[Full-disclosure] [SECURITY] [DSA 2483-1] strongswan security update

2012-05-31 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2483-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez May 31, 2012

[Full-disclosure] VULNERABILITY LAB and why they suck hard

2012-05-31 Thread vulnerabilitylabsucks
READ THIS -> http://attrition.org/security/rants/vulnerability-lab/ Great thanks to attrition.org!!! This was really necessary! These morons have been a pain for some time now! It's more LOL than anything else! ___ Full-Disclosure - We believe in it. Cha

[Full-disclosure] MiniWeb Content-Length DoS PoC

2012-05-31 Thread bugs
MiniWeb DoS PoC Hello everybody! This vulnerability was apparently originally discovered by Luigi Auriemma You can find original advisory here: http://aluigi.altervista.org/adv/winccflex_1-adv.txt I accidentally rediscovered it in the latest version of MiniWeb - available from code.google.co

Re: [Full-disclosure] imagine ..

2012-05-31 Thread Julius Kivimäki
This man knows too much, we'll have to get rid of him. 2012/5/31 RandallM > ..if flame was hidden in angry birds > > -- > been great, thanks > RandyM > a.k.a System > > ___ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-

[Full-disclosure] ScriptFu Server Buffer Overflow in GIMP <= 2.6

2012-05-31 Thread Joseph Sheridan
Vulnerability Summary = There is a buffer overflow in the script-fu server component of GIMP (the GNU Image Manipulation Program) in all 2.6 versions (Windows and Linux versions) affecting both the script-fu console and the script-fu network server. A crafted msg to the s

Re: [Full-disclosure] NSA Cyber security program [ maybe off-topic ]

2012-05-31 Thread Jann Horn
On Mon, May 28, 2012 at 08:06:42PM -0300, Pablo wrote: > InterestingÂ… > > > > http://www.nsa.gov/academia/nat_cae_cyber_ops/index.shtml > > http://www.esecurityplanet.com/network-security/nsa-announces-cyber-security > -program-for-college-students.html > > > > This tells us that there is

[Full-disclosure] Mapserver for Windows (MS4W) Remote Code Execution

2012-05-31 Thread Mike Arnold
--- 1) Overview Title: Mapserver for Windows (MS4W) Remote Code Execution Product: Mapserver for Windows (MS4W) Product URL: http://maptools.org/ms4w/ Vendor: Gateway Geomatics Affected Versions: <=3.0.4 through 2.0 Unaffected Versions: <2.0 CVE-ID: CVE-2012-2950 Vendor notified: 2

Re: [Full-disclosure] imagine ..

2012-05-31 Thread coderman
On Thu, May 31, 2012 at 6:56 AM, RandallM wrote: > ..if flame was hidden in angry birds flame is as successful as it is precisely because it is extremely targeted. indiscriminate, promiscuous infection would defeat the purpose. however, if this same level of skill were applied to mass infection

Re: [Full-disclosure] things you can do with downloads

2012-05-31 Thread Charles Morris
Let's just ditch browsers already. =) On Wed, May 30, 2012 at 4:35 PM, Michal Zalewski wrote: > Another moderately interesting tidbit, I guess... > ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html H

[Full-disclosure] imagine ..

2012-05-31 Thread RandallM
..if flame was hidden in angry birds -- been great, thanks RandyM a.k.a System ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] [ MDVSA-2012:086 ] acpid

2012-05-31 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:086 http://www.mandriva.com/security/ _