SmartDefense Security Advisory

Adobe BlazeDS XML Processing Information Disclosure Vulnerability (APSB10-05)

Industry Reference:CVE-2009-3960.

An information disclosure vulnerability has been identified in Adobe BlazeDS. Adobe BlazeDS is the server-based Java remoting and web messaging technology that enables developers to connect to back-end distributed data and push data in real-time to Adobe Flex and Adobe AIR applications. A remote attacker could exploit this vulnerability to gain access to sensitive information. This protection will detect and block attempts to exploit this vulnerability.

Security Gateway R70: A new protection is now available.
CPAI-2010-036.

Microsoft SMB COPY Command Pathname Overflow Vulnerability (MS10-012)

Industry Reference:CVE-2010-0020.

A remote code execution vulnerability has been reported in the Microsoft Windows Server Message Block (SMB) implementation. The SMB Protocol is a network file sharing protocol that is implemented in Microsoft Windows. A remote attacker may exploit this vulnerability to take complete control of an affected system. This protection will detect and block overly long SMB COPY commands.

IPS-1 & IPS-1 NGX R65: A protection was released in a previous update.
Security Gateway R70: A protection was released in a previous update.
VPN-1 NGX R65 & VSX NGX R65: A protection was released in a previous update.
InterSpect NGX: A new protection is now available.
CPAI-2010-022.

February 14, 2010

IPS Software Blade

Buy Now

Guidelines

Forums

SmartDefense Microsoft Security Resources
You have received this notification because you have subscribed to the SmartDefense mailing list. If you would prefer to no longer receive security alerts and defense notifications please click to Unsubscribe

As always, please feel free to contact us directly if you have any comments or questions.

Read Check Point's Privacy Policy
©2003.2009 Check Point Software Technologies Ltd. (Nasdaq: CHKP) All rights reserved.
800 Bridge Parkway, Redwood City, CA USA 94065