FortiGuard Center

New Vulnerability Coverage




Threat Type: Multiple Vulnerabilities
IPS Definition
Database Versions:
2.514 - 2.517
Coverage Release Date: Jun 16, 2008 - Jun 26, 2008
Published Date: Friday, June 27, 2008
Version #: 1
  
Severity Number of
Vulnerabilities
Active
Exploitation
Critical61
High64
Medium31
Low--
Info-n/a
Total156

Foreword

The FortiGuard Global Threat Research Team has released new security content to cover multiple vulnerabilities. The FortiGuard Team has observed 6 active exploitations of these vulnerabilities to date.

For more information, visit the FortiGuard Center at www.fortiguardcenter.com.


Threat Remediation

Fortinet provides coverage for the vulnerabilities described below as of the 2.517 IPS Definitions database update. A brief description of each vulnerability is provided as follows, in order of severity.

plus  Critical ( 4 )

plus  High ( 5 )

plus  Medium ( 1 )


red arrow up Top of Section

Enhanced Coverage

The FortiGuard Threat Research team updates security content as new vectors of exploitation are discovered. The table below details the security content enhanced with this release.

plus  Critical ( 3 )

plus  High ( 1 )

plus  Medium ( 2 )


red arrow up Top of Section

Active Exploitation

The FortiGuard Threat Research team uses globally distributed probes to monitor exploit activity. Vulnerabilities can be classified as active and given a magnitude level. The magnitude level is the rate of activity across the probes. The value of the magnitude is set to low, medium or high.

The table below lists the vulnerabilities discussed in this bulletin and their corresponding exploit activity magnitude. The data below is as of this writing.

plus  Critical ( 1 of 6 )

plus  High ( 4 of 6 )

plus  Medium ( 1 of 3 )


red arrow up Top of Section

Document History

Revision Date Version Number
Friday, June 27, 2008 1 Initial Documentation.


About Fortinet ( www.fortinet.com )

Fortinet is the pioneer and leading provider of ASIC-accelerated unified threat management, or UTM, security systems, which are used by enterprises and service providers to increase their security while reducing total operating costs. Fortinet solutions were built from the ground up to integrate multiple levels of security protection--including firewall, antivirus, intrusion prevention, VPN, spyware prevention and anti-spam -- designed to help customers protect against network and content level threats. Leveraging a custom ASIC and unified interface, Fortinet solutions offer advanced security functionality that scales from remote office to chassis-based solutions with integrated management and reporting. Fortinet solutions have won multiple awards around the world and are the only security products that are certified in six programs by ICSA Labs: (Firewall, Antivirus, IPSec, SSL, Network IPS, and Anti-Spyware). Fortinet is privately held and based in Sunnyvale, California.

Disclaimer

Although Fortinet has attempted to provide accurate information in these materials, Fortinet assumes no legal responsibility for the accuracy or completeness of the information. Please note that no Fortinet statements herein constitute or contain any guarantee, warranty or legally binding representation. All materials contained in this publication are subject to change without notice, and Fortinet reserves the right to change, modify, transfer, or otherwise revise this publication without notice.

red arrow up Top of page