[Full-disclosure] Paper on the law and Implantable Devices security

2010-07-26 Thread Gadi Evron
A new research paper from the Freedom And Law Center deals with issues that some of us keep raising these past few years, and does a good job at it - bionic hacking (or cybernetic hacking if you prefer). Killed by Code: Software Transparency in Implantable Medical Devices outlines some of the

Re: [Full-disclosure] Paper on the law and Implantable Devices security

2010-07-26 Thread Jeffrey Walton
...even if from the legal standpoint with the main concern of liability. Should that be lack of liability? (Its amazing what corporate America gets away with by bribing congress (err, 'PAC contributions')) On Mon, Jul 26, 2010 at 6:44 AM, Gadi Evron g...@linuxbox.org wrote: A new research

[Full-disclosure] Mac OS X WebDAV kernel extension local denial-of-service

2010-07-26 Thread Dan Rosenberg
===  Mac OS X WebDAV kernel extension local denial-of-service  July 26, 2010  CVE-2010-1794 === ==Description== Web-based Distributed Authoring and Versioning, or

Re: [Full-disclosure] Paper on the law and Implantable Devices security

2010-07-26 Thread Shawn Merdinger
Hi Gadi, On Mon, Jul 26, 2010 at 6:44 AM, Gadi Evron g...@linuxbox.org wrote: A new research paper from the Freedom And Law Center deals with issues Killed by Code: Software Transparency in Implantable Medical Devices One of the more useful aspects I found in that paper are the references to

[Full-disclosure] [USN-958-1] Thunderbird vulnerabilities

2010-07-26 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-958-1 July 26, 2010 thunderbird vulnerabilities CVE-2010-0654, CVE-2010-1205, CVE-2010-1211, CVE-2010-1212, CVE-2010-1213, CVE-2010-2752, CVE-2010-2753, CVE-2010-2754

[Full-disclosure] [USN-957-2] Firefox and Xulrunner vulnerability

2010-07-26 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-957-2 July 26, 2010 firefox, firefox-3.0, xulrunner-1.9.2 vulnerability CVE-2010-2755 === A security issue affects the following Ubuntu

[Full-disclosure] Foofus.net Security Advisory: Symantec AMS Intel Alert Handler service Design Flaw

2010-07-26 Thread spider
== Foofus.net Security Advisory: foofus-20100725 == Title: Symantec Antivirus Corporate Edition AMS Intel Alert Handler Version:10.1.8.8000 and earlier Vendor: Symantec Release

[Full-disclosure] [USN-930-6] Firefox and Xulrunner vulnerability

2010-07-26 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-930-6 July 26, 2010 firefox, firefox-3.0, xulrunner-1.9.2 vulnerability CVE-2010-2755 === A security issue affects the following Ubuntu

Re: [Full-disclosure] Expired certificate

2010-07-26 Thread Marsh Ray
On 07/25/2010 07:24 PM, Dan Kaminsky wrote: You know, it's strange. I never hear stories about networks being taken down for nonpayment of electric bills, but we have straight up UI support for certificate errors. Why do you think that is? Because the Accounting department is in charge of

[Full-disclosure] FuzzDiff tool

2010-07-26 Thread Dan Rosenberg
Hello, I'd like to announce FuzzDiff, a simple tool to help make crash analysis during file format fuzzing a bit easier.  I'm sure many people have written similar tools for their own purposes, but I haven't seen any that are publicly available. Hopefully at least one person finds it useful.

[Full-disclosure] [USN-964-1] Likewise Open vulnerability

2010-07-26 Thread Kees Cook
=== Ubuntu Security Notice USN-964-1 July 26, 2010 likewise-open vulnerability CVE-2010-0833 === A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS