Section: .. / 0803-advisories /
| /// File Name: |
sa29335.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities and security issues have been reported in IBM WebSphere Application Server, some of which have unknown impacts while others can potentially be exploited by malicious, local users to gain knowledge of sensitive information.
| | Homepage: | http://secunia.com/advisories/29335/ | | File Size: | 2624 | | Last Modified: | Mar 12 20:06:24 2008 |
| MD5 Checksum: | 963bdad72a3b0037f75c27f9e30ec21d |
|
| /// File Name: |
sa29341.txt |
Description:
|
Secunia Security Advisory - HP has acknowledged some vulnerabilities in HP-UX, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29341/ | | File Size: | 2343 | | Last Modified: | Mar 12 20:06:24 2008 |
| MD5 Checksum: | a9b5770b1cbf0d5a0bf053a2dc436cae |
|
| /// File Name: |
sa29343.txt |
Description:
|
Secunia Security Advisory - Beyond Security has reported a vulnerability in the Net::DNS Perl module, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29343/ | | File Size: | 2332 | | Last Modified: | Mar 12 20:06:24 2008 |
| MD5 Checksum: | 8346c2f77ac71b2c78e1d5f94939115d |
|
| /// File Name: |
sa29347.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/29347/ | | File Size: | 2549 | | Last Modified: | Mar 12 20:06:24 2008 |
| MD5 Checksum: | 67cb2076d105011ba65f26cbda65585e |
|
| /// File Name: |
sa29348.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for apache. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks and by malicious users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29348/ | | File Size: | 2135 | | Last Modified: | Mar 12 20:06:24 2008 |
| MD5 Checksum: | 7b8417696bbdcd1da909b74900561c21 |
|
| /// File Name: |
sa29354.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for libnet-dns-perl. This fixes some vulnerabilities, which can be exploited by malicious people to poison the DNS cache or to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29354/ | | File Size: | 7789 | | Last Modified: | Mar 12 20:06:24 2008 |
| MD5 Checksum: | 87a8f521ab9db27eafb5f65a5fcf30f5 |
|
| /// File Name: |
MDVSA-2008-065.txt |
Description:
|
Mandriva Linux Security Advisory - Luigi Auriemma found a few programming errors in Pulseaudio, that can be used to crash the Pulseaudio daemon, by authenticated and unauthenticated users.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2874 | | Related CVE(s): | CVE-2007-1804 | | Last Modified: | Mar 12 18:56:11 2008 |
| MD5 Checksum: | 640706c025b80272d23e07ed04de4c28 |
|
| /// File Name: |
glsa-200803-15.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-15 - Richard Cunningham reported that phpMyAdmin uses the $_REQUEST variable of $_GET and $_POST as a source for its parameters. Versions less than 2.11.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2874 | | Related CVE(s): | CVE-2008-1149 | | Last Modified: | Mar 12 18:55:34 2008 |
| MD5 Checksum: | f37c7a57ed8f1b91372947d99206f9a6 |
|
| /// File Name: |
glsa-200803-14.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-14 - Chris Evans (Google Security) discovered a stack-based buffer overflow within the zseticcspace() function in the file zicc.c when processing a PostScript file containing a long Range array in a .seticcscpate operator. Versions less than 8.15.4-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3649 | | Related CVE(s): | CVE-2008-0411 | | Last Modified: | Mar 12 18:54:31 2008 |
| MD5 Checksum: | 6bea26a9670869a60625a228fbb462ca |
|
| /// File Name: |
TKADV2008-001.txt |
Description:
|
The kernel driver cpoint.sys shipped with Panda Internet Security and Antivirus Firewall 2008 contains a vulnerability in the code that handles IOCTL requests. The vulnerability can lead to denial of service and arbitrary code execution attacks.
| | Author: | Tobias Klein | | Homepage: | http://www.trapkit.de/ | | File Size: | 7506 | | Last Modified: | Mar 12 18:31:24 2008 |
| MD5 Checksum: | e01729fb3cbdef6910c36ee5ca6205f0 |
|
| /// File Name: |
MDVSA-2008-064.txt |
Description:
|
Mandriva Linux Security Advisory - A flaw in how tomboy handles LD_LIBRARY_PATH was discovered where by appending paths to LD_LIBRARY_PATH the program would also search the current directory for shared libraries. In directories containing network data, those libraries could be injected into the application.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2830 | | Related CVE(s): | CVE-2005-4790 | | Last Modified: | Mar 12 18:03:11 2008 |
| MD5 Checksum: | 8c601bc60f91546685df116096b447ab |
|
| /// File Name: |
maildisable.txt |
Description:
|
MailEnable Professional and Enterprise versions 3.13 and below suffer from buffer overflow and null pointer vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | maildisable.zip | | File Size: | 2052 | | Last Modified: | Mar 12 18:00:22 2008 |
| MD5 Checksum: | bc35cbc1c90857ea5c019b66d1c26cba |
|
| /// File Name: |
MDVSA-2008-063.txt |
Description:
|
Mandriva Linux Security Advisory - Ulf Harnhammar of Secunia Research discovered a format string flaw in how Evolution displayed encrypted mail content. If a user were to open a carefully crafted email message, arbitrary code could be executed with the permissions of the user running Evolution.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3976 | | Related CVE(s): | CVE-2008-0072 | | Last Modified: | Mar 12 17:40:36 2008 |
| MD5 Checksum: | 6fbf265b975e2c247be78137ec719cad |
|
| /// File Name: |
MDVSA-2008-061.txt |
Description:
|
Mandriva Linux Security Advisory - Multiple cross-site scripting (XSS) vulnerabilities were found in Mailman prior to version 2.1.10b1, which allow remote attackers to inject arbitrary web script or HTML via editing templates and the list's info attribute in the web administrator interface.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 4069 | | Related CVE(s): | CVE-2008-0564 | | Last Modified: | Mar 12 17:38:54 2008 |
| MD5 Checksum: | 6630467d76b59eee278cf3330ed32fa6 |
|
| /// File Name: |
TA08-066A.txt |
Description:
|
Technical Cyber Security Alert TA08-066A - Sun has released alerts to address multiple vulnerabilities affecting the Sun Java Runtime Environment. The most severe of these vulnerabilities could allow a remote attacker to execute arbitrary code.
| | Homepage: | http://www.us-cert.gov/ | | File Size: | 5718 | | Last Modified: | Mar 12 17:37:54 2008 |
| MD5 Checksum: | 4eb5e661a700d24cb71564a76e4ea9bf |
|
| /// File Name: |
dsa-1513-1.txt |
Description:
|
Debian Security Advisory 1513-1 - It was discovered that lighttpd, a fast webserver with minimal memory footprint, would display the source to CGI scripts if their execution failed in some circumstances.
| | Homepage: | http://www.debian.org/security | | File Size: | 14146 | | Related CVE(s): | CVE-2008-1111 | | Last Modified: | Mar 12 17:36:52 2008 |
| MD5 Checksum: | cbd8864575abe6548d68a0c3828f6cae |
|
| /// File Name: |
SUSE-SA-2008-012.txt |
Description:
|
SUSE Security Announcement - The current security update of cups fixes a double-free bug in the function process_browse_data() that can lead to a remote denial-of-service by crashing cupsd or possibly to a remote code execution. The bug can only be exploited if cupsd listens to 631/udp by crafted UDP Browse packets. Additionally two remote denial-of-service bugs were fixed. The first one can be triggered via crafted IPP packets to use a pointer after it was freed and the second issue is a memory-leak caused by a large number of requests to add and remove shared printers.
| | Homepage: | http://www.suse.com | | File Size: | 19377 | | Related CVE(s): | CVE-2008-0596, CVE-2008-0597, CVE-2008-0882 | | Last Modified: | Mar 12 16:42:28 2008 |
| MD5 Checksum: | 51864b80345817ce7b8c9ce7a309ef14 |
|
| /// File Name: |
dsa-1503-2.txt |
Description:
|
Debian Security Advisory 1503-2 - Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 74207 | | Related CVE(s): | CVE-2004-2731, CVE-2006-4814, CVE-2006-5753, CVE-2006-5823, CVE-2006-6053, CVE-2006-6054, CVE-2006-6106, CVE-2007-1353, CVE-2007-1592, CVE-2007-2172, CVE-2007-2525, CVE-2007-3848, CVE-2007-4308, CVE-2007-4311, CVE-2007-5093, CVE-2007-6063, CVE-2007-6151, CVE-2007-6206, CVE-2007-6694, CVE-2008-0007 | | Last Modified: | Mar 12 16:38:11 2008 |
| MD5 Checksum: | 4d782fab669b98a7a56eca8a00c7628d |
|
| /// File Name: |
jdk-overflow.txt |
Description:
|
A couple more JPEG ICC parsing bugs were fixed in the latest JDK updates. Link to a malicious JPEG included.
| | Author: | Chris Evans | | File Size: | 1009 | | Last Modified: | Mar 12 16:32:56 2008 |
| MD5 Checksum: | 6ebec7c73d336738ee4a30a00c038842 |
|
| /// File Name: |
glsa-200803-12.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-12 - Ulf Harnhammar from Secunia Research discovered a format string error in the emf_multipart_encrypted() function in the file mail/em-format.c when reading certain data (e.g. the Version: field) from an encrypted e-mail. Versions less than 2.12.3-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2932 | | Related CVE(s): | CVE-2008-0072 | | Last Modified: | Mar 12 16:25:12 2008 |
| MD5 Checksum: | fec966c95aecd78ec71983543a776515 |
|
| /// File Name: |
perforces.txt |
Description:
|
Perforce Servers versions 2007.3/143793 and below suffer from NULL pointer, invalid memory access, and endless loop vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | perforces.zip | | File Size: | 2409 | | Last Modified: | Mar 12 16:24:26 2008 |
| MD5 Checksum: | 90963f758e9a1066b4a6667ef375c221 |
|
|
|
|
|