Section: .. / 0611-advisories /
| /// File Name: |
MDKSA-2006-202.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-202 - Multiple integer overflows in the WV library in wvWare (formerly mswordview) before 1.2.3, as used by AbiWord?, KWord, and possibly other products, allow user-assisted remote attackers to execute arbitrary code via a crafted Microsoft Word (DOC) file that produces (1) large LFO clfolvl values in the wvGetLFO_records function or (2) a large LFO nolfo value in the wvGetFLO_PLF function.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 4442 | | Related CVE(s): | CVE-2006-4513 | | Last Modified: | Nov 8 21:47:44 2006 |
| MD5 Checksum: | 9327bef1f1b820d3045c101cf5dd8e08 |
|
| /// File Name: |
lackenv.txt |
Description:
|
A lack of environment sanitization in FreeBSD, OpenBSD, and NetBSD dynamic loaders may allow for privilege escalation.
| | Author: | Mark Dowd, John McDonald, Justin Schuh | | File Size: | 4437 | | Last Modified: | Nov 26 20:38:34 2006 |
| MD5 Checksum: | d8ee508ca7429a07de680081ff8bbd39 |
|
| /// File Name: |
sa22822.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22822/ | | File Size: | 4373 | | Last Modified: | Nov 13 10:24:28 2006 |
| MD5 Checksum: | 76c798a132e4142e12779550ad22315a |
|
| /// File Name: |
sa22685.txt |
Description:
|
Secunia Security Advisory - Trustix has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges, or by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22685/ | | File Size: | 4231 | | Last Modified: | Nov 6 13:07:49 2006 |
| MD5 Checksum: | 35f4af40684e7023a25e6a30d716083b |
|
| /// File Name: |
sa22692.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22692/ | | File Size: | 4224 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 31cd49442b980b20a0f3e306b7f7c9fe |
|
| /// File Name: |
secunia-passgosso.txt |
Description:
|
Secunia Research has discovered a security issue in PassGo SSO Plus version 2.1.0.32, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/ | | File Size: | 4157 | | Related CVE(s): | CVE-2006-5965 | | Last Modified: | Nov 26 21:31:12 2006 |
| MD5 Checksum: | 02f7d4d5705f31b3825f6791caf65a32 |
|
| /// File Name: |
sa22878.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22878/ | | File Size: | 4152 | | Last Modified: | Nov 15 22:19:38 2006 |
| MD5 Checksum: | 8ab45ef96654a3743810f3e950c74a53 |
|
| /// File Name: |
sa23022.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for links. This fixes a vulnerability, which can be exploited by malicious people to expose sensitive information and manipulate data.
| | Homepage: | http://secunia.com/advisories/23022/ | | File Size: | 4144 | | Last Modified: | Nov 21 19:45:15 2006 |
| MD5 Checksum: | 8314b82f42d862d5b5d049153a7608b1 |
|
| /// File Name: |
MDKSA-2006-213.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-213 - Chromium is an OpenGL-based shoot them up game with fine graphics. It is built with a private copy of libpng, and as such could be susceptible to some of the same vulnerabilities. A buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name". Tavis Ormandy, of the Gentoo Linux Security Auditing Team, discovered a typo in png_set_sPLT() that may cause an application using libpng to read out of bounds, resulting in a crash.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 4091 | | Related CVE(s): | CVE-2006-3334, CVE-2006-5793 | | Last Modified: | Nov 17 20:44:43 2006 |
| MD5 Checksum: | d1947a6ece50166d6946a3ac95a2dd84 |
|
| /// File Name: |
USN-374-1.txt |
Description:
|
Ubuntu Security Notice 374-1: An integer overflow was discovered in the DOC file parser of the wv library. By tricking a user into opening a specially crafted MSWord (.DOC) file, remote attackers could execute arbitrary code with the user's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4087 | | Last Modified: | Nov 2 19:30:14 2006 |
| MD5 Checksum: | 3e6c8e2766100693559884dedfd96122 |
|
| /// File Name: |
MDKSA-2006-208-1.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-208-1 - An unspecified vulnerability in OpenLDAP allows remote attackers to cause a denial of service (daemon crash) via a certain combination of SASL Bind requests that triggers an assertion failure in libldap.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 4036 | | Related CVE(s): | CVE-2006-5779 | | Last Modified: | Nov 21 22:07:40 2006 |
| MD5 Checksum: | 14c7d1c0f256a254d7a72f446ac2239c |
|
| /// File Name: |
11.26.06-2.txt |
Description:
|
iDefense Security Advisory 11.26.06 - Remote exploitation of a denial of service vulnerability in Qbik IP Management Limited's WinGate allows attackers to cause the application to consume 100% of available CPU cycles. iDefense has confirmed that Qbik Wingate 6.1 is vulnerable. Earlier versions are suspected vulnerable.
| | Author: | Michael Sutton | | Homepage: | http://www.idefense.com | | File Size: | 4024 | | Related CVE(s): | CVE-2006-4518 | | Last Modified: | Nov 29 10:44:53 2006 |
| MD5 Checksum: | f39c8168bf8518eb7814a39e54d00b28 |
|
| /// File Name: |
VMSA-2006-0005.txt |
Description:
|
VMware Security Advisory - A new update has been released for VMware ESX versions 2.5.4 prior to upgrade patch 1. This patch addresses vulnerabilities in ucd-snmp, XFree86, an AMD fxsave/restore security flaw, some minor information leaks, and more.
| | Homepage: | http://www.vmware.com/ | | File Size: | 4024 | | Related CVE(s): | CVE-2005-2177, CVE-2006-3467, CVE-2006-1056, CVE-2006-1342, CVE-2006-1343, CVE-2006-1864, CVE-2006-2071 | | Last Modified: | Nov 14 03:15:16 2006 |
| MD5 Checksum: | 2c2c7135a54317ec1346817dca2e51fc |
|
| /// File Name: |
sa22979.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for asterisk. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22979/ | | File Size: | 3981 | | Last Modified: | Nov 17 18:30:18 2006 |
| MD5 Checksum: | 6c7a1bee34ba271e0765101c58f7e4ac |
|
| /// File Name: |
MDKSA-2006-216.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-216 - The links web browser with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3966 | | Related CVE(s): | CVE-2006-5925 | | Last Modified: | Nov 21 02:22:10 2006 |
| MD5 Checksum: | c128af5e7141ecf08f821f8a39d76113 |
|
| /// File Name: |
11.08.06-1.txt |
Description:
|
iDefense Security Advisory 11.08.06 - Local exploitation of multiple buffer overflow vulnerabilities in IBM's Lotus Domino could allow an attacker to elevate privileges to root. The 'tunekrnl' binary is used to set Linux/proc sysctl settings, allowing Domino to increase the resource limits of the running kernel. It is shipped with the owner set to root and the set-user-id bit on. Since the length of input is improperly validated when copying to fixed-size buffers, buffer overflow can occur.iDefense has confirmed the existence of this vulnerability in version 7.0.1.1 of IBM's Lotus Domino for Linux. Earlier versions may also be vulnerable.
| | Author: | Andrew Christensen | | Homepage: | http://www.idefense.com/ | | Related File: | lotusnotes_keyfiles.pdf | | File Size: | 3943 | | Last Modified: | Nov 8 22:14:26 2006 |
| MD5 Checksum: | 32a3f9881005e5e7b3bd27c6d54ad086 |
|
| /// File Name: |
MDKSA-2006-219.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-219-1 - GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3939 | | Related CVE(s): | CVE-2006-6097, CVE-2002-1216 | | Last Modified: | Nov 30 19:43:41 2006 |
| MD5 Checksum: | fc6c7979ea68386eb384cec8b81642e2 |
|
| /// File Name: |
sa22976.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for pdns. This fixes two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22976/ | | File Size: | 3936 | | Last Modified: | Nov 17 18:30:18 2006 |
| MD5 Checksum: | a62fe5531fd6083f9dead28969383845 |
|
| /// File Name: |
sa22866.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22866/ | | File Size: | 3909 | | Last Modified: | Nov 15 22:19:38 2006 |
| MD5 Checksum: | 63cc1877d350b7fea330855a2a1fc539 |
|
| /// File Name: |
TA06-318A.txt |
Description:
|
Technical Cyber Security Alert TA06-318A - Microsoft has released updates that address critical vulnerabilities in Microsoft Windows, Internet Explorer, and Adobe Flash. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.
| | Homepage: | http://www.us-cert.gov/ | | File Size: | 3903 | | Last Modified: | Nov 16 11:02:41 2006 |
| MD5 Checksum: | cdb5eb5c68a962d3f2542ce4fa05ae83 |
|
| /// File Name: |
sa22956.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for libpng. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22956/ | | File Size: | 3900 | | Last Modified: | Nov 17 18:30:18 2006 |
| MD5 Checksum: | 15cede697ce31c28aca2de7a898b0d9d |
|
| /// File Name: |
sa22705.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for wvWare. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22705/ | | File Size: | 3878 | | Last Modified: | Nov 8 18:29:38 2006 |
| MD5 Checksum: | 2b77904dd3bb439db9830c4b2de868a9 |
|
| /// File Name: |
glsa-200611-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200611-04 - Bugzilla is vulnerable to cross-site scripting, script injection, and request forgery. Versions less than 2.18.6 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3867 | | Last Modified: | Nov 13 11:01:56 2006 |
| MD5 Checksum: | b43590070f7b3bd00f7c82cef15a01a0 |
|
| /// File Name: |
sa22948.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for bind. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions or cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22948/ | | File Size: | 3867 | | Last Modified: | Nov 20 11:05:00 2006 |
| MD5 Checksum: | 53cffc9ed085255c350902a7617d989b |
|
|
|
|
|