Section: .. / 0802-advisories /
| /// File Name: |
sa29131.txt |
Description:
|
Secunia Security Advisory - rgod has discovered a vulnerability in D-Link MPEG4 SHM (Audio) Control, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29131/ | | File Size: | 2454 | | Last Modified: | Feb 27 21:32:52 2008 |
| MD5 Checksum: | 9b2d3f6ba8ddea7924ec9942fae8d408 |
|
| /// File Name: |
sa29133.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Mozilla Thunderbird, which can be exploited by malicious people to potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29133/ | | File Size: | 2484 | | Last Modified: | Feb 27 21:32:52 2008 |
| MD5 Checksum: | a983d3edb90cd552f8b8c88c568d51c9 |
|
| /// File Name: |
sa29137.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has reported a vulnerability in NetWin WebMail, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29137/ | | File Size: | 2177 | | Last Modified: | Feb 27 21:32:52 2008 |
| MD5 Checksum: | 1c3c064fbb2770f0b6758f2a20220d0b |
|
| /// File Name: |
sa29140.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in various Symantec products, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29140/ | | File Size: | 4008 | | Last Modified: | Feb 27 21:32:52 2008 |
| MD5 Checksum: | 74e70324e20800d81676213db50b9752 |
|
| /// File Name: |
sa29141.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update in xine-lib. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29141/ | | File Size: | 2064 | | Last Modified: | Feb 27 21:32:52 2008 |
| MD5 Checksum: | da88f637da2a72c8bed141a5d1851eae |
|
| /// File Name: |
sa29145.txt |
Description:
|
Secunia Security Advisory - rgod has discovered a vulnerability in RTSP MPEG4 SP Control, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29145/ | | File Size: | 2520 | | Last Modified: | Feb 27 21:32:52 2008 |
| MD5 Checksum: | 07ca193f68153bd4d7255159f427a87d |
|
| /// File Name: |
sa29082.txt |
Description:
|
Secunia Security Advisory - A security issue has been reported in Cisco IP Phone 7921, which potentially can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/29082/ | | File Size: | 2355 | | Last Modified: | Feb 27 15:02:28 2008 |
| MD5 Checksum: | 3c7c7f50be95e656aaaab7e7f74fae0a |
|
| /// File Name: |
sa29146.txt |
Description:
|
Secunia Security Advisory - rgod has discovered a vulnerability in 4XEM VatDecoder, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29146/ | | File Size: | 2447 | | Last Modified: | Feb 27 15:02:28 2008 |
| MD5 Checksum: | c9e9ac98af84f05ebbc06869ce519d64 |
|
| /// File Name: |
officescaz.txt |
Description:
|
Trend Micro OfficeScan Corporate Edition versions 8.0 Patch 2 and below and versions 7.3 Patch 3 and below suffer from buffer overflow and dead process vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | officescaz.zip | | File Size: | 4820 | | Last Modified: | Feb 27 14:57:37 2008 |
| MD5 Checksum: | c82af56fdd5d57edf3fd9c330f3f503e |
|
| /// File Name: |
sa28910.txt |
Description:
|
Secunia Security Advisory - Parvez Anwar has discovered some vulnerabilities in InterVideo WinDVD Media Center, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/28910/ | | File Size: | 2310 | | Last Modified: | Feb 27 13:48:21 2008 |
| MD5 Checksum: | 8f0824d1e1f6e23b675e84e4e2a5d6f6 |
|
| /// File Name: |
sa29128.txt |
Description:
|
Secunia Security Advisory - Hanno Boeck has discovered two vulnerabilities in Serendipity, which can be exploited by malicious users to conduct cross-site scripting and script insertion attacks.
| | Homepage: | http://secunia.com/advisories/29128/ | | File Size: | 2805 | | Last Modified: | Feb 27 13:48:21 2008 |
| MD5 Checksum: | 6bdec746359fb8d10a1ecda87562d168 |
|
| /// File Name: |
dsa-1510-1.txt |
Description:
|
Debian Security Advisory 1510-1 - Chris Evans discovered a buffer overflow in the color space handling code of the Ghostscript PostScript/PDF interpreter, which might result in the execution of arbitrary code if a user is tricked into processing a malformed file.
| | Homepage: | http://www.debian.org/security | | File Size: | 12758 | | Related CVE(s): | CVE-2008-0411 | | Last Modified: | Feb 27 13:48:09 2008 |
| MD5 Checksum: | 494c001d4244d76d9882a2ef7cc2fcc3 |
|
| /// File Name: |
2008_symarkpb.pdf |
Description:
|
Symark PowerBroker Security Advisory - A vulnerability has been identified in Symark's PowerBroker suite that allows an attacker with local access to gain root access. Versions up to and including 5.0.1 are vulnerable.
| | Author: | Michael Ligh, Greg Sinclair | | Homepage: | http://www.symark.com/ | | File Size: | 107012 | | Last Modified: | Feb 27 13:31:35 2008 |
| MD5 Checksum: | 35be0bd2cbb4b0b7fba154ae9bfa29e8 |
|
| /// File Name: |
sa25400.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for diatheke. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/25400/ | | File Size: | 13966 | | Last Modified: | Feb 27 01:35:25 2008 |
| MD5 Checksum: | c64d8b1c9cb3e438071949b3eb4cb15d |
|
| /// File Name: |
sa29102.txt |
Description:
|
Secunia Security Advisory - xcorpitx has reported a vulnerability in Porar Webboard, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/29102/ | | File Size: | 2155 | | Last Modified: | Feb 27 01:35:25 2008 |
| MD5 Checksum: | 6d828f77d0066d1d5f4befe796520ad8 |
|
| /// File Name: |
sa29116.txt |
Description:
|
Secunia Security Advisory - Omar Singer has discovered a vulnerability in Plume CMS, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/29116/ | | File Size: | 2364 | | Last Modified: | Feb 27 01:35:25 2008 |
| MD5 Checksum: | 2c58b24b66af8ed27d0decf0081ea68f |
|
| /// File Name: |
sa29136.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for kvm. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/29136/ | | File Size: | 2144 | | Last Modified: | Feb 27 01:35:25 2008 |
| MD5 Checksum: | 99e8ba601371632fa1bc38d0ef1e6dc5 |
|
| /// File Name: |
sa29113.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for wyrd. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/29113/ | | File Size: | 2191 | | Last Modified: | Feb 26 19:38:53 2008 |
| MD5 Checksum: | 659692391c129ae20e9b7782efd6a91a |
|
| /// File Name: |
02.26.08-3.txt |
Description:
|
iDefense Security Advisory 02.26.08 - Remote exploitation of a heap based buffer overflow vulnerability in Mozilla Organization's Thunderbird could allow an attacker to execute arbitrary code with the privileges of the current user. The vulnerability exists when parsing the external-body MIME type in an electronic mail. When calculating the number of bytes to allocate for a heap buffer, sufficient space is not reserved for all of the data being copied into the buffer. This results in up to 3 bytes of the buffer being overflowed, potentially allowing for the execution of arbitrary code. iDefense has confirmed the existence of this vulnerability in Thunderbird version 2.0.0.9 on Linux and Windows. Previous versions may also be affected.
| | Author: | regenrecht | | Homepage: | http://www.idefense.com/ | | File Size: | 3904 | | Related CVE(s): | CVE-2008-0304 | | Last Modified: | Feb 26 19:38:41 2008 |
| MD5 Checksum: | ddaf07621a1a38f7abc2ec79b61d446a |
|
| /// File Name: |
02.26.08-2.txt |
Description:
|
iDefense Security Advisory 02.26.08 - Remote exploitation of a stack based buffer overflow vulnerability in Symantec Scan Engine version 5.1.2 could allow an unauthenticated attacker to execute arbitrary code with the privileges of the scan engine process. Symantec Scan Engine listens on TCP port 1344 to accept files for scanning using the Internet Content Adaptation Protocol (ICAP). If the service is sent a specially malformed RAR file, a stack-based buffer overflow will occur. iDefense has confirmed this vulnerability in the Linux build of the Symantec Scan Engine version 5.1.2. This issue does not affect the Windows build of the product. Previous versions are suspected to be vulnerable.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3619 | | Related CVE(s): | CVE-2008-0309 | | Last Modified: | Feb 26 19:37:32 2008 |
| MD5 Checksum: | 28d026ef014680041c7b0b128293e0ef |
|
| /// File Name: |
02.26.08-1.txt |
Description:
|
iDefense Security Advisory 02.26.08 - Remote exploitation of a Denial of Service vulnerability in Symantec Scan Engine version 5.1.2 could allow an unauthenticated attacker to create a denial of service (DoS) condition. Symantec Scan Engine listens on TCP port 1344 to accept files for scanning using the Internet Content Adaptation Protocol (ICAP). If the service is sent a malformed RAR file, the service will consume massive amounts of memory. This can result in a denial of service condition for the application and operating system. iDefense confirmed the existence of this vulnerability in Symantec Scan Engine 5.1.2. This issue affects both the Windows and Linux builds of the product. Previous versions are suspected to be vulnerable.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3570 | | Related CVE(s): | CVE-2008-0308 | | Last Modified: | Feb 26 19:36:40 2008 |
| MD5 Checksum: | 3bdef4d0c069163afa87e6e53aa82965 |
|
| /// File Name: |
glsa-200802-12.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200802-12 - Damian Frizza and Alfredo Ortega (Core Security Technologies) discovered a stack-based buffer overflow within the open_flac_file() function in the file demux_flac.c when parsing tags within a FLAC file (CVE-2008-0486). A buffer overflow when parsing ASF headers, which is similar to CVE-2006-1664, has also been discovered. Versions less than 1.1.10.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2879 | | Related CVE(s): | CVE-2006-1664, CVE-2008-0486 | | Last Modified: | Feb 26 19:35:06 2008 |
| MD5 Checksum: | 2f5040c756ce9cf9fe09574a5577bc2e |
|
| /// File Name: |
MDVSA-2008-051.txt |
Description:
|
Mandriva Linux Security Advisory - A flaw was found in how CUPS handled the addition and removal of remote printers via IPP that could allow a remote attacker to send a malicious IPP packet to the UDP port causing CUPS to crash.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 7403 | | Related CVE(s): | CVE-2008-0886 | | Last Modified: | Feb 26 19:21:48 2008 |
| MD5 Checksum: | c1ad1151b4d1a2ed06c0b213eb2cba4a |
|
| /// File Name: |
MDVSA-2008-050.txt |
Description:
|
Mandriva Linux Security Advisory - Dave Camp at Critical Path Software discovered a buffer overflow in CUPS 1.1.23 and earlier could allow local admin users to execute arbitrary code via a crafted URI to the CUPS service. The Red Hat Security Team also found two flaws in CUPS 1.1.x where a malicious user on the local subnet could send a set of carefully crafted IPP packets to the UDP port in such a way as to cause CUPS to crash or consume memory and lead to a CUPS crash. Finally, another flaw was found in how CUPS handled the addition and removal of remote printers via IPP that could allow a remote attacker to send a malicious IPP packet to the UDP port causing CUPS to crash.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3852 | | Related CVE(s): | CVE-2007-5848, CVE-2008-0596, CVE-2008-0597, CVE-2008-0886 | | Last Modified: | Feb 26 19:21:01 2008 |
| MD5 Checksum: | 81ed5a71558215cc1fa00282444155b3 |
|
|
|
|
|