Insomnia : ISVA-081209.1 - IE Webdav Request Parsing Heap Corruption Vulnerability

2008-12-10 Thread Brett Moore
__ Insomnia Security Vulnerability Advisory: ISVA-081209.1 ___ Name: IE Webdav Request Parsing Heap Corruption Vulnerability Released: 09 December 2008 Vendor

ISOI 6, Dallas, TX - January 29, 30

2008-12-10 Thread Gadi Evron
Hi all. ISOI is once again happening, and back to the States. Almost final agenda: http://isotf.org/isoi6.html As usual, while attendance is limited to the folks who are busy saving the Internet/fighting crime, it is free of charge. Once again we offer the public at-large the opportunity to

[USN-689-1] Vinagre vulnerability

2008-12-10 Thread Kees Cook
=== Ubuntu Security Notice USN-689-1 December 10, 2008 vinagre vulnerability https://launchpad.net/bugs/305623 === A security issue affects the following Ubuntu releases:

[USN-678-2] GnuTLS regression

2008-12-10 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-678-2 December 10, 2008 gnutls12, gnutls13, gnutls26 regression https://launchpad.net/bugs/305264 === A security issue affects the following

[SECURITY] [DSA 1684-1] New lcms packages fix multiple vulnerabilities

2008-12-10 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1684[EMAIL PROTECTED] http://www.debian.org/security/ Devin Carraway December 10, 2008

[IVIZ-08-011] ClamAV lzh unpacking segmentation fault

2008-12-10 Thread iViZ Security Advisories
--- [ iViZ Security Advisory 08-01110/12/2008 ] --- iViZ Techno Solutions Pvt. Ltd.

[IVIZ-08-012] Bitdefender antivirus for Linux multiple vulnerabilities

2008-12-10 Thread iViZ Security Advisories
--- [ iViZ Security Advisory 08-01210/12/2008 ] --- iViZ Techno Solutions Pvt. Ltd.

[IVIZ-08-013] Avast antivirus for Linux multiple vulnerabilities

2008-12-10 Thread iViZ Security Advisories
--- [ iViZ Security Advisory 08-01310/12/2008 ] --- iViZ Techno Solutions Pvt. Ltd.

[IVIZ-08-014] AVG antivirus for Linux vulnerability

2008-12-10 Thread iViZ Security Advisories
--- [ iViZ Security Advisory 08-01410/12/2008 ] --- iViZ Techno Solutions Pvt. Ltd.

[IVIZ-08-015] Sophos Antivirus for Linux vulnerability

2008-12-10 Thread iViZ Security Advisories
--- [ iViZ Security Advisory 08-01510/12/2008 ] --- iViZ Techno Solutions Pvt. Ltd.

[IVIZ-08-016] F-Secure f-prot Antivirus for Linux corrupted ELF header Security Bypass

2008-12-10 Thread iViZ Security Advisories
--- [ iViZ Security Advisory 08-01610/12/2008 ] --- iViZ Techno Solutions Pvt. Ltd.

Re: Multiple XSRF in DD-WRT (Remote Root Command Execution)

2008-12-10 Thread s . gottschall
this is no security flaw since you must be already logged in within the webinterface of dd-wrt. otherwise this here will not work. we already fixed this issue in our sourcetree as additional information. this is no dd-wrt specific issue. all other firmware like openwrt etc. would suffer from

Microsoft SQL Server 2005 sp_replwritetovarbin memory overwrite (update to SEC Consult SA-20081209)

2008-12-10 Thread Bernhard Mueller
Update to SEC Consult Security Advisory 20081210-0 (Microsoft SQL Server sp_replwritetovarbin limited memory overwrite vulnerability) === Summary: By calling the extended stored procedure sp_replwritetovarbin

CORE-2008-0228: Microsoft Word Malformed FIB Arbitrary Free Vulnerability

2008-12-10 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Microsoft Word Malformed FIB Arbitrary Free Vulnerability 1. *Advisory Information* Title: Microsoft Word Malformed FIB Arbitrary Free

[security bulletin] HPSBUX02393 SSRT080057 rev.1 - HP-UX Running DCE, Remote Denial of Service (DoS)

2008-12-10 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01623009 Version: 1 HPSBUX02393 SSRT080057 rev.1 - HP-UX Running DCE, Remote Denial of Service (DoS) NOTICE: The information in this Security Bulletin should be acted upon as soon as

[ GLSA 200812-09 ] OpenSC: Insufficient protection of smart card PIN

2008-12-10 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200812-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[ GLSA 200812-10 ] Archive::Tar: Directory traversal vulnerability

2008-12-10 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200812-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Max's Guestbook (XSS) Remote Vulnerability

2008-12-10 Thread 08253
% %% %% %% Discovered by: GTADarkDude %% Disconvered on: 10 December 2008 %% Name: Max's Guestbook %% Version: 1.0 %% URL: http://www.phpf1.com/product/php-guestbook-script.html %% URL2: http://www.hotscripts.com/Detailed/78571.html %% Google

iDefense Security Advisory 12.10.08: Microsoft Excel Malformed Object Memoy Corruption Vulnerability

2008-12-10 Thread iDefense Labs
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 iDefense Security Advisory 12.09.08 http://labs.idefense.com/intelligence/vulnerabilities/ Dec 09, 2008 I. BACKGROUND Excel is the spreadsheet application included with Microsoft Corp.'s Office productivity software suite. More information is

[ MDVSA-2008:240 ] vinagre

2008-12-10 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:240 http://www.mandriva.com/security/

CA ARCserve Backup LDBserver Vulnerability

2008-12-10 Thread Williams, James K
Title: CA ARCserve Backup LDBserver Vulnerability CA Advisory Date: 2008-12-10 Reported By: Dyon Balding of Secunia Research Impact: A remote attacker can cause a denial of service or execute arbitrary code. Summary: CA ARCserve Backup contains a vulnerability that can allow a remote