Section: .. / 0608-advisories /
| /// File Name: |
cisco-sa-20060823-firewall.txt |
Description:
|
Cisco Security Advisory - Certain versions of the software for the Cisco PIX 500 Series Security Appliances, the Cisco ASA 5500 Series Adaptive Security Appliances (ASA), and the Firewall Services Module (FWSM) are affected by a software bug that may cause the EXEC password, passwords of locally defined usernames, and the enable password in the startup configuration to be changed without user intervention. Unauthorized users can take advantage of this bug to try to gain access to a device that has been reloaded after passwords in its startup configuration have been changed. In addition, authorized users can be locked out and lose the ability to manage the affected device.
| | Homepage: | http://www.cisco.com | | File Size: | 17734 | | Last Modified: | Aug 27 19:57:20 2006 |
| MD5 Checksum: | b63295e8ec69d97fdaa4140ffa0564bc |
|
| /// File Name: |
dsa-1135-1.txt |
Description:
|
Debian Security Advisory 1135-1 - Kevin Kofler discovered several stack-based buffer overflows in the LookupTRM::lookup function in libtunepimp, a MusicBrainz tagging library, which allows remote attackers to cause a denial of service or execute arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 17692 | | Related CVE(s): | CVE-2006-3600 | | Last Modified: | Aug 17 03:47:28 2006 |
| MD5 Checksum: | 2db7cee67e588681418f188f1d0409d7 |
|
| /// File Name: |
sa21532.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for mozilla-firefox. This fixes some vulnerabilities, which can be exploited by malicious people to trick users into disclosing sensitive information, disclose system information, bypass certain security restrictions, conduct cross-site scripting and HTTP response smuggling attacks, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21532/ | | File Size: | 17564 | | Last Modified: | Aug 18 00:12:30 2006 |
| MD5 Checksum: | 007f2d2f3a8f9ffd6f5ef2ff331b3281 |
|
| /// File Name: |
SUSE-SA-2006-045.txt |
Description:
|
SUSE Security Announcement SUSE-SA:2006:045 - This security update fixes crashes in the PCF handling of freetype2 which might be used to crash freetype2 using applications or even to execute code in them.
| | Homepage: | http://www.suse.com | | File Size: | 17005 | | Related CVE(s): | CVE-2006-3467 | | Last Modified: | Aug 17 03:06:45 2006 |
| MD5 Checksum: | e234516d065322a0d80a7908be412297 |
|
| /// File Name: |
dsa-1151-1.txt |
Description:
|
Debian Security Advisory 1151-1 - Yan Rong Ge discovered out-of-boundary memory access in heartbeat, the subsystem for High-Availability Linux. This could be used by a remote attacker to cause a denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 16934 | | Related CVE(s): | CVE-2006-3121 | | Last Modified: | Aug 27 01:39:04 2006 |
| MD5 Checksum: | ef03585e33afbacbb8a0d7baf24c8902 |
|
| /// File Name: |
dsa-1128-1.txt |
Description:
|
Debian Security Advisory 1128-1 - Yan Rong Ge discovered that wrong permissions on a shared memory page in heartbeat, the subsystem for High-Availability Linux could be exploited by a local attacker to cause a denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 16905 | | Related CVE(s): | CVE-2006-3815 | | Last Modified: | Aug 3 00:42:16 2006 |
| MD5 Checksum: | 6ec1f765a4316651bfb5171c65b0a8df |
|
| /// File Name: |
sa21323.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for libtunepimp. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21323/ | | File Size: | 16446 | | Last Modified: | Aug 2 23:35:36 2006 |
| MD5 Checksum: | 9ca9b538d9cf349604a3d63ae261539a |
|
| /// File Name: |
USN-335-1.txt |
Description:
|
Ubuntu Security Notice USN-335-1 - Yan Rong Ge discovered that heartbeat did not sufficiently verify some packet input data, which could lead to an out-of-boundary memory access. A remote attacker could exploit this to crash the daemon (Denial of Service).
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 15862 | | Related CVE(s): | CVE-2006-3121 | | Last Modified: | Aug 27 03:29:43 2006 |
| MD5 Checksum: | a2ef70f25bb73e37fc6bfe5c41cbec35 |
|
| /// File Name: |
sa21240.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for heartbeat. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/21240/ | | File Size: | 15759 | | Last Modified: | Aug 2 04:14:26 2006 |
| MD5 Checksum: | 3c2410e48dc655bfcae6dbf5dbd8012f |
|
| /// File Name: |
sa21231.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for heartbeat. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/21231/ | | File Size: | 15652 | | Last Modified: | Aug 2 04:14:26 2006 |
| MD5 Checksum: | 1d0a9cc47b28720a53e48ceb80094b7b |
|
| /// File Name: |
dsa-1153-1.txt |
Description:
|
Debian Security Advisory 1153-1 - Damian Put discovered a heap overflow vulnerability in the UPX unpacker of the ClamAV anti-virus toolkit which could allow remote attackers to execute arbitrary code or cause denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 15443 | | Related CVE(s): | CVE-2006-4018 | | Last Modified: | Aug 27 15:30:27 2006 |
| MD5 Checksum: | a4be7326c0ef768583539a022d1bf2f3 |
|
| /// File Name: |
dsa-1131-1.txt |
Description:
|
Debian Security Advisory 1131-1 - Mark Dowd discovered a buffer overflow in the mod_rewrite component of apache, a versatile high-performance HTTP server. In some situations a remote attacker could exploit this to execute arbitary code
| | Homepage: | http://www.debian.org/security | | File Size: | 15233 | | Related CVE(s): | CVE-2006-3747 | | Last Modified: | Aug 17 02:54:39 2006 |
| MD5 Checksum: | 720c4b8d72e955f0a6941f5d82028cff |
|
| /// File Name: |
cisco-sa-20060920-guardxss.txt |
Description:
|
Cisco Security Advisory ID: cisco-sa-20060920-guardxss: Cisco Guard Enables Cross Site Scripting
| | Homepage: | http://www.cisco.com | | File Size: | 14621 | | Last Modified: | Oct 2 17:43:35 2006 |
| MD5 Checksum: | 8fa84997626e97f91d92bdcaa82deb4b |
|
| /// File Name: |
sa21654.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21654/ | | File Size: | 14561 | | Last Modified: | Aug 28 09:56:27 2006 |
| MD5 Checksum: | 957854644efca540b27ae79df9de1da1 |
|
| /// File Name: |
SUSE-SA-2006-046.txt |
Description:
|
SUSE Security Announcement SUSE-SA:2006:046 - Damian Put discovered a bug in the UPX decoder used for scanning UPX compressed Windows executables. The bug allows for a heap buffer overflow and may potentially be exploitable to execute arbitrary code. ClamAV has been version updated to version 0.88.4 in order to fix this problem.
| | Homepage: | http://www.suse.com | | File Size: | 14352 | | Related CVE(s): | CVE-2006-4018 | | Last Modified: | Aug 26 20:37:26 2006 |
| MD5 Checksum: | 333e2c38996341689e5668e8bcc92934 |
|
| /// File Name: |
sa21562.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for clamav. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21562/ | | File Size: | 14332 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | 0801d46c9fc29a1a40bbe13aef5f98c5 |
|
| /// File Name: |
sa21324.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for mozilla-thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting and HTTP response smuggling attacks, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21324/ | | File Size: | 14323 | | Last Modified: | Aug 2 23:35:36 2006 |
| MD5 Checksum: | d5be4167550d48681108bf8b58f643d2 |
|
| /// File Name: |
cisco-sa-20060920-ips.txt |
Description:
|
Cisco Security Advisory ID cisco-sa-20060920-ips: Cisco Intrusion Prevention System Management Interface Denial of Service and Fragmented Packet Evasion Vulnerabilities
| | Homepage: | http://www.cisco.com | | File Size: | 14306 | | Last Modified: | Oct 2 17:44:12 2006 |
| MD5 Checksum: | e5a58a6b7fbbf2328e94cb63399b3610 |
|
| /// File Name: |
sa21525.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for imagemagick. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21525/ | | File Size: | 14177 | | Last Modified: | Aug 18 00:12:30 2006 |
| MD5 Checksum: | 306c04dde08e4983067d0fc34770731f |
|
| /// File Name: |
USN-337-1.txt |
Description:
|
Ubuntu Security Notice USN-337-1 - Damian Put discovered a buffer overflow in imagemagick's SGI file format decoder. By tricking an user or automated system into processing a specially crafted SGI image, this could be exploited to execute arbitrary code with the user's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 14117 | | Related CVE(s): | CVE-2006-4144 | | Last Modified: | Aug 27 14:05:35 2006 |
| MD5 Checksum: | 53dbd706659088c959b65c8a7ae5db88 |
|
| /// File Name: |
dsa-1155-1.txt |
Description:
|
Debian Security Advisory 1155-1 - Frank Sheiness discovered that a MIME conversion routine in sendmail, a powerful, efficient, and scalable mail transport agent, could be tricked by a specially crafted mail to perform an endless recursion.
| | Homepage: | http://www.debian.org/security | | File Size: | 13583 | | Related CVE(s): | CVE-2006-1173 | | Last Modified: | Aug 27 20:20:55 2006 |
| MD5 Checksum: | 6c196000dd646710160eb41ddd2d2ea7 |
|
|
|
|
|