Section: .. / 0708-advisories /
| /// File Name: |
dsa-1354-1.txt |
Description:
|
Debian Security Advisory 1354-1 - It was discovered that an integer overflow in xpdf PDF viewer may lead to the execution of arbitrary code if a malformed PDF file is opened. gpdf includes a copy of the xpdf code and requires an update as well.
| | Homepage: | http://www.debian.org/security | | File Size: | 4892 | | Related CVE(s): | CVE-2007-3387 | | Last Modified: | Aug 14 05:56:53 2007 |
| MD5 Checksum: | 384f933d79e8b6c3baa52f221484a866 |
|
| /// File Name: |
bypassing-servlet.txt |
Description:
|
OWASP Stinger and Struts servlet input validation filters suffer from a bypass vulnerability.
| | Author: | Meder Kydyraliev | | Homepage: | http://o0o.nu/ | | File Size: | 5613 | | Last Modified: | Aug 14 05:55:50 2007 |
| MD5 Checksum: | 09b2efb70510c9796e3e1b76c2a7ee91 |
|
| /// File Name: |
drac-ssh.txt |
Description:
|
The SSH daemon embedded on the Dell DRAC4 is susceptible to a remote denial of service condition when being scanned.
| | Author: | ETES GmbH | | Homepage: | http://www.etes.de/ | | File Size: | 7236 | | Last Modified: | Aug 14 05:52:27 2007 |
| MD5 Checksum: | e876a09adfd0da1c650b1bc62b1ba3ae |
|
| /// File Name: |
infrant-password.txt |
Description:
|
Infrant ReadyNAS RAIDiator suffers from a weakly created root password vulnerability.
| | Author: | Brian Chapados, Felix Domke | | File Size: | 5377 | | Last Modified: | Aug 14 05:43:11 2007 |
| MD5 Checksum: | 0c74b0a2b708f456bc4a210b5d3d7162 |
|
| /// File Name: |
exv2decms.txt |
Description:
|
eXV2.de CMS versions 2.0.5 and below suffer from a cross site scripting vulnerability via an improperly sanitized cookie.
| | Author: | n-tier | | Homepage: | http://www.i-s-o.org/ | | File Size: | 1515 | | Last Modified: | Aug 14 05:38:50 2007 |
| MD5 Checksum: | 47c378c339ca2bc7258de4e40a417a83 |
|
| /// File Name: |
neuron-bypass.txt |
Description:
|
Neuron Blog version 1.1 suffers from administrative bypass and remote file upload vulnerabilities.
| | Author: | Rizgar | | File Size: | 1574 | | Last Modified: | Aug 14 05:36:47 2007 |
| MD5 Checksum: | cd2bc3b7fdeed7d2fa3fd4acbb1c8d2a |
|
| /// File Name: |
ircscripts.txt |
Description:
|
Various "now playing" scripts for various IRC clients allow for forced client side command execution on the IRC server in use.
| | Author: | Wouter Coekaerts | | File Size: | 2688 | | Last Modified: | Aug 14 05:32:22 2007 |
| MD5 Checksum: | f9b4a3b62651bbb9943d7bf8f20c4a3b |
|
| /// File Name: |
ircu-multi.txt |
Description:
|
Ircu, the open source IRC server, is susceptible to multiple vulnerabilities.
| | Author: | Wouter Coekaerts | | File Size: | 9913 | | Last Modified: | Aug 14 05:25:20 2007 |
| MD5 Checksum: | 866874bb6b3a4a534b530e1329122792 |
|
| /// File Name: |
glsa-200708-08.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200708-08 - The functions deletekey(), gpg_check_sign_pgp_mime() and gpg_recv_key() used in the SquirrelMail G/PGP encryption plugin do not properly escape user-supplied data. Versions less than 1.4.10a-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3125 | | Related CVE(s): | CVE-2005-1924, CVE-2006-4169 | | Last Modified: | Aug 14 03:33:17 2007 |
| MD5 Checksum: | 1db27123a22496b63e2abbb26675a784 |
|
| /// File Name: |
glsa-200708-07.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200708-07 - Lasse Karkkainen discovered that the function terminal_helper_execute() in file terminal-helper.c does not properly escape the URIs before processing. Versions less than 0.2.6_p25931 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2678 | | Related CVE(s): | CVE-2007-3770 | | Last Modified: | Aug 14 03:32:58 2007 |
| MD5 Checksum: | 8a06442279241f7b22bb7b0ca2368350 |
|
| /// File Name: |
glsa-200708-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200708-06 - hjp discovered an error when handling DNS query IDs which make them partially predictable. Steffen Ullrich discovered an error in the dn_expand() function which could lead to an endless loop. Versions less than 0.60 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2702 | | Related CVE(s): | CVE-2007-3377, CVE-2007-3409 | | Last Modified: | Aug 14 03:32:37 2007 |
| MD5 Checksum: | d3cd689f865ff74af2e3ef5120ccc28b |
|
| /// File Name: |
dsa-1353-1.txt |
Description:
|
Debian Security Advisory 1353-1 - It was discovered that an integer overflow in the BGP dissector of tcpdump, a powerful tool for network monitoring and data acquisition, may lead to the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 7350 | | Related CVE(s): | CVE-2007-3798 | | Last Modified: | Aug 14 02:35:58 2007 |
| MD5 Checksum: | ea0580ab837c6465107dbc49ab891f73 |
|
| /// File Name: |
MDKSA-2007-157.txt |
Description:
|
Mandriva Linux Security Advisory - The KDE HTML library (kdelibs), as used by Konqueror 3.5.5, does not properly parse HTML comments, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within a comment in a title tag, a related issue to CVE-2007-0478. Also affects kdelibs 3.5.6, as per KDE official advisory.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3112 | | Related CVE(s): | CVE-2007-0537 | | Last Modified: | Aug 14 02:24:12 2007 |
| MD5 Checksum: | e569c31ed38b297ccce25a7fa0be9234 |
|
| /// File Name: |
MDKSA-2007-156.txt |
Description:
|
Mandriva Linux Security Advisory - M Joonas Pihlaja discovered several vulnerabilities in the Imlib2 graphics library. The load() function of several of the Imlib2 image loaders does not check the width and height of an image before allocating memory. As a result, a carefully crafted image file can trigger a segfault when an application using Imlib2 attempts to view the image. The tga loader fails to bounds check input data to make sure the input data does not load outside the memory mapped region. The RLE decoding loops of the load() function in the tga loader does not check that the count byte of an RLE packet does not cause a heap overflow of the pixel buffer. The load() function of the pnm loader writes arbitrary length user data into a fixed size stack allocated buffer buf[] without bounds checking.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3971 | | Related CVE(s): | CVE-2006-4806, CVE-2006-4807, CVE-2006-4808, CVE-2006-4809 | | Last Modified: | Aug 14 02:19:17 2007 |
| MD5 Checksum: | d4af1e18a20cc3f1ee01cf9799dbf0e9 |
|
| /// File Name: |
sa26427.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in Microsoft Internet Explorer, which may expose FTP usernames and passwords.
| | Homepage: | http://secunia.com/advisories/26427/ | | File Size: | 2713 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 5341222c1116932f136495e49149fbe5 |
|
| /// File Name: |
sa26426.txt |
Description:
|
Secunia Security Advisory - Krystian Kloskowski has discovered a vulnerability in DirectX Media SDK, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/26426/ | | File Size: | 2772 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 769ee3c1f9c2e17936eaf969eea8523e |
|
| /// File Name: |
sa26424.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for squirrelmail. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/26424/ | | File Size: | 2108 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | bcbf59a2c5406e800cd62844c97d8d3c |
|
| /// File Name: |
sa26422.txt |
Description:
|
Secunia Security Advisory - vasodipandora has discovered a vulnerability in Php-Stats, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/26422/ | | File Size: | 2296 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 7c77d19451893bd43318a04f04b2bdd0 |
|
| /// File Name: |
sa26421.txt |
Description:
|
Secunia Security Advisory - ilkerkandemir has discovered a vulnerability in Family Connections, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/26421/ | | File Size: | 2346 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 0c70cc00080184b8ef0515a000ac35e8 |
|
| /// File Name: |
sa26420.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in IBM AIX, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/26420/ | | File Size: | 2542 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 9e027a5b2b5db872d335ecafd36d9b86 |
|
| /// File Name: |
sa26418.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for terminal. This fixes a security issue, which can be exploited by malicious people to inject shell commands.
| | Homepage: | http://secunia.com/advisories/26418/ | | File Size: | 2083 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 3fdba4964b7633681e13bb9b3d1cc3f0 |
|
| /// File Name: |
sa26417.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for Net-DNS. This fixes two vulnerabilities, which can be exploited by malicious people to poison the DNS cache or cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/26417/ | | File Size: | 2106 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 1e9fc13ad205e4201e4f90b8012375ce |
|
| /// File Name: |
sa26415.txt |
Description:
|
Secunia Security Advisory - Trustix has issued an update for multiple packages. This fixes some vulnerabilities, which potentially can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service) or to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/26415/ | | File Size: | 2751 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | fe6a81d9596e3cab043385fa79f551e9 |
|
| /// File Name: |
sa26414.txt |
Description:
|
Secunia Security Advisory - Kacper has discovered a vulnerability in Php Blue Dragon CMS, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/26414/ | | File Size: | 2541 | | Last Modified: | Aug 14 02:06:50 2007 |
| MD5 Checksum: | 755f0795c3ac98f58d03f02c92c65684 |
|
|
|
|
|