Archive for Advisories

Security Advisories MU-201202-01 and MU-201202-02 for GnuTLS and Libtasn1

TLS record handling vulnerability in GnuTLS [MU-201202-01] [CVE-2012-1573]
ASN.1 length decoding vulnerability in Libtasn1 [MU-201202-02] [CVE-2012-1569]

Download The PGP Signed Text Version Of This Advisory

Note: Thanks to Red Hat Security Team for requesting the CVE IDs above.

Full Post »

Bookmark and Share

Multiple sscanf vulnerabilities in Asterisk

The Mu Dynamics Research Team released advisory “MU-200908-01â€? today. Details: MU-200908-01

Bookmark and Share

strongSwan IKEv2 Denial-of-Service Vulnerability

The Mu Dynamics Research Team released advisory “MU-200809-01â€? today. Details: MU-200809-01.txt

Bookmark and Share

Remote DoS in reSIProcate

The Mu Dynamics Research Team released advisory “MU-200807-01â€? today. Details: MU-200807-01

Bookmark and Share

Multiple buffer overflows in Asterisk

The Mu Security Research Team released advisory “MU-200803-01â€? today. Details: MU-200803-01

Bookmark and Share

Multiple Remote Arbitrary Execution Vulnerabilities in Mplayer

The Mu Security Research Team released advisory “MU-200802-01â€? today. Details: Mu-200802-01

Full Post »

Bookmark and Share

Widespread DH Implementation Weakness: Conspiracy or Ignorance?

While developing an implementation of IKE for our platform, I noticed an astonishing behavior in the servers I was testing against: Not a single IKE implementation, which included products from the biggest names in network infrastructure, were validating the Diffie-Hellman public keys that I sent. A consequence of this is that any deployment of these servers will allow the disclosure of secret information when a peer is in collusion with a passive attacker.

Full Post »

Bookmark and Share

Dibbler Remote Denial of Service Vulnerability

The Mu Security Research Team released advisory “MU-200709-02â€? today. Details: mu-200709-02.txt

Bookmark and Share

Quagga bgpd Remote Denial of Service Vulnerability

The Mu Security Research Team released advisory “MU-200709-01” today. Details: mu-200709-01.txt

Bookmark and Share

Helix DNA Server Heap Corruption Vulnerability

The Mu Security Research Team released advisory “MU-200708-01″today. Details:
MU-200708-01.txt

Bookmark and Share