Section: .. / 0701-advisories /
| /// File Name: |
glsa-200701-13.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200701-13 - Neil Hoggarth has discovered that when delivering messages to a message delivery agent by means of the mda option, Fetchmail passes a NULL pointer to the ferror() and fflush() functions when refusing a message. Isaac Wilcox has discovered numerous means of plain-text password disclosure due to errors in secure connection establishment. Versions less than 6.3.6 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3043 | | Last Modified: | Jan 23 23:08:26 2007 |
| MD5 Checksum: | bbbbb5a9b5ba6b2d82d6bd8602632926 |
|
| /// File Name: |
MDKSA-2007-014.txt |
Description:
|
Mandriva Linux Security Advisory - hidd in BlueZ (bluez-utils) before 2.25 allows remote attackers to obtain control of the (1) Mouse and (2) Keyboard Human Interface Device (HID) via a certain configuration of two HID (PSM) endpoints, operating as a server, aka HidAttack.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3033 | | Related CVE(s): | CVE-2006-6899 | | Last Modified: | Jan 15 22:40:07 2007 |
| MD5 Checksum: | 927d1fc58efb749cd44ed4b33ea19cf4 |
|
| /// File Name: |
glsa-200701-20.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200701-20 - When interfacing with the LiveJournal service, Centericq does not appropriately allocate memory for incoming data, in some cases creating a buffer overflow. Versions less than or equal to 4.21.0-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3023 | | Last Modified: | Jan 24 01:49:53 2007 |
| MD5 Checksum: | a80760ff41279aa06f56724c5f790c3a |
|
| /// File Name: |
sa23836.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in Cisco products, which can be exploited by malicious people to conduct spoofing attacks.
| | Homepage: | http://secunia.com/advisories/23836/ | | File Size: | 3016 | | Last Modified: | Jan 19 19:09:28 2007 |
| MD5 Checksum: | a8239ac2cc2dab26b504f10c26b6859a |
|
| /// File Name: |
sa23934.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been discovered in MyBB, which can be exploited by malicious people to conduct cross-site request forgery attacks and cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23934/ | | File Size: | 3016 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | fbba2dc29b69498d6de6c3ba08964845 |
|
| /// File Name: |
sa23511.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in various J. Hepple products, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23511/ | | File Size: | 3005 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | 48a14a4c2e00a56ccb69b6abdaf36a96 |
|
| /// File Name: |
sa23976.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for libsoup. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23976/ | | File Size: | 3001 | | Last Modified: | Jan 30 22:46:19 2007 |
| MD5 Checksum: | af9b801c25a111a9ef3548a78c30858a |
|
| /// File Name: |
sa23941.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for cacti. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, manipulate data and compromise vulnerable systems.
| | Homepage: | http://secunia.com/advisories/23941/ | | File Size: | 2997 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | 4196c10c1450d48ce5f119b9bd663628 |
|
| /// File Name: |
MDKSA-2007-019.txt |
Description:
|
Mandriva Linux Security Advisory - The Adobe PDF specification 1.3, as implemented by xpdf 3.0.1 patch 2, kpdf in KDE before 3.5.5, and other products, allows remote attackers to have an unknown impact, possibly including denial of service (infinite loop), arbitrary code execution, or memory corruption, via a PDF file with a crafted catalog dictionary or a crafted Pages attribute that references an invalid page tree node.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2980 | | Related CVE(s): | CVE-2007-0104 | | Last Modified: | Jan 19 22:39:44 2007 |
| MD5 Checksum: | dfb3c9b72fb6e229783449296053ebdf |
|
| /// File Name: |
01.05.07-1.txt |
Description:
|
iDefense Security Advisory 01.05.07 - Remote exploitation of a typecasting bug in Opera Software ASA's Opera Web browser could allow an attacker to execute arbitrary code on the affected host. A flaw exists within Opera's Javascript SVG implementation. When processing a createSVGTransformFromMatrix request Opera does not properly validate the type of object passed to the function. Passing an incorrect object to this function can result in it using a pointer that is user controlled when it attempts to make the virtual function call. iDefense has confirmed the existence of this vulnerability in Opera version 9.02 on both Windows and Linux. Previous versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 2979 | | Last Modified: | Jan 6 19:53:21 2007 |
| MD5 Checksum: | 8b6c9045a44515e5e1faa59cb9858d6e |
|
| /// File Name: |
sa23911.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to overwrite arbitrary files.
| | Homepage: | http://secunia.com/advisories/23911/ | | File Size: | 2973 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | f5d980a81193c59dadcdeb2099e0a018 |
|
| /// File Name: |
sa23575.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Kaspersky Antivirus, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23575/ | | File Size: | 2957 | | Last Modified: | Jan 6 19:54:29 2007 |
| MD5 Checksum: | 9bed4dee46fdbfcd8f5c9294c20c7bf8 |
|
| /// File Name: |
sa23892.txt |
Description:
|
Secunia Security Advisory - David Barroso Berrueta and Alfredo Andres Omella have reported a vulnerability in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23892/ | | File Size: | 2956 | | Last Modified: | Jan 30 22:46:19 2007 |
| MD5 Checksum: | 533b7e96a06c5f68c519ec64819d7c6f |
|
| /// File Name: |
AD20070108.txt |
Description:
|
There is a DACL weakness that exists in the HP all-in-one products drivers, which can be exploited by malicious, local users to gain escalated privileges.
| | Author: | Sowhat | | Homepage: | http://www.nevisnetworks.com/ | | File Size: | 2953 | | Last Modified: | Jan 13 16:54:41 2007 |
| MD5 Checksum: | 06f847963f002265d63e30368df39701 |
|
| /// File Name: |
sa23869.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Citrix Presentation Server, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23869/ | | File Size: | 2951 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | f9d682b4ed892f4d3589bb7e284741e0 |
|
| /// File Name: |
dsa-1250-1.txt |
Description:
|
Debian Security Advisory 1250-1 - It was discovered that cacti, a frontend to rrdtool, performs insufficient validation of data passed to the "cmd" script, which allows SQL injection and the execution of arbitrary shell commands.
| | Homepage: | http://www.debian.org/security | | File Size: | 2949 | | Related CVE(s): | CVE-2006-6799 | | Last Modified: | Jan 19 20:26:55 2007 |
| MD5 Checksum: | dc2bf06d9bd48296c0611d21fa444754 |
|
| /// File Name: |
01.05.07-2.txt |
Description:
|
iDefense Security Advisory 01.05.07 - Remote exploitation of a heap overflow in Opera Software ASA's Opera Web browser could allow an attacker to execute arbitrary code in the security context of the current user. The vulnerability specifically exists due to Opera improperly processing a JPEG DHT marker. The DHT marker is used to define a Huffman Table which is used for decoding the image data. An invalid number of index bytes in the DHT marker will trigger a heap overflow with partially user controlled data. iDefense has confirmed the existence of this vulnerability in Opera version 9.02 on both Windows and Linux. Previous versions may also be affected.
| | Author: | Christoph Diehl | | Homepage: | http://www.idefense.com/ | | File Size: | 2940 | | Last Modified: | Jan 6 19:54:05 2007 |
| MD5 Checksum: | baa00e3119c312f9f99f074d96592fd7 |
|
| /// File Name: |
MDKSA-2007-004.txt |
Description:
|
Mandriva Linux Security Advisory - Dean Gaudet discovered the geoipupdate utility fails to do sanity checking on the filename returned by "GET /app/update_getfilename?product_id=%s".
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2934 | | Last Modified: | Jan 13 17:54:08 2007 |
| MD5 Checksum: | e457892cf44a968efdf07c9fed540c49 |
|
| /// File Name: |
sa23937.txt |
Description:
|
Secunia Security Advisory - Kees Cook has reported some vulnerabilities in smb4K, which can be exploited by malicious, local users to kill arbitrary processes, disclose potentially sensitive information, and gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23937/ | | File Size: | 2932 | | Last Modified: | Jan 29 11:19:09 2007 |
| MD5 Checksum: | 8834e268e8f3ba63c2b20a7993db8d63 |
|
| /// File Name: |
ZDI-07-006.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on systems with vulnerable installations of Citrix Presentation Server, Metaframe Presentation Server or MetaFrame XP. Authentication is not required to exploit this vulnerability.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2926 | | Related CVE(s): | CVE-2007-0444 | | Last Modified: | Jan 26 21:34:15 2007 |
| MD5 Checksum: | e9efacaacf35961b818bbb09ab39a5c1 |
|
| /// File Name: |
sa23763.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for libneon. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23763/ | | File Size: | 2922 | | Last Modified: | Jan 15 20:56:26 2007 |
| MD5 Checksum: | 25d87ce6736f21feb165bd6da714503c |
|
| /// File Name: |
ZDI-07-003.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The specific flaws exists in the Message Engine RPC service which listens by default on TCP ports 6503 and 6504. Affected include BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1, BrightStor ARCserve Backup r11, BrightStor Enterprise Backup r10.5, and BrightStor ARCserve Backup v9.01.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2921 | | Related CVE(s): | CVE-2007-0169 | | Last Modified: | Jan 13 19:15:41 2007 |
| MD5 Checksum: | 97132b2d3b4e89621dff17ca66794441 |
|
| /// File Name: |
sa23583.txt |
Description:
|
Secunia Security Advisory - Will Dormann has discovered a vulnerability in ICONICS Gauge ActiveX, ICONICS Switch ActiveX, and ICONICS Vessel ActiveX, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23583/ | | File Size: | 2921 | | Last Modified: | Jan 3 18:45:45 2007 |
| MD5 Checksum: | 93fcc9173495df829d76c76d2bd24718 |
|
| /// File Name: |
ZDI-07-005.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Sun Microsystems Java Virtual Machine (JVM). User interaction is required to exploit this vulnerability in that the target must visit a malicious website.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2916 | | Related CVE(s): | CVE-2007-0243 | | Last Modified: | Jan 19 20:16:45 2007 |
| MD5 Checksum: | 4be61731d61a0eeec39c080a33cbaeb7 |
|
| /// File Name: |
sa23565.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in various McFunSoft products, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23565/ | | File Size: | 2913 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | b5e900010f674a33f9242b802183db1a |
|
|
|
|
|