[ MDVSA-2011:061 ] ffmpeg

2011-04-04 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:061 http://www.mandriva.com/security/

XCon 2011 XFocus Information Security Conference Call for Paper

2011-04-04 Thread xcon
XCon 2011 XFocus Information Security Conference Call for Paper September, 1st – 2nd, 2011, Beijing, China (http://xcon.xfocus.net) Upholding rigorous work style, XCon sincerely welcomes contributions from information security technique enthusiasts and expects your participation and sharing.

Re: RFI in JAF CMS

2011-04-04 Thread security curmudgeon
CVE-2008-1609 CVE-2006-7128 same issue, 4.0 RC1 and RC2. really guys? at least check VDBs before you publish. : Vulnerability ID: HTB22666 : Status: Not Fixed, Vendor Alerted, Awaiting Vendor Response Did you check the vendor's page? This page last updated on : May 20, 2006

Stored and Reflective XSS in Yaws-Wiki 1.88-1 (Erlang)

2011-04-04 Thread mike
Software: yaws-wiki version affected: 1.88-1 platform: Erlang homepage:http://yaws.hyber.org/ Researcher: Michael Brooks Original Advisory:https://sitewat.ch/en/Advisory/4 Install instructions for Ubuntu: sudo apt-get install yaws-wiki Edit:/etc/yaws/conf.d/yaws-wiki.conf #add this:

[ MDVSA-2011:063 ] xmlsec1

2011-04-04 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:063 http://www.mandriva.com/security/

[SECURITY] [DSA 2210-1] tiff security update

2011-04-04 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2210-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst April 03, 2011

[ MDVSA-2011:062 ] ffmpeg

2011-04-04 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:062 http://www.mandriva.com/security/

[SECURITY] [DSA 2209-1] tgt security update

2011-04-04 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2209-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff April 02, 2011

ZDI-11-115: IBM solidDB solid.exe Authentication Bypass Remote Code Execution Vulnerability

2011-04-04 Thread ZDI Disclosures
ZDI-11-115: IBM solidDB solid.exe Authentication Bypass Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-115 April 1, 2011 -- CVSS: 9.3, (AV:N/AC:M/Au:N/C:C/I:C/A:C) -- Affected Vendors: IBM -- Affected Products: IBM solidDB -- TippingPoint(TM) IPS

THOMSON Router XSS

2011-04-04 Thread edgard . chammas
# # Vendor: THOMSON Router # Product Name: TG585 v7 # Software Release: 7.4.4.7 # Vulnerability type: XSS # Risk rating: Medium # # [Exploit] #

RealNetworks RealGames StubbyUtil.ShellCtl.1 ActiveX Control (InstallerDlg.dll v2.6.0.445) Multiple Remote Commands Execution and Code Execution Vulnerabilities

2011-04-04 Thread nospam
RealNetworks RealGames StubbyUtil.ShellCtl.1 ActiveX Control (InstallerDlg.dll v2.6.0.445) Multiple Remote Commands Execution and Code Execution Vulnerabilities tested against Internet Explorer 9, Vista sp2 download url: http://www.gamehouse.com/ background: When choosing to play with theese

Xymon monitor cross-site scripting vulnerabilities

2011-04-04 Thread Henrik Størner
Several cross-site scripting vulnerabilities have been identified in the Xymon systems- and network-monitoring tool available at http://sourceforge.net/projects/xymon/ All versions prior to 4.3.1 (released April 3, 2011) are vulnerable. I would like to thank David Ferrest for notifying me of

DC4420 - London DEFCON - April meet - Wednesday 22nd April 2011

2011-04-04 Thread Major Malfunction
I know it's 3 weeks out, but there's a lot going on that week so I wanted to make sure you've got this in your calendars! You wanted technical, you got it In March we quantum'd your minds then keylogged you with 13 lines of code: Thanks to Gregoire of IDQ for the drinks and the great

Re: DC4420 - London DEFCON - April meet - Wednesday 20th April 2011

2011-04-04 Thread Adam Laurie
Doh!!! 20th, not 22nd!!! Major Malfunction wrote: I know it's 3 weeks out, but there's a lot going on that week so I wanted to make sure you've got this in your calendars! You wanted technical, you got it In March we quantum'd your minds then keylogged you with 13 lines of code: Thanks

[ MDVSA-2011:064 ] libtiff

2011-04-04 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:064 http://www.mandriva.com/security/

ZDI-11-116: Novell File Reporter Agent XML Parsing Remote Code Execution Vulnerability

2011-04-04 Thread ZDI Disclosures
ZDI-11-116: Novell File Reporter Agent XML Parsing Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-116 April 4, 2011 -- CVE ID: CVE-2011-0994 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Novell -- Affected Products: Novell File

RealNetworks RealGames StubbyUtil.ProcessMgr.1 ActiveX Control (InstallerDlg.dll v2.6.0.445) Multiple Remote Commands Execution Vulnerabilities

2011-04-04 Thread nospam
RealNetworks RealGames StubbyUtil.ProcessMgr.1 ActiveX Control (InstallerDlg.dll v2.6.0.445) Multiple Remote Commands Execution Vulnerabilities tested against Internet Explorer 9, Vista sp2 download url: http://www.gamehouse.com/ background: When choosing to play with theese online games ex.

ZDI-11-041: (0day) Multiple Browser Node Processing Stack Overflow Vulnerability

2011-04-04 Thread ZDI Disclosures
ZDI-11-041: (0day) Multiple Browser Node Processing Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-911 April 1, 2011 -- CVE ID: CVE-C000-00FD -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Microsoft Google Mikul Apple ISC -- Affected Products:

[USN-1103-1] tex-common vulnerability

2011-04-04 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1103-1April 04, 2011 tex-common vulnerability CVE-2011-1400 === A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS

[USN-1102-1] tiff vulnerability

2011-04-04 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1102-1April 04, 2011 tiff vulnerability CVE-2011-1167 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04

Re: Xymon monitor cross-site scripting vulnerabilities

2011-04-04 Thread Henri Salo
On Sun, Apr 03, 2011 at 12:15:12PM +0200, Henrik Størner wrote: Several cross-site scripting vulnerabilities have been identified in the Xymon systems- and network-monitoring tool available at http://sourceforge.net/projects/xymon/ All versions prior to 4.3.1 (released April 3, 2011) are

[USN-1104-1] FFmpeg vulnerabilities

2011-04-04 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1104-1April 04, 2011 ffmpeg vulnerabilities CVE-2010-3429, CVE-2010-3908, CVE-2010-4704, CVE-2011-0480, CVE-2011-0722, CVE-2011-0723 === A