[virusinfo] Remote code execution in Sun ONE Messaging Server - 6-20-05

  • From: "Mike" <mikebike@xxxxxxxxx>
  • To: virusinfo@xxxxxxxxxxxxx
  • Date: Tue, 21 Jun 2005 08:11:00 -0700


From; Panda Oxygen3:


What do you think about Oxygen3? In order to know your opinion and
improve it we'd like you to answer some questions

To take the survey, click on this link:
http://www.pandasoftware.es/enc/pag_transito/trans_oxygen3_eng.html


       "I respect faith, but doubt is what gets you an education." 
              Wilson Mizner (1876 - 1933), US screenwriter

          - Remote code execution in Sun ONE Messaging Server -
      Oxygen3 24h-365d, by Panda Software (http://www.pandasoftware.com)

Madrid, June 20, 2005 - Sun has reported, at
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101770-1, a
vulnerability in Sun ONE Messaging Server (iPlanet Messaging Server), which
could allow a remote user to run arbitrary code on affected systems.

According to the notification published by the company, a remote user could
run JavaScript code on the target system with local user privileges. This
flaw only affects clients using Internet Explorer.

There is no symptom that could indicate that an attacker has successfully
exploited this vulnerability.  Sun is currently working on resolving this
problem.

NOTE: The address above may not show up on your screen as a single line.
This would prevent you from using the link to access the web page. If this
happens, just use the 'cut' and 'paste' options to join the pieces of the
URL.
------------------------------------------------------------ 

The 5 viruses most frequently detected by Panda ActiveScan, Panda
Software's free online scanner:
1)Mhtredir.gen; 2)Netsky.P; 3)Sdbot.ftp; 4)Qhost.gen; 5)sdbot.DYO.

------------------------------------------------------------
To contact with Panda Software, please visit:
http://www.pandasoftware.com/about/contact/
------------------------------------------------------------

*********** MIKE"S REPLY SEPARATOR  ***********
Mike ~ It is a good day if I learned something new.
Editor MikesWhatsNews see a sample on my web page
http://www3.telus.net/mikebike
<mikeswhatsnews-request@xxxxxxxxxxxxx?Subject=subscribe>
http://www3.telus.net/mikebike/worm_removal.htm
See my Anti-Virus pages  http://virusinfo.hackfix.org/index
<virusinfo-request@xxxxxxxxxxxxx?Subject=subscribe>
A Technical Support Alliance  and OWTA Charter Member 



Other related posts:

  • » [virusinfo] Remote code execution in Sun ONE Messaging Server - 6-20-05