Section: .. / 0609-advisories /
| /// File Name: |
MDKSA-2006-162.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-162 - The file_exists and imap_reopen functions in PHP before version 5.1.5 do not check for the safe_mode and open_basedir settings, which allows local users to bypass the settings. A buffer overflow in the LWZReadByte function in ext/gd/libgd/gd_gif_in.c in the GD extension in PHP before version 5.1.5 allows remote attackers to have an unknown impact via a GIF file with input_code_size greater than MAX_LWZ_BITS, which triggers an overflow when initializing the table array.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 6475 | | Related CVE(s): | CVE-2006-4481, CVE-2006-4484, CVE-2006-4485 | | Last Modified: | Sep 8 08:48:56 2006 |
| MD5 Checksum: | f2717b240fe7e3d0f1ac51994e3dd5b4 |
|
| /// File Name: |
MDKSA-2006-163.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-163 - A vulnerability in BIND was discovered where it did not sufficiently verify particular requests and responses from other name servers and users. This could be exploited by sending a specially crafted packet to crash the name server.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 4194 | | Related CVE(s): | CVE-2006-4095, CVE-2006-4096 | | Last Modified: | Sep 9 03:58:25 2006 |
| MD5 Checksum: | 30afe88037aaea41e21ff1edc9fe7b91 |
|
| /// File Name: |
MDKSA-2006-164.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-164: Updated xorg-x11/XFree86 packages fix integer overflow vulnerability.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 9164 | | Last Modified: | Sep 15 01:21:00 2006 |
| MD5 Checksum: | e6a65237d59566b18694fd9fae9045b5 |
|
| /// File Name: |
MDKSA-2006-165.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-165: A flaw was discovered in how Mailman handles MIME multipart messages where an attacker could send a carefully-crafted MIME multipart message to a Mailman-run mailing list causing that mailing list to stop working (CVE-2006-2941).
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3528 | | Last Modified: | Sep 26 21:59:12 2006 |
| MD5 Checksum: | 2ff4cfc7317a05b73e6072c21cd3e206 |
|
| /// File Name: |
MDKSA-2006-166.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-166: verify.c in GnuTLS before 1.4.4, when using an RSA key with exponent 3, does not properly handle excess data in the digestAlgorithm.parameters field when generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents GnuTLS from correctly verifying X.509 and other certificates that use PKCS, a variant of CVE-2006-4339.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 4365 | | Last Modified: | Sep 26 21:58:55 2006 |
| MD5 Checksum: | 3ec6900d539d69ab2170eca859cde3c1 |
|
| /// File Name: |
MDKSA-2006-168.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-168: A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 1.5.0.7.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 34067 | | Last Modified: | Sep 26 21:59:02 2006 |
| MD5 Checksum: | c8ebe0c69634c9c321b71f0927486d26 |
|
| /// File Name: |
MDKSA-2006-169.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006:169: A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Thunderbird program, version 1.5.0.7.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 25780 | | Last Modified: | Oct 3 01:40:01 2006 |
| MD5 Checksum: | 14810ae4b53934fd3c275f5000861790 |
|
| /// File Name: |
MDKSA-2006-170.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-170: Webmin before 1.296 and Usermin before 1.226 does not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3256 | | Last Modified: | Oct 3 01:39:15 2006 |
| MD5 Checksum: | 04b553f5d6581240b9004ff9cdb976a0 |
|
| /// File Name: |
Moodle1.6.1.txt |
Description:
|
Moodle 1.6.1+ and possibly prior versions are vulnerable to an SQL injection flaw in /blog/edit.php.
| | Author: | omid | | File Size: | 242 | | Last Modified: | Sep 22 02:31:01 2006 |
| MD5 Checksum: | 81dd861b7de0b6fea9c14f0c33cc3828 |
|
| /// File Name: |
MyBB-1.2.txt |
Description:
|
MyBB 1.2 suffers from full path disclosure and cross site scripting vulnerabilities.
| | Author: | HACKERS PAL | | Homepage: | http://WwW.SoQoR.NeT | | File Size: | 508 | | Last Modified: | Sep 22 02:34:05 2006 |
| MD5 Checksum: | a40afcc60b0ac3765382553eb8b5346c |
|
| /// File Name: |
nextAgeCart-xss.txt |
Description:
|
NextAge Cart suffers from a cross site scripting vulnerability.
| | Author: | meto5757 | | File Size: | 433 | | Last Modified: | Sep 26 22:31:54 2006 |
| MD5 Checksum: | 6991dae218b729bf538f9ff907960fa0 |
|
| /// File Name: |
NixieAffiliate.txt |
Description:
|
NixieAffiliate suffers from an admin bypass vulnerability as well as cross site scripting.
| | Author: | s3rv3r_hack3r | | File Size: | 250 | | Last Modified: | Sep 27 23:29:39 2006 |
| MD5 Checksum: | 2c599d98ed4626448f2d0308703042d7 |
|
| /// File Name: |
norton91033.txt |
Description:
|
Norton insufficiently protects its driver '\Device\SymEvent' against manipulation from malicious applications and it fails to validate its input buffer.
| | Author: | David Matousek | | Homepage: | http://www.matousec.com/ | | Related Exploit: | BTP00011P002NF.zip | | File Size: | 1144 | | Last Modified: | Sep 16 10:31:31 2006 |
| MD5 Checksum: | 66367b04d2885d7f5a67cbe1c385bf00 |
|
| /// File Name: |
Opial-1.0.txt |
Description:
|
Opial Audio/Video Download Management suffers from cross site scripting in index.php
| | Author: | meto5757 | | File Size: | 572 | | Last Modified: | Oct 3 01:52:36 2006 |
| MD5 Checksum: | 4102a3a0ee3136f47315374f6b7ba61e |
|
| /// File Name: |
pandais.txt |
Description:
|
Panda Platinum Internet Security 2006/2007 suffers from multiple vulnerabilities. Insecure file permissions allow an unprivileged local user the ability to obtain system-level access or access to account of another logged on user. Insecure design of the spam filtering control engine allows remote attackers to control bayesian self learning spam filtering process using a malicious web page.
| | Author: | 3APA3A | | Homepage: | http://www.security.nnov.ru/ | | File Size: | 4629 | | Last Modified: | Sep 8 08:01:28 2006 |
| MD5 Checksum: | 158853187b3ce76c37ca3fe25fac646b |
|
| /// File Name: |
PhotoStore.txt |
Description:
|
PhotoStore suffers from multiple cross site scripting vulnerabilities.
| | Author: | meto5757 | | File Size: | 844 | | Last Modified: | Oct 3 01:54:13 2006 |
| MD5 Checksum: | 9084b2681380764b26cc434db91fa37e |
|
| /// File Name: |
PLESK7.5-7.6.txt |
Description:
|
Plesk 7.5 and prior and 7.6 for windows suffer from an information disclosure vulnerability in the file manager.
| | Author: | GuanYu | | Homepage: | http://www.vnhacker.org | | File Size: | 1094 | | Last Modified: | Oct 3 01:34:05 2006 |
| MD5 Checksum: | 1046960464b77bb56826f884e0e0d616 |
|
| /// File Name: |
RISE-2006002.txt |
Description:
|
RISE-2006002: There exists a vulnerability within a architecture dependent function of the FreeBSD kernel (FreeBSD 5.2-RELEASE through FreeBSD 5.5-RELEASE), which when properly exploited can lead to local compromise of the vulnerable system. This vulnerability was fixed in FreeBSD 6.0-RELEASE, but production (legacy) releases 5.2 through 5.5 are still vulnerable.
| | Author: | RISE Security, Ramon de Carvalho Valle | | Homepage: | http://www.risesecurity.org/ | | File Size: | 6050 | | Last Modified: | Oct 3 01:46:36 2006 |
| MD5 Checksum: | f2780f72b89096adff1c6779d3cc1a1f |
|
| /// File Name: |
RLSA_02-2006.txt |
Description:
|
rfdslabs security advisory: RLSA_02-2006 - OSU httpd for OpenVMS suffers from full path and directory content disclosure.
| | Author: | rfdslabs | | Homepage: | http://www.rfdslabs.com.br | | File Size: | 2835 | | Last Modified: | Sep 26 23:22:08 2006 |
| MD5 Checksum: | b09458634cd42844f8d09cd1273de3cf |
|
| /// File Name: |
roller.txt |
Description:
|
Roller version 2.3 is susceptible to cross site scripting attacks.
| | Author: | Avinash Shenoi | | File Size: | 5266 | | Last Modified: | Sep 16 10:02:44 2006 |
| MD5 Checksum: | e7ac79a0c0bb4fa15519e6b696cb81c2 |
|
|
|
|
|