[ GLSA 200806-04 ] rdesktop: Multiple vulnerabilities

2008-06-14 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200806-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

GSC Privilege Escalation Exploit

2008-06-14 Thread Moose
Name: Michael Gray Website: www.ownerarium.net Contact: [EMAIL PROTECTED] Discovered Exploit: 06-05-2008 Vulnerable Software Title: GSC Vulnerable Version: <= 2067 Severity: CRITICAL Website: http://www.getgsc.com Reported to vendor: Yes Actively exploited: Yes Exploit Discovery

Re: Collection of Vulnerabilities in Fully Patched Vim 7.1

2008-06-14 Thread Bram Moolenaar
Jan Minar wrote: > 1. Summary > > Product : Vim -- Vi IMproved > Version : Tested with 7.1.314 and 6.4 > Impact : Arbitrary code execution > Wherefrom: Local and remote > Original : http://www.rdancer.org/vulnerablevim.html > > Improper quoting in some parts of Vim written in the Vim Script

Collection of Vulnerabilities in Fully Patched Vim 7.1

2008-06-14 Thread Jan Minář
1. Summary Product : Vim -- Vi IMproved Version : Tested with 7.1.314 and 6.4 Impact : Arbitrary code execution Wherefrom: Local and remote Original : http://www.rdancer.org/vulnerablevim.html Improper quoting in some parts of Vim written in the Vim Script can lead to arbitrary code execution

Re: AS/400 Vulnerabilities

2008-06-14 Thread security curmudgeon
: Have you ever nmap-ed a network with AS/400s? If you have, you probably : know that doing so will, in at least half the cases, either crash the : box, hang up one or more services, or really confuse the IP stack to the : point that the box almost screeches to a halt. This is frequently obse

[ MDVSA-2008:114 ] - Updated util-linux-ng packages fix log injection issue

2008-06-14 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:114 http://www.mandriva.com/security/ ___

Technical Details of Security Issues Regarding Safari for Windows

2008-06-14 Thread LIUDIEYU dot COM
The first issue is the one described in Microsoft Security Advisory 953818. It's worked out by Aviv Raff: http://www.microsoft.com/technet/security/advisory/953818.mspx http://aviv.raffon.net/2008/05/31/SafariPwnsInternetExplorer.aspx It's covered by news but Aviv Raff has not published technical d