[Full-disclosure] Akamai Technologies Security Advisory 2008-0003 (Akamai Client Software)
- From: Akamai Security Team <security@xxxxxxxxxx>
- Date: Fri, 06 Jun 2008 11:04:59 -0400
-----BEGIN PGP SIGNED MESSAGE-----
Akamai Technologies Security Advisory 2008-0003
* Akamai ID: 2008-0003
* Date: 2008/06/06
* Product Name: Akamai Client Software (formerly Red Swoosh)
* Affected Versions: Up to and including 3322
* Fixed Version: 3333
* CVE IDs: CVE-2008-1106
* CVSS Base Score: 5.53
* Product Description:
The Akamai Client Software is a software layer that securely stores and
transfers files to enhance content delivery.
* Vulnerability Description:
Akamai has become aware of a security vulnerability within the Akamai
Client Software which can be exploited to conduct cross-site request
forgery attacks. This vulnerability exists only in the Akamai Client
Software and does not affect Akamai's other services in any way.
Akamai has no evidence to date that any attempt has been made to exploit
* Patch Instructions:
No user interaction is required. Clients will be automatically upgraded.
CVE-2008-1106 was independently discovered and brought to Akamai's
attention by Dyon Balding of Secunia Research.
* About Akamai:
Akamai(r) is the leading global service provider for accelerating
content and business processes online. Thousands of organizations have
formed trusted relationships with Akamai, improving their revenue and
reducing costs by maximizing the performance of their online businesses.
Leveraging the Akamai EdgePlatform, these organizations gain business
advantage today, and have the foundation for the emerging Web solutions
of tomorrow. Akamai is "The Trusted Choice for Online Business." For
more information, visit www.akamai.com.
Our GPG public key:
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)
-----END PGP SIGNATURE-----
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- Prev by Date: [Full-disclosure] rPSA-2008-0185-1 vsftpd
- Next by Date: [Full-disclosure] Secunia Research: Akamai Red Swoosh Cross-Site Request Forgery
- Previous by thread: [Full-disclosure] rPSA-2008-0185-1 vsftpd
- Next by thread: [Full-disclosure] Secunia Research: Akamai Red Swoosh Cross-Site Request Forgery