SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Cisco Trust Agent Vulnerability


Arrow  SecurityAlert : 2796
Arrow  CVE : CVE-2007-3184
Arrow  SecurityRisk : Medium  Security Risk Medium  (About)
Arrow  Remote Exploit : No
Arrow  Local Exploit : Yes
Arrow  Exploit Available : No
Arrow  Credit : adblake
Arrow  Published : 15.06.2007

Arrow  Affected Software : Cisco Trust Agent v2.1.103.0



Arrow  Advisory Content :  

Vulnerability:
There is a vulnerability affecting the latest version (v2.1.103.0) of the
Cisco Trust Agent software for MacOS X that can allow an individual with
physical access to an endpoint to bypass authentication and gain
administrative access to the local machine.

Description:
When Cisco Secure Access Control Server is configured to display a message
to the end user following a posture check, the Cisco Trust Agent installed
on a MacOS X machine may display the message over the top of the login
screen when the client is powered up or rebooted. When the message is
displayed, a user can access System Preferences through the Apple Menu as
the root user and make changes to user accounts, including changing
existing passwords.

A malicious user with this access can change an administrator account
password without knowledge of the existing password and then proceed to
login using that account.

Adam Blake of Deloitte UK
(http://www.deloitte.co.uk/security/)





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.