Section: .. / 0606-advisories /
| /// File Name: |
dsa-1098-1.txt |
Description:
|
Debian Security Advisory 1098-1 - Michael Marek discovered that the Horde web application framework performs insufficient input sanitising, which might lead to the injection of web script code through cross-site scripting.
| | Homepage: | http://www.debian.org/security | | File Size: | 2898 | | Related CVE(s): | CVE-2006-2195 | | Last Modified: | Jun 21 10:17:55 2006 |
| MD5 Checksum: | 3f4a2115940b75b3a05e2d014053db78 |
|
| /// File Name: |
dsa-1099-1.txt |
Description:
|
Debian Security Advisory 1099-1 - Michael Marek discovered that the Horde web application framework performs insufficient input sanitising, which might lead to the injection of web script code through cross-site scripting.
| | Homepage: | http://www.debian.org/security | | File Size: | 2886 | | Related CVE(s): | CVE-2006-2195 | | Last Modified: | Jun 21 10:18:42 2006 |
| MD5 Checksum: | 9132086aee8d862b09c9b8ec5766ebc0 |
|
| /// File Name: |
dsa-1100-1.txt |
Description:
|
Debian Security Advisory 1100-1 - A boundary checking error has been discovered in wv2, a library for accessing Microsoft Word documents, which can lead to an integer overflow induced by processing word files.
| | Homepage: | http://www.debian.org/security | | File Size: | 6755 | | Related CVE(s): | CVE-2006-2197 | | Last Modified: | Jun 25 23:26:26 2006 |
| MD5 Checksum: | b22e0a67c933f1715736baf5e395945b |
|
| /// File Name: |
dsa-1101-1.txt |
Description:
|
Debian Security Advisory 1101-1 - A bug has been discovered in the Courier Mail Server that can result in a number of processes to consume arbitrary amounts of CPU power.
| | Homepage: | http://www.debian.org/security | | File Size: | 62614 | | Related CVE(s): | CVE-2006-2659 | | Last Modified: | Jun 27 07:59:13 2006 |
| MD5 Checksum: | ef5f8b11be7a6024d036cdcecd97319d |
|
| /// File Name: |
dsa-1102-1.txt |
Description:
|
Debian Security Advisory 1102-1 - Steve Kemp from the Debian Security Audit project discovered that pinball, a pinball simulator, can be tricked into loading level plugins from user-controlled directories without dropping privileges.
| | Homepage: | http://www.debian.org/security | | File Size: | 7109 | | Related CVE(s): | CVE-2006-2196 | | Last Modified: | Jun 27 08:50:41 2006 |
| MD5 Checksum: | 58bb3bb238c3abf013c5f4cb02a5255f |
|
| /// File Name: |
dsa-1103-1.txt |
Description:
|
Debian Security Advisory 1103-1 - Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 40843 | | Related CVE(s): | CVE-2005-3359, CVE-2006-0038, CVE-2006-0039, CVE-2006-0456, CVE-2006-0554, CVE-2006-0555, CVE-2006-0557, CVE-2006-0558, CVE-2006-0741, CVE-2006-0742, CVE-2006-0744, CVE-2006-1056, CVE-2006-1242, CVE-2006-1368, CVE-2006-1523, CVE-2006-1524, CVE-2006-1525, CVE-2006-1857, CVE-2006-1858, CVE-2006-1863, CVE-2006-1864, CVE-2006-2271, CVE-2006-2272, CVE-2006-2274 | | Last Modified: | Jun 27 09:05:51 2006 |
| MD5 Checksum: | d216555ef855960c2344bf35236ce105 |
|
| /// File Name: |
dsa-1104-1.txt |
Description:
|
Debian Security Advisory 1104-1 - Several vulnerabilities have been discovered in OpenOffice.org, a free office suite. It turned out to be possible to embed arbitrary BASIC macros in documents in a way that OpenOffice.org does not see them but executes them anyway without any user interaction. It is possible to evade the Java sandbox with specially crafted Java applets. Loading malformed XML documents can cause buffer overflows and cause a denial of service or execute arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 14974 | | Related CVE(s): | CVE-2006-2198, CVE-2006-2199, CVE-2006-3117 | | Last Modified: | Jul 2 10:11:49 2006 |
| MD5 Checksum: | cefc0ae21542ef25d3f254cf1cf7e8fa |
|
| /// File Name: |
Eduha.txt |
Description:
|
Eduha Meeting suffers from a PHP shell upload vulnerability.
| | Author: | Liz0ziM | | Homepage: | http://www.biyo.tk | | File Size: | 629 | | Last Modified: | Jun 26 08:16:11 2006 |
| MD5 Checksum: | 447ab851ae4baaea20e05b7a909a041c |
|
| /// File Name: |
EEYEB-20060524.txt |
Description:
|
eEye Digital Security has discovered a vulnerability in the remote management interface for Symantec AntiVirus 10.x and Symantec Client Security 3.x, which could be exploited by an anonymous attacker in order to execute arbitrary code with SYSTEM privileges on an affected system. The management interface is typically enabled in enterprise settings and listens on TCP port 2967 by default, for both server and client systems.
| | Homepage: | http://www.eeye.com/ | | File Size: | 5026 | | Last Modified: | Jun 14 06:47:48 2006 |
| MD5 Checksum: | 1c99f9c0e6ff3ecbdbc76947acf7229b |
|
| /// File Name: |
ERNW-01-2006.txt |
Description:
|
The Online Registration Facility of Algorithmic Research PrivateWire VPN Software does not do proper bounds checking handling normal GET requests. Sending an overly long page or script name, it causes a buffer overflow and an attacker can control the EIP to run arbitrary code on the victims machine.
| | Author: | Michael Thumann | | Homepage: | http://www.ernw.de/ | | File Size: | 1353 | | Last Modified: | Jun 27 08:53:58 2006 |
| MD5 Checksum: | c135ca3824cca6de700edc848227687f |
|
| /// File Name: |
ewsEngine-1.5.0.txt |
Description:
|
NewsEngine 1.5.0 or prior suffers from a remote SQL injection vulnerability in newscomments.php.
| | Author: | ajann | | File Size: | 374 | | Last Modified: | Jun 11 05:12:38 2006 |
| MD5 Checksum: | 62629145abc8020f806826102f32395e |
|
| /// File Name: |
f_bloggit-1.01.txt |
Description:
|
BloggIt versions 1.01 and below suffer from an arbitrary code execution flaw via admin.php.
| | Author: | Federico Fazzi | | File Size: | 1033 | | Last Modified: | Jun 12 08:55:38 2006 |
| MD5 Checksum: | c2ac3a5a0770c6f1772ffc3dec7e0e83 |
|
| /// File Name: |
FLSA-2006-189137-1.txt |
Description:
|
Fedora Legacy Update Advisory: FLSA:189137-1 - Updated mozilla packages fix security issues
| | Homepage: | http://fedoralegacy.org | | File Size: | 24208 | | Last Modified: | Jun 11 05:26:14 2006 |
| MD5 Checksum: | 5e3b485fbf750ca9728fc1b03831dfbf |
|
| /// File Name: |
FLSA-2006-189137-2.txt |
Description:
|
Fedora Legacy Update Advisory - FLSA:189137-2: Updated firefox package fixes security issues
| | Homepage: | http://fedoralegacy.org | | File Size: | 6262 | | Last Modified: | Jun 11 05:27:28 2006 |
| MD5 Checksum: | a74b7de64ffb6c564f79b8a0a510cdc1 |
|
| /// File Name: |
FLSA-2006-190777.txt |
Description:
|
Fedora Legacy Update Advisory - FLSA:190777: Updated X.org packages fix security issue
| | Homepage: | http://fedoralegacy.org | | File Size: | 12494 | | Last Modified: | Jun 11 05:27:57 2006 |
| MD5 Checksum: | 5b3f0017791dfb6b8009c4c0cd78beb2 |
|
| /// File Name: |
FLSA-2006-190884.txt |
Description:
|
Fedora Legacy Update Advisory: FLSA:190884 - Updated squirrelmail package fixes security issues.
| | Homepage: | http://fedoralegacy.org | | File Size: | 5892 | | Last Modified: | Jun 11 05:28:34 2006 |
| MD5 Checksum: | 9d0081341575a85184ad95431f61cfc6 |
|
| /// File Name: |
FLSA-2006-190941.txt |
Description:
|
Fedora Legacy Update Advisory - FLSA:190941: Updated ipsec-tools package fixes security issue
| | Homepage: | http://fedoralegacy.org | | File Size: | 4207 | | Last Modified: | Jun 11 05:26:47 2006 |
| MD5 Checksum: | f83e89373d97bf979cf472689641d60e |
|
| /// File Name: |
FSA-011.txt |
Description:
|
FSA:011: AWF CMS 1.11, Remote command execution.
| | Author: | Federico Fazzi | | File Size: | 732 | | Last Modified: | Jun 14 06:23:35 2006 |
| MD5 Checksum: | 7e9633ae10f66a826a70bde772076fe0 |
|
| /// File Name: |
gallery2.4.0.txt |
Description:
|
gallery 2.4.0 suffers from a remote file disclosure vulnerability.
| | Author: | Federico Fazzi | | File Size: | 2499 | | Last Modified: | Jun 11 04:37:57 2006 |
| MD5 Checksum: | e99e75a74f788e64dd3823ea021b07ab |
|
| /// File Name: |
glsa-200605-16.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200605-16 - Ivo van der Wijk discovered that the staticfilter component of CherryPy fails to sanitize input correctly. Versions less than 2.1.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2417 | | Last Modified: | Jun 1 02:56:35 2006 |
| MD5 Checksum: | 50d302dacce4f0da674bf7feb28099c1 |
|
| /// File Name: |
glsa-200605-17.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200605-17 - Multiple vulnerabilities, ranging from integer overflows and NULL pointer dereferences to double frees, were reported in libTIFF. Versions less than 3.8.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2814 | | Last Modified: | Jun 1 02:56:42 2006 |
| MD5 Checksum: | 5b8a29fddfc1e91d4593d8fd08b27168 |
|
| /// File Name: |
glsa-200606-01.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-01 - SEC Consult has discovered a buffer overflow in the code processing style sheet attributes. It is caused by an integer signedness error in a length check followed by a call to a string function. It seems to be hard to exploit this buffer overflow to execute arbitrary code because of the very large amount memory that has to be copied. Versions less than 8.54 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2735 | | Last Modified: | Jun 11 04:23:39 2006 |
| MD5 Checksum: | cbc6653e675e3450c02b4728d4f281cf |
|
| /// File Name: |
glsa-200606-02.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-02 - When the mailbox is created in useradd, the open() function does not receive the three arguments it expects while O_CREAT is present, which leads to random permissions on the created file, before fchmod() is executed. Versions less than 4.0.15-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2637 | | Last Modified: | Jun 11 04:23:45 2006 |
| MD5 Checksum: | 9288ee1a0cee72ef9353b0caca9b7443 |
|
| /// File Name: |
glsa-200606-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-03 - KaDaL-X discovered a format string error within the handling of filenames. Hans de Goede also discovered several other format string errors in the processing of dia files. Versions less than 0.95.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2626 | | Last Modified: | Jun 11 04:23:49 2006 |
| MD5 Checksum: | 8b6a97f8db8f7f6f21638ec4a3ae0fc0 |
|
|
|
|
|