Section: .. / 0805-advisories /
| /// File Name: |
sa30398.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Ortro, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/30398/ | | File Size: | 2024 | | Last Modified: | May 28 17:49:52 2008 |
| MD5 Checksum: | a1274c942c7073ba149c9853769de303 |
|
| /// File Name: |
sa30403.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Creative Software AutoUpdate Engine ActiveX Control, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/30403/ | | File Size: | 2326 | | Last Modified: | May 28 17:49:52 2008 |
| MD5 Checksum: | beb3613bd70ebb19aefa72c33e44a124 |
|
| /// File Name: |
sa30408.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in spamdyke, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/30408/ | | File Size: | 2156 | | Last Modified: | May 28 17:49:52 2008 |
| MD5 Checksum: | 676d1de89c2459495d010f8f174890bc |
|
| /// File Name: |
sa30409.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Motorola RAZR, which can be exploited by malicious people to compromise a vulnerable device.
| | Homepage: | http://secunia.com/advisories/30409/ | | File Size: | 2242 | | Last Modified: | May 28 17:49:52 2008 |
| MD5 Checksum: | 8128fa9d49005f597ddba03059626a78 |
|
| /// File Name: |
sa30410.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in EMC AlphaStor, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/30410/ | | File Size: | 2767 | | Last Modified: | May 28 17:49:52 2008 |
| MD5 Checksum: | 7b9bf84e19e2fbd3f404eab3c531d535 |
|
| /// File Name: |
secadv_20080528.txt |
Description:
|
OpenSSL Security Advisory - Two moderate severity security flaws have been fixed in OpenSSL 0.9.8h. Testing using the Codenomicon TLS test suite discovered a flaw in the handling of server name extension data in OpenSSL 0.9.8f and OpenSSL 0.9.8g. Testing using the Codenomicon TLS test suite discovered a flaw if the 'Server Key exchange message' is omitted from a TLS handshake in OpenSSL 0.9.8f and OpenSSL 0.9.8g.
| | Homepage: | http://www.openssl.org/ | | Related File: | openssl-0.9.8h.tar.gz | | File Size: | 1525 | | Related CVE(s): | CVE-2008-0891, CVE-2008-1672 | | Last Modified: | May 28 11:04:35 2008 |
| MD5 Checksum: | 8ff6fbfb291984e8b98a3897d4666108 |
|
| /// File Name: |
dsa-1589-1.txt |
Description:
|
Debian Security Advisory 1589-1 - It was discovered that libxslt, an XSLT processing runtime library, could be coerced into executing arbitrary code via a buffer overflow when an XSL style sheet file with a long XSLT "transformation match" condition triggered a large number of steps.
| | Homepage: | http://www.debian.org/security | | File Size: | 11865 | | Related CVE(s): | CVE-2008-1767 | | Last Modified: | May 28 10:43:16 2008 |
| MD5 Checksum: | 7b5f587bc9fed104901ba5bf13c35d8a |
|
| /// File Name: |
sa30360.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in IBM AIX, which can be exploited by malicious people to disclose system information.
| | Homepage: | http://secunia.com/advisories/30360/ | | File Size: | 2550 | | Last Modified: | May 27 21:50:36 2008 |
| MD5 Checksum: | 3e5131371ca94fa4cd937d9fc6968b62 |
|
| /// File Name: |
sa30357.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/30357/ | | File Size: | 2168 | | Last Modified: | May 27 19:45:33 2008 |
| MD5 Checksum: | 2a27257db7829b7e936c480972f8d9cf |
|
| /// File Name: |
ZDI-08-033.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable Motorola RAZR firmware based cell phones. User interaction is required to exploit this vulnerability in that the target must accept a malicious image sent via MMS. The specific flaw exists in the JPEG thumbprint component of the EXIF parser. A corrupt JPEG received via MMS can cause a memory corruption which can be leveraged to execute arbitrary code on the affected device.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3211 | | Last Modified: | May 27 19:45:22 2008 |
| MD5 Checksum: | 127b1780fcc83af434196ea8d141b60e |
|
| /// File Name: |
05.27.08-2.txt |
Description:
|
iDefense Security Advisory 05.27.08 - Remote exploitation of an arbitrary command execution vulnerability in EMC Corp.'s AlphaStor could allow an attacker to execute arbitrary code with SYSTEM privileges. AlphaStor consists of multiple applications, one of which is the Library Manager. The Library Manager is used to manage the replacement of disk drives in distributed locations. The Manager consists of a single process, the "robotd" process, that listens on TCP port 3500 for incoming connections. The Library Manager is prone to an arbitrary command execution vulnerability. When sent a specific request, "robotd" will use a string from the packet as a command to execute on the system via the CreateProcess() function. This allows an attacker to run arbitrary programs on the host with SYSTEM privileges. iDefense has confirmed the existence of this vulnerability in AlphaStor version 3.1 SP1 for Windows. Previous versions, as well as versions for other platforms, may also be affected.
| | Author: | Stephen Fewer | | Homepage: | http://www.idefense.com/ | | File Size: | 3614 | | Related CVE(s): | CVE-2008-2157 | | Last Modified: | May 27 19:44:27 2008 |
| MD5 Checksum: | 6c8ff6e0b7f32b25ed4398d7091c900b |
|
| /// File Name: |
05.27.08-1.txt |
Description:
|
iDefense Security Advisory 05.27.08 - Remote exploitation of multiple stack based buffer overflow vulnerabilities in EMC Corp.'s AlphaStor could allow an attacker to execute arbitrary code with SYSTEM privileges. AlphaStor consists of multiple applications, one of which is the Server Agent. The Server Agent is one of the core components of AlphaStor, and is used to initiate disk management requests. The Agent consists of several processes, one of which is the AlphaStor Command Line Interface process. This process listens on TCP port 41025, and is prone to multiple stack based buffer overflow vulnerabilities. iDefense has confirmed the existence of these vulnerabilities in AlphaStor version 3.1 SP1 for Windows. Previous versions, as well as versions for other platforms, may also be affected.
| | Author: | Stephen Fewer, Sean Larsson | | Homepage: | http://www.idefense.com/ | | File Size: | 3349 | | Related CVE(s): | CVE-2008-2158 | | Last Modified: | May 27 19:42:17 2008 |
| MD5 Checksum: | f0e331dc95a7505a4903764fd5697dca |
|
| /// File Name: |
sa30289.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Cisco Voice Portal (CVP), which can be exploited by malicious users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/30289/ | | File Size: | 2487 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 635aeff26b8151ddd4ff07d9d94e4d8d |
|
| /// File Name: |
sa30316.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Cisco Service Control Engine, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/30316/ | | File Size: | 2880 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | a5715e686c37a2acc6b169a940479077 |
|
| /// File Name: |
sa30322.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Cisco IOS, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/30322/ | | File Size: | 2368 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 800b57d146f3765ca053aefd8d78e4d0 |
|
| /// File Name: |
sa30329.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for compiz. This fixes a security issue, which can be exploited by malicious people with physical access to a system to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/30329/ | | File Size: | 2183 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 42b0196d19a573de048e116aa80a3c0d |
|
| /// File Name: |
sa30334.txt |
Description:
|
Secunia Security Advisory - Digital Security Research Group has reported a vulnerability in SAP Web Application Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/30334/ | | File Size: | 2246 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 437ac5b834edf64990a1b48c73164d8e |
|
| /// File Name: |
sa30336.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Trillian, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/30336/ | | File Size: | 2849 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 36ae529480feddfa4f3186a3a22f1361 |
|
| /// File Name: |
sa30339.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for setroubleshoot. This fixes two security issues, which can be exploited by malicious, local users to conduct script insertion attacks and to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/30339/ | | File Size: | 2626 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 5e99cab2088422758f365660ad3428be |
|
| /// File Name: |
sa30342.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for dovecot. This fixes a weakness and a security issue, which can be exploited by malicious users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/30342/ | | File Size: | 2080 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 1ec429c4c5959d23cf50e2b5de3f5181 |
|
| /// File Name: |
sa30351.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for mysql. This fixes some security issues and vulnerabilities, which can be exploited by malicious users to cause a DoS (Denial of Service), bypass certain security restrictions, and gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/30351/ | | File Size: | 2484 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | 60fff4de48babbdf6ba7e9142b97210d |
|
| /// File Name: |
sa30371.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in PCPIN Chat, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/30371/ | | File Size: | 2154 | | Last Modified: | May 27 19:33:44 2008 |
| MD5 Checksum: | b3c842a145d414558e36072fbb2af7b3 |
|
| /// File Name: |
dsa-1588-1.txt |
Description:
|
Debian Security Advisory 1588-1 - Johannes Bauer discovered an integer overflow condition in the hrtimer subsystem on 64-bit systems. This can be exploited by local users to trigger a denial of service (DoS) by causing the kernel to execute an infinite loop. Jan Kratochvil reported a local denial of service condition that permits local users on systems running the amd64 flavor kernel to cause a system crash. Paul Harks discovered a memory leak in the Simple Internet Transition (SIT) code used for IPv6 over IPv4 tunnels. This can be exploited by remote users to cause a denial of service condition. David Miller and Jan Lieskovsky discovered issues with the virtual address range checking of mmaped regions on the sparc architecture that may be exploited by local users to cause a denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 34460 | | Related CVE(s): | CVE-2007-6712, CVE-2008-1615, CVE-2008-2136, CVE-2008-2137 | | Last Modified: | May 27 19:33:33 2008 |
| MD5 Checksum: | 948ffa8231b344838e89445e5372dd29 |
|
| /// File Name: |
SSRT071454-2.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified HP-UX running the useradd(1M) command. The vulnerability could be exploited locally to allow unauthorized access to directories or files.
| | Homepage: | http://www.hp.com/ | | File Size: | 7063 | | Related CVE(s): | CVE-2008-1660 | | Last Modified: | May 27 19:32:07 2008 |
| MD5 Checksum: | 6a15f7701a6c7e29bf912a9181f066d6 |
|
|
|
|
|