[ MDVSA-2013:014 ] java-1.6.0-openjdk

2013-02-25 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:014 http://www.mandriva.com/security/

[SECURITY] [DSA 2631-1] squid3 security update

2013-02-25 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2630-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso February 24, 2013

NoSuchCon CFP 2.0 / 15-17 May 2013 / Paris, France

2013-02-25 Thread Jonathan Brossard
*** PARENTAL ADVISORY: 100% technical content *** +--+ =

[SE-2012-01] New security issues affecting Oracle's Java SE 7u15

2013-02-25 Thread Security Explorations
Hello All, We had yet another look into Oracle's Java SE 7 software that was released by the company on Feb 19, 2013. As a result, we have discovered two new security issues (numbered 54 and 55), which when combined together can be successfully used to gain a complete Java security sandbox

DC4420 - London DEFCON Tuesday 26th Feb 2013

2013-02-25 Thread Major Malfunction
Apologies for the late announcement... Tomorrow we have a particularly excellent line-up! Primary Speaker: Arron Finnon - Finux Tech Weekly Title: The OSNIF Project: NIDS/NIPS Testing and Auditing Synopsis: Yeah great, I know its not a silver bullet! NIPS/NIDS have issues, and that's

VUPEN Security Research - Microsoft Windows OLE Automation Code Execution Vulnerability

2013-02-25 Thread VUPEN Security Research
VUPEN Security Research - Microsoft Windows OLE Automation Remote Code Execution Vulnerability Website : http://www.vupen.com Twitter : http://twitter.com/vupen I. BACKGROUND - Microsoft Windows is a series of software operating systems and graphical user interfaces

[SECURITY] [DSA 2629-1] openjpeg security update

2013-02-25 Thread Michael Gilbert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2629-1 secur...@debian.org http://www.debian.org/security/ Michael Gilbert February 25, 2013

[Onapsis Security Advisory 2013-001] SAP Portal PDC Information Disclosure

2013-02-25 Thread Onapsis Research Labs
Onapsis Security Advisory 2013-001: SAP Portal PDC Information Disclosure This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand information on upcoming advisories,

[Onapsis Security Advisory 2013-002] SAP SDM Denial of Service

2013-02-25 Thread Onapsis Research Labs
Onapsis Security Advisory 2013-002: SAP SDM Denial of Service This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand information on upcoming advisories, presentations and new

[Onapsis Security Advisory 2013-003] SAP Enterprise Portal Cross-Site-Scripting

2013-02-25 Thread Onapsis Research Labs
Onapsis Security Advisory 2013-003: SAP Enterprise Portal Cross-Site-Scripting This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand information on upcoming advisories,

[Onapsis Security Advisory 2013-004] SAP J2EE Core Service Arbitrary File Access

2013-02-25 Thread Onapsis Research Labs
Onapsis Security Advisory 2013-004: SAP J2EE Core Service Arbitrary File Access This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand information on upcoming advisories,

[Onapsis Security Advisory 2013-006] SAP SMD Agent Code Injection

2013-02-25 Thread Onapsis Research Labs
Onapsis Security Advisory 2013-006: SAP SMD Agent Code Injection This advisory can be downloaded in PDF format from http://www.onapsis.com/. By downloading this advisory from the Onapsis Resource Center, you will gain access to beforehand information on upcoming advisories, presentations and new

Kayako Fusion v4.51.1891 - Multiple Web Vulnerabilities

2013-02-25 Thread Vulnerability Lab
Title: == Kayako Fusion v4.51.1891 - Multiple Web Vulnerabilities Date: = 2013-01-22 References: === http://www.vulnerability-lab.com/get_content.php?id=824 ID: SWIFT-3119 URL: http://dev.kayako.com/browse/SWIFT-3119 VL-ID: = 824 Common Vulnerability Scoring System:

[IA48] Photodex ProShow Producer v5.0.3297 Insecure Library Loading Vulnerability

2013-02-25 Thread Inshell Security
Inshell Security Advisory http://www.inshell.net 1. ADVISORY INFORMATION --- Product:Photodex ProShow Producer Vendor URL: www.photodex.com Type: Uncontrolled Search Path Element [CWE-427] Date found: 2013-02-23 Date published: 2013-02-23 CVSSv2

Fwd: [SECURITY] CVE-2013-0253 Apache Maven 3.0.4

2013-02-25 Thread Olivier Lamy
CVE-2013-0253 Apache Maven Severity: Medium Vendor: The Apache Software Foundation Versions Affected: - Apache Maven 3.0.4 - Apache Maven Wagon 2.1, 2.2, 2.3 Description: Apache Maven 3.0.4 (with Apache Maven Wagon 2.1) has introduced a non-secure SSL mode by default. This mode disables all

CONFidence 2013 - Call for Papers - 28-29.05.2013 Krakow, Poland

2013-02-25 Thread Andrzej Targosz
Calling all practitioners in the field of IT security! The 11th edition of the international IT security conference, CONFidence 2013, is taking place in May 28/29, 2013 (as usual it will be close to BerlinSides and PXE so if you plan to be around Krakow or Berlin you have to try be a part of