument to the SetFontFace method.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3863" target="_blank">CVE-2009-3863</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/groupwise-7-0-3-1294-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Edirectory 8.8.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2009/edirectory-8-8-2-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2009/edirectory-8-8-2-and-prior-medium/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[edirectory]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/edirectory-8-8-2-and-prior-medium/</guid>
		<description><![CDATA[The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value....

CVE Identifier: CVE-2009-3862
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Edirectory 8.8.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>The NDSD process in Novell eDirectory 8.7.3 before 8.7.3.10 ftf2 and eDirectory 8.8 before 8.8.5 ftf1 does not properly handle certain LDAP search requests, which allows remote attackers to cause a denial of service (application hang) via a search request with a NULL BaseDN value.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3862" target="_blank">CVE-2009-3862</a><br />
Severity: Medium
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/edirectory-8-8-2-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Softremote 10.8.8 and prior [High]</title>
		<link>http://olex.openlogic.com/wazi/2009/softremote-10-8-8-and-prior-high/</link>
		<comments>http://olex.openlogic.com/wazi/2009/softremote-10-8-8-and-prior-high/#comments</comments>
		<pubDate>Tue, 30 Nov 1999 06:00:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[softremote]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2009/softremote-10-8-8-and-prior-high/</guid>
		<description><![CDATA[Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd)....

CVE Identifier: CVE-2009-3861
Vulnerability Type(s): 
Severity: High
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Softremote 10.8.8 and prior [High]
</ul>
<h3>Description</h3>
<p>Stack-based buffer overflow in SafeNet SoftRemote 10.8.5 (Build 2) and 10.3.5 (Build 6), and possibly other versions before 10.8.9, allows local users to execute arbitrary code via a long string in a (1) TREENAME or (2) GROUPNAME Policy file (spd).</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3861" target="_blank">CVE-2009-3861</a><br />
Severity: High
</p>

<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2009/softremote-10-8-8-and-prior-high/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
