[Full-disclosure] Suggesting a new defcon event: Hackers Parliamentary Debate or HPD

2009-03-23 Thread Gadi Evron
Hi all, We posted a suggestion for a new defcon event on the defcon forums -- a debate tournament! https://forum.defcon.org/showthread.php?p=103437 If you think this is a good idea, support us on the forum. :) We'd also be happy to answer any question in email. To avoid list clutter, off-list

Re: [Full-disclosure] Kaminsky: MS security assessment tool is a 'game changer'

2009-03-23 Thread Fionnbharr
Thanks for the link, would be terrible if I missed something Kaminsky said. 2009/3/23 Ivan . ivan...@gmail.com: In case anyone missed it http://www.theregister.co.uk/2009/03/20/microsoft_crash_tool/ ___ Full-Disclosure - We believe in it.

[Full-disclosure] FreeBSD/OS X kernel bug dump

2009-03-23 Thread mu-b
All - the following are the exploits from the recent demonstrations at Apple Mac OSX = 10.4.0 local kernel root http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl.c http://www.digit-labs.org/files/exploits/xnu-hfs-fcntl.sh FreeBSD = 7.0 ktimer local kernel root

[Full-disclosure] [ MDVSA-2009:078 ] evolution-data-server

2009-03-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:078 http://www.mandriva.com/security/

[Full-disclosure] CORE-2009-0122: HP OpenView Buffer Overflows

2009-03-23 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ HP OpenView Buffer Overflows 1. *Advisory Information* Title: HP OpenView Buffer Overflows Advisory ID: CORE-2009-0122 Advisory

[Full-disclosure] [ MDVSA-2009:079 ] postgresql

2009-03-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:079 http://www.mandriva.com/security/

Re: [Full-disclosure] Slides from uCon Security Conference 2009 available online

2009-03-23 Thread Krakow Labs
Great materials indeed. Thanks! ~KL uCon Security Conference wrote: For those of you who were unable to attend to uCon 2009, speaker presentations from this year's event have been made available online. Materials can be found at http://www.ucon-conference.org/archives.php We also would

Re: [Full-disclosure] Kaminsky: MS security assessment tool is a 'game changer'

2009-03-23 Thread James Matthews
I want to gets some hands on with that tool. On Mon, Mar 23, 2009 at 1:01 PM, Fionnbharr tho...@gmail.com wrote: Thanks for the link, would be terrible if I missed something Kaminsky said. 2009/3/23 Ivan . ivan...@gmail.com: In case anyone missed it

[Full-disclosure] [USN-744-1] LittleCMS vulnerabilities

2009-03-23 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-744-1 March 23, 2009 lcms vulnerabilities CVE-2009-0581, CVE-2009-0723, CVE-2009-0733 === A security issue affects the following Ubuntu

Re: [Full-disclosure] Kaminsky: MS security assessment tool is a 'game changer'

2009-03-23 Thread T Biehn
I'd like to build up FD credibility by making vague general statements in support of any post. -Travis On Mon, Mar 23, 2009 at 2:53 PM, James Matthews nytrok...@gmail.com wrote: I want to gets some hands on with that tool. On Mon, Mar 23, 2009 at 1:01 PM, Fionnbharr tho...@gmail.com wrote:

Re: [Full-disclosure] Suggesting a new defcon event: Hackers Parliamentary Debate or HPD

2009-03-23 Thread T Biehn
You do realize that #2 is inconsistent with 1 and 3. Have you ever SEEN a parliamentary debate? They're roudiferous. -Travis On Sun, Mar 22, 2009 at 11:10 PM, Gadi Evron g...@linuxbox.org wrote: Hi all, We posted a suggestion for a new defcon event on the defcon forums -- a debate

[Full-disclosure] [USN-743-1] Ghostscript vulnerabilities

2009-03-23 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-743-1 March 23, 2009 ghostscript, gs-gpl vulnerabilities CVE-2009-0583, CVE-2009-0584 === A security issue affects the following Ubuntu

[Full-disclosure] [SECURITY] [DSA 1752-1] New webcit packages fix potential remote code execution

2009-03-23 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1752-1 secur...@debian.org http://www.debian.org/security/ Florian Weimer March 23, 2009

[Full-disclosure] [ GLSA 200903-36 ] MLDonkey: Information disclosure

2009-03-23 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-36 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-37 ] Ghostscript: User-assisted execution of arbitrary code

2009-03-23 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-37 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200903-35 ] Muttprint: Insecure temporary file usage

2009-03-23 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-35 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -