[USN-525-1] libsndfile vulnerability

2007-10-05 Thread Kees Cook
=== Ubuntu Security Notice USN-525-1 October 04, 2007 libsndfile vulnerability CVE-2007-4974 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS

[SECURITY] [DSA 1383-1] New gforge packages fix cross-site scripting

2007-10-05 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1383-1[EMAIL PROTECTED] http://www.debian.org/security/Thijs Kinkhorst October 4th, 2007

[USN-526-1] debian-goodies vulnerability

2007-10-05 Thread Kees Cook
=== Ubuntu Security Notice USN-526-1 October 04, 2007 debian-goodies vulnerability CVE-2007-3912 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS

[ MDKSA-2007:193 ] - Updated openssl packages fix vulnerabilities

2007-10-05 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:193 http://www.mandriva.com/security/

rPSA-2007-0209-1 elinks

2007-10-05 Thread rPath Update Announcements
rPath Security Advisory: 2007-0209-1 Published: 2007-10-05 Products: rPath Linux 1 Rating: Minor Exposure Level Classification: Indirect User Deterministic Information Exposure Updated Versions: elinks=/[EMAIL PROTECTED]:devel//1/0.10.5-3.4-1 rPath Issue Tracking System:

Multiple vulnerabilities in Dropteam 1.3.3

2007-10-05 Thread Luigi Auriemma
### Luigi Auriemma Application: Dropteam http://www.battlefront.com/products/dropteam/news.html Versions: = 1.3.3 Platforms:Windows, Linux and Mac Bugs: A] format

Reporting Vulnerable Public Web mail

2007-10-05 Thread ivan . sanchez
Reporting Vulnerable Public Software Technical Details: +===+ + MailBee WebMail Pro =3.4 (XSS) Multiple Remote Vulnerabilities + +===+

Re: Re: file upload vulnerability in joomla media component

2007-10-05 Thread vinodsharma . mimit
Hi Gavin even with the manager previleges it is possible to exploit this issue.

Format string in The Dawn of Time 1.69s beta4

2007-10-05 Thread Luigi Auriemma
### Luigi Auriemma Application: The Dawn of Time http://www.dawnoftime.org Versions: = 1.69s beta4 (and 1.69r too) Platforms:*nix and Windows Bug: format string in

RE: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

2007-10-05 Thread Roger A. Grimes
[Disclosure: I work for Microsoft. But this is my opinion, not Microsoft's] If I click on the test link in IE 7, by itself, it does not have the vulnerability. The applications in question are accepting abitrary input and not validating correctly. How is that a Microsoft or Windows problem?

[SECURITY] [DSA 1384-1] New xen-utils packages fix several vulnerabilities

2007-10-05 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA 1384-1 [EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp October 5th, 2007