iDefense Security Advisory 07.26.07: IBM AIX capture Terminal Control Sequence Buffer Overflow Vulnerability

2007-07-26 Thread iDefense Labs
IBM AIX capture Terminal Control Sequence Buffer Overflow Vulnerability iDefense Security Advisory 07.26.07 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 26, 2007 I. BACKGROUND The capture program is a setuid root application, installed by default under multiple versions of IBM

FLEA-2007-0034-1:

2007-07-26 Thread Foresight Linux Essential Announcement Service
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Foresight Linux Essential Advisory: 2007-0034-1 Published: 2007-07-26 Rating: Major Updated Versions: lighttpd=/[EMAIL PROTECTED]:devel//1/1.4.15-0.3-1 group-dist=/[EMAIL PROTECTED]:1-devel//1/1.3.2-0.6-2 References:

RE: [CAID 35525, 35526]: CA Products Arclib Library Denial of Service Vulnerabilities

2007-07-26 Thread Williams, James K
-Original Message- From: Williams, James K Sent: Tuesday, July 24, 2007 7:56 PM To: 'bugtraq@securityfocus.com' Subject: [CAID 35525, 35526]: CA Products Arclib Library Denial of Service Vulnerabilities Title: [CAID 35525, 35526]: CA Products Arclib Library Denial of

[ GLSA 200707-11 ] MIT Kerberos 5: Arbitrary remote code execution

2007-07-26 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200707-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[ MDKSA-2007:150 ] - Updated clamav packages fix vulnerabilities

2007-07-26 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:150 http://www.mandriva.com/security/

Guidance Software response to iSEC report on EnCase

2007-07-26 Thread larry . gill
Guidance Software Response to iSEC Report Guidance Software received and reviewed the report drafted by two presenters at the upcoming Black Hat USA conference. We have also spoken to Alex Stamos, one of the testing leaders. The report authors disclose that they conducted, over a period of

SolpotCrew Advisory #14 (S4M3K) - PhpHostBot (login_form) Remote File Inclusion

2007-07-26 Thread s4m3k
+ + PhpHostBot (login_form) Remote File Inclusion + + Download link : http://www.idevspot.com/PhpHostBot.php + + + + + Bug Found By

Re: Mozilla protocol abuse

2007-07-26 Thread Thor Larholm
Since I published this report it has come to my attention that Thunderbird 1.5, unlike Thunderbird 2.0, has not been patched with the osint security flag. As such all Thunderbird 1.5 users are vulnerable against this attack and those exploits. Now would be a good time to upgrade to Thunderbird

libvorbis 1.1.2 - Multiple memory corruption flaws

2007-07-26 Thread David Thiel
iSEC Partners Security Advisory - 2007-003-libvorbis http://www.isecpartners.com libvorbis 1.1.2 - Multiple memory corruption flaws Vendor: Xiph.org Vendor URL: http://www.xiph.org Systems Affected: All tested software based upon libvorbis 1.1.2

[security bulletin] HPSBMA02133 SSRT061201 rev.5 - HP Oracle for OpenView (OfO) Critical Patch Update

2007-07-26 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c00727143 Version: 5 HPSBMA02133 SSRT061201 rev.5 - HP Oracle for OpenView (OfO) Critical Patch Update NOTICE: The information in this Security Bulletin should be acted upon as soon as

iDefense Security Advisory 07.26.07: IBM AIX ftp gets() Multiple Buffer Overflow Vulnerabilities

2007-07-26 Thread iDefense Labs
IBM AIX ftp gets() Multiple Buffer Overflow Vulnerabilities iDefense Security Advisory 07.26.07 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 26, 2007 I. BACKGROUND The ftp program is a client application for accessing data stored on FTP servers. This client is responsible for

Dependet Forums (Username Field) Remote SQL Injection

2007-07-26 Thread Advisory
_ A R I A - S E C U R I T Y _ Dependet Forums (Username Field) RemotE SQL Injection DORK: Powered by: Dependent Forums v1.02 Insert Your SQL Injection Code into the Username field. For Example ' union select * from members where member=1 Credits:

iDefense Security Advisory 07.26.07: IBM AIX pioout Arbitrary Library Loading Vulnerability

2007-07-26 Thread iDefense Labs
IBM AIX pioout Arbitrary Library Loading Vulnerability iDefense Security Advisory 07.26.07 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 26, 2007 I. BACKGROUND The pioout program is a setuid root application, installed by default under multiple versions of IBM AIX, that is used to

[SECURITY] [DSA 1342-2] New bind9 packages fix DNS cache poisoning

2007-07-26 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1341-2[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff July 25th, 2007

PHPSysInfo Index.php Cross Site Scripting

2007-07-26 Thread DoZ
[HSC] PHPSysInfo Index.php Cross Site Scripting PhpSysInfo is a PHP script that displays information about the host being accessed. An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may