Re: [Full-disclosure] AVAST Internet Security Suite - Persistent Vulnerabilities

2013-07-06 Thread security curmudgeon
Seriously? Your avast! issues weren't tested properly it seems. The command shell you invoke is running with the same privileges as the user installing/running the software. There is no privilege escalation based on the 'exploit' you report. These are not vulnerabilities.

[Full-disclosure] [SECURITY] [DSA 2720-1] icedove security update

2013-07-06 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2720-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff July 06, 2013

Re: [Full-disclosure] WordPress User Account Information Leak / Secunia Advisory SA23621

2013-07-06 Thread Tavis Ormandy
xxx ryandewhu...@gmail.com wrote: (self promotion not intended, highlighting other issues in WordPress) Check out WPScan for other such issues with WordPress that have existed for a long time but never patched. WordPress are aware of these issues but for whatever reason decided not to patch

[Full-disclosure] DAVOSET v.1.0.9

2013-07-06 Thread MustLive
Hello participants of Mailing List. After making public release of DAVOSET (http://lists.webappsec.org/pipermail/websecurity_lists.webappsec.org/2013-June/008850.html), I've made next update of the software. On Friday, 05.07.2013, DAVOSET v.1.0.9 was released - DDoS attacks via other sites