[SECURITY] [DSA 1577-1] New gforge packages fix insecure temporary files

2008-05-14 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1577-1 [EMAIL PROTECTED] http://www.debian.org/security/ Thijs Kinkhorst May 14, 2008

Microsoft Office Publisher PUB File Parsing Remote Memory Corruption Vulnerability

2008-05-14 Thread cocoruder
/ Please join us to pray for the people still in the huge earthquake in eastern Sichuan, China. */ Microsoft

Malformed Acrobat Distiller 8 .joboptions

2008-05-14 Thread Paul Craig
= = Malformed Acrobat Distiller 8 .joboptions = = Vendor Website: = http://www.adobe.com = = Affected Version: = Adobe Acrobat Reader, Acrobat Professional 7, Acrobat Professional 8 = = Vendor Notified - February 2007 = Public

[USN-612-4] ssl-cert vulnerability

2008-05-14 Thread Kees Cook
=== Ubuntu Security Notice USN-612-4 May 14, 2008 ssl-cert vulnerability CVE-2008-0166, http://www.ubuntu.com/usn/usn-612-1 === A security issue affects the following

[SECURITY] [DSA 1576-1] New openssh packages fix predictable randomness

2008-05-14 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1576-1 [EMAIL PROTECTED] http://www.debian.org/security/ Florian Weimer May 14, 2008

CFP: European Conference on Computer Network Defense

2008-05-14 Thread Stefano Zanero
CALL FOR PAPERS: EC2ND 2008 European Conference on Computer Network Defense (in cooperation with ENISA) December 11th 12th 2008, Dublin City University, Dublin, Ireland. http://2008.ec2nd.org/ Call for Papers The fourth annual EC2ND conference will take place on December 11th 12th 2008 in

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities

2008-05-14 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities Advisory ID: cisco-sa-20080514-cucmdos Revision 1.0

[USN-612-5] OpenSSH update

2008-05-14 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-612-5 May 14, 2008 openssh update https://launchpad.net/bugs/230029 http://www.ubuntu.com/usn/usn-612-2 === A security issue affects the

[ GLSA 200805-15 ] libid3tag: Denial of Service

2008-05-14 Thread Tobias Heinlein
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200805-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Cisco Security Advisory: Cisco Content Switching Module Memory Leak Vulnerability

2008-05-14 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Content Switching Module Memory Leak Vulnerability Advisory ID: cisco-sa-20080514-csm http://www.cisco.com/warp/public/707/cisco-sa-20080514-csm.shtml Revision 1.0 For Public Release 2008 May 14 1600 UTC (GMT

Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilities

2008-05-14 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilities Advisory ID: cisco-sa-20080514-cup Revision 1.0 +- Summary

Re: Cisco BBSM Captive Portal Cross-site Scripting

2008-05-14 Thread Eloy Paris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello, This is the Cisco PSIRT response to an issue that was discovered and reported to Cisco by Brad Antoniewicz from Mcafee/Foundstone Professional Services regarding a cross-site scripting (XSS) vulnerability in Cisco's Building Broadband Service

Correction to BID 29112 Apache Server HTML Injection and UTF-7 XSS Vulnerability

2008-05-14 Thread William A. Rowe, Jr.
HTTP User and Desktop Security Communities; With respect to http://www.securityfocus.com/bid/29112 Per http://www.ietf.org/rfc/rfc2616.txt 3.7.1 Canonicalization and Text Defaults [...] The charset parameter is used with some media types to define the character set (section 3.4) of the

[ GLSA 200805-16 ] OpenOffice.org: Multiple vulnerabilities

2008-05-14 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200805-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[USN-612-6] OpenVPN regression

2008-05-14 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-612-6 May 14, 2008 openvpn regression https://launchpad.net/bugs/230193 https://launchpad.net/bugs/230208 http://www.ubuntu.com/usn/usn-612-3