Monday, August 29, 2016

Kaspersky fixes antivirus crash bug


Internet and antivirus giant Kaspersky has fixed a number of flaws, which could be used to crash its flagship software, rendering its protection useless.

Talos Group, the security arm of Cisco, said in a blog post that three of the flaws were denial-of-service flaws, which could crash the software, and the fourth could leak data, which may allow an attacker to exploit a local system.

Though the flaws are "not particularly severe," the security team warned that security systems can become targets of attacks.

Crashing an application may not be the most frieghtening vulnerability on the cards. But in the case of an antivirus, it could be used by an attacker to further run malicious code while the antivirus is restarting.

Kaspersky has since fixed the vulnerabilities.



from Latest Topic for ZDNet in... http://ift.tt/2c3JpXN

IBM Security Bulletin: Vulnerabilities in OpenSSH affect IBM Security Network Protection (CVE-2015-5352, CVE-2015-6563, and CVE-2015-6564)

Security vulnerabilities have been discovered in OpenSSH, which is used by IBM Security Network Protection.

CVE(s): CVE-2015-5352, CVE-2015-6563, CVE-2015-6564

Affected product(s) and affected version(s):

IBM Security Network Protection 5.3.1
IBM Security Network Protection 5.3.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2bZYDhf
X-Force Database: http://ift.tt/2c8WB0w
X-Force Database: http://ift.tt/2bZYLgC
X-Force Database: http://ift.tt/2c8Vyh9



from IBM Product Security Incident Response Team http://ift.tt/2bZZ9vB

IBM Security Bulletin: Multiple vulnerabilities in IBM Java SDK and IBM Java Runtime IBM affect Decision Optimization Center (CVE-2016-3598)

There are multiple vulnerabilities in IBM® Runtime Environment Java™ and IBM® Runtime Environment Java™ Version 6 and Version 7 that are used by IBM Decision Optimization Center. These issues were disclosed as part of the IBM Java SDK updates in July 2016.

CVE(s): CVE-2016-3598

Affected product(s) and affected version(s):

IBM Decision Optimization Center v3.9 and earlier

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2c8VfT9
X-Force Database: http://ift.tt/2aGcUP3



from IBM Product Security Incident Response Team http://ift.tt/2bZY07b

IBM Security Bulletin: Multiple vulnerabilities in IBM Java Runtime affect IBM ILOG CPLEX Optimization Studio and IBM ILOG CPLEX Enterprise Server (CVE-2016-3550, CVE-2016-3587, CVE-2016-3598, CVE-2016-3606, CVE-2016-3610)

There are multiple vulnerabilities in IBM® Runtime Environment Java™ Version 6 and Version 7 that are used by IBM ILOG CPLEX Optimization Studio and IBM ILOG CPLEX Enterprise Server. These issues were disclosed as part of the IBM Java SDK updates in July 2016.

CVE(s): CVE-2016-3610, CVE-2016-3598, CVE-2016-3606, CVE-2016-3587, CVE-2016-3550

Affected product(s) and affected version(s):

IBM CPLEX Optimization Studio (COS) v12.6.3 and earlier
IBM CPLEX Enterprise Server (CES) v12.6.3 and earlier

NOTE: CVE-2016-3610, CVE-2016-3606, CVE-2016-3587 and CVE-2016-3550 affect IBM SDK, Java Technology Edition on Solaris, HP-UX and Mac OS only.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2bZYV7E
X-Force Database: http://ift.tt/2b7GBwx
X-Force Database: http://ift.tt/2aGcUP3
X-Force Database: http://ift.tt/2b7H1Te
X-Force Database: http://ift.tt/2aGbWSW
X-Force Database: http://ift.tt/2aGc4lp



from IBM Product Security Incident Response Team http://ift.tt/2bZYVEZ

IBM Security Bulletin: Multiple vulnerabilities in libxml2 affect IBM Security Network Protection

The libxml2 library is a development toolbox providing the implementation of various XML standards. Multiple vulnerabilities have been discovered in libxml2 used with IBM Security Network Protection.

CVE(s): CVE-2016-1762, CVE-2016-1833, CVE-2016-1834, CVE-2016-1835, CVE-2016-1836, CVE-2016-1837, CVE-2016-1838, CVE-2016-4448, CVE-2016-4449, CVE-2016-1839, CVE-2016-1840, CVE-2016-3627, CVE-2016-3705, CVE-2016-4447

Affected product(s) and affected version(s):

IBM Security Network Protection 5.3.1
IBM Security Network Protection 5.3.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2c8VwFN
X-Force Database: http://ift.tt/2bl3bgj
X-Force Database: http://ift.tt/2b1F7UX
X-Force Database: http://ift.tt/2bl3E26
X-Force Database: http://ift.tt/2b1FhM0
X-Force Database: http://ift.tt/2bl4gom
X-Force Database: http://ift.tt/2b1F2R8
X-Force Database: http://ift.tt/2bl3pEf
X-Force Database: http://ift.tt/29hoGgb
X-Force Database: http://ift.tt/29qou1O
X-Force Database: http://ift.tt/2b1F5Mr
X-Force Database: http://ift.tt/2bl4UC0
X-Force Database: http://ift.tt/2b1F6Qx
X-Force Database: http://ift.tt/1syye00
X-Force Database: http://ift.tt/29qofDU



from IBM Product Security Incident Response Team http://ift.tt/2bZXZA9

IBM Security Bulletin: Multiple vulnerabilities in file affect IBM Security Network Protection

There are multiple vulnerabilities in file that is used by IBM Security Network Protection. These vulnerabilities include CVE-2014-3538, CVE-2014-3587, CVE-2014-3710, CVE-2014-8116, CVE-2014-8117, CVE-2014-9620, and CVE-2014-9653.

CVE(s): CVE-2014-3538, CVE-2014-3587, CVE-2014-3710, CVE-2014-8116, CVE-2014-8117, CVE-2014-9620, CVE-2014-9653

Affected product(s) and affected version(s):

IBM Security Network Protection 5.3.1
IBM Security Network Protection 5.3.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2c8W4eN
X-Force Database: http://ift.tt/2bZYWbX
X-Force Database: http://ift.tt/2c8VRsf
X-Force Database: http://ift.tt/2bZYUkp
X-Force Database: http://ift.tt/2c8VgXs
X-Force Database: http://ift.tt/2bZYzxZ
X-Force Database: http://ift.tt/2c8X6r4
X-Force Database: http://ift.tt/2bZXxlN



from IBM Product Security Incident Response Team http://ift.tt/2c8VvSf

IBM Security Bulletin: Multiple vulnerabilities in NTP affect IBM Security Network Protection

There are multiple vulnerabilities in NTP that is used by IBM Security Network Protection. These vulnerabilities include CVE-2015-5194, CVE-2015-5195, CVE-2015-5219, CVE-2015-7691, CVE-2015-7692, CVE-2015-7701, CVE-2015-7702, CVE-2015-7703, CVE-2015-7852, CVE-2015-7977, CVE-2015-7978, CVE-2015-7979, CVE-2016-1547, CVE-2016-1548, CVE-2016-1550, and CVE-2016-2518.

CVE(s): CVE-2015-7691, CVE-2015-7692, CVE-2015-7701, CVE-2015-5194, CVE-2015-5195, CVE-2015-5219, CVE-2015-7702, CVE-2015-7703, CVE-2015-7852, CVE-2015-7977, CVE-2015-7978, CVE-2015-7979, CVE-2016-1547, CVE-2016-1548, CVE-2016-1550, CVE-2016-2518

Affected product(s) and affected version(s):

IBM Security Network Protection 5.3.1
IBM Security Network Protection 5.3.2

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2bZXvKH
X-Force Database: http://ift.tt/1XbCMXn
X-Force Database: http://ift.tt/2aLrohw
X-Force Database: http://ift.tt/2axFUfS
X-Force Database: http://ift.tt/2aLr2r0
X-Force Database: http://ift.tt/2axFNRC
X-Force Database: http://ift.tt/2aLraa8
X-Force Database: http://ift.tt/2aLrzJK
X-Force Database: http://ift.tt/1UrnSIt
X-Force Database: http://ift.tt/2aLrbei
X-Force Database: http://ift.tt/1Q1mFcj
X-Force Database: http://ift.tt/2aLqPUS
X-Force Database: http://ift.tt/1Q1ol5w
X-Force Database: http://ift.tt/28MbfXh
X-Force Database: http://ift.tt/28PlwWo
X-Force Database: http://ift.tt/28Plttu
X-Force Database: http://ift.tt/28MbhOU



from IBM Product Security Incident Response Team http://ift.tt/2c8Wim5