Section: .. / 0603-advisories /
| /// File Name: |
FLSA-2006-157459-4.txt |
Description:
|
Fedora Legacy Update Advisory FLSA:157459-4 - Updated kernel packages that fix several security issues are now available
| | Homepage: | http://fedoralegacy.org | | File Size: | 7897 | | Last Modified: | Mar 21 22:51:21 2006 |
| MD5 Checksum: | 47ecad5cf388bf80b7332f2499e01ef1 |
|
| /// File Name: |
DMA-2006-0313a.txt |
Description:
|
DMA[2006-0313a] - Apple OSX Mail.app RFC1740 Real Name Buffer Overflow - After applying Security Update 2006-001 Mail.app becomes vulnerable to a buffer overflow that may be triggered via a properly formatted MIME Encapsuled Macintosh file. Sending a file in the AppleDouble format with a long Real Name entry will invoke the overflow. Reading through RFC1740 should provide enough information to trigger the issue. The overflow is triggered by the file that contains the AppleDouble header information.
| | Author: | Kevin Finisterre | | Homepage: | http://www.digitalmunition.com/DMA[2006-0313a].txt | | Related Exploit: | SuperTastey.pl | | File Size: | 7854 | | Last Modified: | Mar 14 23:24:53 2006 |
| MD5 Checksum: | ecf75713c657587ff99ac0445f2f3d28 |
|
| /// File Name: |
dsa-995-1.txt |
Description:
|
Debian Security Advisory DSA 995-1 - Ulf Harnhammar discoverd a buffer overflow in metamail, an implementation of MIME (Multi-purpose Internet Mail Extensions), that could lead to a denial of service or potentially execute arbitrary code when processing messages.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 7700 | | Last Modified: | Mar 13 22:09:12 2006 |
| MD5 Checksum: | bd572f1d3ac620ede3a01b4748349cb3 |
|
| /// File Name: |
FLSA-2006-173274.txt |
Description:
|
Fedora Legacy Update Advisory FLSA:173274 - A bug was found in the way gdk-pixbuf processes XPM images. An attacker could create a carefully crafted XPM file in such a way that it could cause an application linked with gdk-pixbuf to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-3186 to this issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 7684 | | Last Modified: | Mar 21 22:52:05 2006 |
| MD5 Checksum: | 5938187a915dace9cfb5e94e0048e73b |
|
| /// File Name: |
dsa-993-2.txt |
Description:
|
Debian Security Advisory DSA 993-2 - Tavis Ormandy noticed that gnupg, the GNU privacy guard - a free PGP replacement, can be tricked to emit a "good signature" status message when a valid signature is included which does not belong to the data packet. This update basically adds fixed packages for woody whose version turned out to be vulnerable as well.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 7605 | | Last Modified: | Mar 13 22:10:47 2006 |
| MD5 Checksum: | 309b31f349f13cea601e5b8e0fb0e24b |
|
| /// File Name: |
dsa-1013-1.txt |
Description:
|
Debian Security Advisory DSA 1013-1 - Will Aoki discovered that snmptrapfmt, a configurable snmp trap handler daemon for snmpd, does not prevent overwriting existing files when writing to a temporary log file.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 7596 | | Last Modified: | Mar 23 21:45:53 2006 |
| MD5 Checksum: | fd25fc65d9ca0d6667b2034cb8dee2af |
|
| /// File Name: |
dsa-1003-1.txt |
Description:
|
Debian Security Advisory DSA 1003-1 - Eric Romang discovered that xpvm, a graphical console and monitor for PVM, creates a temporary file that allows local attackers to create or overwrite arbitrary files with the privileges of the user running xpvm.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 7508 | | Last Modified: | Mar 17 01:17:56 2006 |
| MD5 Checksum: | 7b8aef2a0aed77a4615239f8e1a4fe0a |
|
| /// File Name: |
SSRT051078.txt |
Description:
|
HPSBUX02102 SSRT051078 rev.1 - HP-UX usermod(1M) Local UnaUthorized Access A vulnerability has been identified with certain versions of the HP-UX usermod(1M) command. A certain combination of options can result in recursively changing the ownership of all directories and files under a user's new home directory. This may result in unauthorized access to these directories and files.
| | Homepage: | http://www.itrc.hp.com/service/cki/secBullArchive.do | | File Size: | 7484 | | Last Modified: | Mar 21 23:15:44 2006 |
| MD5 Checksum: | d43349d319bb8ef248504f1781825554 |
|
| /// File Name: |
dsa-1012-1.txt |
Description:
|
Debian Security Advisory DSA 1012-1 - A buffer overflow in the command line argument parsing has been discovered in unzip, the de-archiver for ZIP files that could lead to the execution of arbitrary code.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 7475 | | Last Modified: | Mar 21 22:42:19 2006 |
| MD5 Checksum: | 77e4f82d23b11e01bcbf557d7b44c952 |
|
| /// File Name: |
dsa-991-1.txt |
Description:
|
Debian Security Advisory DSA 991-1 - Jean-Sebastien Guay-Leroux discovered a buffer overflow in zoo, a utility to manipulate zoo archives, that could lead to the execution of arbitrary code when unpacking a specially crafted zoo archive.
| | Author: | Steve Kemp | | Homepage: | http://www.debian.org/security/ | | File Size: | 7416 | | Related CVE(s): | CVE-2006-0855 | | Last Modified: | Mar 11 03:35:20 2006 |
| MD5 Checksum: | 3b882e1e51638d039dacff23697abfb9 |
|
| /// File Name: |
sa19138.txt |
Description:
|
Secunia Security Advisory - Multiple vulnerabilities have been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/19138/ | | File Size: | 7395 | | Last Modified: | Mar 15 05:10:17 2006 |
| MD5 Checksum: | ae71ea47da988f960508986ffba7a688 |
|
| /// File Name: |
SSRT051128.txt |
Description:
|
HPSBUX02101 SSRT051128 rev.1 - HP-UX VirtualVault running Apache 1.3.X Remote Unauthorized Access - A security vulnerability has been identified in Apache HTTP server versions prior to Apache 1.3.34 that may allow HTTP Request Splitting/Spoofing attacks, resulting in remote unauthorized access.
| | Homepage: | http://www.itrc.hp.com/service/cki/secBullArchive.do | | File Size: | 7368 | | Last Modified: | Mar 21 23:11:49 2006 |
| MD5 Checksum: | 4bce37ff29a05b4ee84921ce4148926f |
|
| /// File Name: |
FreeBSD-SA-06-09.openssh.txt |
Description:
|
FreeBSD Security Advisory FreeBSD-SA-06:09.openssh - Because OpenSSH and OpenPAM have conflicting designs (one is event-driven while the other is callback-driven), it is necessary for OpenSSH to fork a child process to handle calls to the PAM framework. However, if the unprivileged child terminates while PAM authentication is under way, the parent process incorrectly believes that the PAM child also terminated. The parent process then terminates, and the PAM child is left behind. Due to the way OpenSSH performs internal accounting, these orphaned PAM children are counted as pending connections by the master OpenSSH server process. Once a certain number of orphans has accumulated, the master decides that it is overloaded and stops accepting client connections.
| | Homepage: | http://www.freebsd.org/security/ | | File Size: | 7234 | | Related CVE(s): | CVE-2006-0883 | | Last Modified: | Mar 3 04:17:28 2006 |
| MD5 Checksum: | c7a571211f30729cc3ab9b9b33605a91 |
|
| /// File Name: |
dsa-1005-1.txt |
Description:
|
Debian Security Advisory DSA 1005-1 - Simon Kilvington discovered that specially crafted PNG images can trigger a heap overflow in libavcodec, the multimedia library of ffmpeg, which may lead to the execution of arbitrary code. xine-lib includes a local copy of libavcodec.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 7005 | | Last Modified: | Mar 21 22:43:38 2006 |
| MD5 Checksum: | 877cefa2220f34d9d8acb7a9f768970b |
|
| /// File Name: |
CORE-2006-0124.txt |
Description:
|
Core Security Technologies Advisory ID: CORE-2006-0124 - Cross-Site Scripting in Verisigns haydn.exe CGI script: A cross-site scripting vulnerability found in Verisigns haydn.exe could allow an attacker to execute scripting code in the machine of a user within the user's web browser with the same trust level as that of the site hosting the haydn.exe file (this is usually a trusted site, since it is used to enroll, revoke or validate certificates).
| | Homepage: | http://www.coresecurity.com/corelabs/ | | File Size: | 6962 | | Last Modified: | Mar 23 22:18:30 2006 |
| MD5 Checksum: | 3e07374c4cb9157b78fca5d6ec1510a3 |
|
| /// File Name: |
dsa-984-1.txt |
Description:
|
Debian Security Advisory DSA 984-1 - Derek Noonburg has fixed several potential vulnerabilities in xpdf, the Portable Document Format (PDF) suite.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 6944 | | Last Modified: | Mar 3 10:10:06 2006 |
| MD5 Checksum: | 0d5ee648aa6febe452629991b0779803 |
|
| /// File Name: |
sa19318.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for snmptrapfmt. This fixes a vulnerability, which potentially can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges.
| | Homepage: | http://secunia.com/advisories/19318/ | | File Size: | 6725 | | Last Modified: | Mar 22 14:23:07 2006 |
| MD5 Checksum: | e1d4523c540b22d2b752cc4628ecc8e8 |
|
| /// File Name: |
TUVSA-0603-003.txt |
Description:
|
Technical University of Vienna Security Advisory - Multiple XSS vulnerabilities in txtForum Versions 1.0.4-dev and prior.
| | Homepage: | http://www.seclab.tuwien.ac.at | | File Size: | 6688 | | Last Modified: | Mar 10 02:09:46 2006 |
| MD5 Checksum: | 81100adc49effb901438f504cd2beafe |
|
| /// File Name: |
sa19226.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for metamail. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/19226/ | | File Size: | 6686 | | Last Modified: | Mar 13 21:05:36 2006 |
| MD5 Checksum: | 76592f96cbf29095aaed31ba31fd4c24 |
|
| /// File Name: |
FLSA-2006-174479.txt |
Description:
|
Fedora Legacy Update Advisory - FLSA:174479 - Several bugs in the way libungif decodes GIF images were discovered. An attacker could create a carefully crafted GIF image file in such a way that it could cause an application linked with libungif to crash or execute arbitrary code when the file is opened by a victim.
| | Homepage: | http://fedoralegacy.org | | File Size: | 6656 | | Last Modified: | Mar 21 22:52:38 2006 |
| MD5 Checksum: | b43dba0d8772ca21a8d0627e7366c91b |
|
| /// File Name: |
SSRT061134.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified in HP-UX running swagentd. The vulnerability could be exploited remotely by an unauthenticated user to cause swagentd to abort resulting in a Denial of Service (DoS).
| | Author: | HP | | Homepage: | http://www.hp.com | | File Size: | 6645 | | Last Modified: | Apr 1 05:51:19 2006 |
| MD5 Checksum: | 7a8cc266033a6bd5d956de301ed79fdf |
|
| /// File Name: |
SSRT061118.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with HP System Management homepage (SMH) versions 2.0.0 through 2.1.4 running on Microsoft Windows. The vulnerability could be exploited remotely to allow unauthorized access to files via directory traversal.
| | Author: | HP | | Homepage: | http://www.hp.com | | File Size: | 6567 | | Last Modified: | Mar 2 11:33:37 2006 |
| MD5 Checksum: | 86ca941ee04bb667c0c210d777b94ba5 |
|
| /// File Name: |
sa19251.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for xpvm. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges.
| | Homepage: | http://secunia.com/advisories/19251/ | | File Size: | 6556 | | Last Modified: | Mar 18 22:11:21 2006 |
| MD5 Checksum: | abff18f2e0cfe11c666017665d56fbe6 |
|
| /// File Name: |
sa19166.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for zoo. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/19166/ | | File Size: | 6512 | | Last Modified: | Mar 11 03:24:56 2006 |
| MD5 Checksum: | 39429e4b5e5f625f37d96686832adb73 |
|
| /// File Name: |
sa19092.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for libtasn1-2. This fixes some vulnerabilities, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/19092/ | | File Size: | 6282 | | Last Modified: | Mar 8 05:17:23 2006 |
| MD5 Checksum: | 475bf75289b935e2cc27203f7ce6df14 |
|
|
|
|
|