Malicious Code Execution in PCI Expansion ROM

2012-07-03 Thread Adam Behnke
The malicious code in x86/x64 firmware can potentially reside in many places. One of them is in the PCI expansion ROM. In the past, the small amount of memory during PCI expansion ROM execution acted as a hindrance to malicious code. The limited space for code and data limited the possible tasks

[IA30] Photodex ProShow Producer v5.0.3256 Local Buffer Overflow Vulnerability

2012-07-03 Thread Inshell Security
Inshell Security Advisory http://www.inshell.net/ 1. ADVISORY INFORMATION --- Product:Photodex ProShow Producer Vendor URL: www.photodex.com Type: Stack-based Buffer Overflow [CWE-121] Date found: 2012-06-06 Date published: 2012-07-02 CVSSv2 Score:

[SECURITY] [DSA 2506-1] libapache-mod-security security update

2012-07-03 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2506-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez July 02, 2012

Slideware of IPv6 hacking training (HIP 2012 edition), and future trainings (Portugal Belgium)

2012-07-03 Thread Fernando Gont
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Folks, We have posted online part of the materials of the Hack In Paris 2012 edition of our training Hacking IPv6 Networks. The slideware is available at:

[security bulletin] HPSBUX02795 SSRT100878 rev.1 - HP-UX Running BIND, Remote Denial of Service (DoS)

2012-07-03 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20566.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03388901 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03388901 Version: 1 HPSBUX02795