Hancom Office '.hml' file heap-based buffer overflow

2013-12-17 Thread diroverflow
There is a vulnerability in Hancom Office 2010 SE, which can be exploited by malicious people to compromise a user's system. '.hml' is a type of XML document files which is defined by Hancom. Contructing a long TEXTART tag will cause a heap-based buffer overflow. Such as: Successful exploitati

[slackware-security] seamonkey (SSA:2013-350-07)

2013-12-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] seamonkey (SSA:2013-350-07) New seamonkey packages are available for Slackware 14.0, 14.1, and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--+ patches/packa

[slackware-security] ruby (SSA:2013-350-06)

2013-12-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] ruby (SSA:2013-350-06) New ruby packages are available for Slackware 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--+ patches/p

[slackware-security] libjpeg (SSA:2013-350-02)

2013-12-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] libjpeg (SSA:2013-350-02) New libjpeg packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +-

[slackware-security] llvm (SSA:2013-350-03)

2013-12-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] llvm (SSA:2013-350-03) New llvm packages are available for Slackware 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--+ patches/packages/llvm-

[slackware-security] mozilla-thunderbird (SSA:2013-350-05)

2013-12-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2013-350-05) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--+

[slackware-security] libiodbc (SSA:2013-350-01)

2013-12-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] libiodbc (SSA:2013-350-01) New libiodbc packages are available for Slackware 13.1, 13.37, 14.0, 14.1, and -current to fix a security issue. Here are the details from the Slackware 14.1 ChangeLog: +--+ p

[SECURITY] [DSA 2820-1] nspr security update

2013-12-17 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2820-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert December 17, 2013

[slackware-security] mozilla-firefox (SSA:2013-350-04)

2013-12-17 Thread Slackware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [slackware-security] mozilla-firefox (SSA:2013-350-04) New mozilla-firefox packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--+ patches/

QuickHeal AntiVirus 7.0.0.1 - Stack Overflow Vulnerability

2013-12-17 Thread Vulnerability Lab
Document Title: === QuickHeal AntiVirus 7.0.0.1 - Stack Overflow Vulnerability References (Source): http://www.vulnerability-lab.com/get_content.php?id=1171 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6767 CVE-ID: = CVE-2013-6767 Release Date:

AST-2013-007: Asterisk Manager User Dialplan Permission Escalation

2013-12-17 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-007 ProductAsterisk SummaryAsterisk Manager User Dialplan Permission Escalation Nature of Advisory Permission Escalation

AST-2013-006: Buffer Overflow when receiving odd length 16 bit SMS message

2013-12-17 Thread Asterisk Security Team
Asterisk Project Security Advisory - AST-2013-006 ProductAsterisk SummaryBuffer Overflow when receiving odd length 16 bit SMS message

FileMaster SY-IT v3.1 iOS - Multiple Web Vulnerabilities

2013-12-17 Thread Vulnerability Lab
Document Title: === FileMaster SY-IT v3.1 iOS - Multiple Web Vulnerabilities References (Source): http://www.vulnerability-lab.com/get_content.php?id=1170 Release Date: = 2013-12-16 Vulnerability Laboratory ID (VL-ID): =

APPLE-SA-2013-12-16-1 Safari 6.1.1 and Safari 7.0.1

2013-12-17 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 APPLE-SA-2013-12-16-1 Safari 6.1.1 and Safari 7.0.1 Safari 6.1.1 and Safari 7.0.1 are now available and address the following: Safari Available for: OS X Lion v10.7.5, OS X Lion Server v10.7.5, OS X Mountain Lion v10.8.5, OS X Mavericks v10.9 Impact

APPLE-SA-2013-12-16-2 OS X Mavericks v10.9.1

2013-12-17 Thread Apple Product Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 APPLE-SA-2013-12-16-2 OS X Mavericks v10.9.1 OS X Mavericks v10.9.1 is now available and includes the content of Safari 7.0.1. For further details see "About the security content of Safari 6.1.1 and Safari 7.0.1" at http://support.apple.com/kb/HT6082