Section: .. / 0804-advisories /
| /// File Name: |
glsa-200804-13.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200804-13 - Multiple vulnerabilities have been found in Asterisk allowing for SQL injection, session hijacking and unauthorized usage. Versions less than 1.2.27 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3318 | | Related CVE(s): | CVE-2007-6170, CVE-2007-6430, CVE-2008-1332 | | Last Modified: | Apr 14 19:00:49 2008 |
| MD5 Checksum: | 8b5069d31ac6bad4492d0e424adcf705 |
|
| /// File Name: |
USN-601-1.txt |
Description:
|
Ubuntu Security Notice 601-1 - It was discovered that Squid did not perform proper bounds checking when processing cache update replies. A remote authenticated user may be able to trigger an assertion error and cause a denial of service. This vulnerability is due to an incorrect fix for CVE-2007-6239.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 12069 | | Related CVE(s): | CVE-2007-6239, CVE-2008-1612 | | Last Modified: | Apr 14 19:00:09 2008 |
| MD5 Checksum: | 1aa71f11f950e52824311ffca966e3ae |
|
| /// File Name: |
sa29792.txt |
Description:
|
Secunia Security Advisory - Tavis Ormandy has reported a vulnerability in libpng, which can be exploited by malicious people to cause a DoS (Denial of Service), disclose potentially sensitive information, or potentially compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/29792/ | | File Size: | 2988 | | Last Modified: | Apr 14 18:51:47 2008 |
| MD5 Checksum: | e6697616f36363840cd4c09667d8e5eb |
|
| /// File Name: |
sa29805.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Novell eDirectory, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29805/ | | File Size: | 2730 | | Last Modified: | Apr 14 18:51:47 2008 |
| MD5 Checksum: | f320980ad0aadb0f1de1e45e357c337c |
|
| /// File Name: |
sa29806.txt |
Description:
|
Secunia Security Advisory - IBM has acknowledged some vulnerabilities in IBM HTTP Server, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/29806/ | | File Size: | 2388 | | Last Modified: | Apr 14 18:51:47 2008 |
| MD5 Checksum: | 3af2d26b37e653d79c820fac21ae5cf8 |
|
| /// File Name: |
sa29812.txt |
Description:
|
Secunia Security Advisory - t0pP8uZz has discovered a vulnerability in CcMail, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/29812/ | | File Size: | 2578 | | Last Modified: | Apr 14 18:51:47 2008 |
| MD5 Checksum: | e8d01c014e3ae027aab1be4738cdccbf |
|
| /// File Name: |
sa29795.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been discovered in Coppermine Photo Gallery, which can be exploited by malicious users to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/29795/ | | File Size: | 2580 | | Last Modified: | Apr 14 17:48:17 2008 |
| MD5 Checksum: | 181ba60192c3104050ccf5feca122c09 |
|
| /// File Name: |
sa29796.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in HP OpenView Network Node Manager, which can be exploited by malicious people to disclose certain information or cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29796/ | | File Size: | 3357 | | Last Modified: | Apr 14 17:48:17 2008 |
| MD5 Checksum: | 9c9f8d207bca67b6152fa6be70e7981a |
|
| /// File Name: |
sa29808.txt |
Description:
|
Secunia Security Advisory - Luigi Auriemma has discovered a vulnerability in Nero MediaHome, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29808/ | | File Size: | 2490 | | Last Modified: | Apr 14 17:48:17 2008 |
| MD5 Checksum: | 4d7d336cac971de130d4d60e7e6c7b3b |
|
| /// File Name: |
secunia-hpopenwide.txt |
Description:
|
Secunia Research has discovered a vulnerability in HP OpenView Network Node Manager, which can be exploited by malicious people to disclose certain information. It is possible to download or view arbitrary files by sending a HTTP request to the OpenView5.exe CGI application and passing strings containing directory traversal sequences to the "Action" parameter. HP OpenView Network Node Manager version 7.51 is affected.
| | Author: | JJ Reyes | | Homepage: | http://secunia.com/ | | File Size: | 4311 | | Related CVE(s): | CVE-2008-0068 | | Last Modified: | Apr 14 17:46:36 2008 |
| MD5 Checksum: | fe82ad6a60c92b2a8a4138eb93854f3c |
|
| /// File Name: |
secunia-graphics.txt |
Description:
|
Secunia Research has discovered some vulnerabilities in Autonomy Keyview utilised in Lotus Notes, which can be exploited by malicious people to compromise a vulnerable system when viewing Applix documents. Lotus Notes versions 7.0.3 and 8.0 are affected.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 4937 | | Related CVE(s): | CVE-2007-5405, CVE-2007-5406 | | Last Modified: | Apr 14 17:43:43 2008 |
| MD5 Checksum: | 6b1e5c2f43af293caf0561ec4dd4a5e9 |
|
| /// File Name: |
secunia-activeapplix.txt |
Description:
|
Secunia Research has discovered some vulnerabilities in activePDF DocConverter, which can be exploited by malicious people to compromise a vulnerable system when converting Applix documents. A couple of boundary errors and an unsafe call may allow for arbitrary code execution. A logic error may cause a denial of service condition.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 4770 | | Related CVE(s): | CVE-2007-5405, CVE-2007-5406 | | Last Modified: | Apr 14 17:43:35 2008 |
| MD5 Checksum: | 57556bf4ae454d318bc134811ae3017c |
|
| /// File Name: |
secunia-symanapplix.txt |
Description:
|
Secunia Research has discovered some vulnerabilities Symantec Mail Security, which can be exploited by malicious people to compromise a vulnerable system when scanning Applix documents. A couple of boundary errors and an unsafe call may allow for arbitrary code execution. A logic error may cause a denial of service condition.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 5312 | | Related CVE(s): | CVE-2007-5405, CVE-2007-5406 | | Last Modified: | Apr 14 17:41:27 2008 |
| MD5 Checksum: | 26481917edf681de247a0112ffd45302 |
|
| /// File Name: |
secunia-activefolio.txt |
Description:
|
Secunia Research has discovered 21 vulnerabilities in activePDF DocConverter, which can be exploited by malicious people to compromise a vulnerable system. Boundary errors within the "Folio Flat File" speed reader (foliosr.dll) when handling attribute values of a number of tags (eg. DI, FD, FT, JD, JL, LE, OB, OD, OL, PN, PS, PW, RD, QL, or TS) can be exploited to cause stack-based buffer overflows.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 4427 | | Related CVE(s): | CVE-2007-6020 | | Last Modified: | Apr 14 17:37:16 2008 |
| MD5 Checksum: | 1c9df97a790f8ff13a24742726f83853 |
|
| /// File Name: |
secunia-symantec.txt |
Description:
|
Secunia Research has discovered 21 vulnerabilities in Symantec Mail Security, which can be exploited by malicious people to compromise a vulnerable system. Boundary errors within the "Folio Flat File" speed reader (foliosr.dll) when handling attribute values of a number of tags (eg. DI, FD, FT, JD, JL, LE, OB, OD, OL, PN, PS, PW, RD, QL, or TS) can be exploited to cause stack-based buffer overflows.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 4780 | | Related CVE(s): | CVE-2007-6020 | | Last Modified: | Apr 14 17:35:59 2008 |
| MD5 Checksum: | e7d7d5429a32af526b6677bedbf2cdec |
|
| /// File Name: |
secunia-datastream.txt |
Description:
|
Secunia Research has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to an error when processing data streams and can be exploited to trigger a use-after-free condition by returning a specially crafted data stream of e.g. an unexpected MIME-type for which no handler is registered. Successful exploitation allows execution of arbitrary code when a user visits a malicious website. Versions 5.01, 6, and 7 are affected.
| | Author: | Carsten Eiram | | Homepage: | http://secunia.com/ | | File Size: | 4256 | | Related CVE(s): | CVE-2008-1085 | | Last Modified: | Apr 14 17:34:40 2008 |
| MD5 Checksum: | 1f288ff9a8f03d249d4baf06e66ac53c |
|
| /// File Name: |
secunia-emlreader.txt |
Description:
|
Secunia Research has discovered multiple vulnerabilities in Autonomy Keyview, which can be exploited by malicious people to compromise a user's system. Various boundary errors exist in the EML reader (emlsr.dll). Autonomy Keyview version 10.3.0.0 is affected.
| | Author: | Carsten Eiram | | Homepage: | http://secunia.com/ | | File Size: | 4842 | | Related CVE(s): | CVE-2007-5399 | | Last Modified: | Apr 14 17:33:35 2008 |
| MD5 Checksum: | 2b9ab8c858a1e87599cd6acaed1cc49d |
|
| /// File Name: |
secunia-applix.txt |
Description:
|
Secunia Research has discovered some vulnerabilities in Autonomy Keyview, which can be exploited by malicious people to compromise a vulnerable system. A couple of boundary errors and an unsafe call may allow for arbitrary code execution. A logic error may cause a denial of service condition.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 4877 | | Related CVE(s): | CVE-2007-5405 | | Last Modified: | Apr 14 17:31:57 2008 |
| MD5 Checksum: | 722239f5c8c2446ddc8174a02afe027c |
|
| /// File Name: |
secunia-keyview.txt |
Description:
|
Secunia Research has discovered 21 vulnerabilities in Autonomy Keyview, which can be exploited by malicious people to compromise a vulnerable system. Boundary errors within the "Folio Flat File" speed reader (foliosr.dll) when handling attribute values of a number of tags (eg. DI, FD, FT, JD, JL, LE, OB, OD, OL, PN, PS, PW, RD, QL, or TS) can be exploited to cause stack-based buffer overflows. Autonomy Keyview version 10.3.0.0 is affected.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 4229 | | Related CVE(s): | CVE-2007-6020 | | Last Modified: | Apr 14 17:22:08 2008 |
| MD5 Checksum: | 355e6bf2288853d5658d3ab39bceee50 |
|
| /// File Name: |
secunia-eml.txt |
Description:
|
Secunia Research has discovered multiple vulnerabilities in Lotus Notes, which can be exploited by malicious people to compromise a user's system. Various boundary errors exist in the EML reader (emlsr.dll). Lotus Notes version 8.0 is affected.
| | Author: | Carsten Eiram | | Homepage: | http://secunia.com/ | | File Size: | 4727 | | Related CVE(s): | CVE-2007-5399 | | Last Modified: | Apr 14 17:18:04 2008 |
| MD5 Checksum: | e6020892898385c53e8429c09144723d |
|
| /// File Name: |
secunia-folioflat.txt |
Description:
|
Secunia Research has discovered 21 vulnerabilities in Lotus Notes, which can be exploited by malicious people to compromise a vulnerable system. Boundary errors within the "Folio Flat File" speed reader (foliosr.dll) when handling attribute values of a number of tags (eg. DI, FD, FT, JD, JL, LE, OB, OD, OL, PN, PS, PW, RD, QL, or TS) can be exploited to cause stack-based buffer overflows. Lotus Notes versions 7.0.3 and 8.0 are affected.
| | Author: | Dyon Balding | | Homepage: | http://secunia.com/ | | File Size: | 4305 | | Related CVE(s): | CVE-2007-6020 | | Last Modified: | Apr 14 17:15:20 2008 |
| MD5 Checksum: | 658d6de2e5bf506bdc6b9c42899cd2ed |
|
| /// File Name: |
secunia-htmsr.txt |
Description:
|
Secunia Research has discovered some vulnerabilities in Lotus Notes, which can be exploited by malicious people to compromise a user's system. A boundary error within the HTML speed reader (htmsr.dll) when handling links in e.g. the "background" attribute of BODY tags can be exploited to cause a stack-based buffer overflow. A boundary error within the HTML speed reader (htmsr.dll) when handling e.g. the "src" attribute of IMG tags can be exploited to cause a stack-based buffer overflow. A boundary error within the HTML speed reader (htmsr.dll) when handling large chunks of data inside an HTML document can be exploited to cause a heap-based buffer overflow. Lotus Notes version 7.0.2 and 7.0.3 are affected.
| | Author: | Secunia Research | | Homepage: | http://secunia.com/ | | File Size: | 4381 | | Related CVE(s): | CVE-2008-0066 | | Last Modified: | Apr 14 17:13:29 2008 |
| MD5 Checksum: | a558444c02a80ac7014bcf1ad4adba8f |
|
| /// File Name: |
secunia-lotusnotes.txt |
Description:
|
Secunia Research has discovered a vulnerability in Lotus Notes, which can be exploited by malicious people to compromise a user's system. A boundary error within kvdocve.dll when processing overly long paths can be exploited to cause a buffer overflow via e.g. an overly long link inside the "src" attribute of an tag in an HTML document. Lotus Notes versions 7.0.2 and 7.0.3 are affected.
| | Author: | Secunia Research | | Homepage: | http://secunia.com/ | | File Size: | 4052 | | Related CVE(s): | CVE-2008-1101 | | Last Modified: | Apr 14 16:50:35 2008 |
| MD5 Checksum: | c73dd6de3a917119766b3fc6935c9997 |
|
| /// File Name: |
secunia-adobeheap.txt |
Description:
|
Secunia Research has discovered a vulnerability in Adobe Flash Player, which potentially can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to a boundary error in the processing of "Declare Function (V7)" tags. This can be exploited to cause a heap-based buffer overflow via specially crafted argument preload flags. Successful exploitation may allow execution of arbitrary code. Adobe Flash Player 9.0.115.0 is affected.
| | Author: | Alin Rad Pop | | Homepage: | http://secunia.com/ | | File Size: | 4263 | | Related CVE(s): | CVE-2007-6019 | | Last Modified: | Apr 14 16:49:44 2008 |
| MD5 Checksum: | 85907b98a4a0365807e5c2b1c7cfffaf |
|
| /// File Name: |
secunia-clamav.txt |
Description:
|
Secunia Research has discovered a vulnerability in ClamAV, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to a boundary error within the "cli_scanpe()" function in libclamav/pe.c. This can be exploited to cause a heap-based buffer overflow via a specially crafted "Upack" executable. Successful exploitation allows execution of arbitrary code. Versions 0.92 and 0.92.1 are affected.
| | Author: | Alin Rad Pop | | Homepage: | http://secunia.com/ | | File Size: | 4482 | | Related CVE(s): | CVE-2008-1100 | | Last Modified: | Apr 14 16:48:27 2008 |
| MD5 Checksum: | bc71a35fc0ef71c2746cdc41b8e30f13 |
|
|
|
|
|