[Full-disclosure] [HITB-Announce] #HITB2013KUL Call for Papers

2013-04-30 Thread Hafez Kamal
Hi everyone - This is a Call for Papers for the 11th annual HITB Security Conference in Malaysia, #HITB2013KUL which takes place on the 16th and 17th of October in Kuala Lumpur. Keynote speakers for the conference will be Joe Sullivan (Chief Security Officer, Facebook) and Andy Ellis (Chief Secur

[Full-disclosure] Breakpoint 2013 Call For Papers

2013-04-30 Thread cfp
Breakpoint 2013 Call For Papers Melbourne, Australia, October 24th-25th Intercontinental Rialto http://www.ruxconbreakpoint.com .[x]. Introduction .[x]. The Ruxcon team is pleased to announce Call For Papers for Breakpoint 2013. Breakpoint showcases the work of expert security researchers fro

[Full-disclosure] n.runs-SA-2013.005 - IBM Lotus Notes - arbitrary code execution

2013-04-30 Thread security
n.runs AG http://www.nruns.com/ security(at)nruns.com n.runs-SA-2013.005 30-APR-2013 Vendors:IBM, http://www.IBM.com Product:Lotus

[Full-disclosure] [SECURITY] [DSA 2665-1] strongswan security update

2013-04-30 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2665-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez April 30, 2013

[Full-disclosure] [ MDVSA-2013:159 ] clamav

2013-04-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:159 http://www.mandriva.com/en/support/security/ __

[Full-disclosure] [ MDVSA-2013:158 ] krb5

2013-04-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:158 http://www.mandriva.com/en/support/security/ __

[Full-disclosure] [ MDVSA-2013:157 ] krb5

2013-04-30 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:157 http://www.mandriva.com/en/support/security/ __

[Full-disclosure] WowzaMediaServer SecureToken bypass (and worse)

2013-04-30 Thread Michal J.
Product: Wowza Media Server URL: http://www.wowza.com/ Description: WMS is a quite popular RTMP/HLS/HDS/RTSP streaming server Issue: By default all installations of WMS use four modules in their application's config file: base, properties, logging, flvplayback. I've found out that the `propertie

[Full-disclosure] WowzaMediaServer StorageDir escape (regression)

2013-04-30 Thread Michal J.
Product: Wowza Media Server URL: http://www.wowza.com/ Description: WMS is a quite popular RTMP/HLS/HDS/RTSP streaming server Issue: In early 2009 I reported problem with processing of requests with relative paths. The issue surfaced again. In a nutshell, you can escape Applications StorageDir