Welcome Guest. | Log In| Register | Membership Benefits


DARK READING NEWSLETTER SUBSCRIPTION PAGE
To join our mailing lists, please submit the following information:
[To unsubscribe to our newsletter(s), click here]
 
* - required
*E-Mail:
 
 First Name:
 
 Last Name:
 
 Company Name:
 
 Postal Code:
 
  Country:
 
Check If You Will Receive Newsletters on a Mobile Device
   
Dark Reader Weekly Newsletter:
Your weekly keyhole into the chaos and mystery of network and data security. Look for this compilation every Thursday, chock-full of product and industry news, threat reports, vulnerability discoveries, compliance issues, and user experiences. In addition, there's also our enlightened and delusional commentary, as well best-of security stories from around the web.
Delivered: Thursdays
   
Dark Reading Daily Newsletter:
Your daily dose of the latest news, analysis and opinion from the editors and contributors of Dark Reading, the Internet's most paranoid publicaton for security intel.
Delivered: Daily
   
Dark Reading Database Security Weekly:
The Dark Reading Database Security Weekly offers news, analysis, and opinion on all aspects of database security. It brings readers insights on the latest threats and breaches in the database environment, as well as breaking news on the tools, practices and technologies for database defense.
Delivered: Tuesdays
   
CHECK BOTH
   
* Job Title:
 
  Business Address:
 
  City:
 
  State Prov:
 
  Phone Number (no dashes or spaces):
 
* Company Annual Revenues:
 
* Job Function:
 
  Company URL:
 
* Primary Business:
 
* Employees in Organization:
 

E-Mail Preference:

 






Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:legato networker, informix dynamic server
Published:2010-03-05
Severity:High
Description:Multiple buffer overflows in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allow remote attackers to execute arbitrary code via a crafted parameter size.
Vulnerability:legato networker, informix dynamic server
Published:2010-03-05
Severity:High
Description:Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.
Vulnerability:http server
Published:2010-03-05
Severity:Medium
Description:The ap_proxy_ajp_request function in mod_proxy_ajp.c in mod_proxy_ajp in the Apache HTTP Server 2.2.x before 2.2.15 does not properly handle certain situations in which a client sends no request body, which allows remote attackers to cause a denial of service (backend server outage) via a crafted request, related to use of a 500 error code instead of the appropriate 400 error code.
Vulnerability:kvm
Published:2010-03-05
Severity:Medium
Description:The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which might allow guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO port or (2) MMIO region, and replacing an instruction in between emulator entry and instruction fetch.
Vulnerability:unified communications manager
Published:2010-03-05
Severity:High
Description:Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)