RECON 2011 CFP

2011-03-07 Thread hfortier
/* ++ + + + + + + + \ / + _- _+_ - ,__ _=.

Kodak InSite Login Page Cross-Site Scripting

2011-03-07 Thread vulns
Class Input Validation Error CVE Remote Yes Local No Published Feb 14 2011 08:55AM Credit Dionach Vulnerable Kodak InSite 5.5.2 Kodak InSite is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

InSite Troubleshooting Cross-Site Scripting

2011-03-07 Thread vulns
Class Input Validation Error CVE Remote Yes Local No Published Feb 14 2011 08:55AM Credit Dionach Vulnerable Kodak InSite 5.5.2 Kodak InSite is prone to a cross-site scripting vulnerability because it fails to sufficiently sanitize user-supplied data.

[USN-1085-1] tiff vulnerabilities

2011-03-07 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1085-1March 07, 2011 tiff vulnerabilities CVE-2010-2482, CVE-2010-2483, CVE-2010-2595, CVE-2010-2597, CVE-2010-2598, CVE-2010-2630, CVE-2010-3087, CVE-2011-0191, CVE-2011-0192

[TEHTRI-Security] Security and iPhone iOS 4.3 Personal Hotspot feature

2011-03-07 Thread Laurent OUDOT at TEHTRI-Security
Gents, Here is a tiny mail dealing with the new feature of the iPhone 4 with iOS 4.3, which turns it into a Wireless Hotspot in order to share your 3G session through a WLAN. We wanted to share a quick geeky and security overview of this awesome functionality. Basically, we only found one tiny

[ MDVSA-2011:042 ] mozilla-thunderbird

2011-03-07 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:042 http://www.mandriva.com/security/

Plaintext injection in STARTTLS (multiple implementations)

2011-03-07 Thread Wietse Venema
This is a writeup about a flaw that I found recently, and that existed in multiple implementations of SMTP (Simple Mail Transfer Protocol) over TLS (Transport Layer Security) including my Postfix open source mailserver. I give an overview of the problem and its impact, how to find out if a server