Section: .. / 0702-advisories /
| /// File Name: |
sa24226.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for gnucash. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/24226/ | | File Size: | 3426 | | Last Modified: | Feb 22 21:32:16 2007 |
| MD5 Checksum: | 6e473ff54718b9090751c2fd637064f2 |
|
| /// File Name: |
sa24126.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/24126/ | | File Size: | 3380 | | Last Modified: | Feb 14 14:41:53 2007 |
| MD5 Checksum: | 7eb19abbbd86da567c913e234e3bb097 |
|
| /// File Name: |
sa24121.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Step-by-Step Interactive Training, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24121/ | | File Size: | 3368 | | Last Modified: | Feb 14 14:41:53 2007 |
| MD5 Checksum: | 6207d6127472052355ef36e4e1e02775 |
|
| /// File Name: |
sa24069.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in various Trend Micro products, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/24069/ | | File Size: | 3364 | | Last Modified: | Feb 12 19:06:32 2007 |
| MD5 Checksum: | 01f8f2e8c6fc355250ce86678688bb7c |
|
| /// File Name: |
readirchange.txt |
Description:
|
ReadDirectoryChangesW() in Microsoft Windows 2000/XP/2003/Vista does not check a user's permissions for child objects, making it possible to retrieve information about objects that a user has no LIST permissions for.
| | Author: | 3APA3A | | Homepage: | http://securityvulns.com/ | | Related Exploit: | spydir.c | | File Size: | 3321 | | Related CVE(s): | CVE-2007-0843 | | Last Modified: | Feb 23 21:45:58 2007 |
| MD5 Checksum: | 6c04fac47932131d4237f8749f08f6fa |
|
| /// File Name: |
02.16.07-1.txt |
Description:
|
iDefense Security Advisory 02.16.07 - TrendMicro's ServerProtect product uses a web interface which runs on port TCP 14942 to configure the product. This interface is protected with a user configurable password. Upon successful login, a cookie is set with the name 'splx_2376_info' and a valid session id as its value. The ServerProtect web application suffers from a design error vulnerability in its authorization checking routines. Attackers can gain full access to the web application by requesting any internal page while supplying their own 'splx_2376_info' cookie with an arbitrary value. iDefense has confirmed this vulnerability in Trend ServerProtect v1.3 for Linux. This vulnerability is not present in the Windows based versions of Server protect.
| | Author: | Damian Put | | Homepage: | http://www.idefense.com/ | | File Size: | 3317 | | Last Modified: | Feb 23 20:44:29 2007 |
| MD5 Checksum: | f95f0a15b78c940c6b57b3b8b6290278 |
|
| /// File Name: |
trendmicro-escalate.txt |
Description:
|
TmComm.sys is exposed through various Trend Micro products allowing for arbitrary code execution.
| | Author: | Ruben Santamarta | | File Size: | 3305 | | Last Modified: | Feb 13 01:01:46 2007 |
| MD5 Checksum: | 725a5887d0ddf9548ab8e3d77c976790 |
|
| /// File Name: |
sa24160.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Cisco PIX and ASA, which can be exploited by malicious users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24160/ | | File Size: | 3297 | | Last Modified: | Feb 16 01:49:41 2007 |
| MD5 Checksum: | 88da80e78af219f04541e5be599bad47 |
|
| /// File Name: |
sa24256.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for spamassassin. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24256/ | | File Size: | 3293 | | Last Modified: | Feb 27 11:54:22 2007 |
| MD5 Checksum: | 371d7e5cc5c449d03b8b8193d9847ece |
|
| /// File Name: |
n.runs-SA-2007.001.txt |
Description:
|
A flaw in an authorization component allows for unauthorized access to the Wireless LAN through a Captive Portal, VPN, and administrative access using either the web-based administration or the command line interface. This vulnerability affects all versions of the Aruba Controller beginning with version 2.3.
| | Homepage: | http://www.nruns.com/ | | File Size: | 3286 | | Last Modified: | Feb 14 15:02:05 2007 |
| MD5 Checksum: | 6980987bd144f6f1768b0d92349b39ab |
|
| /// File Name: |
02.07.07-1.txt |
Description:
|
iDefense Security Advisory 02.07.07 - Remote exploitation of a stack based buffer overflow vulnerability in RARLabs Unrar may allow an attacker to execute arbitrary code with the privileges of the user opening the archive. Unrar is prone to a stack based buffer overflow when processing specially crafted password protected archives. iDefense has confirmed the existence of this vulnerability in version 3.60 for Linux and 3.61 for Windows. Previous versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3258 | | Last Modified: | Feb 8 00:32:53 2007 |
| MD5 Checksum: | 03062898bdeb5529fa5123e2e1a4f2c1 |
|
| /// File Name: |
02.22.07-1.txt |
Description:
|
iDefense Security Advisory 02.22.07 - Remote exploitation of a buffer overflow vulnerability in VeriSign Inc.'s ConfigChk ActiveX Control could allow an attacker to execute arbitrary code within the security context of the victim. iDefense has confirmed the existence of this vulnerability within version 2.0.0.2 of VeriSign Inc's VSCnfChk.dll. All versions are suspected to be vulnerable.
| | Author: | David D. Rude II | | Homepage: | http://www.idefense.com/ | | File Size: | 3252 | | Last Modified: | Feb 23 21:48:48 2007 |
| MD5 Checksum: | df82f344e125c06ae77aa1dfeb7c8a42 |
|
| /// File Name: |
MDKSA-2007-046.txt |
Description:
|
Mandriva Security Advisory - Gnucash versions 2.0.4 and earlier allow local users to overwrite arbitrary files via a symlink attack on the (1) gnucash.trace, (2) qof.trace, and (3) qof.trace.[PID] temporary files.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3245 | | Related CVE(s): | CVE-2007-0007 | | Last Modified: | Feb 23 19:10:06 2007 |
| MD5 Checksum: | 8d141b4bf9618a03f0f4c24f90e06cd4 |
|
| /// File Name: |
sa24148.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24148/ | | File Size: | 3211 | | Last Modified: | Feb 19 17:55:20 2007 |
| MD5 Checksum: | 8ccd736f4fd7a919cddbb4a8db6bb32a |
|
| /// File Name: |
02.13.07-2.txt |
Description:
|
iDefense Security Advisory 02.13.07 - Remote exploitation of a design error within Hewlett-Packard's "SLSd" daemon could allow an attacker to execute privileges as the superuser. The problem specifically exists due to a design error within the "SLSd_daemon" RPC daemon that provides connectivity between the distributed systems. This daemon registers itself under the RPC PROGID of 536870913 or 351456, depending on the HP-UX version. By sending a specially crafted request, the daemon will write attacker supplied data to an arbitrary file as the superuser. iDefense has confirmed the existence of this vulnerability within the "SLSd_daemon" binary as shipped with HP-UX 11.11i and 10.20. All versions are suspected to be vulnerable.
| | Homepage: | http://www.idefense.com | | File Size: | 3194 | | Last Modified: | Feb 14 15:45:24 2007 |
| MD5 Checksum: | 941e1f5e13db359a50c195fe44b121cf |
|
| /// File Name: |
sa24089.txt |
Description:
|
Secunia Security Advisory - Several vulnerabilities have been reported in PHP. Some have unknown impacts, while others can be exploited to disclose potentially sensitive information or bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/24089/ | | File Size: | 3192 | | Last Modified: | Feb 12 19:06:32 2007 |
| MD5 Checksum: | 17ff3c24ff1b854192add6a09e38f5a5 |
|
| /// File Name: |
sa24144.txt |
Description:
|
Secunia Security Advisory - John Munther and Maxim Salomon have reported two vulnerabilities in Aruba Mobility Controller, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24144/ | | File Size: | 3189 | | Last Modified: | Feb 14 14:41:53 2007 |
| MD5 Checksum: | 33c7d0df0f0b89db2b35295513688624 |
|
| /// File Name: |
MDKSA-2007-032.txt |
Description:
|
Mandriva Linux Security Advisory - The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3124 | | Related CVE(s): | CVE-2007-0578 | | Last Modified: | Feb 5 23:21:54 2007 |
| MD5 Checksum: | f7025f13a7d027995e4910ea0d7b896c |
|
| /// File Name: |
glsa-200702-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200702-06 - An unspecified improper usage of an already freed context has been reported. Additionally, an assertion error could be triggered in the DNSSEC validation of some responses to type ANY queries with multiple RRsets. Versions less than 9.3.4 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3117 | | Related CVE(s): | CVE-2007-0493, CVE-2007-0494 | | Last Modified: | Feb 19 19:56:33 2007 |
| MD5 Checksum: | 10a59ea72a839fc8b8c79974e0e057a1 |
|
| /// File Name: |
sa24013.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for kdelibs. This fixes a weakness, which potentially can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/24013/ | | File Size: | 3111 | | Last Modified: | Feb 5 22:03:53 2007 |
| MD5 Checksum: | 3c7afb03a7bd6e507cc0f774bcf790a9 |
|
| /// File Name: |
sa24115.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Adobe ColdFusion MX, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/24115/ | | File Size: | 3079 | | Last Modified: | Feb 14 14:41:53 2007 |
| MD5 Checksum: | ad355d51f850d3c9eec227013ddc8e1e |
|
| /// File Name: |
sa24011.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24011/ | | File Size: | 3075 | | Last Modified: | Feb 5 22:03:43 2007 |
| MD5 Checksum: | 5c2c935a357afa03716007f371c9483e |
|
| /// File Name: |
sa24134.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP Serviceguard for Linux, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24134/ | | File Size: | 3060 | | Last Modified: | Feb 16 01:49:41 2007 |
| MD5 Checksum: | f2c3c807a52012b9af16de376fcb2490 |
|
| /// File Name: |
sa24262.txt |
Description:
|
Secunia Security Advisory - Some security issues have been reported in Cisco Unified IP Conference Station and IP Phones, which can be exploited by malicious people to access a vulnerable device.
| | Homepage: | http://secunia.com/advisories/24262/ | | File Size: | 3052 | | Last Modified: | Feb 22 21:32:16 2007 |
| MD5 Checksum: | e37e3d9bd2f070d6d56706456527a981 |
|
| /// File Name: |
sa24008.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Office, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24008/ | | File Size: | 3044 | | Last Modified: | Feb 4 23:30:20 2007 |
| MD5 Checksum: | 374ed8c95e256a8687c2e267e767a6b7 |
|
|
|
|
|