Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2013.0015 Security Update to Novell Sentinel 7 February 2013 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Novell Sentinel Operating System: Red Hat Enterprise Linux Server 6 SUSE Impact/Access: Cross-site Scripting -- Remote with User Interaction Resolution: Patch/Upgrade Member content until: Saturday, March 9 2013 OVERVIEW A vulnerability has been identified in Novell Sentinel prior to version 7.0 SP3 (7.0.3.0). [1] IMPACT The vendor has provided the following details regarding a vulnerability which affects version 7.0.2.0 and earlier versions: "When users specify a script in HTTP or RPC requests sent to the server, the browser executes the script, which could allow cross-site scripting (XSS) attacks. (BUG 779352)" [1] MITIGATION The vendor recommends updating to the latest version of Novell Sentinel 7.0 SP3 (7.0.3.0) to correct these issues. [1] REFERENCES [1] Sentinel 7.0 SP3 (Sentinel 7.0.3.0) http://download.novell.com/Download?buildid=F2ekpMizoI0~ AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBURM2Nu4yVqjM2NGpAQIY4Q//VhSWg4wCxEywIh+gL9QYNZc7RO/vgxAk Tufk3j0v+zax2zdpnJw00TEqP8TOFyA2veDK+U5P0mHTC/um+Cc4i2dpGnVWZiIU brq3NvNROZuIlv54GpDYpPygh8dnr+9FGLxnHdfwXCkYBesHPUOiPzhIbPzihBtk swHh6Kqe/2vYA0/JV3LLYyi0QhejwSB7S9a/HKMki1kT+qQlJ1Q027jrQyAMbf38 1g+gQyHxne4NugGcjnfvz7qWZsmXIS+kCUlozxNTPKvwYSOMpInvIpuuyUi04E1y Z4MkXdq41XK6JEGriyu1QEzZ28KeQvLlUxXLwSNy+68tQK/SypiiSqV5Ftwn+JAE n5bxKhBTo2JopvVmLLOkFsyu9uXygNDxstemjs/BorWPrW4BD4OiQZmv8tF5IpJV s24gAtbx/JkQvIHn+O4TzA2h/WpkoAXElqExxtYK44VqtQQItPSPF7oSi11uCySi mMuf8HtnN5jrCAaEEyxLRZno1E+oEq+AMeylCKYr4aliUfWITMystxp7/sRny71c 6j7uu1k1cWbgAYefgxq4Wee991u5iU8ng+ERNPiVUPcdod/1vQD2Fqgs2ZGeVC+q vjV0Y5NlKG48cWSCwKUi++A0LRmkQlScTBCvLM602VPNyADV27hC1gmX5uEYLm+6 7vx0IyUekz8= =rTdn -----END PGP SIGNATURE-----