Section: .. / 0604-advisories /
| /// File Name: |
FLSA-2006-156290.txt |
Description:
|
Fedora Legacy Update Advisory - Updated cyrus-imapd packages fix security issues.
| | Homepage: | http://fedoralegacy.org | | File Size: | 5435 | | Last Modified: | Apr 6 18:27:47 2006 |
| MD5 Checksum: | ffeaf4533d1176428eed252a49518199 |
|
| /// File Name: |
FLSA-2006-170411.txt |
Description:
|
Fedora Legacy Update Advisory - Updated imap packages fix security issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 5732 | | Last Modified: | Apr 6 18:28:15 2006 |
| MD5 Checksum: | 6a7125347fa14ae4b410780f8e2c0c41 |
|
| /// File Name: |
FLSA-2006-180159.txt |
Description:
|
Fedora Legacy Update Advisory - Updated unzip package fixes security issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 6119 | | Last Modified: | Apr 6 18:29:47 2006 |
| MD5 Checksum: | 79b1dfdf9987e2fc16c10758ead6ddd5 |
|
| /// File Name: |
FLSA-2006-183571-1.txt |
Description:
|
Fedora Legacy Update Advisory - Updated tar package fixes security issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 5782 | | Last Modified: | Apr 6 18:28:55 2006 |
| MD5 Checksum: | bd4e1398c56b8da2ae7864a45701b273 |
|
| /// File Name: |
FLSA-2006-183571-2.txt |
Description:
|
Fedora Legacy Update Advisory - Updated tar package fixes security issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 4434 | | Last Modified: | Apr 6 18:29:24 2006 |
| MD5 Checksum: | c5afb9488ef208b9a6d552fb7995de0e |
|
| /// File Name: |
FLSA-2006-184074.txt |
Description:
|
Fedora Legacy Update Advisory - Updated pine package fixes security issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 4576 | | Last Modified: | Apr 6 18:30:16 2006 |
| MD5 Checksum: | 25da682c0b5ddded5383ce03c5265ab6 |
|
| /// File Name: |
FLSA-2006-184098.txt |
Description:
|
Fedora Legacy Update Advisory - Updated libc-client packages fixes security issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 4419 | | Last Modified: | Apr 6 18:30:45 2006 |
| MD5 Checksum: | fdded2f46ba894ad2819595a4ea0be9e |
|
| /// File Name: |
FLSA-2006-186277.txt |
Description:
|
Fedora Legacy Update Advisory - Updated sendmail packages fix security issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 11266 | | Last Modified: | Apr 6 18:31:10 2006 |
| MD5 Checksum: | 0ccbe2ca81171716fd2d4d340021d2ca |
|
| /// File Name: |
FN15294.txt |
Description:
|
Findnot.com IP Address Privacy Breach and Unencrypted Data Vulnerability - Several vulnerabilities have been reported in Findnot.com's Microsoft PPTP VPN Service Client, which can cause intermittent immediate loss of anonymity and privacy while using the service.
| | Author: | 123 Privacy Advisories | | File Size: | 7684 | | Last Modified: | Apr 28 17:09:59 2006 |
| MD5 Checksum: | 3b6d1f7db178452fcb159d6ffa7aecdb |
|
| /// File Name: |
FN15398.txt |
Description:
|
Findnot.com DNS Privacy Breach, DNS Spoofing Exposure, and ISP Monitoring Vulnerability - Several vulnerabilities have been reported in Findnot.com's SSH Proxy Service which can cause all DNS requests for lookup of sites visited to be resolved using local DNS servers.
| | Author: | 123 Privacy Advisories | | Homepage: | http://findnot.com | | File Size: | 5825 | | Last Modified: | Apr 28 17:11:47 2006 |
| MD5 Checksum: | 853ece9e020bd4aaaf3d8dfab6d6d27c |
|
| /// File Name: |
FreeContent.txt |
Description:
|
Freecontent v2.9 and 3.0 suffer from a remote file inclusion vulnerability.
| | Author: | Silitix | | File Size: | 4264 | | Last Modified: | Apr 17 19:21:58 2006 |
| MD5 Checksum: | 5f18e0b4955c546addb248af5aee3cb6 |
|
| /// File Name: |
GamingLadder.txt |
Description:
|
My Gaming Ladder Combo System versions less than or equal to 7.0 suffer from a remote file inclusion vulnerability.
| | Homepage: | http://www.nukedx.com | | File Size: | 1143 | | Last Modified: | Apr 28 13:29:57 2006 |
| MD5 Checksum: | 861222dd181bada7508e56a9e8641dd0 |
|
| /// File Name: |
ggg-XSS |
Description:
|
GMail and Google Groups are vulnerable to an cross site scripting (XSS) attack due to their reliance on Content-Disposition to provide separation between the HTML file download and application scopes.
| | Author: | Darren Bounds | | File Size: | 1172 | | Last Modified: | Apr 13 20:57:47 2006 |
| MD5 Checksum: | f2ffc51de82d27cb3424edb7163db9e5 |
|
| /// File Name: |
glsa-200602-13.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200602-13 - The SetImageInfo function was found vulnerable to a format string mishandling. Daniel Kobras discovered that the handling of %-escaped sequences in filenames passed to the function is inadequate in ImageMagick GLSA 200602-06 and the same vulnerability exists in GraphicsMagick. Versions less than 1.1.7 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2747 | | Last Modified: | Mar 31 03:43:06 2006 |
| MD5 Checksum: | dca584621e625df95b471b97a995c50f |
|
| /// File Name: |
glsa-200603-26.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200603-26 - Tavis Ormandy of the Gentoo Linux Security Audit Team discovered that the checkscores() function in scores.c reads in the data from the /var/games/tetris-bsd.scores file without validation, rendering it vulnerable to buffer overflows and incompatible with the system used for managing games on Gentoo Linux. As a result, it cannot be played securely on systems with multiple users. Please note that this is probably a Gentoo-specific issue. Versions less than 2.17-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2713 | | Last Modified: | Apr 1 01:54:59 2006 |
| MD5 Checksum: | abff991f33fcb4f2f9629e0bda27869f |
|
| /// File Name: |
glsa-200604-01.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-01 - MediaWiki fails to decode certain encoded URLs correctly. Versions less than 1.4.15 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3080 | | Last Modified: | Apr 6 18:21:15 2006 |
| MD5 Checksum: | bbe49c6e26708959174386570a3caa41 |
|
| /// File Name: |
glsa-200604-02.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-02 - Jan Schneider of the Horde team discovered a vulnerability in the help viewer of the Horde Application Framework that could allow remote code execution (CVE-2006-1491). Paul Craig reported that services/go.php fails to validate the passed URL parameter correctly (CVE-2006-1260). Versions less than 3.1.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3556 | | Last Modified: | Apr 6 18:21:20 2006 |
| MD5 Checksum: | 2fdc349ca72f8efd24d3a74e17964b51 |
|
| /// File Name: |
glsa-200604-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-03 - FreeRADIUS suffers from insufficient input validation in the EAP-MSCHAPv2 state machine. Versions less than 1.1.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3389 | | Last Modified: | Apr 6 18:21:26 2006 |
| MD5 Checksum: | e2ee344ab3e69ddcfb01bbaa4335deab |
|
| /// File Name: |
glsa-200604-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-04 - Kaffeine uses an unchecked buffer when fetching remote RAM playlists via HTTP. Versions less than 0.7.1-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3026 | | Last Modified: | Apr 6 18:21:34 2006 |
| MD5 Checksum: | d0f1966a9444c3ebe679a064ff15face |
|
| /// File Name: |
glsa-200604-05.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-05 - Luigi Auriemma discovered that Doomsday incorrectly implements formatted printing. Versions less than or equal to 1.8.6-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3397 | | Last Modified: | Apr 6 18:21:07 2006 |
| MD5 Checksum: | 9cfb8de8ac8249973bdd46173cf6073b |
|
| /// File Name: |
glsa-200604-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-06 - ClamAV contains format string vulnerabilities in the logging code (CVE-2006-1615). Furthermore Damian Put discovered an integer overflow in ClamAV's PE header parser (CVE-2006-1614) and David Luyer discovered that ClamAV can be tricked into performing an invalid memory access (CVE-2006-1630). Versions less than 0.88.1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2957 | | Last Modified: | Apr 12 02:48:08 2006 |
| MD5 Checksum: | a95b3faca93ca8d775c8f1279c6cff5e |
|
| /// File Name: |
glsa-200604-07.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-07 - Several vulnerabilities have been identified in the copy of ADOdb included in Cacti. Andreas Sandblad discovered a dynamic code evaluation vulnerability (CVE-2006-0147) and a potential SQL injection vulnerability (CVE-2006-0146). Andy Staudacher reported another SQL injection vulnerability (CVE-2006-0410), and Gulftech Security discovered multiple cross-site-scripting issues (CVE-2006-0806). Versions less than 0.8.6h_p20060108-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3959 | | Last Modified: | Apr 17 18:14:50 2006 |
| MD5 Checksum: | cba79aeb7e3fb7b1b502b6818ebc4fb6 |
|
| /// File Name: |
glsa-200604-08.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-08 - A vulnerability has been reported in the apreq_parse_headers() and apreq_parse_urlencoded() functions of Apache2::Request. Versions less than 2.07 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2608 | | Last Modified: | Apr 17 18:14:38 2006 |
| MD5 Checksum: | 65243d3f443c621f6459a153f501237d |
|
| /// File Name: |
glsa-200604-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-09 - Cyrus-SASL contains an unspecified vulnerability in the DIGEST-MD5 process that could lead to a Denial of Service. Versions less than 2.1.21-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3015 | | Last Modified: | Apr 27 18:00:45 2006 |
| MD5 Checksum: | 71606e1fd6e8c068caba352912a191e3 |
|
| /// File Name: |
glsa-200604-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200604-10 - Andrea Barisani of Gentoo Linux discovered xzgv and zgv allocate insufficient memory when rendering images with more than 3 output components, such as images using the YCCK or CMYK colour space. When xzgv or zgv attempt to render the image, data from the image overruns a heap allocated buffer. Versions less than 0.8-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3579 | | Last Modified: | Apr 27 18:00:53 2006 |
| MD5 Checksum: | 6d74dc7fcf3ca5ace04339a1f91513d6 |
|
|
|
|
|