[SECURITY] [DSA 2480-4] request-tracker3.8 regression update

2012-09-17 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2480-4 secur...@debian.org http://www.debian.org/security/ Raphael Geissert September 15, 2012

[SECURITY] [DSA 2549-1] devscripts security update

2012-09-17 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2549-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert September 15, 2012

[ MDVSA-2012:153 ] dhcp

2012-09-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:153 http://www.mandriva.com/security/

[SECURITY] [DSA 2548-1] Debian Security Team PGP/GPG key change notice

2012-09-17 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2548-1 secur...@debian.org http://www.debian.org/security/Nico Golde September 13, 2012

ipv6mon v1.0 released! (IPv6 address monitoring daemon)

2012-09-17 Thread Fernando Gont
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Folks, We are pleased to announce the release of ipv6mon v1.0! ** Description ** ipv6mon (http://www.si6networks.com/tools/ipv6mon) is a tool for monitoring IPv6 address usage on a local network. It is meant to be particularly useful in networks

ASTPP VoIP Billing (4cf207a) - Multiple Web Vulnerabilities

2012-09-17 Thread Vulnerability Lab
Title: == ASTPP VoIP Billing (4cf207a) - Multiple Web Vulnerabilities Date: = 2012-08-17 References: === http://www.vulnerability-lab.com/get_content.php?id=687 VL-ID: = 687 Common Vulnerability Scoring System: 4 Introduction:

NeoBill CMS v0.8 Alpha - Multiple Web Vulnerabilities

2012-09-17 Thread Vulnerability Lab
Title: == NeoBill CMS v0.8 Alpha - Multiple Web Vulnerabilities Date: = 2012-08-18 References: === http://www.vulnerability-lab.com/get_content.php?id=685 VL-ID: = 685 Common Vulnerability Scoring System: 3.5 Introduction:

[INTREST SEC] Atlassian Confluence Wiki XSS Vulnerability

2012-09-17 Thread INTREST SEC
--- INTREST SEC | Security Advisory --- Product: Confluence Wiki Vendor:Atlassian (www.atlassian.com) Vulnerability Type:Cross Site Scripting (XSS) Risk Level:High (classified by vendor)

[slackware-security] patch (SSA:2012-257-02)

2012-09-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] patch (SSA:2012-257-02) New patch packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix a security issue. Here are the details from the Slackware 13.37 ChangeLog: +--+

[slackware-security] bind (SSA:2012-257-01)

2012-09-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] bind (SSA:2012-257-01) New bind packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix a security issue. Here are the details from the Slackware 13.37 ChangeLog: +--+

[slackware-security] dhcp (SSA:2012-258-01)

2012-09-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] dhcp (SSA:2012-258-01) New dhcp packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix a security issue. Here are the details from the Slackware 13.37 ChangeLog: +--+

IPv6 Toolkit v1.2.3 released! (and upcoming IPv6 security trainings)

2012-09-17 Thread Fernando Gont
Folks, I realize we never announced the toolkit on these lists, so here you go. ** SI6 Networks' IPv6 toolkit ** We've released SI6 Networks' IPv6 toolkit v1.2.3. It is available at: http://www.si6networks.com/ipv6toolkit. The toolkit contains a number of IPv6 security/troubleshooting tools,

[IA38] NCMedia Sound Editor Pro v7.5.1 MRUList201202.dat File Handling Local Buffer Overflow

2012-09-17 Thread Inshell Security
Inshell Security Advisory http://www.inshell.net 1. ADVISORY INFORMATION --- Product:Sound Editor Pro v7.5.1 Vendor URL: www.soundeditorpro.com Type: Stack-based Buffer Overflow [CWE-121] Date found: 2012-08-15 Date published: 2012-09-16 CVSSv2

Secunia Research: Novell GroupWise iCalendar Date/Time Parsing Denial of Service

2012-09-17 Thread Secunia Research
== Secunia Research 17/09/2012 - Novell GroupWise iCalendar Date/Time Parsing Denial of Service - == Table of Contents Affected

[waraxe-2012-SA#089] - Multiple Vulnerabilities in TorrentTrader 2.08

2012-09-17 Thread come2waraxe
[waraxe-2012-SA#089] - Multiple Vulnerabilities in TorrentTrader 2.08 === Author: Janek Vind waraxe Date: 17. September 2012 Location: Estonia, Tartu Web: http://www.waraxe.us/advisory-89.html Description of vulnerable

[Positive Research] Intel SMEP overview and partial bypass on Windows 8 (whitepaper)

2012-09-17 Thread noreply
Intel SMEP overview and partial bypass on Windows 8 (whitepaper). ... It is natural to conclude that if you can’t store your shellcode in the user-mode, you have to find a way to store it somewhere in the kernel space. The most obvious solution is using windows objects such as WinAPI (Events,