Provided and/or discovered by: 2) An anonymous researcher working with ZDI
3, 15) "regenrecht" working with iDefense.
4) Sebastian Apelt working with iDefense
5, 6, 7) Peter Csepely working with ZDI
8) Virtual Security Research
9) The vendor credits Billy Rios of Microsoft and Nate Mcfeters of Ernst and Young.
10) The vendor credits Peter Csepely working with ZDI and John Heasman of NGSSoftware.
12) The vendor credits Francisco Amato.
13) Stefan Middendorf
14) The vendor credits Sami Koivu.
17) The vendor credits Henri Torgemane and Sami Koivu.
19) The vendor credits Jan Grant of Bristol University.
20) The vendor credits Adam Gowdiak.
21) The vendor credits University of Oulu.
23) Sean Larsson, iDefense Labs
Changelog: 2008-12-05: Added vulnerability #23 to the advisory. Updated "Description" section with additional vulnerability details. Added reporter links to the "Original Advisory" section and updated credits.
2008-12-08: Added CVE references.
2008-12-12: Added CVE reference.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.