Section: .. / 0611-advisories /
| /// File Name: |
sa23086.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for phpMyAdmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/23086/ | | File Size: | 3433 | | Last Modified: | Nov 25 23:47:38 2006 |
| MD5 Checksum: | bc33ed681eb87651b60db4c153b099b5 |
|
| /// File Name: |
sa23138.txt |
Description:
|
Secunia Security Advisory - Some bugs have been discovered in Adobe Reader and Adobe Acrobat, which may cause an included ActiveX control to crash.
| | Homepage: | http://secunia.com/advisories/23138/ | | File Size: | 3425 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 2261c6a5a44a87edf76e4d48b242dc3a |
|
| /// File Name: |
dragonflybsd-firewire.txt |
Description:
|
The Firewire device enabled by default in the GENERIC kernel for DragonFlyBSD defines an IOCTL function which can be malicious called passing a negative buffer length value. This value will bypass the length check (because the value is negative) and will be used in a copyout operation. This is a kernel bug and the system can be compromised by local users and important system information can be disclosed.
| | Author: | Rodrigo Rubira Branco | | Homepage: | http://www.kernelhacking.com/rodrigo | | Related File: | bsd.patch | | File Size: | 3423 | | Last Modified: | Nov 16 12:15:20 2006 |
| MD5 Checksum: | e1730287e3cb0a8eb2886226197ccde0 |
|
| /// File Name: |
trustedbsd-firewire.txt |
Description:
|
The Firewire device enabled by default in the GENERIC kernel for TrusedBSD* defines an IOCTL function which can be malicious called passing a negative buffer length value. This value will bypass the length check (because the value is negative) and will be used in a copyout operation. This is a kernel bug and the system can be compromised by local users and important system information can be disclosed.
| | Author: | Rodrigo Rubira Branco | | Homepage: | http://www.kernelhacking.com/rodrigo | | Related File: | bsd.patch | | File Size: | 3422 | | Last Modified: | Nov 16 12:15:54 2006 |
| MD5 Checksum: | c4aa48265643c1fa61a56a7322579d01 |
|
| /// File Name: |
freebsd-firewire.txt |
Description:
|
The Firewire device enabled by default in the GENERIC kernel for FreeBSD defines an IOCTL function which can be malicious called passing a negative buffer length value. This value will bypass the length check (because the value is negative) and will be used in a copyout operation. This is a kernel bug and the system can be compromised by local users and important system information can be disclosed.
| | Author: | Rodrigo Rubira Branco | | Homepage: | http://www.kernelhacking.com/rodrigo | | Related File: | bsd.patch | | File Size: | 3418 | | Last Modified: | Nov 16 12:13:44 2006 |
| MD5 Checksum: | 9bf61a2d6a3b88f11455cec5f19352c2 |
|
| /// File Name: |
netbsd-firewire.txt |
Description:
|
The Firewire device enabled by default in the GENERIC kernel for NetBSD defines an IOCTL function which can be malicious called passing a negative buffer length value. This value will bypass the length check (because the value is negative) and will be used in a copyout operation. This is a kernel bug and the system can be compromised by local users and important system information can be disclosed.
| | Author: | Rodrigo Rubira Branco | | Homepage: | http://www.kernelhacking.com/rodrigo | | Related File: | bsd.patch | | File Size: | 3417 | | Last Modified: | Nov 16 12:14:36 2006 |
| MD5 Checksum: | d64c96b48c1144754f29164eff425a33 |
|
| /// File Name: |
VMSA-2006-0009.txt |
Description:
|
VMware Security Advisory - A new update has been released for VMware ESX Server version 3.0.0. This patch addresses the AMD fxsave/restore security vulnerability.
| | Homepage: | http://www.vmware.com/ | | File Size: | 3413 | | Related CVE(s): | CAN-2006-1056 | | Last Modified: | Nov 14 03:22:15 2006 |
| MD5 Checksum: | fbb068276771c1e7463a3712434aea83 |
|
| /// File Name: |
sa22570.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Borland products, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22570/ | | File Size: | 3399 | | Last Modified: | Nov 29 10:21:40 2006 |
| MD5 Checksum: | 1df445d9dfe69da2db71a7818f8a2bb0 |
|
| /// File Name: |
sa22825.txt |
Description:
|
Secunia Security Advisory - Aria-Security has reported some vulnerabilities in cPanel, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/22825/ | | File Size: | 3390 | | Last Modified: | Nov 15 22:19:38 2006 |
| MD5 Checksum: | 035fec5aed80300ed181487092da6b13 |
|
| /// File Name: |
sa22916.txt |
Description:
|
Secunia Security Advisory - Aria-Security Team have reported some vulnerabilities in Helm Web Hosting Control Panel, which can be exploited by malicious users to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/22916/ | | File Size: | 3381 | | Last Modified: | Nov 16 10:09:27 2006 |
| MD5 Checksum: | e7449f5817a8815b1d582f26a4a3c038 |
|
| /// File Name: |
advisory_142006.139.txt |
Description:
|
Hardened PHP Project Security Advisory - Dotdeb PHP versions below 5.2.0 revision 3 suffer from an email header injection vulnerability.
| | Author: | Stefan Esser | | Homepage: | http://www.hardened-php.net/ | | File Size: | 3377 | | Last Modified: | Nov 16 10:48:56 2006 |
| MD5 Checksum: | 94a0d7b89c35c24b152070fece362157 |
|
| /// File Name: |
sa22898.txt |
Description:
|
Secunia Security Advisory - Trustix has issued an update for multiple packages. This fixes some vulnerabilities and a weakness, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22898/ | | File Size: | 3377 | | Last Modified: | Nov 15 22:19:38 2006 |
| MD5 Checksum: | b52f0fd548532ca34b2fbad0c4ad53c0 |
|
| /// File Name: |
sa23080.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered two vulnerabilities in MailEnable, which can be exploited by malicious users to cause a DoS (Denial of service) or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23080/ | | File Size: | 3372 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | ef6a76c3b154cdd628ae42954ec2f93b |
|
| /// File Name: |
sa23045.txt |
Description:
|
Secunia Security Advisory - trueend5 has discovered some vulnerabilities in CuteNews, which can be exploited by malicious users to conduct script insertion attacks and malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23045/ | | File Size: | 3371 | | Last Modified: | Nov 25 23:47:38 2006 |
| MD5 Checksum: | e0ac8e5559a2b62993ffd1eae4fbc959 |
|
| /// File Name: |
sa22945.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious, local users to bypass certain security restrictions, expose potentially sensitive information, or to cause a DoS (Denial of Service), and by malicious people to cause a DoS.
| | Homepage: | http://secunia.com/advisories/22945/ | | File Size: | 3362 | | Last Modified: | Nov 17 18:30:18 2006 |
| MD5 Checksum: | 61d914ce86cae872b0a18a40cb63487b |
|
| /// File Name: |
sa23049.txt |
Description:
|
Secunia Security Advisory - Laurent Gaffié and Benjamin Mossé have reported some vulnerabilities in Rialto, which can be exploited by malicious people to conduct cross-site scripting and SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23049/ | | File Size: | 3354 | | Last Modified: | Nov 21 19:45:15 2006 |
| MD5 Checksum: | fe6227886d697049b717943b2eedb12b |
|
| /// File Name: |
MDKSA-2006-201.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-201 - Pam_ldap does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if authentication has failed, as originally reported for xscreensaver. This might lead to an attacker being able to login into a suspended system account.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3345 | | Related CVE(s): | CVE-2006-5170 | | Last Modified: | Nov 8 21:47:01 2006 |
| MD5 Checksum: | cc0d043ec3e7eadad6fc898762760f90 |
|
| /// File Name: |
maildrives.txt |
Description:
|
viksoe's GMail Drive shell extension and GSpace suffers from flaws that allow for arbitrary file injection, folder creation, and more.
| | Author: | Attila Gerendi | | File Size: | 3344 | | Last Modified: | Nov 6 00:03:23 2006 |
| MD5 Checksum: | 7f2e3f3603cf03981acf3b9f19de8136 |
|
| /// File Name: |
sa22958.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for doxygen. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22958/ | | File Size: | 3312 | | Last Modified: | Nov 17 18:30:18 2006 |
| MD5 Checksum: | d52968bac2ed9848808e51d91aa7ec33 |
|
| /// File Name: |
n.runs-SA-2006.002.txt |
Description:
|
The Grisoft Inc. AVG Antivirus system has had multiple vulnerabilities discovered in the file parsing engine that allow for arbitrary code execution. The vulnerabilities are present in AVG Antivirus software versions prior to 7.1.407.
| | Author: | Sergio Alvarez | | Homepage: | http://www.nruns.com/ | | File Size: | 3308 | | Last Modified: | Nov 14 02:27:16 2006 |
| MD5 Checksum: | 3bbd0c7852ae5559f60d243ce8a9a966 |
|
| /// File Name: |
sa22749.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for libx11. This fixes a vulnerability, which can be exploited by malicious, local users to disclose potentially sensitive information.
| | Homepage: | http://secunia.com/advisories/22749/ | | File Size: | 3304 | | Last Modified: | Nov 8 18:29:38 2006 |
| MD5 Checksum: | cdd2daa5c12c4df60bcce49a808f1bb2 |
|
| /// File Name: |
sa22743.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP Tru64, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/22743/ | | File Size: | 3301 | | Last Modified: | Nov 13 11:18:47 2006 |
| MD5 Checksum: | d07f30c41e9404c4700c0f9f5e31bf7d |
|
| /// File Name: |
MDKSA-2006-164-1.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-164-1 - Local exploitation of an integer overflow vulnerability in the 'CIDAFM()' function in the X.Org and XFree86 X server could allow an attacker to execute arbitrary code with privileges of the X server, typically root. Local exploitation of an integer overflow vulnerability in the 'scan_cidfont()' function in the X.Org and XFree86 X server could allow an attacker to execute arbitrary code with privileges of the X server, typically root.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3255 | | Related CVE(s): | CVE-2006-3740, CVE-2006-3739 | | Last Modified: | Nov 20 11:10:25 2006 |
| MD5 Checksum: | 525faee36903bfd7a1303ad01c93fe1e |
|
| /// File Name: |
sa23064.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged some vulnerabilities in various Avaya products, which can be exploited by malicious, local users to bypass certain security restrictions, to disclose potentially sensitive information, or to cause a DoS (Denial of Service), and by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23064/ | | File Size: | 3251 | | Last Modified: | Nov 25 23:47:38 2006 |
| MD5 Checksum: | bd4940f9c8bae90efe4dede808880d0a |
|
| /// File Name: |
sa22802.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Citrix Presentation Server, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22802/ | | File Size: | 3241 | | Last Modified: | Nov 10 11:02:24 2006 |
| MD5 Checksum: | 176d61759474f569d984a291f76ee8ee |
|
|
|
|
|