.:[ packet storm ]:.
                         
security in numbers
security in numbers

 Section:  .. / 0907-advisories  /

Page 24 of 25
<< 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 >> Files 575 - 600 of 600
Currently sorted by: File NameSort By: Last Modified, File Size

 ///  File Name: TA09-204A.txt
Description:
Technical Cyber Security Alert TA09-204A - Adobe has released Security advisory APSA09-03, which describes a vulnerability affecting Adobe Flash. Other Adobe applications that include the Flash runtime, such as Adobe Reader 9, are also affected.
Homepage:http://www.us-cert.gov/
File Size:3970
Last Modified:Jul 23 18:33:27 2009
MD5 Checksum:eed8590316c59c372fe0798a7e4f2373

 ///  File Name: TA09-209A.txt
Description:
Technical Cyber Security Alert TA09-209A - Microsoft has released out-of-band updates to address critical vulnerabilities in Microsoft Internet Explorer running on most supported versions of Windows. The updates also help mitigate attacks against ActiveX controls developed with vulnerable versions of the Microsoft Active Template Library (ATL).
Homepage:http://www.us-cert.gov/
File Size:6037
Related CVE(s):CVE-2008-0015
Last Modified:Jul 28 19:48:20 2009
MD5 Checksum:2cdf46239baa999ca58293c7a5088ee4

 ///  File Name: terratec-poorinstall.txt
Description:
Terratec's TV software HomeCinema version 6.3 installs vulnerable and outdated DLLs.
Author:Stefan Kanthak
File Size:2927
Last Modified:Jul 17 14:49:03 2009
MD5 Checksum:c5a8ecfe6adc3f21c388407e40ed526a

 ///  File Name: TPTI-09-05.txt
Description:
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required in that a target must visit a malicious page or open a malicious video file. The specific flaw exists within Microsoft's DirectShow module quartz.dll. While parsing QuickTime atoms the NumberOfEntries field is trusted and if modified can control the location of several pointers meant to track stream positions. Specifying values that are larger than the number of bytes left to process in the input file will cause corruption that can be leveraged to execute arbitrary code.
Author:Aaron Portnoy
Homepage:http://www.tippingpoint.com/
File Size:1573
Related CVE(s):CVE-2009-1539
Last Modified:Jul 14 16:34:50 2009
MD5 Checksum:e16bfcbae52be9ce88926b9310a928f4

 ///  File Name: USN-793-1.txt
Description:
Ubuntu Security Notice USN-793-1 - Multiple vulnerabilities associated with the Linux 2.6 kernel have been addressed. These issues range from arbitrary code execution to denial of service vulnerabilities.
Homepage:http://security.ubuntu.com/
File Size:123428
Related CVE(s):CVE-2009-1072, CVE-2009-1184, CVE-2009-1192, CVE-2009-1242, CVE-2009-1265, CVE-2009-1336, CVE-2009-1337, CVE-2009-1338, CVE-2009-1360, CVE-2009-1385, CVE-2009-1439, CVE-2009-1630, CVE-2009-1633, CVE-2009-1914, CVE-2009-1961
Last Modified:Jul 2 11:40:16 2009
MD5 Checksum:7f9722ad5f2b4194ed1dea71b4ea44e1

 ///  File Name: USN-794-1.txt
Description:
Ubuntu Security Notice USN-794-1 - It was discovered that the Compress::Raw::Zlib Perl module incorrectly handled certain zlib compressed streams. If a user or automated system were tricked into processing a specially crafted compressed stream or file, a remote attacker could crash the application, leading to a denial of service.
Homepage:http://security.ubuntu.com/
File Size:17283
Related CVE(s):CVE-2009-1391
Last Modified:Jul 2 15:00:43 2009
MD5 Checksum:ca703b6ed4622d14c84d66fc189cf758

 ///  File Name: USN-795-1.txt
Description:
Ubuntu Security Notice USN-795-1 - It was discovered that Nagios did not properly parse certain commands submitted using the WAP web interface. An authenticated user could exploit this flaw and execute arbitrary programs on the server.
Homepage:http://security.ubuntu.com/
File Size:8778
Related CVE(s):CVE-2009-2288
Last Modified:Jul 2 15:01:00 2009
MD5 Checksum:dc97f2b134cd141f48a912279e4bb62b

 ///  File Name: USN-796-1.txt
Description:
Ubuntu Security Notice USN-796-1 - Yuriy Kaminskiy discovered that Pidgin did not properly handle certain messages in the ICQ protocol handler. A remote attacker could send a specially crafted message and cause Pidgin to crash.
Homepage:http://security.ubuntu.com/
File Size:14484
Related CVE(s):CVE-2009-1889
Last Modified:Jul 6 14:48:06 2009
MD5 Checksum:ca4112317e66f3452f733d79e891f18c

 ///  File Name: USN-797-1.txt
Description:
Ubuntu Security Notice USN-797-1 - It was discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, a remote attacker could cause an application linked against libtiff to crash, leading to a denial of service.
Homepage:http://security.ubuntu.com/
File Size:18952
Related CVE(s):CVE-2009-2285
Last Modified:Jul 6 14:48:21 2009
MD5 Checksum:6764f0068e53bf3c1cabf06f73b0cd31

 ///  File Name: USN-798-1.txt
Description:
Ubuntu Security Notice USN-798-1 - Several flaws were discovered in the Firefox browser and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. Attila Suszter discovered a flaw in the way Firefox processed Flash content. If a user were tricked into viewing and navigating within a specially crafted Flash object, a remote attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. It was discovered that Firefox did not properly handle some SVG content. An attacker could exploit this to cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. A flaw was discovered in the JavaScript engine. If a user were tricked into viewing a malicious website, an attacker could exploit this perform cross-site scripting attacks.
Homepage:http://security.ubuntu.com/
File Size:38686
Related CVE(s):CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2467, CVE-2009-2469, CVE-2009-2472
Last Modified:Jul 22 17:04:28 2009
MD5 Checksum:4a176b3bedf4635cf94c874be5b4b46d

 ///  File Name: USN-799-1.txt
Description:
Ubuntu Security Notice USN-799-1 - It was discovered that the D-Bus library did not correctly validate signatures. If a local user sent a specially crafted D-Bus key, they could spoof a valid signature and bypass security policies.
Homepage:http://security.ubuntu.com/
File Size:19265
Related CVE(s):CVE-2009-1189
Last Modified:Jul 13 17:14:52 2009
MD5 Checksum:1512e132e97366d4a8db1dcb1ff681b4

 ///  File Name: USN-800-1.txt
Description:
Ubuntu Security Notice USN-800-1 - It was discovered that irssi did not properly check the length of strings when processing WALLOPS messages. If a user connected to an IRC network where an attacker had IRC operator privileges, a remote attacker could cause a denial of service.
Homepage:http://security.ubuntu.com/
File Size:10201
Related CVE(s):CVE-2009-1959
Last Modified:Jul 13 17:15:18 2009
MD5 Checksum:c86740cdc4279025e9c6aeee88842556

 ///  File Name: USN-801-1.txt
Description:
Ubuntu Security Notice USN-801-1 - Tielei Wang and Tom Lane discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, an attacker could execute arbitrary code with the privileges of the user invoking the program.
Homepage:http://security.ubuntu.com/
File Size:18955
Related CVE(s):CVE-2009-2347
Last Modified:Jul 13 17:15:40 2009
MD5 Checksum:d7dae23ae367916f0423437eb1b2dc98

 ///  File Name: USN-802-1.txt
Description:
Ubuntu Security Notice USN-802-1 - It was discovered that mod_proxy_http did not properly handle a large amount of streamed data when used as a reverse proxy. A remote attacker could exploit this and cause a denial of service via memory resource consumption. This issue affected Ubuntu 8.04 LTS, 8.10 and 9.04. It was discovered that mod_deflate did not abort compressing large files when the connection was closed. A remote attacker could exploit this and cause a denial of service via CPU resource consumption.
Homepage:http://security.ubuntu.com/
File Size:32914
Related CVE(s):CVE-2009-1890, CVE-2009-1891
Last Modified:Jul 13 17:16:00 2009
MD5 Checksum:cdb0124957822229f0d460d314ac009a

 ///  File Name: USN-803-1.txt
Description:
Ubuntu Security Notice USN-803-1 - It was discovered that the DHCP client as included in dhcp3 did not verify the length of certain option fields when processing a response from an IPv4 dhcp server. If a user running Ubuntu 6.06 LTS or 8.04 LTS connected to a malicious dhcp server, a remote attacker could cause a denial of service or execute arbitrary code as the user invoking the program, typically the 'dhcp' user. For users running Ubuntu 8.10 or 9.04, a remote attacker should only be able to cause a denial of service in the DHCP client. In Ubuntu 9.04, attackers would also be isolated by the AppArmor dhclient3 profile.
Homepage:http://security.ubuntu.com/
File Size:23739
Related CVE(s):CVE-2009-0692
Last Modified:Jul 14 16:26:27 2009
MD5 Checksum:13c59926aecfb14856f64bee352d4038

 ///  File Name: USN-804-1.txt
Description:
Ubuntu Security Notice USN-804-1 - Tavis Ormandy and Yorick Koster discovered that PulseAudio did not safely re-execute itself. A local attacker could exploit this to gain root privileges.
Homepage:http://security.ubuntu.com/
File Size:64286
Related CVE(s):CVE-2009-1894
Last Modified:Jul 17 15:21:32 2009
MD5 Checksum:9f799cad6b956a0f03897b8bf5a17138

 ///  File Name: USN-805-1.txt
Description:
Ubuntu Security Notice USN-805-1 - It was discovered that Ruby did not properly validate certificates. An attacker could exploit this and present invalid or revoked X.509 certificates. It was discovered that Ruby did not properly handle string arguments that represent large numbers. An attacker could exploit this and cause a denial of service.
Homepage:http://security.ubuntu.com/
File Size:51507
Related CVE(s):CVE-2009-0642, CVE-2009-1904
Last Modified:Jul 20 21:25:05 2009
MD5 Checksum:789059447e9e13417e0c4a5130ee83b7

 ///  File Name: USN-806-1.txt
Description:
Ubuntu Security Notice USN-806-1 - It was discovered that Python incorrectly handled certain arguments in the imageop module. If an attacker were able to pass specially crafted arguments through the crop function, they could execute arbitrary code with user privileges. For Python 2.5, this issue only affected Ubuntu 8.04 LTS. Multiple integer overflows were discovered in Python's stringobject and unicodeobject expandtabs method. If an attacker were able to exploit these flaws they could execute arbitrary code with user privileges or cause Python applications to crash, leading to a denial of service.
Homepage:http://security.ubuntu.com/
File Size:19393
Related CVE(s):CVE-2008-4864, CVE-2008-5031
Last Modified:Jul 23 18:34:08 2009
MD5 Checksum:daba5b850884a80a1b4d15e19899b8fb

 ///  File Name: USN-807-1.txt
Description:
Ubuntu Security Notice USN-807-1 - Michael Tokarev discovered that the RTL8169 network driver did not correctly validate buffer sizes. A remote attacker on the local network could send specially traffic traffic that would crash the system or potentially grant elevated privileges. Julien Tinnes and Tavis Ormandy discovered that when executing setuid processes the kernel did not clear certain personality flags. A local attacker could exploit this to map the NULL memory page, causing other vulnerabilities to become exploitable. Ubuntu 6.06 was not affected. Matt T. Yourst discovered that KVM did not correctly validate the page table root. A local attacker could exploit this to crash the system, leading to a denial of service. Ubuntu 6.06 was not affected. Ramon de Carvalho Valle discovered that eCryptfs did not correctly validate certain buffer sizes. A local attacker could create specially crafted eCryptfs files to crash the system or gain elevated privileges. Ubuntu 6.06 was not affected.
Homepage:http://security.ubuntu.com/
File Size:120683
Related CVE(s):CVE-2009-1389, CVE-2009-1895, CVE-2009-2287, CVE-2009-2406, CVE-2009-2407
Last Modified:Jul 29 14:40:43 2009
MD5 Checksum:e38a3fc62c247224d7479101484e3b18

 ///  File Name: USN-808-1.txt
Description:
Ubuntu Security Notice USN-808-1 - Micha Krause discovered that Bind did not correctly validate certain dynamic DNS update packets. An unauthenticated remote attacker could send specially crafted traffic to crash the DNS server, leading to a denial of service.
Homepage:http://security.ubuntu.com/
File Size:38387
Related CVE(s):CVE-2009-0696
Last Modified:Jul 29 14:59:32 2009
MD5 Checksum:a75bca17cd57d1864b584f3783bfd3ad

 ///  File Name: VMSA-2009-0008.txt
Description:
VMware Security Advisory - An input validation flaw in the asn1_decode_generaltime function in MIT Kerberos 5 before 1.6.4 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
Homepage:http://www.vmware.com/
File Size:4219
Related CVE(s):CVE-2009-0846
Last Modified:Jul 1 12:53:40 2009
MD5 Checksum:4f0734141a168fd7c0c58057eb4527e3

 ///  File Name: VMSA-2009-0009.txt
Description:
VMware Security Advisory - A vulnerability in the udev program did not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. Sudo versions 1.6.9p17 through 1.6.9p19 do not properly interpret a system group in the sudoers file during authorization decisions for a user who belongs to that group, which might allow local users to leverage an applicable sudoers file and gain root privileges by using a sudo command. The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to trigger arbitrary requests to intranet servers, read or overwrite arbitrary files by using a redirect to a file: URL, or execute arbitrary commands by using a redirect to an scp: URL.
Homepage:http://www.vmware.com/
File Size:6984
Related CVE(s):CVE-2009-1185, CVE-2009-0034, CVE-2009-0037
Last Modified:Jul 13 14:26:12 2009
MD5 Checksum:caab72c494daa95336f0081118a4a3bc

 ///  File Name: ZDI-09-045.txt
Description:
Zero Day Initiative Advisory 09-045 - This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required in that a target must visit a malicious page or open a malicious video file. The specific flaw exists within the parsing of the length records of certain QuickTime atoms. The application implicitly trusts the length during a transformation which will lead to memory corruption and can be leveraged to execute arbitrary code under the context of the current user.
Homepage:http://www.zerodayinitiative.com/
File Size:2706
Related CVE(s):CVE-2009-1539
Last Modified:Jul 14 16:34:29 2009
MD5 Checksum:880ec874756b2f62a365bb8d8f4e4a5a

 ///  File Name: ZDI-09-046.txt
Description:
Zero Day Initiative Advisory 09-046 - This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Novell's Privileged User Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within the unifid.exe service which binds on port 29010 for a protocol providing RPC-like functionality encapsulated over SSL. This protocol allows a client to make a method call into a module. The 'spf' RPC call is implemented unsafely allowing remote attackers to load arbitrary modules over the network resulting in code execution under the context of the service.
Homepage:http://www.zerodayinitiative.com/
File Size:2817
Last Modified:Jul 21 17:15:02 2009
MD5 Checksum:eb427c20b685af98a6c32a3d713cb2fc

 ///  File Name: zortamid3-overflow.txt
Description:
Zortam ID3 Tag Editor version 5.0 suffers from a remote stack overflow vulnerability.
Author:LiquidWorm
Homepage:http://www.zeroscience.org/
Related Exploit:aimp251-overflow.tgz
File Size:1017
Last Modified:Jul 17 14:50:57 2009
MD5 Checksum:28a7a3e370e8860501b4c52bcc6594e7