Section: .. / 0704-advisories /
| /// File Name: |
cosign-vuln-2007-002.txt |
Description:
|
A remotely exploitable vulnerability has been discovered that allows attackers who are already authenticated via cosign to assume the identity of an arbitrary user on a cosign-protected service. Organizations that run their own central cosign weblogin server should upgrade their weblogin server to cosign 2.0.2a, cosign 1.9.4b, or back-port the patch available at http://weblogin.org/download.html to the version of cosign they are running.
| | Author: | Jon Oberheide | | File Size: | 10551 | | Last Modified: | Apr 12 21:05:54 2007 |
| MD5 Checksum: | 57cbaedc206501891415eefa6f3dbc58 |
|
| /// File Name: |
MDKSA-2007-077.txt |
Description:
|
Mandriva Linux Security Advisory - A vulnerability was found in the username handling of the MIT krb5 telnet daemon. A remote attacker that could access the telnet port of a target machine could login as root without requiring a password. Buffer overflows in the kadmin server daemon were discovered that could be exploited by a remote attacker able to access the KDC. Successful exploitation could allow for the execution of arbitrary code with the privileges of the KDC or kadmin server processes. Finally, a double-free flaw was discovered in the GSSAPI library used by the kadmin server daemon, which could lead to a denial of service condition or the execution of arbitrary code with the privileges of the KDC or kadmin server processes.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 10113 | | Related CVE(s): | CVE-2007-0956, CVE-2007-0957, CVE-2007-1216 | | Last Modified: | Apr 5 08:43:17 2007 |
| MD5 Checksum: | 1a9263cf88baf98da32dc273dc1ec498 |
|
| /// File Name: |
sa24699.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for qt3 and qt4. This fixes a vulnerability, which potentially can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/24699/ | | File Size: | 9511 | | Last Modified: | Apr 5 07:27:45 2007 |
| MD5 Checksum: | f91f3b99ee3ed05a481fb3aa546f8b44 |
|
| /// File Name: |
SSRT071365.txt |
Description:
|
HP Security Bulletin - Various potential security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Some of these vulnerabilities may be pertinent to the SMA, please check the table in the Resolution section of this Security Bulletin.
| | Homepage: | http://www.hp.com | | File Size: | 9488 | | Last Modified: | Apr 23 05:36:37 2007 |
| MD5 Checksum: | d35a186f94ca44dd8214355b056fa3a6 |
|
| /// File Name: |
MDKSA-2007-074.txt |
Description:
|
Mandriva Linux Security Advisory - Andreas Nolden discover a bug in qt3, where the UTF8 decoder does not reject overlong sequences, which can cause "/../" injection or (in the case of konqueror) a " | |
|