[slackware-security] mozilla-firefox (SSA:2013-260-02)

2013-09-18 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] mozilla-firefox (SSA:2013-260-02) New mozilla-firefox packages are available for Slackware 13.37, 14.0, and -current to fix security issues. Here are the details from the Slackware 14.0 ChangeLog: +--+

[slackware-security] mozilla-thunderbird (SSA:2013-260-03)

2013-09-18 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2013-260-03) New mozilla-thunderbird packages are available for Slackware 13.37, 14.0, and -current to fix security issues. Here are the details from the Slackware 14.0 ChangeLog:

[ MDVSA-2013:237 ] firefox

2013-09-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:237 http://www.mandriva.com/en/support/security/

SQL Injection in vtiger CRM

2013-09-18 Thread High-Tech Bridge Security Research
Advisory ID: HTB23168 Product: vtiger CRM Vendor: vtiger Vulnerable Version(s): 5.4.0 and probably prior Tested Version: 5.4.0 Vendor Notification: August 7, 2013 Vendor Patch: September 17, 2013 Public Disclosure: September 18, 2013 Vulnerability Type: SQL Injection [CWE-89] CVE Reference:

[SECURITY] [DSA 2759-1] iceweasel security update

2013-09-18 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2759-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff September 18, 2013

[security bulletin] HPSBMU02917 rev.1 - HP System Management Homepage (SMH) running on Linux and Windows, Remote Command Execution and Privilege Escalation

2013-09-18 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03895050 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03895050 Version: 1 HPSBMU02917

Cisco Security Advisory: Multiple Vulnerabilities in Cisco Prime Data Center Network Manager

2013-09-18 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Cisco Security Advisory: Multiple Vulnerabilities in Cisco Prime Data Center Network Manager Advisory ID: cisco-sa-20130918-dcnm Revision 1.0 For Public Release 2013 September 18 16:00 UTC (GMT

Cisco Security Advisory: Cisco Prime Central for Hosted Collaboration Solution Assurance Unauthenticated Username and Password Enumeration Vulnerability

2013-09-18 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Cisco Security Advisory: Cisco Prime Central for Hosted Collaboration Solution Assurance Unauthenticated Username and Password Enumeration Vulnerability Advisory ID: cisco-sa-20130918-pc Revision 1.0 For Public Release 2013 September 18 16:00

[SECURITY] [DSA 2760-1] chrony security update

2013-09-18 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2760-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff September 18, 2013

APPLE-SA-2013-09-18-1 iTunes 11.1

2013-09-18 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 APPLE-SA-2013-09-18-1 iTunes 11.1 iTunes 11.1 is now available and addresses the following: iTunes Available for: Windows 7, Vista, XP SP2 or later Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or

APPLE-SA-2013-09-18-2 iOS 7

2013-09-18 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 APPLE-SA-2013-09-18-2 iOS 7 iOS 7 is now available and addresses the following: Certificate Trust Policy Available for: iPhone 4 and later, iPod touch (5th generation) and later, iPad 2 and later Impact: Root certificates have been updated

[security bulletin] HPSBUX02927 SSRT101288 rev.1 - HP-UX Apache Web Server, Remote Execution of Arbitrary Code, Denial of Service (DoS)

2013-09-18 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c03922406 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03922406 Version: 1 HPSBUX02927

CVE-2013-5210 Adtran Netvanta Remote Code Injection via XSS

2013-09-18 Thread J. Oquendo
Multiple Vulnerabilities in the Adtran Netvanta 7100 Impact: Multiple Local and Remote Compromise, XSS and other Injection Attacks Version(s): firmware prior to R10.5.3.HA Author: J. Oquendo (joquendo at e-fensive dot net) I. ADVISORY Title: Multiple Vulnerabilities in Adtran Netvanta 7100 Date

Wordpress Plugin Complete Gallery Manager 3.3.3 - Arbitrary File Upload Vulnerability

2013-09-18 Thread Vulnerability Lab
Title: == Wordpress Plugin Complete Gallery Manager 3.3.3 - Arbitrary File Upload Vulnerability Date: = 2013-09-17 References: === http://www.vulnerability-lab.com/get_content.php?id=1080 VL-ID: = 1080 Common Vulnerability Scoring System:

APPLE-SA-2013-09-18-3 Xcode 5.0

2013-09-18 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 APPLE-SA-2013-09-18-3 Xcode 5.0 Xcode 5.0 is now available and addresses the following: Git Available for: OS X Mountain Lion v10.8.4 or later Impact: An attacker with a privileged network position may intercept user credentials or other sensitive

[slackware-security] glibc (SSA:2013-260-01)

2013-09-18 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] glibc (SSA:2013-260-01) New glibc packages are available for Slackware 13.0, 13.1, 13.37, 14.0, and -current to fix security issues. Here are the details from the Slackware 14.0 ChangeLog: +--+