Section: .. / 0705-advisories /
| /// File Name: |
cisco-sa-20070509-iosftp.txt |
Description:
|
Cisco Security Advisory - Multiple vulnerabilities exist in the Cisco IOS File Transfer Protocol (FTP) Server feature. These vulnerabilities include Denial of Service, improper verification of user credentials and the ability to read or write any file in the device's filesystem, including the device's saved configuration, which may include passwords or other sensitive information.
| | Homepage: | http://www.cisco.com/ | | File Size: | 26707 | | Last Modified: | May 10 05:51:47 2007 |
| MD5 Checksum: | 791578dc6480cac0bd73f4d88fbef5d1 |
|
| /// File Name: |
mts-tls.txt |
Description:
|
Microsoft's Terminal Server on Windows 2003 Server with all of the current service packs fails to enforce its own settings.
| | Author: | Anonymous | | File Size: | 1216 | | Last Modified: | May 10 05:50:43 2007 |
| MD5 Checksum: | 43225560381e4dcb7faf779e29d8bb6b |
|
| /// File Name: |
05.08.07-1.txt |
Description:
|
iDefense Security Advisory 05.08.07 - Remote exploitation of a buffer overflow in an ActiveX control distributed with McAfee Security Center could allow for the execution of arbitrary code. iDefense confirmed the existence of this vulnerability using McAfee Virus Scan 10.0.27 running on Windows XP SP2. However, many additional McAfee products are reported to install this component.
| | Author: | Peter Vreugdenhil | | Homepage: | http://www.idefense.com/ | | File Size: | 4695 | | Last Modified: | May 10 04:22:18 2007 |
| MD5 Checksum: | 55724073f11143b0ac7a085bacb12eb7 |
|
| /// File Name: |
MDKSA-2007-099.txt |
Description:
|
Mandriva Linux Security Advisory - An off-by-one error was discovered in the PyLocale_strxfrm function in Python 2.4 and 2.5 that could allow context-dependent attackers the ability to read portions of memory via special manipulations that trigger a buffer over-read due to missing null termination.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 8041 | | Related CVE(s): | CVE-2007-2052 | | Last Modified: | May 10 04:20:04 2007 |
| MD5 Checksum: | 81e8b3a63ba41ed78498606f4867461a |
|
| /// File Name: |
MDKSA-2007-098.txt |
Description:
|
Mandriva Linux Security Advisory - iDefense discovered a stack-based overflow in ClamAV when processing negative values in .cab files. As well, multiple file descriptor leaks were also reported and fixed in chmunpack.c, pdf.c, and dblock.c.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 10146 | | Related CVE(s): | CVE-2007-1745, CVE-2007-1997, CVE-2007-2029 | | Last Modified: | May 10 04:18:55 2007 |
| MD5 Checksum: | cfca507cc140144be51f7b12b72d5ae9 |
|
| /// File Name: |
modprops-dos.txt |
Description:
|
Determina Security Research has discovered a denial of service vulnerability in the code responsible for parsing iCal email attachments in Microsoft Exchange. This vulnerability can be exploited by a malicious email message and results in a denial of service. The vulnerable code is present in Exchange 2000 and 2003.
| | Author: | Alexander Sotirov | | Homepage: | http://www.determina.com/ | | File Size: | 3806 | | Related CVE(s): | CVE-2007-0039 | | Last Modified: | May 10 04:17:36 2007 |
| MD5 Checksum: | 517efa884b7027c6bb781a308e87eb6b |
|
| /// File Name: |
dsa-1288-1.txt |
Description:
|
Debian Security Advisory 1288-1 - It was discovered that the PoPToP Point to Point Tunneling Server contains a programming error, which allows the tear-down of a PPTP connection through a malformed GRE packet, resulting in denial of service.
| | Homepage: | http://www.debian.org/security | | File Size: | 6397 | | Related CVE(s): | CVE-2007-0244 | | Last Modified: | May 10 03:43:30 2007 |
| MD5 Checksum: | a14b7fc739049a2723d4bec220d3656e |
|
| /// File Name: |
TA07-128A.txt |
Description:
|
Technical Cyber Security Alert TA07-128A - Microsoft has released updates that address critical vulnerabilities in Microsoft Windows, Internet Explorer, Office, Exchange, Cryptographic API Component Object Model (CAPICOM), and BizTalk. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.
| | Homepage: | http://www.us-cert.gov/ | | File Size: | 4518 | | Last Modified: | May 10 03:42:20 2007 |
| MD5 Checksum: | d3d88bcd62b8340216fb50ed8ba3fe48 |
|
| /// File Name: |
SSRT071326.txt |
Description:
|
HP Security Bulletin - A potential security vulnerability has been identified with the HP Tru64 UNIX Operating System running the dop command. The vulnerability could be exploited by a local, authorized user to execute arbitrary code with the privileges of the root user.
| | Homepage: | http://www.hp.com | | File Size: | 6731 | | Last Modified: | May 10 03:41:08 2007 |
| MD5 Checksum: | f66784706b7cd679c1a2c3633a9b9465 |
|
| /// File Name: |
ZDI-07-027.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Internet Explorer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2690 | | Related CVE(s): | CVE-2007-0944 | | Last Modified: | May 10 03:40:19 2007 |
| MD5 Checksum: | 86df24dec24193dcc84c91240b57414e |
|
| /// File Name: |
ZDI-07-026.txt |
Description:
|
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Office Excel. Exploitation requires that the attacker coerce the target into opening a malicious .XLS file.
| | Author: | Manuel Santamarina Suarez | | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2647 | | Related CVE(s): | CVE-2007-0215 | | Last Modified: | May 10 03:39:18 2007 |
| MD5 Checksum: | cbfb13003f84a5ef4c8519777a101fc6 |
|
| /// File Name: |
ap-pwn.txt |
Description:
|
The AP Newspower software installs with a MySQL instance that has a blank root password, allowing for remote attackers to manipulate the news.
| | Author: | gobbles_fo_evar | | File Size: | 1517 | | Last Modified: | May 10 03:37:40 2007 |
| MD5 Checksum: | 42bd122436e11e042e559ada335afce4 |
|
| /// File Name: |
glsa-200705-11.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200705-11 - mu-b discovered a NULL pointer dereference in item_cmpfunc.cc when processing certain types of SQL requests. Sec Consult also discovered another NULL pointer dereference when sorting certain types of queries on the database metadata. Versions less than 5.0.38 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2758 | | Related CVE(s): | CVE-2007-1420 | | Last Modified: | May 10 02:58:21 2007 |
| MD5 Checksum: | b658ddedd31ec26c23e8aec9b7a2dbe9 |
|
| /// File Name: |
glsa-200705-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200705-10 - The libXfont code is prone to several integer overflows, in functions ProcXCMiscGetXIDList(), bdfReadCharacters() and FontFileInitTable(). TightVNC contains a local copy of this code and is also affected. Versions less than 1.2.9-r4 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3206 | | Related CVE(s): | CVE-2007-1003, CVE-2007-1351, CVE-2007-1352 | | Last Modified: | May 10 02:58:06 2007 |
| MD5 Checksum: | 4f3107dd626f8a2fd9887a41ac986405 |
|
| /// File Name: |
USN-458-1.txt |
Description:
|
Ubuntu Security Notice 458-1 - A flaw was discovered in MoinMoin's error reporting when using the AttachFile action. By tricking a user into viewing a crafted MoinMoin URL, an attacker could execute arbitrary JavaScript as the current MoinMoin user, possibly exposing the user's authentication information for the domain where MoinMoin was hosted. Flaws were discovered in MoinMoin's ACL handling for calendars and includes. Unauthorized users would be able to read pages that would otherwise be unavailable to them.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4131 | | Related CVE(s): | CVE-2007-2423 | | Last Modified: | May 10 02:56:28 2007 |
| MD5 Checksum: | e218d5152cdd15624a8e2c7f038d9ff1 |
|
| /// File Name: |
glsa-200705-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200705-09 - The isakmp_info_recv() function in src/racoon/isakmp_inf.c does not always check that DELETE (ISAKMP_NPTYPE_D) and NOTIFY (ISAKMP_NPTYPE_N) packets are encrypted. Versions less than 0.6.7 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2641 | | Related CVE(s): | CVE-2007-1841 | | Last Modified: | May 10 02:56:26 2007 |
| MD5 Checksum: | f126868f00f4214b95df1a8be4d9353d |
|
| /// File Name: |
sa25219.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in IBM WebSphere Application Server, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/25219/ | | File Size: | 2276 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | 4b7367cb022c94cfd1215e0d9138bcdb |
|
| /// File Name: |
sa25218.txt |
Description:
|
Secunia Security Advisory - Will Dormann has reported a vulnerability in RIM's TeamOn Import Object ActiveX control, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/25218/ | | File Size: | 2526 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | abb02d68c27a13fe658392cd766d6a29 |
|
| /// File Name: |
sa25217.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for python. This fixes a security issue, which can be exploited by malicious people to disclose potentially sensitive information.
| | Homepage: | http://secunia.com/advisories/25217/ | | File Size: | 3294 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | 6bb145e81a138ec93872e203ab2ab25c |
|
| /// File Name: |
sa25214.txt |
Description:
|
Secunia Security Advisory - GolD_M has reported some vulnerabilities in CGX, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/25214/ | | File Size: | 2310 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | a4a1af83f3e5bc025d4edf920d3bd06a |
|
| /// File Name: |
sa25212.txt |
Description:
|
Secunia Security Advisory - Johannes Greil has reported some vulnerabilities in Nokia's Intellisync Mobile Suite, which can be exploited by malicious people to gain knowledge of sensitive information, conduct cross-site scripting attacks, manipulate certain data, or cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/25212/ | | File Size: | 2971 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | 2ac9867408db3fe2e6327a87e582e4e0 |
|
| /// File Name: |
sa25211.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in RoboHelp, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/25211/ | | File Size: | 2799 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | 8ac7552ec1f5e7de281e803df3b68b4c |
|
| /// File Name: |
sa25209.txt |
Description:
|
Secunia Security Advisory - shinnai has discovered a vulnerability in BarCodeWiz Barcode ActiveX control, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/25209/ | | File Size: | 2548 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | 43c83359ed9e6290fe764f039209fe02 |
|
| /// File Name: |
sa25205.txt |
Description:
|
Secunia Security Advisory - ciri has reported some vulnerabilities in OTRS (Open Ticket Request System), which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.
| | Homepage: | http://secunia.com/advisories/25205/ | | File Size: | 2638 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | f006b21eaa9a61c645710daa521a44dd |
|
| /// File Name: |
sa25203.txt |
Description:
|
Secunia Security Advisory - shinnai has discovered a vulnerability in SmartCode VNC Manager, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/25203/ | | File Size: | 2523 | | Last Modified: | May 10 02:32:46 2007 |
| MD5 Checksum: | 5eca4fbeadf8528c93f948c683bfdb4f |
|
|
|
|
|