[SECURITY] [DSA 1633-1] New slash packages fix multiple vulnerabilities

2008-09-02 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1633-1 [EMAIL PROTECTED] http://www.debian.org/security/ Florian Weimer September 01, 2008

[SECURITY] [DSA 1634-1] New wordnet packages fix arbitrary code execution

2008-09-02 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1634-1 [EMAIL PROTECTED] http://www.debian.org/security/ Thijs Kinkhorst September 01, 2008

HPSBUX02354 SSRT080113 rev.1 - HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS)

2008-09-02 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01532861 Version: 1 HPSBUX02354 SSRT080113 rev.1 - HP-UX Running Netscape / Red Hat Directory Server, Remote Cross Site Scripting (XSS) or Remote Denial of Service (DoS) NOTICE: The

[security bulletin] HPSBMA02362 SSRT080044, SSRT080045 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS)

2008-09-02 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01537275 Version: 1 HPSBMA02362 SSRT080044, SSRT080045 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote Denial of Service (DoS) NOTICE: The information in this Security Bulletin

Postfix Linux-only local denial of service

2008-09-02 Thread Wietse Venema
An on-line version of this announcement is available at http://www.postfix.org/announcements/20080902.html Summary: Postfix 2.4 and later, on Linux kernel 2.6, is vulnerable to a denial of service attack by a local user. There is no breach of data confidentiality or data integrity

[AJECT] Softalk IMAP Server 8.5.1 DoS vulnerability

2008-09-02 Thread João Antunes
Synopsis Softalk IMAP Server 8.5.1 is vulnerable to denial-of-service (DoS) attacks. The IMAP server crashes when processing an APPEND command with a strange parameter (see details bellow). Other commands may

ToorCon X Lineup Training Seminars Posted Pre-Registration Ending

2008-09-02 Thread h1kari
[*] TOORCON X LINEUP TRAINING SEMINARS POSTED PRE-REGISTRATION ENDING We're very proud to announce our lineup for this year and wanted to remind everyone that ToorCon is happening in less than a month! We also have a couple different training workshops and a day of seminars in addition to the

[ MDVSA-2008:182 ] wordnet

2008-09-02 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:182 http://www.mandriva.com/security/

CS-Cart = 1.3.5 SQL Injection

2008-09-02 Thread GulfTech Security Research
## # GulfTech Security Research September 02, 2008 ## # Vendor : CS-Cart.com # URL : http://www.cs-cart.com/ # Version : CS-Cart = 1.3.5 # Risk : SQL Injection

[Tool] sqlmap 0.6 released

2008-09-02 Thread Bernardo Damele A. G.
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, I am glad to release sqlmap version 0.6. Introduction sqlmap is an automatic SQL injection tool developed in Python. Its goal is to detect and take advantage of SQL injection vulnerabilities on web applications. Once it detects one

[USN-639-1] tiff vulnerability

2008-09-02 Thread Kees Cook
=== Ubuntu Security Notice USN-639-1 September 02, 2008 tiff vulnerability CVE-2008-2327 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu

[Suspected Spam]New IETF I-D-: Security Assessment of the Internet Protocol version 4

2008-09-02 Thread Fernando Gont
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello, folks, We have published an IETF Internet-Draft entitled Security Assessment of the Internet Protocol version 4, which is heavily based on the Security Assessment of the Internet Protocol that was recently released by the UK CPNI

In search of examples of malicious source code

2008-09-02 Thread Steve . Coleman
I am currently working on a research project and designing an application specifically aimed at locating malicious logic embedded in source code (C/C++ for now, other languages will be addressed later). As a test of the future implementation I would like to use as many real life examples of

[ MDVSA-2008:183 ] opensc

2008-09-02 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:183 http://www.mandriva.com/security/

T2´08 Challenge - Free Tickets Availa ble

2008-09-02 Thread Tomi Tuominen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Everyone, Quite many people have emailed us lately asking if there will be T2'08 Challenge - the answer is yes :) The purpose of the Challenge is to have an opportunity to win a free tickets to T2'08 infosec conference: http://www.t2.fi/ The

Has anyone implemented double forward DNS?

2008-09-02 Thread Duncan Simpson
Double reverse DNS, which checks the name found using reverse DNS matches the IP adrdess enquired about is now common. I was wondering wether about has applied the same technique to forward DNS queries too. The idea here is that a client that finds www.example.com is 192.168.3.42 does not

Exploit

2008-09-02 Thread Admin
Dear Securiteam moderator: I found a bug in BizDirectory that allows to us to occur a Cross-Site Scripting on a Remote machin. It works tested with the Vulnerable Software 2.04. An Exploit Released For This Vulnerability. A Full Description Can be found in the document: