[SECURITY] [DSA 1871-1] New wordpress packages fix several vulnerabilities

2009-08-24 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1871-1 secur...@debian.org http://www.debian.org/security/ Steffen Joeris August 23, 2009

Local Kernel Buffer Overflow vulnerability in Avast!

2009-08-24 Thread s . leberre
//- Advisory Program : avast! 4.8.1335 Professional Homepage : http://www.avast.com Discovery: 2009/07/29 Author Contacted : 2009/07/31 Found by : Heurs This Advisory: Heurs Contact : he...@ghostsinthstack.org, s.lebe...@sysdream.com

FreeBSD = 6.1 kqueue() NULL pointer dereference

2009-08-24 Thread Przemyslaw Frasunek
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 FreeBSD = 6.1 suffers from classical check/use race condition on SMP systems in kevent() syscall, leading to kernel mode NULL pointer dereference. It can be triggered by spawning two threads: 1st thread looping on open() and close() syscalls, and the

[ MDVSA-2009:211 ] expat

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:211 http://www.mandriva.com/security/

[ MDVSA-2009:212 ] python

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:212 http://www.mandriva.com/security/

Radvision's Scopia Cross Site Scripting Vulnerabilities

2009-08-24 Thread Francesco Bianchino
Radvision's Scopia Cross Site Scripting Vulnerabilities *** Author: Francesco Bianchino contact: f.bianchino at gmail dot com Product: Radvision's Scopia Version: 5.7 Vendor Site: http://www.radvision.com Product

[ MDVSA-2009:212 ] python

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:212 http://www.mandriva.com/security/

CoolPreviews - Firefox Extension - Chrome Privileged Code Injection

2009-08-24 Thread Roberto Suggi Liverani
(, ) (, . `.' ) ('.', ). , ('. ( ) ( (_,) .`), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( _ ) Y Y \ /__ /\___|__ / \___ /|__|_| / \/ \/.-.\/ \/:wq

[ MDVSA-2009:213 ] wxgtk

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:213 http://www.mandriva.com/security/

WM Downloader (.Smi/ .Ram/ .pls/ .smil/ .wax/ .wpl File) Local Buffer Overflow Exploit

2009-08-24 Thread the_3dit0r
#!/usr/bin/perl #[+] Bug : WM Downloader (.Smi/ .Ram/ .pls/ .smil/ .wax/ .wpl File) Local Buffer Overflow Exploit #[+] Author : the_Edit0r # Contact me : the_3dit0r[at]Yahoo[dot]coM #[+] Greetz to all my friends #[+] Tested on: Windows XP Pro SP3 #[+] Big thnx: Expl0iters.ir * Anti-security.ir

[ MDVSA-2009:213 ] wxgtk

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:213 http://www.mandriva.com/security/

[ MDVSA-2009:214 ] python-celementtree

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:214 http://www.mandriva.com/security/

[ MDVSA-2009:215 ] audacity

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:215 http://www.mandriva.com/security/

[ MDVSA-2009:216 ] mozilla-thunderbird

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:216 http://www.mandriva.com/security/

[ MDVSA-2009:217 ] mozilla-thunderbird

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:217 http://www.mandriva.com/security/

Feed Sidebar Firefox Extension - Privileged Code Injection

2009-08-24 Thread Nick Freeman
(, ) (, . `.' ) ('.', ). , ('. ( ) ( (_,) .`), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( _ ) Y Y \ /__ /\___|__ / \___ /|__|_| / \/ \/.-.\/ \/:wq

ScribeFire Firefox Extension - Privileged Code Injection

2009-08-24 Thread Nick Freeman
(, ) (, . `.' ) ('.', ). , ('. ( ) ( (_,) .`), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( _ ) Y Y \ /__ /\___|__ / \___ /|__|_| / \/ \/.-.\/ \/:wq

WizzRSS Firefox Extension - Privileged Code Injection

2009-08-24 Thread Nick Freeman
(, ) (, . `.' ) ('.', ). , ('. ( ) ( (_,) .`), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( _ ) Y Y \ /__ /\___|__ / \___ /|__|_| / \/ \/.-.\/ \/:wq

Update Scanner - Firefox Extension - Chrome Privileged Code Injection

2009-08-24 Thread Roberto Suggi Liverani
(, ) (, . `.' ) ('.', ). , ('. ( ) ( (_,) .`), ) _ _, / _/ / _ \ _ \ \==/ /_\ \ _/ ___\/ _ \ / \ / \/ |\\ \__( _ ) Y Y \ /__ /\___|__ / \___ /|__|_| / \/ \/.-.\/ \/:wq

DoS vulnerability in Google Chrome

2009-08-24 Thread MustLive
Hello Bugtraq! I want to warn you about Denial of Service vulnerability in Google Chrome. This vulnerability I found already at 26.12.2008. Attack belongs to type of blocking DoS and DoS via resources consumption (http://websecurity.com.ua/2550/). DoS:

Packet Storm is back online.

2009-08-24 Thread Packet Storm
We had a provider outage but the site is now back online.

Re: SQL Injection vulnerabilities in Subdreamer CMS

2009-08-24 Thread ziad
This vulnerability has been patched in version 2.5.3.3: http://www.subdreamer.com/forum/showthread.php?t=15846

[ MDVSA-2009:218 ] w3c-libwww

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:218 http://www.mandriva.com/security/

[ MDVSA-2009:219 ] kompozer

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:219 http://www.mandriva.com/security/

[SECURITY] [DSA 1872-1] New Linux 2.6.18 packages fix several vulnerabilities

2009-08-24 Thread dann frazier
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-1872-1secur...@debian.org http://www.debian.org/security/ dann frazier August 24, 2009

[USN-822-1] KDE-Libs vulnerabilities

2009-08-24 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-822-1August 24, 2009 kde4libs, kdelibs vulnerabilities CVE-2009-0945, CVE-2009-1687, CVE-2009-1690, CVE-2009-1698 === A security issue affects

rPSA-2009-0122-1 idle python

2009-08-24 Thread rPath Update Announcements
rPath Security Advisory: 2009-0122-1 Published: 2009-08-24 Products: rPath Appliance Platform Linux Service 1 rPath Appliance Platform Linux Service 2 rPath Linux 1 rPath Linux 2 Rating: Major Exposure Level Classification: Deterministic Weakness Updated Versions:

[ MDVSA-2009:220 ] davfs

2009-08-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:220 http://www.mandriva.com/security/

[USN-823-1] KDE-Graphics vulnerabilities

2009-08-24 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-823-1August 24, 2009 kdegraphics vulnerabilities CVE-2009-0945, CVE-2009-1709 === A security issue affects the following Ubuntu releases:

rPSA-2009-0123-1 apr-util

2009-08-24 Thread rPath Update Announcements
rPath Security Advisory: 2009-0123-1 Published: 2009-08-24 Products: rPath Appliance Platform Linux Service 1 rPath Appliance Platform Linux Service 2 rPath Linux 1 rPath Linux 2 Rating: Major Exposure Level Classification: Remote Deterministic Denial of Service Updated

[USN-825-1] libvorbis vulnerability

2009-08-24 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-825-1August 24, 2009 libvorbis vulnerability CVE-2008-1420, CVE-2009-2663 === A security issue affects the following Ubuntu releases: Ubuntu