Section: .. / 0805-advisories /
| /// File Name: |
sa30046.txt |
Description:
|
Secunia Security Advisory - IRCRASH has reported two vulnerabilities in vlbook, which can be exploited by malicious people to conduct cross-site scripting attacks or disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/30046/ | | File Size: | 2454 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 4653d953c1bdf2902d57131873d40e0b |
|
| /// File Name: |
sa30048.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in PHP, where some have unknown impacts and others can be exploited by malicious users to bypass certain security restrictions, and potentially by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/30048/ | | File Size: | 3701 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 34518482e65a14d08df17ed7be68c225 |
|
| /// File Name: |
sa30049.txt |
Description:
|
Secunia Security Advisory - IRCRASH has discovered a vulnerability in Mjguest, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/30049/ | | File Size: | 2184 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 68c15194970ac3be92f97cbd0462fd46 |
|
| /// File Name: |
sa30052.txt |
Description:
|
Secunia Security Advisory - IRCRASH has discovered a vulnerability in ActualAnalyzer, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/30052/ | | File Size: | 2160 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 018d85347824fc4e631b4dc81a924d87 |
|
| /// File Name: |
sa30054.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in ALAXALA Networks AX series, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/30054/ | | File Size: | 2432 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 1b38930fb421a38d11699620dc82f6f5 |
|
| /// File Name: |
sa30073.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for egroupware. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/30073/ | | File Size: | 1988 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | cd77723c8b3d5946703948152ff7b0ac |
|
| /// File Name: |
sa30077.txt |
Description:
|
Secunia Security Advisory - rPath has issued an update for the kernel. This can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/30077/ | | File Size: | 1995 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 9f12cf8605dfbfb4cc67c05454afdce5 |
|
| /// File Name: |
sa30091.txt |
Description:
|
Secunia Security Advisory - Christian Holler has reported a vulnerability in mvnForum, which can be exploited by malicious users to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/30091/ | | File Size: | 2225 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 73bcc720813bf3cecd18cba1d931e745 |
|
| /// File Name: |
sa30098.txt |
Description:
|
Secunia Security Advisory - RoMaNcYxHaCkEr has discovered a vulnerability in CMS Faethon, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/30098/ | | File Size: | 2166 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 916d787186c86e153d89b3a7eb4398b4 |
|
| /// File Name: |
sa30107.txt |
Description:
|
Secunia Security Advisory - HaCkeR-EgY has reported a vulnerability in Musicbox, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/30107/ | | File Size: | 2110 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | fd6a1a9650811313b1dfd2b52e7c6858 |
|
| /// File Name: |
sa30118.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in rdesktop, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/30118/ | | File Size: | 3103 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 58ad392870dcc436c40f31e2fc98dd03 |
|
| /// File Name: |
sa30122.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun Java System Web Server and Sun Java System Application Server, which can be exploited by malicious people to disclose certain sensitive information.
| | Homepage: | http://secunia.com/advisories/30122/ | | File Size: | 3924 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 1cb072aca923bb421573cf708dff2a04 |
|
| /// File Name: |
sa30128.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in SAP Internet Transaction Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/30128/ | | File Size: | 2368 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 1aa9f216c77cab17aaec223b2190cd49 |
|
| /// File Name: |
sa30129.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged some vulnerabilities in the Tcl GUI Toolkit Library included in Solaris, which can be exploited by malicious people to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/30129/ | | File Size: | 2349 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | d6df10f60a64d24921c75e15cbde1283 |
|
| /// File Name: |
sa30132.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP-UX, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/30132/ | | File Size: | 2184 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | ed8612b77319e883c6cb5ade0f377b07 |
|
| /// File Name: |
sa30133.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun Java System Web Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/30133/ | | File Size: | 3555 | | Last Modified: | May 8 13:30:50 2008 |
| MD5 Checksum: | 58e28bc0a6d2f40dff95bf5aa4c0018e |
|
| /// File Name: |
05.07.08-3.txt |
Description:
|
iDefense Security Advisory 05.07.08 - Remote exploitation of an integer signedness vulnerability in rdesktop, as included in various vendors' operating system distributions, allows attackers to execute arbitrary code with the privileges of the logged-in user. The vulnerability exists within the code responsible for reallocating dynamic buffers. The rdesktop xrealloc() function uses a signed comparison to determine if the requested allocation size is less than 1. When this occurs, the function will incorrectly set the allocation size to be 1. This results in an improperly sized heap buffer being allocated, which can later be overflowed. iDefense confirmed the existence of this vulnerability in rdesktop version 1.5.0. Previous versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3416 | | Related CVE(s): | CVE-2008-1803 | | Last Modified: | May 7 20:43:37 2008 |
| MD5 Checksum: | c3320ef9f586bf2a8eadea9bdb952524 |
|
| /// File Name: |
05.07.08-2.txt |
Description:
|
iDefense Security Advisory 05.07.08 - Remote exploitation of a BSS overflow vulnerability in rdesktop, as included in various vendors' operating system distributions, allows attackers to execute arbitrary code with the privileges of the logged-in user. The vulnerability exists within the code responsible for reading in an RDP redirect request. This request is used to redirect an RDP connection from one server to another. When parsing the redirect request, the rdesktop client reads several 32-bit integers from the request packet. These integers are then used to control the number of bytes read into statically allocated buffers. This results in several buffers located in the BSS section being overflowed, which can lead to the execution of arbitrary code. iDefense confirmed the existence of this vulnerability in rdesktop version 1.5.0. Previous versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3480 | | Related CVE(s): | CVE-2008-1802 | | Last Modified: | May 7 20:42:49 2008 |
| MD5 Checksum: | dcb778aa36d5093d53a1522ad73f6ceb |
|
| /// File Name: |
05.07.08-1.txt |
Description:
|
iDefense Security Advisory 05.07.08 - Remote exploitation of an integer underflow vulnerability in rdesktop, as included in various vendors' operating system distributions, allows attackers to execute arbitrary code with the privileges of the logged-in user. The vulnerability exists within the code responsible for reading in an RDP request. When reading a request, a 16-bit integer value that represents the number of bytes that follow is taken from the packet. This value is then decremented by 4, and used to calculate how many bytes to read into a heap buffer. The subtraction operation can underflow, which will then lead to the heap buffer being overflowed. iDefense confirmed the existence of this vulnerability in rdesktop version 1.5.0. Previous versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3393 | | Related CVE(s): | CVE-2008-1801 | | Last Modified: | May 7 20:42:04 2008 |
| MD5 Checksum: | c018aff3b2b98000cb2a48058984a14d |
|
| /// File Name: |
google-spam.txt |
Description:
|
It appears that manipulating the forwarding functionality in Google's GMail service allows people to spam.
| | Homepage: | http://ece.uprm.edu/~andre/insert | | File Size: | 2123 | | Last Modified: | May 7 20:40:32 2008 |
| MD5 Checksum: | f7d31e6f454a2e5814a14ca9ac14dcfb |
|
| /// File Name: |
glsa-200805-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200805-04 - A vulnerability has been reported in FCKEditor due to the way that file uploads are handled in the file editor/filemanager/upload/php/upload.php when a filename has multiple file extensions (CVE-2008-2041). Another vulnerability exists in the _bad_protocol_once() function in the file phpgwapi/inc/class.kses.inc.php, which allows remote attackers to bypass HTML filtering (CVE-2008-1502). Versions less than 1.4.004 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3609 | | Related CVE(s): | CVE-2008-1502, CVE-2008-2041 | | Last Modified: | May 7 20:38:18 2008 |
| MD5 Checksum: | 0ef7dd1b359cd5c05af051363a60b6d3 |
|
| /// File Name: |
glsa-200805-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200805-03 - Bernhard R. Link discovered that Eterm opens a terminal on :0 if the -display option is not specified and the DISPLAY environment variable is not set. Further research by the Gentoo Security Team has shown that aterm, Mrxvt, multi-aterm, RXVT, rxvt-unicode, and wterm are also affected. Versions less than 1.0.1-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 4335 | | Related CVE(s): | CVE-2008-1142, CVE-2008-1692 | | Last Modified: | May 7 20:37:56 2008 |
| MD5 Checksum: | e7bce4b2f319f035e053ff26dbb0497a |
|
| /// File Name: |
sa29968.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for cpio. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29968/ | | File Size: | 4357 | | Last Modified: | May 7 20:31:38 2008 |
| MD5 Checksum: | 4339669fe7fbfb5d144cfa520fa2f1df |
|
| /// File Name: |
sa29969.txt |
Description:
|
Secunia Security Advisory - Juan Pablo Lopez Yacubian has reported a vulnerability in Novell GroupWise, which can be exploited by malicious people to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/29969/ | | File Size: | 2291 | | Last Modified: | May 7 20:31:38 2008 |
| MD5 Checksum: | 483eefea6f5569822e2d258139f40417 |
|
|
|
|
|