[Full-disclosure] [ MDVSA-2010:074 ] kdebase

2010-04-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:074 http://www.mandriva.com/security/

[Full-disclosure] Hackproofing Oracle Financials 11i R12

2010-04-15 Thread Joxean Koret
Hi all, Yesterday a friend of mine told me that I forget to share with the general public one small detail about a presentation [1] I given at the conference RootedCon 2010 [2]. In the presentation there is a currently working 0day against Oracle Financials R12. The 0day is too obvious and

[Full-disclosure] [USN-890-6] CMake vulnerabilities

2010-04-15 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-890-6 April 15, 2010 cmake vulnerabilities CVE-2009-3560, CVE-2009-3720 === A security issue affects the following Ubuntu releases: Ubuntu

[Full-disclosure] [ MDVSA-2010:075 ] openoffice.org

2010-04-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:075 http://www.mandriva.com/security/

[Full-disclosure] Imperva SecureSphere Web Application Firewall and Database Firewall Bypass Vulnerability

2010-04-15 Thread Clear Skies Security
CSS10-01: Imperva SecureSphere Web Application Firewall and Database Firewall Bypass Vulnerability April 5, 2010 BACKGROUND == The Imperva SecureSphere Web Application Firewall protects web applications and sensitive data against sophisticated attacks and brute force attacks, stops

Re: [Full-disclosure] Anthology of attacks via captchas

2010-04-15 Thread MustLive
Hello Jan! You are welcome. adding you to my killfile, now. I did reciprocally (symmetrically) - added you to my blacklist. Thanks for this short conversation. In your letter there were some mistakes on which I need to answer. As for all readers of the list, as for you (in case if you'll read

[Full-disclosure] stratsec Security Advisory: SS-2010-004 Microsoft SMB Client Kernel Stack Overflow

2010-04-15 Thread stratsec Research
=== stratsec Security Advisory: SS-2010-004 === Title: Microsoft SMB Client Kernel Stack Overflow Version:1.0

[Full-disclosure] Cert-Lexsi - Microsoft Windows Media Services MMS Buffer Overflow Vulnerability

2010-04-15 Thread Fabien PERIGAUD
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cert-Lexsi - Microsoft Windows Media Services MMS Buffer Overflow Vulnerability 13/04/2010 Priority: High Type: Remote Impact: Remote code execution CVE id: CVE-2010-0478 CVSSv2 Base Score: 9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C) - -- 1. Software

[Full-disclosure] Secunia Research: Visualization Library DAT File Parsing Vulnerabilities

2010-04-15 Thread Secunia Research
== Secunia Research 14/04/2010 - Visualization Library DAT File Parsing Vulnerabilities - == Table of Contents Affected

[Full-disclosure] How to disable Java Deployment Toolkit

2010-04-15 Thread Kristof Zelechovski
Regarding the Java Deployment http://seclists.org/fulldisclosure/2010/Apr/119 Toolkit vulnerability: On Windows XP and later: open the Local Security Settings console and create a prohibition ms-its:C:\WINDOWS\help\SAFERconcepts.chm::/SRP_path.htm rule for the path

[Full-disclosure] Vulnerability in CB Captcha for Joomla and Mambo

2010-04-15 Thread MustLive
Hello Full-Disclosure! I want to warn you about security vulnerability in plugin CB Captcha (plug_cbcaptcha) for component Community Builder (com_comprofiler) for Joomla and Mambo. The posting of this advisory to mailing lists was delayed, because I found that there are two different vulnerable

[Full-disclosure] [SECURITY] [DSA 2033-1] New ejabberd packages fix denial of service

2010-04-15 Thread Sébastien Delafond
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2033-1 secur...@debian.org http://www.debian.org/security/ Sébastien Delafond April 15th, 2010

[Full-disclosure] [CVE-2010-0432] Apache OFBiz Multiple XSS Vulnerabilities

2010-04-15 Thread Lucas Apa
Bonsai Information Security - Advisory http://www.bonsai-sec.com/research/ Multiple XSS in Apache OFBiz 1. *Advisory Information* Title: Multiple XSS in Apache OFBiz Advisory ID: BONSAI-2010-0103 Advisory URL:

Re: [Full-disclosure] Vulnerabilities in phpCOIN

2010-04-15 Thread MustLive
Hello Jan, Valdis, Christian and Jeff! I'll answer at all your letters in one message. Even if I already banned Jan and he put my email to his blacklist, it's possible that he will read it in the list. First, it's good that my advisory about vulnerabilities in phpCOIN (and also many previous

Re: [Full-disclosure] Vulnerability in CB Captcha for Joomla and Mambo

2010-04-15 Thread Benji
By this point, if these advisories arent automated, you're doing it wrong. On Thu, Apr 15, 2010 at 12:24 PM, MustLive mustl...@websecurity.com.uawrote: Hello Full-Disclosure! I want to warn you about security vulnerability in plugin CB Captcha (plug_cbcaptcha) for component Community Builder

Re: [Full-disclosure] Vulnerabilities in phpCOIN

2010-04-15 Thread Benji
tl;dr you're all supposedly wrong On Thu, Apr 15, 2010 at 9:55 PM, MustLive mustl...@websecurity.com.uawrote: Hello Jan, Valdis, Christian and Jeff! I'll answer at all your letters in one message. Even if I already banned Jan and he put my email to his blacklist, it's possible that he will

[Full-disclosure] [USN-929-1] irssi vulnerabilities

2010-04-15 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-929-1 April 16, 2010 irssi vulnerabilities CVE-2010-1155, CVE-2010-1156 === A security issue affects the following Ubuntu releases: Ubuntu