Section: .. / 0803-advisories /
| /// File Name: |
MDVSA-2008-078.txt |
Description:
|
Mandriva Linux Security Advisory - OpenSSH allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when another process is listening on the associated port.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 9256 | | Related CVE(s): | CVE-2008-1483 | | Last Modified: | Mar 27 02:27:42 2008 |
| MD5 Checksum: | de77ae8f4d8fdb1e6877407958c10937 |
|
| /// File Name: |
MDVSA-2008-079.txt |
Description:
|
Mandriva Linux Security Advisory - A stack-based buffer overflow in sarg (Squid Analysis Report Generator) allowed remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. A cross-site scripting vulnerability in sarg version 2.x prior to 2.2.5 allowed remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. In addition, a number of other fixes have been made such as making the getword() function more robust which should prevent any overflows, other segfaults have been fixed, and the useragent report is now more consistent with the other reports.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3896 | | Related CVE(s): | CVE-2008-1168, CVE-2008-1167 | | Last Modified: | Mar 28 17:12:30 2008 |
| MD5 Checksum: | 6af2f57b4645d90a917e19aa7812867a |
|
| /// File Name: |
MDVSA-2008-080.txt |
Description:
|
Mandriva Linux Security Advisory - A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 2.0.0.13.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 61836 | | Related CVE(s): | CVE-2007-4879, CVE-2008-1195, CVE-2008-1233, CVE-2008-1234, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237, CVE-2008-1238, CVE-2008-1240, CVE-2008-1241 | | Last Modified: | Mar 29 15:49:18 2008 |
| MD5 Checksum: | 2218b65744065e433bf5b605e7dd01af |
|
| /// File Name: |
meccaffi.txt |
Description:
|
McAfee Framework versions 3.6.0.569 and below suffer from a format string vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | meccaffi.zip | | File Size: | 2006 | | Last Modified: | Mar 13 01:54:38 2008 |
| MD5 Checksum: | 13ac7c2291390d7e54f0ea02f534bab8 |
|
| /// File Name: |
MITKRB5-SA-2008-002.txt |
Description:
|
MIT krb5 Security Advisory 2008-002 - Two bugs in the RPC library server code, used in the kadmin server, causes an array overrun if too many file descriptors are opened. Memory corruption can result.
| | Homepage: | http://web.mit.edu/ | | File Size: | 7715 | | Related CVE(s): | CVE-2008-0947, CVE-2008-0948 | | Last Modified: | Mar 18 22:22:52 2008 |
| MD5 Checksum: | 548fe30eb399d6ce1de24ef032f0fda9 |
|
| /// File Name: |
MSA01240108.txt |
Description:
|
Internet Explorer 7 allows the setting of header "Transfer Encoding: chunked" in setRequestHeader exposing the browser to HTTP request splitting/smuggling attacks.
| | Author: | Stefano Di Paola | | Homepage: | http://www.mindedsecurity.com/ | | File Size: | 4869 | | Last Modified: | Mar 21 18:23:16 2008 |
| MD5 Checksum: | 79a4a9d6a18fb214f42a3063df7b678f |
|
| /// File Name: |
MSA02240108.txt |
Description:
|
Internet Explorer 7 allows the overwrite of headers such as Content-Length, Host and Referer, exposing the browser to HTTP request splitting attacks.
| | Author: | Stefano Di Paola | | Homepage: | http://www.mindedsecurity.com/ | | File Size: | 4114 | | Last Modified: | Mar 21 18:24:17 2008 |
| MD5 Checksum: | 0ba0b74eea72c57621a0aad45af45c2f |
|
| /// File Name: |
MU-200803-01.txt |
Description:
|
The Mu Security Research team has found two security issues in the SDP parser in Asterisk 1.4.18. One is an invalid write to an attacker-controllable, almost arbitrary memory location and the other is a stack buffer overflow with limited attacker-controllable values.
| | Author: | Mu Security research team | | Homepage: | http://labs.musecurity.com/ | | File Size: | 4075 | | Related CVE(s): | CVE-2008-1289 | | Last Modified: | Mar 19 19:27:01 2008 |
| MD5 Checksum: | 1acd9d2850c2a2dd67e09664685f20d1 |
|
| /// File Name: |
perforces.txt |
Description:
|
Perforce Servers versions 2007.3/143793 and below suffer from NULL pointer, invalid memory access, and endless loop vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | perforces.zip | | File Size: | 2409 | | Last Modified: | Mar 12 16:24:26 2008 |
| MD5 Checksum: | 90963f758e9a1066b4a6667ef375c221 |
|
| /// File Name: |
pt360-dos.txt |
Description:
|
The pt360 Tool Suite Pro versions 2.0.3901.0 and below suffer from a denial of service vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | tftpx.zip | | File Size: | 2820 | | Last Modified: | Mar 12 23:37:50 2008 |
| MD5 Checksum: | 42c6a1239b56b98765a4b0754a58cb5d |
|
| /// File Name: |
R7-0032.txt |
Description:
|
Internet Explorer 5 and 6 are vulnerable to a File Transfer Protocol (FTP) CSRF-like command injection attack, whereby an attacker could execute arbitrary commands on an unsuspecting user's authenticated or unauthenticated FTP session.
| | Author: | Derek Abdine | | Homepage: | http://www.rapid7.com/ | | File Size: | 6131 | | Last Modified: | Mar 13 00:11:33 2008 |
| MD5 Checksum: | aeaa9d97f40245e844c59f5f515ba642 |
|
| /// File Name: |
realplayer-activex.txt |
Description:
|
The Real Networks RealPlayer ActiveX controller appears to suffer from a heap corruption vulnerability.
| | Author: | Elazar Broad | | File Size: | 1605 | | Last Modified: | Mar 12 20:28:29 2008 |
| MD5 Checksum: | e3deff0c9f224a77d42d8d83eb5fec3a |
|
| /// File Name: |
sa27885.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered some vulnerabilities in Symantec Backup Exec for Windows Servers, which can be exploited by malicious people to overwrite arbitrary files or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27885/ | | File Size: | 3491 | | Last Modified: | Mar 3 13:30:08 2008 |
| MD5 Checksum: | 9e2b5d9e26e0b79f43d7f15d5563c960 |
|
| /// File Name: |
sa28203.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Orb, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28203/ | | File Size: | 2395 | | Last Modified: | Mar 26 16:17:54 2008 |
| MD5 Checksum: | b2cd9878b0b8a996f5db6ff4c311f4c4 |
|
| /// File Name: |
sa28659.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been discovered in Numara FootPrints, which can be exploited by malicious users to conduct script insertion attacks and by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/28659/ | | File Size: | 2744 | | Last Modified: | Mar 12 13:55:23 2008 |
| MD5 Checksum: | bfe72c5f1a8ff721accf5309a1749ed5 |
|
| /// File Name: |
sa28694.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in xine-lib, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/28694/ | | File Size: | 2441 | | Last Modified: | Mar 20 16:39:31 2008 |
| MD5 Checksum: | b7d96461dc40fc468b40a4c5f424f630 |
|
| /// File Name: |
sa29025.txt |
Description:
|
Secunia Security Advisory - Nir Goldshlager (Avnet) has reported a vulnerability in IBM Lotus QuickPlace, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/29025/ | | File Size: | 2341 | | Last Modified: | Mar 12 13:55:23 2008 |
| MD5 Checksum: | ad7c97ff148e0f12f2251afc675d8f2e |
|
| /// File Name: |
sa29057.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Evolution, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29057/ | | File Size: | 2523 | | Last Modified: | Mar 12 13:55:23 2008 |
| MD5 Checksum: | c7a9ad3b8a8a4124e9dd2065fa947c4e |
|
| /// File Name: |
sa29098.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29098/ | | File Size: | 17575 | | Last Modified: | Mar 3 20:59:13 2008 |
| MD5 Checksum: | 4e995d1a79245b4c6a2996394d46538f |
|
| /// File Name: |
sa29101.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for ghostscript. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29101/ | | File Size: | 13310 | | Last Modified: | Mar 3 13:30:08 2008 |
| MD5 Checksum: | e7f8118ea771e7998f6ff3815497a868 |
|
| /// File Name: |
sa29126.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in pfSense, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/29126/ | | File Size: | 2202 | | Last Modified: | Mar 3 17:45:20 2008 |
| MD5 Checksum: | e14a3ba0f3e27c118156ad59766e3f9e |
|
| /// File Name: |
sa29134.txt |
Description:
|
Secunia Security Advisory - CraCkEr has reported a vulnerability in GROUP-E Collaboration Software, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/29134/ | | File Size: | 2419 | | Last Modified: | Mar 4 17:48:04 2008 |
| MD5 Checksum: | 985993c7e1c8ed82f9ab145480ed481b |
|
| /// File Name: |
sa29143.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for phpMyAdmin. This fixes a vulnerability, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/29143/ | | File Size: | 2177 | | Last Modified: | Mar 4 21:01:47 2008 |
| MD5 Checksum: | bdd08d70855c255083643fb6aa4b623e |
|
| /// File Name: |
sa29147.txt |
Description:
|
Secunia Security Advisory - rPath has issued an update for espgs. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29147/ | | File Size: | 2021 | | Last Modified: | Mar 3 13:30:08 2008 |
| MD5 Checksum: | d7ec66460f209bb445f33d296862429a |
|
|
|
|
|