.:[ packet storm ]:.
                           
know better
know better

 Section:  .. / Last 20 Files /

 ///  File Name:MDVSA-2010-062.txt
Description:
Mandriva Linux Security Advisory 2010-062 - content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit. Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers. The updated packages have been patched to correct this issue.
Author:does not properly restrict the amount of callback data sent to an application that requests automatic decompression, when zlib is enabled,Mandriva,http://www.mandriva.com/security/.
Homepage:http://www.mandriva.com/security/
File Size:8250
Related CVE(s):CVE-2010-0734
Last Modified:Mar 19 22:41:17 2010
MD5 Checksum:05c20c297f8da93108c96e8fddbd13cc

 ///  File Name:CA20100318-01.txt
Description:
CA's support is alerting customers to security risks with CA ARCserve Backup. The version of JRE shipped with ARCserve Backup is potentially susceptible to multiple vulnerabilities and has also reached end of life. Support is providing JRE 1.6 upgrades as remediation.
Author:Kevin Kotas
Homepage:http://www3.ca.com/
File Size:2468
Last Modified:Mar 19 22:39:58 2010
MD5 Checksum:39b4f795f0d4f2b19a949182519db623

 ///  File Name:opennhrp-0.11.5.tar.bz2
Description:
OpenNHRP implements the NBMA Next Hop Resolution Protocol (as defined in RFC 2332). It makes it possible to create a dynamic multipoint VPN Linux router using NHRP, GRE, and IPsec. It aims to be Cisco DMVPN compatible.
Author:Timo Teras
Homepage:http://sourceforge.net/projects/opennhrp/
Changes:Shortcut renewals were fixed. Negative cached entries of a peer are now cleared when it sends a resolution request (which proves it\'s alive again), improving convergence time. The libev version was updated, and some related fixes were made.
File Size:128482
Last Modified:Mar 19 22:37:26 2010
MD5 Checksum:0982ce7c39bd760f0b58161f0883d4ec

 ///  File Name:libnids-1.24.tar.gz
Description:
Libnids is a library that provides a functionality of one of NIDS (Network Intrusion Detection System) components, namely E-component. It means that libnids code watches all local network traffic, cooks received datagrams a bit, and provides convenient information on them to analyzing modules of NIDS. So, if you intend to develop a custom NIDS, you do not have to build low-level network code. If you decide to use libnids, and you have got E-component ready - you can focus on implementing other parts of NIDS.
Author:Nergal
Homepage:http://libnids.sourceforge.net
Changes:This release fixes another remotely triggerable dereference in ip_fragment.c. An unofficial patch enables tracking of already established TCP connections. Missing reset of some tcp_* variables upon nids_exit has been fixed. This release has correct calculation of the radiotap header, compilation warning fixes with newer gcc, and uses pcap_get_selectable_fd() instead of pcap_fileno().
File Size:151021
Last Modified:Mar 19 22:35:28 2010
MD5 Checksum:72d37c79c85615ffe158aa524d649610

 ///  File Name:skipfish-1.03b.tgz
Description:
Skipfish is a fully automated, active web application security reconnaissance tool. It is high speed, has a low false positive rate, and is easy to use.
Author:Michal Zalewski
Homepage:http://code.google.com/p/skipfish/
File Size:179934
Last Modified:Mar 19 22:32:22 2010
MD5 Checksum:b2a37c1049c03afc8b216e73e3112c39

 ///  File Name:wazzumdating-shell.txt
Description:
Wazzum Dating Software suffers from a remote shell upload vulnerability.
Author:indoushka
File Size:1745
Last Modified:Mar 19 22:29:51 2010
MD5 Checksum:3ef4c2549dffb91ea6281278c35e35d9

 ///  File Name:edisplay-postauth.txt
Description:
eDisplay Personal FTP server version 1.0.0 post-authentication proof of concept crash exploit.
Author:loneferret
File Size:2396
Last Modified:Mar 19 22:28:22 2010
MD5 Checksum:69fffd05db4e2f001185396c204c7b56

 ///  File Name:edisplay-preauth.txt
Description:
eDisplay Personal FTP server version 1.0.0 pre-authentication proof of concept crash exploit.
Author:loneferret
File Size:3244
Last Modified:Mar 19 22:26:57 2010
MD5 Checksum:9923b0f4ff83cf3f1dff337ef4e3d6c1

 ///  File Name:ibmlotus-httpsplitting.txt
Description:
IBM Lotus version 6.x suffers from a HTTP response splitting vulnerability.
Author:Yaniv Miron
File Size:1304
Last Modified:Mar 19 22:25:08 2010
MD5 Checksum:744e9dcbb4315b585b5dab5d3fe641e4

 ///  File Name:joomlajetooltip-lfi.txt
Description:
The Joomla JE Tooltip component suffers from a local file inclusion vulnerability.
Author:Chip D3 Bi0s
File Size:1708
Last Modified:Mar 19 22:23:36 2010
MD5 Checksum:cdcc8823d483d70d240131646d7a221d

 ///  File Name:directadmin1344-xsrf.txt
Description:
DirectAdmin version 1.34.4 suffers from a cross site request forgery vulnerability.
Author:K053
File Size:3530
Last Modified:Mar 19 22:22:04 2010
MD5 Checksum:9ba28f02c4b37d7413c604296f30c7e2

 ///  File Name:islamicvoice-insecure.txt
Description:
Islamic Voice suffers from an insecure cookie handling vulnerability.
Author:jiko
File Size:640
Last Modified:Mar 19 22:20:37 2010
MD5 Checksum:ba4c423ae9874d3adf9ca99dd6e57fa1

 ///  File Name:islamicvoice-sql.txt
Description:
Islamic Voice suffers from a remote SQL injection vulnerability.
Author:jiko
File Size:742
Last Modified:Mar 19 22:19:45 2010
MD5 Checksum:1d1c86b377f2a98ef248d68cc8062d67

 ///  File Name:xilisoft-overflow.py.txt
Description:
Xilisoft Video Converter stack buffer overflow exploit that creates a malicious .yuv file.
Author:Itsecteam
File Size:1129
Last Modified:Mar 19 22:17:45 2010
MD5 Checksum:6e809f6ad5bb8fcd2245876399f61d1c

 ///  File Name:phpwind-xss.txt
Description:
PHPWind version 6.0 suffers from a cross site scripting vulnerability.
Author:Liscker
File Size:1375
Last Modified:Mar 19 22:16:30 2010
MD5 Checksum:2920e6b8677c8cec38eeaf3e0a640ce5

 ///  File Name:varicad_dwb.rb.txt
Description:
This Metasploit module exploits a stack-based buffer overflow in VariCAD 2010-2.05 EN. An attacker must send the file to victim and the victim must open the file.
Author:Alexey Sintsov,MC,n00b
Homepage:http://www.metasploit.com
File Size:2381
Last Modified:Mar 19 22:15:28 2010
MD5 Checksum:47732020345d48689e39fc3d483c642d

 ///  File Name:mediacoder-overflow.c
Description:
MediaCoder local buffer overflow exploit that creates a malicious .lst file.
Author:fl0 fl0w
File Size:14664
Last Modified:Mar 19 22:14:16 2010
MD5 Checksum:e81a3df8e03ecdd1eab70c69a94e1a46

 ///  File Name:phpscripte24liveshop-sql.txt
Description:
phpscripte24 Preisschlacht Liveshop System suffers from a remote SQL injection vulnerability.
Author:Easy Laster
File Size:1711
Last Modified:Mar 19 22:12:14 2010
MD5 Checksum:41e039e538a32fc1fc86d4a32221bc79

 ///  File Name:qualitypoint-sqlxss.txt
Description:
Quality Point version 1.0 NewsFeed suffers from cross site scripting and remote SQL injection vulnerabilities.
Author:Red-D3v1L
File Size:2054
Last Modified:Mar 19 22:10:30 2010
MD5 Checksum:6bc8cee6c6eeb80a8f9521328964afb4

 ///  File Name:dewnewphplinks-lfi.txt
Description:
DewNewPHPLinks version 2.1.0.1 suffers from a local file inclusion vulnerability.
Author:Itsecteam
File Size:695
Last Modified:Mar 18 22:39:07 2010
MD5 Checksum:d06a5a6a0e3c231c86a8f9fd5556ca56