Section: .. / 0611-advisories /
| /// File Name: |
asterisk-bugtraq.asc |
Description:
|
A vulnerability exists in the SIP channel driver (channels/chan_sip.c) in all versions of Asterisk prior to 1.2.13. Local and remote attackers are able to cause a denial of service (resource consumption) via unspecified vectors that result in the creation of "a real pvt structure" that uses more resources than necessary.
| | Author: | Jesus Oquendo | | Homepage: | http://www.infiltrated.net/ | | Related Exploit: | asteroidv1.tar.gz | | File Size: | 2514 | | Related CVE(s): | CVE-2006-5445 | | Last Modified: | Nov 2 21:14:59 2006 |
| MD5 Checksum: | e5c5eb45d2ab59585538ccce2b60b60b |
|
| /// File Name: |
SSRT061266.txt |
Description:
|
HP Security Bulletin - A security vulnerability has been identified in OpenSSL used in HP VirtualVault 4.7, 4.6, 4.5 and HP WebProxy that may allow remote unauthorized access.
| | Homepage: | http://www.hp.com/ | | File Size: | 7663 | | Related CVE(s): | CVE-2006-4339 | | Last Modified: | Nov 2 21:10:30 2006 |
| MD5 Checksum: | 7059a2e4d6a736a8705ab8cbc3df5c63 |
|
| /// File Name: |
MOKB-02-11-2006.html |
Description:
|
The squashfs module of the Linux kernel (2.6.x) fails to properly handle corrupted fs structures, leading to a denial of service and possible data corruption condition. A specially crafted squashfs image will cause the kernel to double free a buffer when a read operation is performed on the corrupted filesystem.
| | Author: | LMH | | Homepage: | http://projects.info-pull.com/ | | Related Exploit: | MOKB-02-11-2006.img.gz | | File Size: | 6497 | | Last Modified: | Nov 2 21:02:31 2006 |
| MD5 Checksum: | 0cf04f31eeb59d9181f07ed34f2987f8 |
|
| /// File Name: |
Armorize-ADV-2006-0008.txt |
Description:
|
Armorize Technologies Security Advisory Armorize-ADV-2006-0008 - ZendGData Preview version 0.2.0 is susceptible to a cross site scripting vulnerability.
| | Author: | Armorize | | Homepage: | http://www.armorize.com | | File Size: | 1996 | | Last Modified: | Nov 2 20:44:08 2006 |
| MD5 Checksum: | ccf50576537bf0e4315931f35d89e2f0 |
|
| /// File Name: |
walla-xss.txt |
Description:
|
The Web Mail service by "Walla! Communications LTD" suffers from a cross site scripting flaw.
| | Author: | Tal Argoni | | File Size: | 1906 | | Last Modified: | Nov 2 20:42:54 2006 |
| MD5 Checksum: | a14fb3f6596c2db75bc4714e0e553547 |
|
| /// File Name: |
virtech-xss.txt |
Description:
|
The VIRtechs Netquery system suffers from a cross site scripting flaw.
| | Author: | Tal Argoni | | File Size: | 1846 | | Last Modified: | Nov 2 20:42:15 2006 |
| MD5 Checksum: | a86194c66a8c5cd85e4dbaffa70d6b3d |
|
| /// File Name: |
webmail-xss.txt |
Description:
|
The Web Mail platform by "Mirapoint" suffers from a cross site scripting flaw.
| | Author: | Tal Argoni | | File Size: | 2306 | | Last Modified: | Nov 2 20:41:29 2006 |
| MD5 Checksum: | e6a6b2cc18b61d5b4529491d0d66c77f |
|
| /// File Name: |
iplanet-xss.txt |
Description:
|
The iPlanet Messaging Server Messenger Express by "Sun" suffers from a cross site scripting flaw.
| | Author: | Tal Argoni | | File Size: | 2010 | | Last Modified: | Nov 2 20:40:55 2006 |
| MD5 Checksum: | e513e3a78a7efc79a99c6142d1beb6b7 |
|
| /// File Name: |
BlooMooWeb.txt |
Description:
|
BlooMooWeb's ActiveX control suffers from multiple vulnerabilities.
| | Author: | Max Gipehtykrop | | File Size: | 6328 | | Last Modified: | Nov 2 20:38:46 2006 |
| MD5 Checksum: | cafc953a42cc6cf6dd40ace94f98d133 |
|
| /// File Name: |
USN-373-1.txt |
Description:
|
Ubuntu Security Notice 373-1: Race conditions were discovered in mutt's handling of temporary files. Under certain conditions when using a shared temp directory (the default), other local users could overwrite arbitrary files owned by the user running mutt. This vulnerability is more likely when the temp directory is over NFS.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4945 | | Last Modified: | Nov 2 19:46:29 2006 |
| MD5 Checksum: | 891f01c876d47c20c081d75524f1a6db |
|
| /// File Name: |
cisco-sa-20061101-csamc.txt |
Description:
|
Cisco Security Advisory - cisco-sa-20061101-csamc: Cisco Security Agent Management Center (CSAMC) contains an administrator authentication bypass vulnerability when configured to use an external Lightweight Directory Access Protocol (LDAP) server for authentication.
| | Homepage: | http://www.cisco.com | | File Size: | 10939 | | Last Modified: | Nov 2 19:39:42 2006 |
| MD5 Checksum: | 19c5e35ff0855aabb2fd78e20fa9a9be |
|
| /// File Name: |
Daronet-viewimage.txt |
Description:
|
Daronet Internet Solutions website platform is prone to a cross site scripting vulnerability in "ViewImage.asp"
| | Author: | LegendaryZion | | Homepage: | http://www.zion-security.com | | File Size: | 2497 | | Last Modified: | Nov 2 19:37:22 2006 |
| MD5 Checksum: | b8e4947c6d8131e7fa18da7ef16a1a2e |
|
| /// File Name: |
B-FOCuS_router.txt |
Description:
|
The B-FOCuS Wireless 802.11b and g ADSL2+ Router by "ECI Telecom LTD" is prone to a directory listing Vulnerability in the web based management system.
| | Author: | LegendaryZion | | Homepage: | http://www.zion-security.com | | File Size: | 824 | | Last Modified: | Nov 2 19:35:37 2006 |
| MD5 Checksum: | 3f1a8054b332d85f427705c5514e5ed9 |
|
| /// File Name: |
10.31.06-1.txt |
Description:
|
iDefense Security Advisory 10.31.06 - Novell iManager Tomcat DoS Vulnerability: Remote exploitation of a DoS vulnerability in Novell Inc.'s iManager could allow attackers to crash the iManager Tomcat server.
| | Homepage: | http://www.idefense.com/intelligence/vulnerabilities/ | | File Size: | 2858 | | Last Modified: | Nov 2 19:33:23 2006 |
| MD5 Checksum: | 00b13a1612fd5ace43c33cec4027ae0d |
|
| /// File Name: |
10.31.06-2.txt |
Description:
|
iDefense Security Advisory 10.31.06 - Sophos Anti-Virus Petite File Denial of Service Vulnerability: Remote exploitation of a denial of service vulnerability in version 5.1 of Sophos Anti-Virus could result in unusable system conditions. The problem manifests itself when the scanning engine encounters an executable compressed with petite that contains a large number of sections.
| | Homepage: | http://www.idefense.com/intelligence/vulnerabilities/ | | File Size: | 2943 | | Last Modified: | Nov 2 19:32:42 2006 |
| MD5 Checksum: | ec154f68f717003f05c2ccf57ada6f55 |
|
| /// File Name: |
10.27.06-1.txt |
Description:
|
iDefense Security Advisory 10.27.06 - Novell eDirectory NMAS BerDecodeLoginDataRequeset DoS Vulnerability: Remote exploitation of a denial of service (DoS) vulnerability in Novell Inc.'s eDirectory product could allow an attacker to force the running daemon to cease servicing requests.
| | Homepage: | http://www.idefense.com/intelligence/vulnerabilities/ | | File Size: | 3738 | | Last Modified: | Nov 2 19:31:53 2006 |
| MD5 Checksum: | 99f4ad06ebb5da602cb14b3e9070ebb7 |
|
| /// File Name: |
USN-374-1.txt |
Description:
|
Ubuntu Security Notice 374-1: An integer overflow was discovered in the DOC file parser of the wv library. By tricking a user into opening a specially crafted MSWord (.DOC) file, remote attackers could execute arbitrary code with the user's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4087 | | Last Modified: | Nov 2 19:30:14 2006 |
| MD5 Checksum: | 3e6c8e2766100693559884dedfd96122 |
|
| /// File Name: |
SSRT061265-1.txt |
Description:
|
HPSBUX02164 SSRT061265 rev.1 - HP-UX VirtualVault Running Apache 1.3.X Remote Denial of Service (DoS) and Arbitrary Code Execution.
| | Homepage: | http://www.hp.com | | File Size: | 7294 | | Last Modified: | Nov 2 19:29:19 2006 |
| MD5 Checksum: | 1c42d78896f3e9ae89efbf6a18f54593 |
|
| /// File Name: |
SSRT061269-1.txt |
Description:
|
HPSBUX02172 SSRT061269 rev.1 - HP-UX VirtualVault running Apache Remote Execution of Arbitrary Code, Denial of Service (DoS) , and Unauthorized Access
| | Homepage: | http://www.hp.com | | File Size: | 6181 | | Last Modified: | Nov 2 19:28:28 2006 |
| MD5 Checksum: | dd214bfb8e395c8dfeaf4d70cc37a95c |
|
| /// File Name: |
USN-371-1.txt |
Description:
|
Ubuntu Security Notice 371-1: An error was found in Ruby's CGI library that did not correctly check for the end of multipart MIME requests. Using a crafted HTTP request, a remote user could cause a denial of service, where Ruby CGI applications would end up in a loop, monopolizing a CPU.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 35183 | | Last Modified: | Nov 2 19:24:37 2006 |
| MD5 Checksum: | db049394245c6abb33ab670b9606a8ac |
|
| /// File Name: |
USN-370-1.txt |
Description:
|
Ubuntu Security Notice 370-1: cstone and Rich Felker discovered a programming error in the UTF8 string handling code of "screen" leading to a denial of service. If a crafted string was displayed within a screen session, screen would crash or possibly execute arbitrary code.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 6277 | | Last Modified: | Nov 2 19:24:32 2006 |
| MD5 Checksum: | 5b4a81192dffbf487afe42b9c0e0875c |
|
| /// File Name: |
USN-372-1.txt |
Description:
|
Ubuntu Security Notice 372-1: M. Joonas Pihlaja discovered that ImageMagick did not sufficiently verify the validity of PALM and DCM images. When processing a specially crafted image with an application that uses imagemagick, this could be exploited to execute arbitrary code with the application's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 20129 | | Last Modified: | Nov 2 19:24:27 2006 |
| MD5 Checksum: | d03135b6964ce1ae856b12e458c1ff0f |
|
| /// File Name: |
USN-369-2.txt |
Description:
|
Ubuntu Security Notice 369-2: multiple vulnerabilities in postgresql-8.1 server.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 12260 | | Last Modified: | Nov 2 19:24:21 2006 |
| MD5 Checksum: | 8c226ca83dec25799b2980fe173bd0ab |
|
| /// File Name: |
sa22633.txt |
Description:
|
Secunia Security Advisory - Nortel has acknowledged a vulnerability in OpenSSL included in various Nortel products, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22633/ | | File Size: | 3102 | | Last Modified: | Nov 2 19:05:01 2006 |
| MD5 Checksum: | c71c2ddd79ac625f9548b31de2e3e310 |
|
|
|
|
|