Section: .. / 0611-advisories /
| /// File Name: |
glsa-200611-21.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200611-21 - Kile fails to set the same permissions on backup files as on the original file. This is similar to CVE-2005-1920. Versions less than 1.9.2-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2364 | | Last Modified: | Nov 28 21:56:45 2006 |
| MD5 Checksum: | 6e410cbf905558bbe954fd4483e6ec81 |
|
| /// File Name: |
glsa-200611-22.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200611-22 - Ingo H3 fails to properly escape shell metacharacters in procmail rules. Versions less than 1.1.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2443 | | Last Modified: | Nov 28 21:57:00 2006 |
| MD5 Checksum: | 33308e82b0f272c074e66a26af01b11f |
|
| /// File Name: |
googleInclusion.txt |
Description:
|
The Google Crawler could be leveraged as an anonymizer for launching remote file inclusion attacks.
| | Author: | Noam Rathaus | | File Size: | 2078 | | Last Modified: | Nov 26 22:14:54 2006 |
| MD5 Checksum: | 87dafacbeaf0cfd1da7f16f5f388b377 |
|
| /// File Name: |
Gotfault-05.txt |
Description:
|
Gotfault Security - Advisory #05 - 27/10/06: Mozilla Firefox versions 1.5.0.7 and below and 2.0 are vulnerable to a DoS condition within its javascript Range object. In a special condition, a NULL Pointer Deference occurs and Firefox crashes.
| | Homepage: | http://gotfault.net | | File Size: | 8462 | | Last Modified: | Oct 31 18:27:36 2006 |
| MD5 Checksum: | 86e20d14f971d917f97ad727e8934c28 |
|
| /// File Name: |
gpgtaketwo.txt |
Description:
|
While fixing a bug reported by Hugh Warrington, a buffer overflow has been identified in all released GnuPG versions. The current versions 1.4.5 and 2.0.0 are affected. A small patch is provided.
| | Author: | Werner Koch | | File Size: | 2502 | | Last Modified: | Nov 30 19:03:24 2006 |
| MD5 Checksum: | b61c2ceb35b9de65ad9a82a807753b38 |
|
| /// File Name: |
icq-overflow.txt |
Description:
|
The Icq 2003 client is prone to a local heap overflow vulnerability in the "Answering Service" function due to a lack of bounds checking.
| | Author: | LegendaryZion | | Homepage: | http://www.zion-security.com | | File Size: | 892 | | Last Modified: | Nov 1 18:09:13 2006 |
| MD5 Checksum: | a289e665ea4b8a64c1e45ecdf162404e |
|
| /// File Name: |
iplanet-xss.txt |
Description:
|
The iPlanet Messaging Server Messenger Express by "Sun" suffers from a cross site scripting flaw.
| | Author: | Tal Argoni | | File Size: | 2010 | | Last Modified: | Nov 2 20:40:55 2006 |
| MD5 Checksum: | e513e3a78a7efc79a99c6142d1beb6b7 |
|
| /// File Name: |
lackenv.txt |
Description:
|
A lack of environment sanitization in FreeBSD, OpenBSD, and NetBSD dynamic loaders may allow for privilege escalation.
| | Author: | Mark Dowd, John McDonald, Justin Schuh | | File Size: | 4437 | | Last Modified: | Nov 26 20:38:34 2006 |
| MD5 Checksum: | d8ee508ca7429a07de680081ff8bbd39 |
|
| /// File Name: |
lotusnotes_keyfiles.pdf |
Description:
|
FortConsult Security Advisory - It is possible to retrieve unencrypted data from the "names.nsf" database on Lotus Notes servers without being logged in.
| | Author: | Andrew Christensen | | Homepage: | http://www.fortconsult.net/ | | Related File: | 11.08.06-1.txt | | File Size: | 465791 | | Last Modified: | Nov 8 22:17:22 2006 |
| MD5 Checksum: | da0ec7b5b5e3e08dfef96944411396a9 |
|
| /// File Name: |
LS-20061113.txt |
Description:
|
LSsec has discovered a vulnerability in Computer Associates BrightStor ARCserve Backup version 11.5, which could be exploited by an anonymous attacker in order to execute arbitrary code with SYSTEM privileges on an affected system.
| | Homepage: | http://www.lssec.com/ | | File Size: | 462 | | Last Modified: | Nov 21 21:27:00 2006 |
| MD5 Checksum: | 31e92d00fbcd76854d1b61346e9c44e1 |
|
| /// File Name: |
macosx-preauth.txt |
Description:
|
The network kernel extension com.apple.nke.pppoe that works concurrently with the pppd has a critical vulnerability that may lead to arbitrary code execution with system privileges. Affected product and versions include Mac OS X version 10.3.9, Mac OS X Server version 10.3.9, Mac OS X version 10.4.8, and Mac OS X Server version 10.4.8.
| | Author: | Mu Security Research | | Homepage: | http://labs.musecurity.com/ | | File Size: | 2911 | | Last Modified: | Nov 30 19:42:21 2006 |
| MD5 Checksum: | f44848b5ca7af2a87549157a6f34a57f |
|
| /// File Name: |
maildrives.txt |
Description:
|
viksoe's GMail Drive shell extension and GSpace suffers from flaws that allow for arbitrary file injection, folder creation, and more.
| | Author: | Attila Gerendi | | File Size: | 3344 | | Last Modified: | Nov 6 00:03:23 2006 |
| MD5 Checksum: | 7f2e3f3603cf03981acf3b9f19de8136 |
|
| /// File Name: |
major_rls30.txt |
Description:
|
admin.tool CMS versions 3 and below suffer from multiple cross site scripting flaws.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1761 | | Last Modified: | Nov 6 00:21:07 2006 |
| MD5 Checksum: | 51680d43affbd9e332c54fa85b053e54 |
|
| /// File Name: |
major_rls31.txt |
Description:
|
Xenis.creator CMS suffers from multiple cross site scripting and SQL injection flaws.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 2184 | | Last Modified: | Nov 6 00:21:53 2006 |
| MD5 Checksum: | 5855653303157a4647bf0cb8d3e99455 |
|
| /// File Name: |
major_rls32.txt |
Description:
|
phpComasy CMS versions 0.7.9 pre and below suffer from multiple cross site scripting issues.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1888 | | Last Modified: | Nov 7 00:35:49 2006 |
| MD5 Checksum: | 061f7fd11405e83eab3530d4c62e69b0 |
|
| /// File Name: |
major_rls33.txt |
Description:
|
ShopSystems versions 4.0 and below suffer from a SQL injection vulnerability.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1661 | | Last Modified: | Nov 14 00:40:22 2006 |
| MD5 Checksum: | f22121ef3410a5434b965e97c00539e9 |
|
| /// File Name: |
major_rls34.txt |
Description:
|
Plesk versions 8.0.1 and below suffer from multiple cross site scripting issues.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 2072 | | Last Modified: | Nov 17 19:07:46 2006 |
| MD5 Checksum: | 0b168cfe4aaea915b7e9599f3cdb1074 |
|
| /// File Name: |
major_rls35.txt |
Description:
|
Travelsized CMS versions 0.4.1 and below suffer from multiple cross site scripting issues.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 1782 | | Last Modified: | Nov 20 11:11:37 2006 |
| MD5 Checksum: | f4b1f739125939857682836820c27f28 |
|
| /// File Name: |
major_rls36.txt |
Description:
|
dev4u CMS suffers from multiple SQL injection and cross site scripting issues.
| | Author: | David "Aesthetico" Vieira-Kurz | | Homepage: | http://www.majorsecurity.de | | File Size: | 2205 | | Last Modified: | Nov 20 11:12:29 2006 |
| MD5 Checksum: | eeeee3b9863e1b85fdf8041defc6873e |
|
| /// File Name: |
mcafee-netware.txt |
Description:
|
A boundary error in Client Service for Netware (CSNW) can be exploited to cause a buffer overflow via a specially crafted network message sent to the system. Successful exploitation allows execution of arbitrary code and an attacker could remotely take complete control of the affected system. A denial of service vulnerability exists in Client Service for NetWare (CSNW) that could allow an attacker to send a specially crafted network message to an affected system running the Client Service for NetWare service. An attacker could cause the system to stop responding and automatically restart thus causing the affected system to stop accepting requests.
| | Author: | Sam Arun Raj | | File Size: | 2784 | | Related CVE(s): | CVE-2006-4688, CVE-2006-4689 | | Last Modified: | Nov 17 20:38:30 2006 |
| MD5 Checksum: | 29c9301fcea9d17b0478bdafd59f2672 |
|
| /// File Name: |
MDKSA-2006-164-1.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-164-1 - Local exploitation of an integer overflow vulnerability in the 'CIDAFM()' function in the X.Org and XFree86 X server could allow an attacker to execute arbitrary code with privileges of the X server, typically root. Local exploitation of an integer overflow vulnerability in the 'scan_cidfont()' function in the X.Org and XFree86 X server could allow an attacker to execute arbitrary code with privileges of the X server, typically root.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3255 | | Related CVE(s): | CVE-2006-3740, CVE-2006-3739 | | Last Modified: | Nov 20 11:10:25 2006 |
| MD5 Checksum: | 525faee36903bfd7a1303ad01c93fe1e |
|
| /// File Name: |
MDKSA-2006-193.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-193: Multiple buffer overflows in GraphicsMagick before 1.1.7 and ImageMagick 6.0.7 allow user-assisted attackers to cause a denial of service and possibly execute execute arbitrary code via (1) a DCM image that is not properly handled by the ReadDCMImage function in coders/dcm.c, or (2) a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 7308 | | Last Modified: | Nov 1 17:19:25 2006 |
| MD5 Checksum: | 1426136a4d924930eb1a5e843d54eb2f |
|
| /// File Name: |
MDKSA-2006-194.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-194: A vulnerability in PostgreSQL 8.1.x allowed remote authenticated users to cause a Denial of Service (daemon crash) via certain aggregate functions in an UPDATE statement which were not handled correctly
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 15532 | | Last Modified: | Nov 1 17:19:31 2006 |
| MD5 Checksum: | 0f85e201fdaae2ce584087dacf4b0d3f |
|
| /// File Name: |
MDKSA-2006-195.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-195: Vulnerabilities in the HTTP, LDAP, XOT, WBXML, and MIME Multipart dissectors were discovered in versions of wireshark less than 0.99.4, as well as various other bugs.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 5410 | | Last Modified: | Nov 3 18:04:35 2006 |
| MD5 Checksum: | f8121899a7b32febaf6feffa93d3299a |
|
| /// File Name: |
MDKSA-2006-196.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-196: The Hardened-PHP Project discovered buffer overflows in htmlentities/htmlspecialchars internal routines to the PHP Project. Of course the whole purpose of these functions is to be filled with user input. (The overflow can only be when UTF-8 is used)
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 8280 | | Last Modified: | Nov 3 18:02:46 2006 |
| MD5 Checksum: | f9729a71047aec99b0736602d9135186 |
|
|
|
|
|