Section: .. / 0703-advisories /
| /// File Name: |
MDKSA-2007-071.txt |
Description:
|
Mandriva Linux Security Advisory - Integer overflow in X MultiMedia System (xmms) 1.2.10, and possibly other versions, allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which triggers memory corruption. Integer underflow in X MultiMedia System (xmms) 1.2.10 allows user-assisted remote attackers to execute arbitrary code via crafted header information in a skin bitmap image, which results in a stack- based buffer overflow.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 4030 | | Related CVE(s): | CVE-2007-0653, CVE-2007-0654 | | Last Modified: | Apr 2 23:32:09 2007 |
| MD5 Checksum: | 342b18e956fca5df199d1e16e3964f76 |
|
| /// File Name: |
MDKSA-2007-072.txt |
Description:
|
Mandriva Linux Security Advisory - The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers, perform a proxied port scan, or obtain sensitive information by specifying an alternate server address in a FTP PASV command.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 5071 | | Related CVE(s): | CVE-2007-1564 | | Last Modified: | Apr 2 23:32:36 2007 |
| MD5 Checksum: | e80664e938b846e1b7aa9f3fb3ee6d61 |
|
| /// File Name: |
MDKSA-2007-073.txt |
Description:
|
Mandriva Linux Security Advisory - Stack-based buffer overflow in the StarCalc parser in OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary code via a crafted document. OpenOffice.org (OOo) Office Suite allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a prepared link in a crafted document.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 21570 | | Related CVE(s): | CVE-2007-0238, CVE-2007-0239 | | Last Modified: | Apr 2 23:43:55 2007 |
| MD5 Checksum: | cc4084a02836a4fc46679d725b688a54 |
|
| /// File Name: |
minigzip.txt |
Description:
|
Python version 2.5 (Modules/zlib) minigzip suffers from a local buffer overflow vulnerability.
| | Author: | starcadi | | File Size: | 692 | | Last Modified: | Mar 20 04:27:50 2007 |
| MD5 Checksum: | 966ec760b9fb7249d4fae827165b099f |
|
| /// File Name: |
ms0713.txt |
Description:
|
The original MS07-012 patch was released to fix an issue in the MFC library MFC42u.dll. The issue was the result of MS not taking into account that a TCHAR string is actually twice as big as its CHAR counterparts. To fix this, the patch readjusted the nMaxCount variable to half of its original value in the GetMenuStringW(...) call. Unfortunately, GetMenuStringW will null terminate a long string at the end adding two additional characters to the string. This gives a returned string of (nMaxCount*2) + 2 bytes in size.
| | Author: | Greg Sinclair | | File Size: | 3021 | | Last Modified: | Mar 20 06:45:12 2007 |
| MD5 Checksum: | e483bae6d51075d3fc6bbbdc4adb0750 |
|
| /// File Name: |
msfilemanagement.txt |
Description:
|
Article discussing file management security issues in Microsoft Windows Vista/2003/XP/2000.
| | Author: | 3APA3A | | Homepage: | http://securityvulns.com/ | | File Size: | 9725 | | Last Modified: | Mar 9 04:23:22 2007 |
| MD5 Checksum: | 60fcecd6b876c994b1fd5658afc80a4f |
|
| /// File Name: |
mshtmldll.txt |
Description:
|
It appears that Microsoft Internet Explorer 6 suffers from some denial of services vulnerabilities that result in a browser crash.
| | Author: | SaiedHacker | | File Size: | 10751 | | Last Modified: | Mar 21 04:00:23 2007 |
| MD5 Checksum: | 99422e45796e2bcc4c787f37eba9f016 |
|
| /// File Name: |
MU-200703-01.txt |
Description:
|
Asterisk crashes when handed an otherwise valid request message but with no URI and no SIP-version in the request-line of the message. Asterisk versions 1.2.15 and 1.4.0, along with prior versions, are affected.
| | Author: | Mu Security research team | | Homepage: | http://labs.musecurity.com/ | | File Size: | 2191 | | Last Modified: | Mar 9 03:55:31 2007 |
| MD5 Checksum: | 6121b1df2013a98c7d28e32af079e4af |
|
| /// File Name: |
n.runs-SA-2007.003.txt |
Description:
|
PHProjekt version 5.2.0 suffers from a SQL injection vulnerability.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3742 | | Last Modified: | Mar 20 04:02:16 2007 |
| MD5 Checksum: | 1b6f4d8350d2713a6ef18e077f149916 |
|
| /// File Name: |
n.runs-SA-2007.004.txt |
Description:
|
PHProjekt version 5.2.0 suffers from cross site scripting and filter evasion vulnerabilities.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3786 | | Last Modified: | Mar 20 04:03:07 2007 |
| MD5 Checksum: | 18ee3380c9805f3b32320c501dee4051 |
|
| /// File Name: |
n.runs-SA-2007.005.txt |
Description:
|
PHProjekt version 5.2.0 suffers from a cross site request forgery vulnerability.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3784 | | Last Modified: | Mar 20 04:03:59 2007 |
| MD5 Checksum: | 6279521fc77b42d5bd00fcb54de756c9 |
|
| /// File Name: |
n.runs-SA-2007.006.txt |
Description:
|
PHProjekt version 5.2.0 suffers from a privilege escalation vulnerability.
| | Author: | Alexios Fakos | | Homepage: | http://www.nruns.com/ | | File Size: | 3392 | | Last Modified: | Mar 20 04:04:46 2007 |
| MD5 Checksum: | 66dd131430a93cb420337e9ab18cbb4c |
|
| /// File Name: |
NB07-07.txt |
Description:
|
The Takebishi Electric DeviceXplorer HIDIC OPC server has security vulnerabilities, allowing an attacker with access to the OPC interface to arbitrarily read and write the process memory, potentially leading to the execution of attacker-provided code.
| | Author: | Lluis Mora, Xavier Panadero | | Homepage: | http://www.neutralbit.com/ | | File Size: | 2282 | | Related CVE(s): | CVE-2007-1319 | | Last Modified: | Mar 24 02:45:28 2007 |
| MD5 Checksum: | 0649ab35773a8250050b3c9eab7ae6f8 |
|
| /// File Name: |
NB07-08.txt |
Description:
|
The Takebishi Electric DeviceXplorer MELSEC OPC server has security vulnerabilities, allowing an attacker with access to the OPC interface to arbitrarily read and write the process memory, potentially leading to the execution of attacker-provided code.
| | Author: | Lluis Mora, Xavier Panadero | | Homepage: | http://www.neutralbit.com/ | | File Size: | 2287 | | Related CVE(s): | CVE-2007-1319 | | Last Modified: | Mar 24 02:46:19 2007 |
| MD5 Checksum: | 88be9f99d72c0a33a1919d31773a2541 |
|
| /// File Name: |
NB07-09.txt |
Description:
|
The Takebishi Electric DeviceXplorer FA-M3 OPC server has security vulnerabilities, allowing an attacker with access to the OPC interface to arbitrarily read and write the process memory, potentially leading to the execution of attacker-provided code.
| | Author: | Lluis Mora, Xavier Panadero | | Homepage: | http://www.neutralbit.com/ | | File Size: | 2280 | | Related CVE(s): | CVE-2007-1319 | | Last Modified: | Mar 24 02:47:12 2007 |
| MD5 Checksum: | 0a1cfe46a539160447f7eb1f134b0baa |
|
| /// File Name: |
NB07-10.txt |
Description:
|
The Takebishi Electric DeviceXplorer MODBUS OPC server has security vulnerabilities, allowing an attacker with access to the OPC interface to arbitrarily read and write the process memory, potentially leading to the execution of attacker-provided code.
| | Author: | Lluis Mora, Xavier Panadero | | Homepage: | http://www.neutralbit.com/ | | File Size: | 2287 | | Related CVE(s): | CVE-2007-1319 | | Last Modified: | Mar 24 02:47:59 2007 |
| MD5 Checksum: | 757597d4518f28d811e515b48ae9b4b0 |
|
| /// File Name: |
NB07-17.txt |
Description:
|
The Takebishi Electric DeviceXplorer SYSMAC OPC server has security vulnerabilities, allowing an attacker with access to the OPC interface to arbitrarily read and write the process memory, potentially leading to the execution of attacker-provided code.
| | Author: | Lluis Mora, Xavier Panadero | | Homepage: | http://www.neutralbit.com/ | | File Size: | 2287 | | Related CVE(s): | CVE-2007-1319 | | Last Modified: | Mar 24 02:48:39 2007 |
| MD5 Checksum: | 0f21a39cc66efbf7426bfb8ca22ee0d8 |
|
| /// File Name: |
NB07-22.txt |
Description:
|
The NetxEIB OPC server has security vulnerabilities, allowing an attacker with access to the OPC interface to arbitrarily read and write the process memory, potentially leading to the execution of attacker-provided code.
| | Author: | Lluis Mora, Xavier Panadero | | Homepage: | http://www.neutralbit.com/ | | File Size: | 2408 | | Related CVE(s): | CVE-2007-1313 | | Last Modified: | Mar 24 02:44:15 2007 |
| MD5 Checksum: | 6d6d7eeb6a4d1657c4f2dd4ebd16ac5c |
|
| /// File Name: |
ndistapi.txt |
Description:
|
The NDISTAPI.sys kernel-mode component of Microsoft Windows XP SP2 and Microsoft Windows 2003 Server SP1 is exposed to unprivileged users.
| | Author: | Ruben Santamarta | | Homepage: | http://www.reversemode.com/ | | File Size: | 7516 | | Last Modified: | Mar 20 16:36:25 2007 |
| MD5 Checksum: | 5b2a01374c341e50b8d84313b4532179 |
|
| /// File Name: |
NETRAGARD-20070316.txt |
Description:
|
Netragard, L.L.C Advisory - An exploitable vulnerability exists in FrontBase that can be used to gain NT AUTHORITY\SYSTEM or root privileges on an affected system. FrontBase versions 4.2.7 and below are affected.
| | Author: | Kevin Finisterre, Adriel T. Desautels | | Homepage: | http://www.netragard.com/html/recent_research.html | | File Size: | 9460 | | Last Modified: | Mar 20 16:07:44 2007 |
| MD5 Checksum: | 0f094283a3727f1618c74cdc736e5348 |
|
| /// File Name: |
netrekfs.txt |
Description:
|
Netrek versions 2.12.0 and below suffer from a format string vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | netrekfs.zip | | File Size: | 1973 | | Last Modified: | Mar 8 23:25:54 2007 |
| MD5 Checksum: | 7c7c823ba8ce3115f39bad50638c6691 |
|
| /// File Name: |
Norton-symtdi.txt |
Description:
|
Norton insufficiently protects its driver \Device\SymEvent against a manipulation by malicious applications and it fails to validate its input buffer.
| | Homepage: | http://www.matousec.com/ | | Related Exploit: | BTP00012P002NF.zip | | File Size: | 1260 | | Last Modified: | Mar 20 05:52:15 2007 |
| MD5 Checksum: | d9c914d2896555ba0270ede4ad91d5f3 |
|
| /// File Name: |
notgood.txt |
Description:
|
Apparently, the phishing protection provided in Firefox 2.0.0.3 and Opera 9.10 fails to take iframes into account.
| | Author: | nsp | | File Size: | 759 | | Last Modified: | Mar 29 08:18:46 2007 |
| MD5 Checksum: | 2897825f94a26911417c4e233687db1e |
|
| /// File Name: |
oem-redir.txt |
Description:
|
The Oracle Enterprise Manager suffers from a redirection flaw that may assist in phishing attacks.
| | Author: | Handrix | | Homepage: | http://www.morx.org/ | | File Size: | 2002 | | Last Modified: | Mar 27 05:29:55 2007 |
| MD5 Checksum: | 033d99bac182853107210e8d1fa68133 |
|
| /// File Name: |
phpftp.txt |
Description:
|
PHP version 5.1.6 is susceptible to a CRLF injection vulnerability via its ftp function.
| | Author: | fangxiaodun | | File Size: | 877 | | Last Modified: | Mar 24 02:55:38 2007 |
| MD5 Checksum: | 5bc360bc13704702828042809a3e986a |
|
|
|
|
|