Section: .. / 0611-advisories /
| /// File Name: |
sa23132.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious users to cause a DoS (Denial of Service), and by malicious people to bypass certain security restrictions, expose sensitive information, and manipulate data.
| | Homepage: | http://secunia.com/advisories/23132/ | | File Size: | 3834 | | Last Modified: | Nov 27 10:22:48 2006 |
| MD5 Checksum: | fc887b2dc8a22da500aea4193b723ca6 |
|
| /// File Name: |
MDKSA-2006-211.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-211 - PXELINUX is a PXE bootloader. It is built with a private copy of libpng, and as such could be susceptible to some of the same vulnerabilities. A buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name". Tavis Ormandy, of the Gentoo Linux Security Auditing Team, discovered a typo in png_set_sPLT() that may cause an application using libpng to read out of bounds, resulting in a crash.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3821 | | Related CVE(s): | CVE-2006-3334, CVE-2006-5793 | | Last Modified: | Nov 17 20:43:39 2006 |
| MD5 Checksum: | 8b08f4bc0d0efcb8a331c409f64a8f1c |
|
| /// File Name: |
PR05-06.txt |
Description:
|
PR05-06 - Immediacy .NET CMS suffers from a possible cross site scripting flaw due to a malformed cookie.
| | Author: | Gemma Hughes | | File Size: | 3818 | | Last Modified: | Nov 8 22:07:34 2006 |
| MD5 Checksum: | 314525efc889be6ae5d5b9ae9b793a87 |
|
| /// File Name: |
MDKSA-2006-214.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-214 - A stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the DocumentMedia header.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3816 | | Related CVE(s): | CVE-2006-5864 | | Last Modified: | Nov 18 20:49:04 2006 |
| MD5 Checksum: | 83fa75f6fcedca8e0d31f44235d84294 |
|
| /// File Name: |
sa22777.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for texinfo. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22777/ | | File Size: | 3808 | | Last Modified: | Nov 10 11:02:24 2006 |
| MD5 Checksum: | 4e74d65d0016e3913a0c9924369b0141 |
|
| /// File Name: |
sa22762.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions or cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22762/ | | File Size: | 3794 | | Last Modified: | Nov 7 17:19:16 2006 |
| MD5 Checksum: | a5ce48b4ec58548d501da1605bf65b7b |
|
| /// File Name: |
10.27.06-1.txt |
Description:
|
iDefense Security Advisory 10.27.06 - Novell eDirectory NMAS BerDecodeLoginDataRequeset DoS Vulnerability: Remote exploitation of a denial of service (DoS) vulnerability in Novell Inc.'s eDirectory product could allow an attacker to force the running daemon to cease servicing requests.
| | Homepage: | http://www.idefense.com/intelligence/vulnerabilities/ | | File Size: | 3738 | | Last Modified: | Nov 2 19:31:53 2006 |
| MD5 Checksum: | 99f4ad06ebb5da602cb14b3e9070ebb7 |
|
| /// File Name: |
ZDI-06-042.txt |
Description:
|
A vulnerability allows remote attackers to proxy web attacks and scan internal hosts through vulnerable installations of Verity Ultraseek. Authentication is not required to exploit this vulnerability. The specific flaw exists within the highlight script used to highlight search terms on spidered pages. An attacker can directly access the highlight script at '/highlight/index.html' to pass parameters to and retrieve content from arbitrary URLs. The same script can also be abused to enumerate otherwise inaccessible internal addresses and open ports.
| | Author: | sullo | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 3735 | | Related CVE(s): | CVE-2006-5819 | | Last Modified: | Nov 16 12:26:07 2006 |
| MD5 Checksum: | 99c032d405a177ee8e3a87b4df6ceef2 |
|
| /// File Name: |
sa22875.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities, security issues, and a weakness have been reported in VMware ESX Server, which can be exploited by malicious, local users to bypass certain security restrictions and disclose potentially sensitive information, or by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22875/ | | File Size: | 3695 | | Last Modified: | Nov 15 22:19:38 2006 |
| MD5 Checksum: | 49351b10236766b6b5d2f644987a711b |
|
| /// File Name: |
sa22932.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, and by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22932/ | | File Size: | 3690 | | Last Modified: | Nov 20 11:05:00 2006 |
| MD5 Checksum: | 154516a001add15f4aa64eb4feafc3cd |
|
| /// File Name: |
VMSA-2006-0010.txt |
Description:
|
VMware Security Advisory - VMware VirtualCenter client 2.x before 2.0.1 Patch 1 (Build 33643) and 1.4.x before 1.4.1 Patch 1 (Build 33425), does not verify the server's X.509 certificate when creating an SSL session, which allows remote malicious servers to spoof valid servers via a man-in-the-middle attack.
| | Homepage: | http://www.vmware.com/ | | File Size: | 3676 | | Related CVE(s): | CAN-2006-5990 | | Last Modified: | Nov 26 20:35:21 2006 |
| MD5 Checksum: | fdd92aee26baac028d88a86ede28df38 |
|
| /// File Name: |
glsa-200611-01.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200611-01 - cstone and Richard Felker discovered a flaw in Screen's UTF-8 combining character handling. Versions less than 4.0.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3662 | | Last Modified: | Nov 3 18:04:42 2006 |
| MD5 Checksum: | 458197d688275073032e419c428941f9 |
|
| /// File Name: |
sa22719.txt |
Description:
|
Secunia Security Advisory - Laurent Gaffié and Benjamin Mossé have discovered several vulnerabilities in All In One Control Panel (AIOCP), which can be exploited by malicious people to conduct SQL injection attacks or cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/22719/ | | File Size: | 3633 | | Last Modified: | Nov 7 17:19:16 2006 |
| MD5 Checksum: | f3b07ebdf78010784ffd5555272afa11 |
|
| /// File Name: |
sa21554.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a security issue in MDaemon, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/21554/ | | File Size: | 3548 | | Last Modified: | Nov 16 10:09:27 2006 |
| MD5 Checksum: | 6462dfa2cbdb734860135ea8a24f6cba |
|
| /// File Name: |
sa22770.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Mozilla Thunderbird, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22770/ | | File Size: | 3518 | | Last Modified: | Nov 8 18:29:38 2006 |
| MD5 Checksum: | 54fe12374b811d8bf68fe8860dd76cd9 |
|
| /// File Name: |
EEYE-MSWS.txt |
Description:
|
A flaw exists in a default Windows component called the "Workstation Service" that when exploited allows for remote code execution in SYSTEM context, allowing an attacker to take complete control of affected systems. Systems affected include Windows 2000 (Remote Code Execution), Windows XP SP1 (Local Privilege Escalation).
| | Author: | JeongWook Matt Oh, Derek Soeder | | Homepage: | http://research.eeye.com/ | | File Size: | 3492 | | Last Modified: | Nov 16 11:01:48 2006 |
| MD5 Checksum: | ab5e44c09d742521217e98290229c887 |
|
| /// File Name: |
sa22747.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Cisco Secure Desktop, which can be exploited by malicious, local users to gain knowledge of sensitive information, bypass certain security restrictions, or gain escalated privileges on a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22747/ | | File Size: | 3491 | | Last Modified: | Nov 10 11:02:24 2006 |
| MD5 Checksum: | 64e078704bfa3bf9fd34573580c7dd35 |
|
| /// File Name: |
sa22781.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for phpmyadmin. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, HTTP response splitting attacks, and cross-site forgery request attacks.
| | Homepage: | http://secunia.com/advisories/22781/ | | File Size: | 3482 | | Last Modified: | Nov 10 11:02:24 2006 |
| MD5 Checksum: | 470fe4e51c8beff093aab5b0a79b939e |
|
| /// File Name: |
sa22687.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft XML Core Services, which can be exploited by malicious people to compromise a users system.
| | Homepage: | http://secunia.com/advisories/22687/ | | File Size: | 3478 | | Last Modified: | Nov 6 00:09:25 2006 |
| MD5 Checksum: | 5ee2f49c93d99c8994b67570ea8ceb33 |
|
| /// File Name: |
dsa-1208-1.txt |
Description:
|
Debian Security Advisory 1208-1 - Several remote vulnerabilities have been discovered in the Bugzilla bug tracking system, which may lead to the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 3461 | | Related CVE(s): | CVE-2005-4534, CVE-2006-5453 | | Last Modified: | Nov 14 00:38:59 2006 |
| MD5 Checksum: | 70817affb3085dabfe771ac22e8b1115 |
|
| /// File Name: |
sa22826.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for bugzilla. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges, and by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/22826/ | | File Size: | 3445 | | Last Modified: | Nov 13 10:24:28 2006 |
| MD5 Checksum: | 4d5da80cdc0d8bd22de1e1ba3eb6611a |
|
| /// File Name: |
MDKSA-2006-210.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-210 - SYSLINUX is a boot loader for the Linux operating system which operates off an MS-DOS/Windows FAT filesystem. It is built with a private copy of libpng, and as such could be susceptible to some of the same vulnerabilities. A buffer overflow in the png_decompress_chunk function in pngrutil.c in libpng before 1.2.12 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via unspecified vectors related to "chunk error processing," possibly involving the "chunk_name". Tavis Ormandy, of the Gentoo Linux Security Auditing Team, discovered a typo in png_set_sPLT() that may cause an application using libpng to read out of bounds, resulting in a crash.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3443 | | Related CVE(s): | CVE-2006-3334, CVE-2006-5793 | | Last Modified: | Nov 17 20:43:05 2006 |
| MD5 Checksum: | a336fddb70e34c79a3e8c1ab3b1e7554 |
|
| /// File Name: |
sa22722.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Mozilla Firefox and Mozilla SeaMonkey, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22722/ | | File Size: | 3443 | | Last Modified: | Nov 8 18:29:38 2006 |
| MD5 Checksum: | 401db24ac1799aca540bf1bb9e97503c |
|
| /// File Name: |
sa22695.txt |
Description:
|
Secunia Security Advisory - Dedi Dwianto has discovered several vulnerabilities in OpenEMR, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22695/ | | File Size: | 3440 | | Last Modified: | Nov 7 17:19:16 2006 |
| MD5 Checksum: | a8ad130716d8a313bf8c8ebc6125cf2a |
|
|
|
|
|