Section: .. / 0704-advisories /
| /// File Name: |
04.02.07-1.txt |
Description:
|
iDefense Security Advisory 04.02.07 - Remote exploitation of a buffer overflow vulnerability in an ActiveX control installed by Hewlett-Packard Mercury Quality Center could allow for the execution of arbitrary code. iDefense has confirmed this vulnerability in the control that is installed with the 9.0 version of Hewlett-Packard Mercury Quality Center. The vulnerable ActiveX control is version 9.1.0.4353.
| | Author: | Eric Detoisien, Titon, Ri0t | | Homepage: | http://www.idefense.com/ | | File Size: | 3376 | | Last Modified: | Apr 3 02:53:44 2007 |
| MD5 Checksum: | 05cb3a803519f121f8fa5bf004dd3404 |
|
| /// File Name: |
03.31.07-1.txt |
Description:
|
iDefense Security Advisory 03.31.07 - Remote exploitation of several buffer overflow vulnerabilities in ImageMagick, as included in various vendors' operating system distributions, allows attackers to execute arbitrary code with the credentials used for image processing. An integer overflow exists ImageMagick's handling of DCM (Digital Imaging and Communications in Medicine) format files which allows an attacker to cause a heap-based buffer overflow. This vulnerability specifically exists in the ReadDCMImage() function. Two integer overflows exists ImageMagick's handling of XWD (X Windows Dump) format files that allows an attacker to cause a heap-based buffer overflow. The vulnerabilities specifically exist in the ReadXWDImage() function. An integer overflow could occur when calculating the amount of memory to allocate for the 'colors' or 'comment' field. iDefense has confirmed the existence of these vulnerabilities in ImageMagick version 6.3.x. Additionally, the source code for versions 6.3.1, 6.3.2, 6.3.3-3 and 6.2.9 contain the affected code. It is suspected that earlier versions of ImageMagick are also vulnerable.
| | Homepage: | http://www.idefense.com/ | | File Size: | 4032 | | Last Modified: | Apr 3 02:52:07 2007 |
| MD5 Checksum: | e3db8efadfc4cefbd2fd80dafc869eba |
|
| /// File Name: |
apop-protocol.txt |
Description:
|
A security vulnerability has been discovered in the APOP protocol that is related to the recent collision attacks by Wang and al. against MD5. Using the man in the middle setting, one can recover the first characters of the password with a few hundred authentications from the client.
| | Author: | Gaetan Leurent | | File Size: | 3943 | | Related CVE(s): | CVE-2007-1558 | | Last Modified: | Apr 3 02:50:55 2007 |
| MD5 Checksum: | 1da7794eae5e8de66bf5e76901e835aa |
|
| /// File Name: |
SSRT061177.txt |
Description:
|
HP Security Bulletin - A potential vulnerability has been identified with HP OpenView Network Node Manager (OV NNM). This vulnerability could be exploited remotely to gain unauthorized access to certain facilities of the NNM server.
| | Homepage: | http://www.hp.com | | File Size: | 8604 | | Last Modified: | Apr 3 02:48:43 2007 |
| MD5 Checksum: | eee11b60a8ee7a3f80449afa18e42d73 |
|
| /// File Name: |
dsa-1274-1.txt |
Description:
|
Debian Security Advisory 1274-1 - An integer underflow bug has been found in the file_printf function in file, a tool to determine file types based analysis of file content. The bug could allow an attacker to execute arbitrary code by inducing a local user to examine a specially crafted file that triggers a buffer overflow.
| | Homepage: | http://www.debian.org/security | | File Size: | 16380 | | Related CVE(s): | CVE-2007-1536 | | Last Modified: | Apr 3 02:47:46 2007 |
| MD5 Checksum: | 46d59b1c361fb254128ece808b24bfe2 |
|
| /// File Name: |
sa24734.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for gpg. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions when applications use GnuPG in an insecure manner.
| | Homepage: | http://secunia.com/advisories/24734/ | | File Size: | 5910 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | 9a5f85f515134d1b284388e1c5e47696 |
|
| /// File Name: |
sa24732.txt |
Description:
|
Secunia Security Advisory - D. Matscheko has reported a security issue in Apache Tomcat, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/24732/ | | File Size: | 2459 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | cc7d4b980783801963e7bca4f3d50124 |
|
| /// File Name: |
sa24714.txt |
Description:
|
Secunia Security Advisory - TippingPoint Security Research Team has discovered a vulnerability in America Online, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24714/ | | File Size: | 2502 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | ac28471127e35bc7c52f5618f7790e3f |
|
| /// File Name: |
sa24701.txt |
Description:
|
Secunia Security Advisory - Crackers_Child has discovered a vulnerability in BT-Sondage, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24701/ | | File Size: | 2271 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | 0dc8aff2dba1c668f1a774fd760b8a8a |
|
| /// File Name: |
sa24692.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP Mercury Quality Center, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24692/ | | File Size: | 2671 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | fff4d2c2b8e614d9e7eecd1d5095347a |
|
| /// File Name: |
sa24683.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in Hitachi products, which potentially can be exploited by malicious people to disclose certain sensitive information or bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/24683/ | | File Size: | 2961 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | be9d96f1f1cee6c2e4d5de212f1f8223 |
|
| /// File Name: |
sa24677.txt |
Description:
|
Secunia Security Advisory - Matousec has discovered a vulnerability in Symantec Norton Personal Firewall 2006, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24677/ | | File Size: | 2510 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | fc741402ce2e5499c6f14c485444d969 |
|
| /// File Name: |
sa24662.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24662/ | | File Size: | 1993 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | 1760a0bf8f5c653c8f067de0b3da8337 |
|
| /// File Name: |
sa24660.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24660/ | | File Size: | 1990 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | d9732c2982dc21a2d1e1a2aedd9114f2 |
|
| /// File Name: |
sa24624.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Mozilla 1.7 for Sun Solaris, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24624/ | | File Size: | 2548 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | abd49a6468af189a4254783fd0399af2 |
|
| /// File Name: |
sa24608.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for file. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24608/ | | File Size: | 1995 | | Last Modified: | Apr 3 01:13:40 2007 |
| MD5 Checksum: | 5c1ab7afef4e8f08c1262722cba203bb |
|
| /// File Name: |
BTP00000P002NF.txt |
Description:
|
Symantec Norton Personal Firewall hooks many functions in SSDT and in at least two cases it fails to validate arguments that come from the user mode.
| | Homepage: | http://www.matousec.com/ | | Related Exploit: | BTP00000P002NF.zip | | File Size: | 1347 | | Last Modified: | Apr 3 01:11:56 2007 |
| MD5 Checksum: | 651ce3be1613c437460c49ad041b7923 |
|
|
|
|
|