[DRUPAL-SA-2006-001] Drupal 4.6.6 / 4.5.8 fixes access control issue

2006-03-14 Thread Uwe Hermann
Drupal security advisory DRUPAL-SA-2006-001 Advisory ID:DRUPAL-SA-2006-001 Project:Drupal core

[DRUPAL-SA-2006-003] Drupal 4.6.6 / 4.5.8 fixes session fixation issue

2006-03-14 Thread Uwe Hermann
Drupal security advisory DRUPAL-SA-2006-003 Advisory ID:DRUPAL-SA-2006-003 Project:Drupal core

[DRUPAL-SA-2006-002] Drupal 4.6.6 / 4.5.8 fixes XSS issue

2006-03-14 Thread Uwe Hermann
Drupal security advisory DRUPAL-SA-2006-002 Advisory ID:DRUPAL-SA-2006-002 Project:Drupal core

[SECURITY] [DSA 999-1] New lurker packages fix several vulnerabilities

2006-03-14 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 999-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 14th, 2006

[SECURITY] [DSA 998-1] New libextractor packages fix several vulnerabilities

2006-03-14 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 998-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 14th, 2006

DMA[2006-0313a] - 'Apple OSX Mail.app RFC1740 Real Name Buffer Overflow'

2006-03-14 Thread KF (lists)
DMA[2006-0313a] - 'Apple OSX Mail.app RFC1740 Real Name Buffer Overflow' Author: Kevin Finisterre Vendor: http://www.apple.com/macosx/ Product: 'Mac OSX 10.4.5 with Security Update 2006-001' References: http://www.digitalmunition.com/DMA[2006-0313a].txt http://rfc.net/rfc1740.html

[SECURITY] [DSA 1000-1] New Apache2::Request packages fix denial of service

2006-03-14 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1000-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze March 14th, 2006

[SECURITY] [DSA 1001-1] New crossfire packages fix arbitrary code execution

2006-03-14 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1001-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff March 14th, 2006

Linux zero IP ID vulnerability?

2006-03-14 Thread Marco Ivaldi
Hello Bugtraq, I've recently stumbled upon an interesting behaviour of some Linux kernels that may be exploited by a remote attacker to abuse the ID field of IP packets, effectively bypassing the zero IP ID in DF packets countermeasure implemented since 2.4.8 (IIRC). This is the correct

[eVuln] CyBoards PHP Lite SQL Injection Vulnerability

2006-03-14 Thread alex
New eVuln Advisory: CyBoards PHP Lite SQL Injection Vulnerability http://evuln.com/vulns/91/summary.html Summary eVuln ID: EV0091 CVE: CVE-2006-1134 Software: CyBoards PHP Lite Sowtware's Web Site:

High Risk Vulnerability in Microsoft Excel

2006-03-14 Thread NGSSoftware Insight Security Research
Peter Winter-Smith of NGSSoftware has discovered a high risk vulnerability in Microsoft Excel which may allow an remote attacker to execute arbitrary code on a user's system via the Internet Explorer Excel plugin. This issue has been resolved in the Microsoft bulletin MS06-012, which may be

ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability

2006-03-14 Thread zdi-disclosures
ZDI-06-004: Microsoft Excel File Format Parsing Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-06-004.html March 14, 2006 -- CVE ID: CVE-2006-0028 -- Affected Vendor: Microsoft -- Affected Products: Office 2000 Office XP Office 2003 -- TippingPoint(TM) IPS Customer Protection:

Re: histhost v1.0.0 xss and possible rmdir

2006-03-14 Thread Steven M. Christey
retard said: as you see line 19 raises suspision of the possibility of rming 0777 dirs i've tried it on on my personal server with no sucess, if someone knows of a way let me know. According to the PHP manual, rmdir only works on empty directories. Did you try to remove an empty directory? -

Fortinet Security Advisory: FSA-2006-09

2006-03-14 Thread Fortinet Research
Fortinet Security Advisory: FSA-2006-09 Microsoft Excel Formula Size Stack Overflow Advisory Date : March 14, 2006 Reported Date : January 24, 2006 Vendor : Microsoft Affected Products : Microsoft Excel 2003 Chinese Version

Fortinet Security Advisory: FSA-2006-08

2006-03-14 Thread Fortinet Research
Fortinet Security Advisory: FSA-2006-08 Microsoft Excel Column Index Improper Memory Access Advisory Date : March 14, 2006 Reported Date : January 24, 2006 Vendor : Microsoft Affected Products : Microsoft Excel 2003 Chinese Version

SYMSA-2006-001: Buffer overflow in Microsoft Office 2000, Office XP (2002), and Office 2003 Routing Slip Metadata

2006-03-14 Thread CS_Advisories Mailbox
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Symantec Professional Services www.symantec.com Security Advisory Advisory ID : SYMSA-2006-001 Advisory Name: Buffer overflow in Microsoft Office 2000, Office XP