[Full-disclosure] Akamai Technologies Security Advisory 2008-0003 (Akamai Client Software)



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ----------------------------------------------------
Akamai Technologies Security Advisory 2008-0003


* Akamai ID: 2008-0003
* Date: 2008/06/06
* Product Name: Akamai Client Software (formerly Red Swoosh)
* Affected Versions: Up to and including 3322
* Fixed Version: 3333
* CVE IDs: CVE-2008-1106
* CVSS Base Score: 5.53

* Product Description:

The Akamai Client Software is a software layer that securely stores and
transfers files to enhance content delivery.


* Vulnerability Description:

Akamai has become aware of a security vulnerability within the Akamai
Client Software which can be exploited to conduct cross-site request
forgery attacks. This vulnerability exists only in the Akamai Client
Software and does not affect Akamai's other services in any way.
Akamai has no evidence to date that any attempt has been made to exploit
this vulnerability.


* Patch Instructions:

No user interaction is required. Clients will be automatically upgraded.


* Credit:

CVE-2008-1106 was independently discovered and brought to Akamai's
attention by Dyon Balding of Secunia Research.


* About Akamai:

Akamai(r) is the leading global service provider for accelerating
content and business processes online. Thousands of organizations have
formed trusted relationships with Akamai, improving their revenue and
reducing costs by maximizing the performance of their online businesses.
Leveraging the Akamai EdgePlatform, these organizations gain business
advantage today, and have the foundation for the emerging Web solutions
of tomorrow. Akamai is "The Trusted Choice for Online Business." For
more information, visit www.akamai.com.


Our GPG public key:
http://www.akamai.com/dl/akamai/Akamai_Security_General.pub

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (Darwin)

iQIcBAEBAgAGBQJISVIbAAoJEEngXEVbkoPOqpMP/ifrjjCTc+M4L2Hy/1OMvKa+
1tpO24oinIWw1q8NSiHjzLt81Qkv7Yd/Whp/439c8p5W+0EpU/h/0L8dF44Au6IE
KV2YaidiG0w+TiBPtkn1AhPHanKGuv5q1z1T/Ud5Y0Nh+Ph0RxoKKtB+MCJT5C62
jD3p6Vi10cVV57AbayyOGxqkJB2dem/qkGWtq/Ck1lzYRwBI3UDd59Y4U1b2NJdL
UF+W6rtMqLcWXCd8/OowEFrhMX4Ipaow1AeEaPkpIrp/75h9caq+7gop3QWtb7S9
zxaC+bAMuI+fQbmU5S09kQNycWQEGnXvhUqgiD2pPAV5S0gMxwcRaFbx98YCQb1Y
ePgDGMrIPI9Toy9QTuUGf2eb4s8/0upu0EF1T1iI6xETiMpOhbTh/oYjhrnadT7M
wJFgbeXVYSyWVZf7+CmCsXVOpinkAKMuZWDIRiHDRm5p7RicYQqHo7h3rZ1Jvw5k
qmN67SqUlu6uw9mNd9aR1ysdFxLf8GXKl5qIqyJNQgNJ9kr709zXnp8Bxuq4UPIK
0iPgKvmuHYZLGrM1ZXf8AQpska/qzix7Z58fxLXYAcT261yWQMadXWzKPOrlyk1f
QPbAQ3v6C7kMGUOtXV5g8TM0e8iQyTsLRoi6eDmM7Q3rKdFa7H9ZXiRokgLzg2Hy
uLS+FsUucKIMGvHpbC/e
=nm3S
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/