Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2013.0084 A vulnerability has been reported in Barracuda Spam & Virus Firewall 12 July 2013 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Barracuda Spam & Virus Firewall Operating System: Network Appliance Impact/Access: Cross-site Scripting -- Remote with User Interaction Resolution: Patch/Upgrade Member content until: Sunday, August 11 2013 OVERVIEW A vulnerability has been reported in Barracuda Spam & Virus Firewall. [1] IMPACT Barracuda has provided the following details regarding these issues: "On June 3, 2013, security researcher Justin Steven (justinsteven.com) reported two related instances of a remotely exploitable persistent XSS attack against the Barracuda Spam & Virus Firewall. Our research has confirmed that all versions of the Barracuda Spam & Virus Firewall are affected." [1] MITIGATION The vendor recommends that users with automatic updates for their Security Definitions confirm that their current installed version is 2.0.8 or higher. Users who have disabled automatic updates should manually update to the latest Security Definition. REFERENCES [1] Tech Alerts https://www.barracuda.com/support/techalerts AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBUd+OMBLndAQH1ShLAQKWuBAAopZqr7r/WVtxJDfH2AuYrDtdty0u6DoF Z1GfB31tzOKZIiMeYBdzyrtd4bgB5G8faeOznvnxzSJN+tBh2DyxDwI5mThhzfXs w1YqeLY5X3pxC45q6vHLzQGQnGQeLfi7l742iBH9X77xv077p0SG/yAhIvkTgFkT eJT4pfhJB6QGGAo+OsG5VF/C2u2XMDrtTOI50o9PS0K3P3roX49Zei48i/UissKr rKX4yU9X5MX4XR99ZO509ErEoQ1Oy/DRY/Z/sfX3PvKKFLluUEcADUZBIiExHbM1 SsC5a9i6NY+ZV/WijboArgqvq2snbAi4mMvHBeYl3BKrLqteMn/3KSjK8flQWAOU Aykdb5jIRMfuPorTGzhUQRvCOAIHmbl8lFp9PtgB7NL+QBt9WnbyERnGBoN65p+K DYVPw0rPYX3vA42vDHzjuurjPWzAOqcdxoUdD2dJB7L3clB82tl3uk9QmC5q1Xxv Kr61cl9DQMai1K6ZXyUrFnvWXHaQtUBy4QRwlvCr89Lnm4Nc3T9jJFLDqeKJ3JCi eWZ3DH6mJwZiW3Aj/NrdGfxelpP9yhtkCnbCzcSWkpMUP5RRvVY4DeyqruKkBqHf YvCW/gT0PBzkBwNe5fYv3i+le+VCQi56n+LvoiPN9pMaq1oDchQsVTulY/ZVxiL9 67g/shySF2g= =2tFr -----END PGP SIGNATURE-----