SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

Akamai Technologies Security Advisory 2008-0003 (Akamai Client Software)


Arrow  SecurityAlert : 3930
Arrow  CVE : CVE-2008-1106
Arrow  CWE : CWE-287
Arrow  CWE : CWE-352
Arrow  SecurityRisk : High  Security Risk High  (About)
Arrow  Remote Exploit : Yes
Arrow  Local Exploit : No
Arrow  Victim interaction required : Yes
Arrow  Exploit Available : No
Arrow  Credit : Akamai Security Team
Arrow  Published : 11.06.2008

Arrow  Affected Software : Akamai Technologies, Client, 3322, and previous
Red_swoosh, Client, 3322, and previous



Arrow  Advisory Content :  

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ----------------------------------------------------
Akamai Technologies Security Advisory 2008-0003

* Akamai ID: 2008-0003
* Date: 2008/06/06
* Product Name: Akamai Client Software (formerly Red Swoosh)
* Affected Versions: Up to and including 3322
* Fixed Version: 3333
* CVE IDs: CVE-2008-1106
* CVSS Base Score: 5.53

* Product Description:

The Akamai Client Software is a software layer that securely stores and
transfers files to enhance content delivery.

* Vulnerability Description:

Akamai has become aware of a security vulnerability within the Akamai
Client Software which can be exploited to conduct cross-site request
forgery attacks. This vulnerability exists only in the Akamai Client
Software and does not affect Akamai's other services in any way.
Akamai has no evidence to date that any attempt has been made to exploit
this vulnerability.

* Patch Instructions:

No user interaction is required. Clients will be automatically upgraded.

* Credit:

CVE-2008-1106 was independently discovered and brought to Akamai's
attention by Dyon Balding of Secunia Research.

* About Akamai:

Akamai(r) is the leading global service provider for accelerating
content and business processes online. Thousands of organizations have
formed trusted relationships with Akamai, improving their revenue and
reducing costs by maximizing the performance of their online businesses.
Leveraging the Akamai EdgePlatform, these organizations gain business
advantage today, and have the foundation for the emerging Web solutions
of tomorrow. Akamai is "The Trusted Choice for Online Business." For
more information, visit www.akamai.com.

Our GPG public key:
http://www.akamai.com/dl/akamai/Akamai_Security_General.pub
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)

iQIcBAEBAgAGBQJISVLQAAoJEEngXEVbkoPOu3IQAJ4gOT9aCwG+f1ZJYLReUC8Y
C5GIL0W2IVPhiRsNbFBZvlDze+d0y8kHLuXgNPerD0biGIi97Jl1mOU/RcnO2Ynn
bV3glkkDdfdUtobrHRl9A8Fd2Y8GekF0QkB6ehqqFbRl81CMftykVwm/PkwqXFTF
GxUOaw2TsjLwrYMQdkR+PN9P5P2oNwG3khtMnFugSNeEmtH5EoE8QYVWqFovho3X
o6+e8/XzHC5eoF8S3VU7xHzQaoL45Wc6oRGMPn/FAbD+r5jmpzsI+vutc+yo1ZkG
GYJMxu33ny+OVncKrQo+WmX1yPqA5ahWlBEWn0FuPzaxW8SomAu02OV77mspcG9j
ApJc9S53zDP+fFiCwcEYiogzOfkHO7rt1qtwrj6jCvPphh3GKHR2zOt48zCOqY6c
Q6poYoZyPSTUQz1UQzTJ2ck0oyOGSQpOMXDPxBK81g5DPhkt8BlxZ8KDXMBH49Pt
zCQeMTSYu3cjBab49fc1NB40bB0WO/isz7lCHtPvudiItpqVAvngZp6hpKX2fLF4
KFR4qyoBU6zYA0VWnWiM5TMP+aEW/zumt9WcruauqtC8UbHGHlMftptAEa9ZmmEu
RwDb3UPinnOmeF3dz32l3EY9t39/Eqop/hglpyKkj44UjCRwAy/a1N7pU7NmDdWj
YR5C4Mv+U3Ptp0SNPFvt
=ie/v
-----END PGP SIGNATURE-----



Arrow  References :

http://secunia.com/advisories/30135
http://xforce.iss.net/xforce/xfdb/42895
http://www.securityfocus.com/archive/1/archive/1/493170/100/0/threaded
http://www.securityfocus.com/archive/1/archive/1/493169/100/0/threaded
http://secunia.com/secunia_research/2008-19/advisory/




Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc:fts_*() Multiple Denial of Service

Security Risk Medium- 2009-10-02

The fts functions are provided for traversing UNIX file hierarchies...

Apache RSS Apache Alert

» Apache 1.3.41 mod_proxy
   Integer overflow (code
   execution)

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion in work
   directory

» Apache Tomcat 6.0.20 and
   5.5.28 insecure partial
   deploy after failed
   undeploy

» Apache Tomcat 6.0.20 and
   5.5.28 unexpected file
   deletion and/or
   alteration

PHP RSS PHP Alert

» PHP 5.2.12/5.3.1
   session.save_path
   safe_mode and
   open_basedir bypass

» PHP 5.2.12/5.3.1 Multiple
   Vulnerabilities

» PHP 5.2.11 libgd multiple
   vulnerabilities

» PHP 5.2.11 tempnam()
   safe_mode bypass

Copyright © SecurityReason.com. All Rights Reserved.