[SECURITY] [DSA 2078-1] New kvirc packages fix arbitrary IRC command execution

2010-08-02 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2078-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff July 31, 2010

[SECURITY] [DSA 2078-1] New mapserver packages fix arbitrary code execution

2010-08-02 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-2078-1secur...@debian.org http://www.debian.org/security/ Nico Golde July 31nd, 2010

Directory Traversal Vulnerability in FTP Commander Pro

2010-08-02 Thread advisory
Vulnerability ID: HTB22511 Reference: http://www.htbridge.ch/advisory/directory_traversal_vulnerability_in_ftp_commander_pro.html Product: FTP Commander Pro Vendor: InternetSoft Corporation ( http://www.internet-soft.com/ftpcomm.htm ) Vulnerable Version: 8.0 and Probably Prior Versions Vendor

2nd. OWASP Ibero-American Web-Applications Secu rity conference (IBWAS’10) - Call for Tra ining

2010-08-02 Thread Carlos Serrão
2nd. OWASP Ibero-American Web-Applications Security conference (IBWAS’10) ISCTE – Lisbon University Institute 25th – 26th November 2010 Lisboa, Portugal http://www.ibwas.com **CALL FOR TRAINING SESSIONS** IBWAS and OWASP is currently soliciting training proposals for the OWASP Ibero-American

Directory Traversal Vulnerability in TurboFTP Server

2010-08-02 Thread advisory
Vulnerability ID: HTB22514 Reference: http://www.htbridge.ch/advisory/directory_traversal_vulnerability_in_turboftp_server.html Product: TurboFTP Server Vendor: TurboSoft, Inc ( http://turboftp.com/ ) Vulnerable Version: 1.20 Build 745 and Probably Prior Versions Vendor Notification: 19 July

[SECURITY] [DSA 2080-1] New ghostscript packages fix several vulnerabilities

2010-08-02 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2080-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff August 01, 2010

Directory Traversal Vulnerability in TurboFTP 6 Client

2010-08-02 Thread advisory
Vulnerability ID: HTB22509 Reference: http://www.htbridge.ch/advisory/directory_traversal_vulnerability_in_turboftp_6_client.html Product: TurboFTP 6 Client Vendor: TurboSoft, Inc ( http://www.turboftp.com/ ) Vulnerable Version: 6.30.806 (32 and 64 bit) and Probably Prior Versions Vendor

[SECURITY] [DSA 2082-1] New gmime2.2 packages fix arbitrary code execution

2010-08-02 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2082-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff August 02, 2010

[ MDVSA-2010:143 ] gnupg2

2010-08-02 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:143 http://www.mandriva.com/security/

[SECURITY] [DSA 2081-1] New libmikmod packages fix arbitrary code execution

2010-08-02 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2081-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff August 01, 2010

Directory Traversal Vulnerability in FTP Commander Deluxe

2010-08-02 Thread advisory
Vulnerability ID: HTB22513 Reference: http://www.htbridge.ch/advisory/directory_traversal_vulnerability_in_ftp_commander_deluxe.html Product: FTP Commander Deluxe Vendor: InternetSoft Corporation ( http://www.internet-soft.com/ftpcomm.htm ) Vulnerable Version: 9.20 and Probably Prior Versions

Directory Traversal Vulnerability in 32bit FTP Client

2010-08-02 Thread advisory
Vulnerability ID: HTB22512 Reference: http://www.htbridge.ch/advisory/directory_traversal_vulnerability_in_32bit_ftp_client.html Product: 32bit FTP Client Vendor: ElectraSoft ( http://www.electrasoft.com/32ftp.htm ) Vulnerable Version: 10.07.09 and Probably Prior Versions Vendor Notification: 19

[DCA-0006] Baby ASP Web Server DoS

2010-08-02 Thread Rodrigo Escobar
[DCA-0006] [Software]  - Baby ASP Server [Vendor Product Description]  - This program was build as an alternative for Microsoft's IIS. The main goal was to design a simple web server with support for ASP. Setting up Baby ASP Web Server is very easy: copy the executable to a directory of your

[DCA-0008] Quick 'n Easy WEB Server DoS

2010-08-02 Thread Rodrigo Escobar
[DCA-0008] [Software] - Quick 'n Easy WEB Server [Vendor Product Description] - Do you want run your own personal webserver or just want to test your ASP/PHP scripts before you upload them to your webhosting server? No problem, Quick ’n Easy Web Server can handle it! Quick ‘n Easy Web Server

[DCA-0007] Quick 'n Easy FTP Server v3.2

2010-08-02 Thread Rodrigo Escobar
[DCA-0007] [Software] - Quick 'n Easy FTP Server [Vendor Product Description] - Quick 'n Easy FTP Server Professional is a multi threaded FTP server for Windows 98/NT/XP and Vista(32 bits) that can be easily setup even by inexperienced users. New users can be easily created by a wizard which

[DCA-0005] Baby POP Server DoS

2010-08-02 Thread Rodrigo Escobar
[DCA-0005] [Software]  - Baby POP Server [Vendor Product Description]  - In the past I have done several projects related to e-mail (POP3/SMTP/IMAP4). One of the problems (at least in my company) is that there are never good test servers available. So that's why I decided to create this simple

[SECURITY] [DSA 2083-1] New moin packages fix cross-site scripting

2010-08-02 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-2083-1secur...@debian.org http://www.debian.org/security/ Nico Golde August 2nd, 2010

Information Leakage and Full path disclosure vulnerabilities in WordPress

2010-08-02 Thread MustLive
Hello Bugtraq! I want to warn you about security vulnerabilities in WordPress which I published at 30.07.2010 during my Day of bugs in WordPress 2 project. -- Advisory: Day of bugs in WordPress 2: Information Leakage and Full path disclosure vulnerabilities in

[DCA-0004] Baby FTP Server DoS

2010-08-02 Thread Rodrigo Escobar
[DCA-0004] [Software]  - Baby FTP Server [Vendor Product Description]  - Baby FTP server has only the most necessary features and is yet powerful enough to be a basis for a more complex server [Bug Description]  - The FTP Server can't handle multiple/simultaneous connections leading to