[Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-06 Thread Ivan .
For those who don't frequent slashdot... Enterprises are spending huge amounts of money on compliance programs related to PCI-DSS, HIPAA and other regulations, but those funds may be misdirected in light of the priorities of most information security programs, a new study has found. A paper

Re: [Full-disclosure] Weev's Mugshot

2010-04-06 Thread BMF
On Mon, Apr 5, 2010 at 8:36 PM, Scarf Pride Worldwide terdlinkmob...@gmail.com wrote: Allegedly he obstructed justice by giving a false name.. most likely didn't put money in the parking meter at the synagogue He doesn't look very Jewish to me. ___

Re: [Full-disclosure] Weev's Mugshot

2010-04-06 Thread Benji
Try squinting and turning your head at a 780o angle parallel with the moon. On Tue, Apr 6, 2010 at 8:37 AM, BMF badmotherfs...@gmail.com wrote: On Mon, Apr 5, 2010 at 8:36 PM, Scarf Pride Worldwide terdlinkmob...@gmail.com wrote: Allegedly he obstructed justice by giving a false name.. most

[Full-disclosure] [SECURITY] [DSA 2028-1] New xpdf packages fix several vulnerabilities

2010-04-06 Thread Luciano Bello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-2028-1secur...@debian.org http://www.debian.org/security/ Luciano Bello April 5th, 2010

[Full-disclosure] [SECURITY] [DSA 2029-1] New imlib2 packages fix arbitrary code execution

2010-04-06 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-2029-1secur...@debian.org http://www.debian.org/security/ Nico Golde April 5th, 2010

[Full-disclosure] Vulnerabilities in TAK cms

2010-04-06 Thread MustLive
Hello Full-Disclosure! I want to warn you about security vulnerabilities in TAK cms. It's Ukrainian commercial CMS. - Advisory: Vulnerabilities in TAK cms - URL: http://websecurity.com.ua/4050/ - Timeline:

[Full-disclosure] Hack.lu 2010 CfP

2010-04-06 Thread info
Call for Papers Hack.lu 2010 The purpose of the hack.lu convention is to give an open and free playground where people can discuss the implication of new technologies in society. hack.lu is a balanced mix convention where technical and non-technical people can meet each

[Full-disclosure] [SECURITY] - Jzip (.zip) Unicode bof Vulnerability

2010-04-06 Thread Steven Seeley
|--| | __   __  | |   _    / /___ _ / /  _ ___  | |  / ___/ __ \/ ___/ _ \/ / __ `/ __ \   / __/ _ \/ __ `/ __ `__ \ | | / /__/ /_/ / /  / 

[Full-disclosure] ZDI-10-065: CA XOsoft xosoapapi.asmx Multiple Remote Code Execution Vulnerabilities

2010-04-06 Thread ZDI Disclosures
ZDI-10-065: CA XOsoft xosoapapi.asmx Multiple Remote Code Execution Vulnerabilities http://www.zerodayinitiative.com/advisories/ZDI-10-065 April 6, 2010 -- CVE ID: CVE-2010-1223 -- Affected Vendors: Computer Associates -- Affected Products: Computer Associates XOsoft High Availability Computer

[Full-disclosure] ZDI-10-066: CA XOsoft Control Service entry_point.aspx Remote Code Execution Vulnerability

2010-04-06 Thread ZDI Disclosures
ZDI-10-066: CA XOsoft Control Service entry_point.aspx Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-066 April 6, 2010 -- CVE ID: CVE-2010-1223 -- Affected Vendors: Computer Associates -- Affected Products: Computer Associates XOsoft High Availability

[Full-disclosure] CA20100406-01: Security Notice for CA XOsoft

2010-04-06 Thread Kotas, Kevin J
-BEGIN PGP SIGNED MESSAGE- CA20100406-01: Security Notice for CA XOsoft Issued: April 6, 2010 CA's support is alerting customers to multiple security risks with CA XOsoft products. Multiple vulnerabilities exist that can allow a remote attacker to gain sensitive information, cause a

[Full-disclosure] ZDI-10-067: Apple QuickTime Pict BkPixPat Remote Code Execution Vulnerability

2010-04-06 Thread ZDI Disclosures
ZDI-10-067: Apple QuickTime Pict BkPixPat Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-067 April 6, 2010 -- CVE ID: CVE-2010-0529 -- Affected Vendors: Apple -- Affected Products: Apple Quicktime -- TippingPoint(TM) IPS Customer Protection: TippingPoint

[Full-disclosure] CORE-2010-0323: XSS Vulnerability in NextGEN Gallery Wordpress Plugin

2010-04-06 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ XSS Vulnerability in NextGEN Gallery Wordpress Plugin 1. *Advisory Information* Title: XSS Vulnerability in

[Full-disclosure] [ MDVSA-2010:069 ] nss

2010-04-06 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:069 http://www.mandriva.com/security/

[Full-disclosure] [USN-923-1] OpenJDK vulnerabilities

2010-04-06 Thread Kees Cook
=== Ubuntu Security Notice USN-923-1 April 07, 2010 openjdk-6 vulnerabilities CVE-2009-3555, CVE-2010-0082, CVE-2010-0084, CVE-2010-0085, CVE-2010-0088, CVE-2010-0091, CVE-2010-0092, CVE-2010-0093, CVE-2010-0094, CVE-2010-0095,

[Full-disclosure] [USN-924-1] Kerberos vulnerabilities

2010-04-06 Thread Kees Cook
=== Ubuntu Security Notice USN-924-1 April 07, 2010 krb5 vulnerabilities CVE-2007-5901, CVE-2007-5902, CVE-2007-5971, CVE-2007-5972, CVE-2010-0629 === A security issue