Section: .. / 0602-advisories /
| /// File Name: |
OpenPKG-SA-2006.003.txt |
Description:
|
OpenPKG Security Advisory - Ulrich Drepper discovered [0] a weakness in OpenSSH [1] version 4.2p1 and earlier, caused due to the insecure use of the system(3) function in scp(1) when performing copy operations using filenames that are supplied by the user from the command line. This can be exploited to execute shell commands with privileges of the user running scp(1).
| | Homepage: | http://www.openpkg.org/ | | File Size: | 2358 | | Last Modified: | Feb 20 21:38:30 2006 |
| MD5 Checksum: | cfe3463202634882f2b5699eddc825e5 |
|
| /// File Name: |
OpenPKG-SA-2006.004.txt |
Description:
|
OpenPKG Security Advisory - According to vendor security information [0], privilege escalation vulnerabilities exist in the PostgreSQL RDBMS [1] before version 8.1.3. The bug allowed any logged-in user to "SET ROLE" to any other database user id. Due to inadequate validity checking, a user could exploit the special case that "SET ROLE" normally uses to restore the previous role setting after an error. This allowed ordinary users to acquire superuser status, for example.
| | Homepage: | http://www.openpkg.org/ | | File Size: | 2794 | | Last Modified: | Feb 20 23:30:26 2006 |
| MD5 Checksum: | f7c2932dfd01b6098ce708d7b1df93b3 |
|
| /// File Name: |
OpenPKG-SA-2006.005.txt |
Description:
|
OpenPKG Security Advisory - An allocation off-by-one bug exists in the TIN [1] news reader version 1.8.0 and earlier which can lead to a buffer overflow.
| | Homepage: | http://www.openpkg.org/ | | File Size: | 1840 | | Last Modified: | Feb 20 23:31:01 2006 |
| MD5 Checksum: | b4e9f3edc4ae3c51e02316a77ca794bc |
|
| /// File Name: |
pearAuthSQL.txt |
Description:
|
PEAR::Auth version less than 1.2.4 and 1.3.0r4 suffer from SQL injection flaws.
| | Author: | Matt Van Gundy | | File Size: | 886 | | Last Modified: | Feb 25 23:34:39 2006 |
| MD5 Checksum: | 73272548cc7945988381dfc4bdc028fa |
|
| /// File Name: |
pearLiveUser.txt |
Description:
|
PEAR LiveUser versions 0.16.8 and below suffer from an arbitrary file access vulnerability.
| | Author: | James Bercegay | | Homepage: | http://www.gulftech.org/ | | File Size: | 3915 | | Last Modified: | Feb 25 23:30:18 2006 |
| MD5 Checksum: | 7d0033bc72b2a4cac3db0c5251426443 |
|
| /// File Name: |
PlaySmS.txt |
Description:
|
PlaySmS suffers from a XSS vulnerability.
| | Homepage: | http://mohajali.lezr.org | | File Size: | 1539 | | Last Modified: | Feb 13 10:53:38 2006 |
| MD5 Checksum: | 400a15c7c5981d9a0b35f8b3843081bd |
|
| /// File Name: |
plus-6.2.0.189.txt |
Description:
|
PLUS (PatchLink Update Server) version: 6.2.0.189 suffers from several bugs and security issues.
| | Author: | Brian Boner | | File Size: | 12199 | | Last Modified: | Feb 20 22:19:51 2006 |
| MD5 Checksum: | 7cbb9e4d755998f24ea49dfbe015bed5 |
|
| /// File Name: |
PostgreSQL8.1.3.txt |
Description:
|
Multiple security problems were fixed in PostgreSQL 8.1.3.
| | Homepage: | http://www.postgresql.org/ | | File Size: | 2531 | | Last Modified: | Feb 20 22:16:11 2006 |
| MD5 Checksum: | f04e73fd0e8da50f3ac5477b0c02fc7b |
|
| /// File Name: |
PSCipher-enc.txt |
Description:
|
PeopleSoft People Tools 8.4x uses PSCipher() for encryption/hashing purposes which suffers from several problems that can allow the encryption to become compromised.
| | Author: | i-assure | | Homepage: | http://www.i-assure.com | | File Size: | 4641 | | Last Modified: | Feb 7 22:24:38 2006 |
| MD5 Checksum: | 7cf00ba2bb6d69badc7809d35111270a |
|
| /// File Name: |
PseudoRandom-php.txt |
Description:
|
Due to poor design the gen_rand_string() can only generate up to 1 million hashes or random strings. This allow an attacker to reset any account through the lost password request form by "predicting" the validation id and the new password for the account. Vulnerabilities verified on phpBB 2.0.19 and IPB 2.1.4.
| | Author: | r-security | | Homepage: | http://www.r-security.net/tutorials/view/readtutorial.php?id=4 | | File Size: | 8520 | | Last Modified: | Feb 7 22:37:41 2006 |
| MD5 Checksum: | 0bd874e0735c50fd106fc6de4339c80e |
|
| /// File Name: |
sa16100.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered multiple vulnerabilities in Verity KeyView SDK, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system.
| | Homepage: | http://secunia.com/advisories/16100/ | | File Size: | 3999 | | Last Modified: | Feb 11 20:35:30 2006 |
| MD5 Checksum: | bbac6e7a89d0472ddcbee68ed2670a94 |
|
| /// File Name: |
sa16280.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered multiple vulnerabilities in Lotus Notes, which can be exploited by malicious people to bypass certain security restrictions or compromise a user's system.
| | Homepage: | http://secunia.com/advisories/16280/ | | File Size: | 4876 | | Last Modified: | Feb 11 20:35:30 2006 |
| MD5 Checksum: | 41777dc60c48863a4ec9e1ad7be41de6 |
|
| /// File Name: |
sa16340.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered some vulnerabilities in Lotus Domino iNotes Client, which can be exploited by malicious people to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/16340/ | | File Size: | 3502 | | Last Modified: | Feb 11 20:35:30 2006 |
| MD5 Checksum: | ee16cef353bb4f2eacbc87edd7680b56 |
|
| /// File Name: |
sa16583.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Visnetic AntiVirus Plug-in for MailServer, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/16583/ | | File Size: | 1909 | | Last Modified: | Feb 23 21:22:26 2006 |
| MD5 Checksum: | 774cbb40bc32990f8e04bd0811113360 |
|
| /// File Name: |
sa16902.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in PHPLIB, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/16902/ | | File Size: | 1610 | | Last Modified: | Feb 25 01:55:07 2006 |
| MD5 Checksum: | acf561c1a6af3a356ad7515178df1053 |
|
| /// File Name: |
sa16921.txt |
Description:
|
Secunia Security Advisory - rgod has discovered some vulnerabilities and a security issue in NOCC, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people to conduct cross-site scripting attacks and disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/16921/ | | File Size: | 3213 | | Last Modified: | Feb 23 21:22:26 2006 |
| MD5 Checksum: | e455f60a9c691c7cf1817aa053777d81 |
|
| /// File Name: |
sa17251.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in WinACE, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/17251/ | | File Size: | 1948 | | Last Modified: | Feb 23 21:22:26 2006 |
| MD5 Checksum: | f4c40cfd6f4f5d05299bc2eb7003287f |
|
| /// File Name: |
sa18274.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in GNUStep PDFKit Framework, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/18274/ | | File Size: | 1678 | | Last Modified: | Feb 15 19:37:35 2006 |
| MD5 Checksum: | 21391cd732b38d080770737d3c7660cd |
|
| /// File Name: |
sa18598.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in PAM-MySQL, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/18598/ | | File Size: | 2304 | | Last Modified: | Feb 10 03:08:04 2006 |
| MD5 Checksum: | 1e1d8d2d98810519a5050fa5d3dbbbbf |
|
| /// File Name: |
sa18637.txt |
Description:
|
Secunia Security Advisory - Hamid Ebadi has reported a vulnerability in FarsiNews, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/18637/ | | File Size: | 1952 | | Last Modified: | Feb 2 11:19:07 2006 |
| MD5 Checksum: | 2858796da96bceec4693f3d9a35c08be |
|
|
|
|
|