Section: .. / 0608-advisories /
| /// File Name: |
EEYE-MS06-042-2.txt |
Description:
|
eEye Digital Security has discovered a heap overflow vulnerability in the MS06-042 cumulative Internet Explorer update that would allow an attacker to execute arbitrary code on the system of a victim who attempts to access a malicious URL. Only Windows 2000 and Windows XP SP1 systems running Internet Explorer 6 SP1 with the MS06-042 patch applied are vulnerable.
| | Author: | Derek Soeder | | Homepage: | http://www.eeye.com/ | | File Size: | 5037 | | Last Modified: | Aug 27 20:37:09 2006 |
| MD5 Checksum: | b710d1b8ded5db4cbade77bb1cc43d44 |
|
| /// File Name: |
EEYE-MS06-042.txt |
Description:
|
eEye has confirmed that the Internet Explorer crash vulnerability as described in MS06-042 is indeed exploitable.
| | Author: | Derek Soeder | | Homepage: | http://www.eeye.com/ | | File Size: | 4689 | | Last Modified: | Aug 27 19:41:54 2006 |
| MD5 Checksum: | 9ef47386e4e24ffcfa4cb0702d3629b0 |
|
| /// File Name: |
EEYEB-20060703.txt |
Description:
|
eEye Digital Security has discovered a security vulnerability in IBM's eGatherer ActiveX control. This is the second vulnerability found in this control by eEye Research, the first being from Drew Copley. This control is typically installed by default on IBM workstations and laptops, and is used by default for auto-finding drivers/updates on IBM's/Lenovo's support site.
| | Author: | Andre Derek Protas | | Homepage: | http://www.eeye.com/ | | File Size: | 4844 | | Last Modified: | Aug 27 13:53:37 2006 |
| MD5 Checksum: | 4e5a3bc31eee6ca62b7f8bf8c82d6cc9 |
|
| /// File Name: |
EEYEB-20060719.txt |
Description:
|
eEye Digital Security has discovered a vulnerability in McAfee Security Center that ships with all McAfee consumer products. There is a remote code execution vulnerability that allows an attacker to take complete control of a remote computer by exploiting a vulnerability found in the Subscription Manager ActiveX control.
| | Homepage: | http://www.eeye.com/ | | File Size: | 4772 | | Last Modified: | Aug 18 01:23:22 2006 |
| MD5 Checksum: | 7bc189cfeb13dd834ac8dd9109dc3f18 |
|
| /// File Name: |
eichhorn.txt |
Description:
|
The Eichhorn Portal is susceptible to multiple SQL injection and cross site scripting flaws.
| | Author: | MC Iglo | | File Size: | 942 | | Last Modified: | Aug 27 17:07:21 2006 |
| MD5 Checksum: | fc03b07e74529f90c43393f47af989f4 |
|
| /// File Name: |
FCEUltra.txt |
Description:
|
FCE Ultra versions 0.98.1 and below suffer from a buffer overflow vulnerability.
| | Author: | KaiJern, Lau | | File Size: | 3361 | | Last Modified: | Aug 18 01:47:52 2006 |
| MD5 Checksum: | 9dd2b44e9702133a550b74ffad5f01d8 |
|
| /// File Name: |
firefox15.txt |
Description:
|
Stacking multiple CSS style attributes across span tags leads to a race condition which can result in denial of service or arbitrary code execution in Mozilla Firefox versions 1.5 and below.
| | Author: | Andrew A | | File Size: | 1962 | | Last Modified: | Aug 17 01:26:12 2006 |
| MD5 Checksum: | 6b4f736094545aa6899ccb46f6cfddc0 |
|
| /// File Name: |
flashTheft.txt |
Description:
|
By forging HTTP request headers with flash, virtual hosted systems can be susceptible to cookie theft using IE.
| | Author: | Amit Klein | | File Size: | 2302 | | Last Modified: | Aug 27 01:21:38 2006 |
| MD5 Checksum: | 2777e8c2e5632edcfbb7a1ec727cf509 |
|
| /// File Name: |
ftd373.txt |
Description:
|
FTD versions 3.7.3 and below suffer from a cross site scripting flaw.
| | Author: | O.G. | | File Size: | 739 | | Last Modified: | Aug 18 00:17:36 2006 |
| MD5 Checksum: | a0cfd84550afec8f00b153d968e36ac8 |
|
| /// File Name: |
fuji-xerox.txt |
Description:
|
Indiana University Security Advisory - The Fuji Xerox Printing Systems print engine suffers from multiple vulnerabilities. An FTP bounce attack is possible when FTP printing is enabled. The embedded HTTP server allows unauthenticated access to system configuration and settings.
| | Homepage: | https://itso.iu.edu/ | | File Size: | 3634 | | Related CVE(s): | CVE-2006-2112, CVE-2006-2113 | | Last Modified: | Aug 28 01:06:00 2006 |
| MD5 Checksum: | 2cb98e5ba87c4422a8755026ba9cd46c |
|
| /// File Name: |
glsa-2006-05-08-02.txt |
Description:
|
Gentoo Linux Security Advisory [UPDATE] GLSA 200605-08:02 - The initial fix for PHP did not fix CVE-2006-1990 on 64 bit systems. Versions less than 5.1.4 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2591 | | Last Modified: | Aug 17 01:29:48 2006 |
| MD5 Checksum: | ca46b348065b684be8e771fc08c02351 |
|
| /// File Name: |
glsa-200607-11.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200607-11 - Kevin Kofler has reported a vulnerability where three stack variables are allocated with 255, 255 and 100 bytes respectively, yet 256 bytes are read into each. This could lead to buffer overflows. Versions less than or equal to 0.4.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3049 | | Last Modified: | Aug 3 01:19:36 2006 |
| MD5 Checksum: | e3f442210498e5392341299deefc06d7 |
|
| /// File Name: |
glsa-200607-12.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200607-12 - Internal security audits by OpenOffice.org have discovered three security vulnerabilities related to Java applets, macros and the XML file format parser. Versions less than 2.0.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3671 | | Last Modified: | Aug 3 01:28:25 2006 |
| MD5 Checksum: | bd78ad8de07d6a5b6a5c179766000d6a |
|
| /// File Name: |
glsa-200607-13.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200607-13 - Luigi Auriemma has found that the adplug library fails to verify the size of the destination buffers in the unpacking instructions, resulting in various possible heap and buffer overflows. Versions less than 1.1.0 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2775 | | Last Modified: | Aug 17 01:09:54 2006 |
| MD5 Checksum: | 4376d909d137c5adf832cf7091026c9e |
|
| /// File Name: |
glsa-200608-01.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-01 - An off-by-one flaw has been found in Apache's mod_rewrite module by Mark Dowd of McAfee Avert Labs. This flaw is exploitable depending on the types of rewrite rules being used. Versions less than 2.0.58-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3011 | | Last Modified: | Aug 17 02:56:21 2006 |
| MD5 Checksum: | f5ee4aae5a11bf911201dd0610fd26b9 |
|
| /// File Name: |
glsa-200608-02.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-02 - The Mozilla Foundation has reported numerous security vulnerabilities related to Mozilla SeaMonkey. Versions less than 1.0.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 6422 | | Last Modified: | Aug 17 04:49:38 2006 |
| MD5 Checksum: | 28cbf2af6b70fdb2ee247e7ad0befd42 |
|
| /// File Name: |
glsa-200608-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-03 - The Mozilla Foundation has reported numerous security vulnerabilities related to Mozilla Firefox. Versions less than 1.5.0.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 6665 | | Last Modified: | Aug 17 04:57:00 2006 |
| MD5 Checksum: | a1b52bdc95fdd950006e489bfd251dcd |
|
| /// File Name: |
glsa-200608-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-04 - The Mozilla Foundation has reported numerous security vulnerabilities related to Mozilla Thunderbird. Versions less than 1.5.0.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 5939 | | Last Modified: | Aug 17 04:58:01 2006 |
| MD5 Checksum: | 1b426d46dd37c36117b4522e946d22e7 |
|
| /// File Name: |
glsa-200608-05.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-05 - LibVNCServer fails to properly validate protocol types effectively letting users decide what protocol to use, such as Type 1 - None. LibVNCServer will accept this security type, even if it is not offered by the server. Versions less than 0.8.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2619 | | Last Modified: | Aug 17 05:12:09 2006 |
| MD5 Checksum: | 662e3e9ab748c3420baefd516d1fbc67 |
|
| /// File Name: |
glsa-200608-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-06 - Courier MTA has fixed a security issue relating to usernames containing the = character, causing high CPU utilization. Versions less than 0.53.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2491 | | Last Modified: | Aug 17 05:12:27 2006 |
| MD5 Checksum: | 7fb0b52e9b717b4447b4aacf54710c16 |
|
| /// File Name: |
glsa-200608-07.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-07 - Tavis Ormandy of the Google Security Team discovered several heap and stack buffer overflows and other flaws in libTIFF. The affected parts include the TIFFFetchShortPair(), TIFFScanLineSize() and EstimateStripByteCounts() functions, and the PixarLog and NeXT RLE decoders. Versions less than 3.8.2-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3149 | | Last Modified: | Aug 17 23:45:12 2006 |
| MD5 Checksum: | c30405f980da7c413bf46e27ad797940 |
|
| /// File Name: |
glsa-200608-08.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-08 - Evgeny Legerov discovered a vulnerability in GnuPG that when certain packets are handled an integer overflow may occur. Versions less than 1.4.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2546 | | Last Modified: | Aug 18 00:10:26 2006 |
| MD5 Checksum: | 383b71fb55b7dc2aa6c566a6e407c3a4 |
|
| /// File Name: |
glsa-200608-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-09 - Jean-David Maillefer discovered a format string vulnerability in time.cc where MySQL fails to properly handle specially formatted user input to the date_format function. Versions less than 4.1.21 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2524 | | Last Modified: | Aug 18 00:55:33 2006 |
| MD5 Checksum: | 2c78ccbac03c0cb39d1a844ba46892c9 |
|
| /// File Name: |
glsa-200608-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200608-10 - Some input is not properly sanitized before being used in a SQL statement in the underlying PostgreSQL database. Versions less than 7.6.86 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2482 | | Last Modified: | Aug 18 00:59:53 2006 |
| MD5 Checksum: | ada496521f9d9a7431494521637d404d |
|
|
|
|
|