Section: .. / 0711-advisories /
| /// File Name: |
sa27625.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27625/ | | File Size: | 2200 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | ac6d55d2fe1fff6c1d9ae7b93452a4c7 |
|
| /// File Name: |
sa27629.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27629/ | | File Size: | 2930 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | 4ef59c9eb404179bf07f38cecc2d4e1b |
|
| /// File Name: |
sa27633.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in Citrix Presentation Server, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27633/ | | File Size: | 4401 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | 501a859de3e44bf2b1cb0b2937c6aea2 |
|
| /// File Name: |
sa27641.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for poppler. This fixes some vulnerabilities, which can be exploited by malicious people to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/27641/ | | File Size: | 3509 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | c7dcbf82769d03a0fc91a847aa79e4cd |
|
| /// File Name: |
sa27648.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities and weaknesses have been reported in PHP, where some have unknown impacts and others can be exploited to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/27648/ | | File Size: | 2790 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | f37510528efd9c8e847554260b72f2e5 |
|
| /// File Name: |
sa27665.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for firefox, seamonkey, and xulrunner. This fixes some vulnerabilities and a weakness, which can be exploited by malicious people to disclose sensitive information, conduct phishing attacks, manipulate certain data, and potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27665/ | | File Size: | 2745 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | 6492cd9282e0a4275b93e6f12f853e37 |
|
| /// File Name: |
sa27671.txt |
Description:
|
Secunia Security Advisory - L4teral has discovered a vulnerability in AutoIndex PHP Script, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/27671/ | | File Size: | 2357 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | 117f48f11e5d49fd224f00bb29ee81dd |
|
| /// File Name: |
sa27673.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for ruby. This fixes some security issues, which can be exploited by malicious people to conduct spoofing attacks.
| | Homepage: | http://secunia.com/advisories/27673/ | | File Size: | 2370 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | 96236a58af82046f703ba5c15885ea83 |
|
| /// File Name: |
sa27677.txt |
Description:
|
Secunia Security Advisory - ShAy6oOoN has discovered a vulnerability in X7 Chat, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/27677/ | | File Size: | 2457 | | Last Modified: | Nov 15 11:27:52 2007 |
| MD5 Checksum: | 0059c12916385ce6a9011f9008e90ebd |
|
| /// File Name: |
sa27566.txt |
Description:
|
Secunia Security Advisory - Emiliano Scavuzzo has discovered a vulnerability in TorrentStrike, which can be exploited by malicious users to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/27566/ | | File Size: | 2414 | | Last Modified: | Nov 14 21:23:22 2007 |
| MD5 Checksum: | 9c52e38d4890ce02e63df39f05f3778a |
|
| /// File Name: |
sa27628.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for flac. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27628/ | | File Size: | 24939 | | Last Modified: | Nov 14 21:23:15 2007 |
| MD5 Checksum: | eab938ee4a5f521db9999e6ac96b0da5 |
|
| /// File Name: |
11.14.07-4.txt |
Description:
|
iDefense Security Advisory 11.14.07 - Local exploitation of an access validation vulnerability in Apple Inc.'s Mac OS X could allow an attacker to execute arbitrary code with root privileges. When executing a setuid-root binary, the Mach kernel does not reset the current thread Mach port, or the current thread Mach Exception Port. By first creating and obtaining write access to a Mach port, and then executing a set-uid root binary, an attacker can write arbitrary data into the address space of the process running as root. This leads to arbitrary code execution in the privileged process.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3382 | | Related CVE(s): | CVE-2007-3749 | | Last Modified: | Nov 14 21:20:49 2007 |
| MD5 Checksum: | db69f1be2a8ab12fae9c857505ecbf9d |
|
| /// File Name: |
11.14.07-3.txt |
Description:
|
iDefense Security Advisory 11.14.07 - Local exploitation of a heap based buffer overflow in Apple Inc.'s OS X may allow an attacker to execute arbitrary code in kernel context. The vulnerability exists within a function responsible for allocating an mbuf. mbufs are a BSD concept, long used by BSD kernels to allocate buffers for storing network related data. iDefense has confirmed the existence of this vulnerability in Mac OS X 10.4.10, Workstation and Server editions. Previous versions may also be affected.
| | Author: | Sean Larsson | | Homepage: | http://www.idefense.com/ | | File Size: | 4105 | | Related CVE(s): | CVE-2007-4268 | | Last Modified: | Nov 14 21:20:14 2007 |
| MD5 Checksum: | 6de650a9d042d02fefa2db42ec8f8855 |
|
| /// File Name: |
11.14.07-2.txt |
Description:
|
iDefense Security Advisory 11.14.07 - Local exploitation of a stack based buffer overflow in Apple Inc.'s OS X may allow an attacker to execute arbitrary code in kernel context. The vulnerability exists within the function responsible for adding an AppleTalk zone to an interface's routing table. A zone can be thought of as something similar to a Windows Domain. iDefense has confirmed the existence of this vulnerability in Mac OS X 10.4.10, Workstation and Server editions. Previous versions may also be affected.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3858 | | Related CVE(s): | CVE-2007-4267 | | Last Modified: | Nov 14 21:19:25 2007 |
| MD5 Checksum: | ea8d9166977c7f47a836f402e57a0fd4 |
|
| /// File Name: |
11.14.07-1.txt |
Description:
|
iDefense Security Advisory 11.14.07 - Local exploitation of a heap based buffer overflow in Apple Inc.'s OS X may allow an attacker to execute arbitrary code in kernel context. The vulnerability exists within a function responsible for sending an ASP (AppleTalk Session Protocol) message on an AppleTalk socket. When allocating a buffer, the kernel uses a user provided integer to perform an arithmetic operation that calculates the number of bytes to allocate. This calculation can overflow, leading to the allocation of a buffer of insufficient size. This results in an exploitable heap based buffer overflow within the kernel. iDefense has confirmed the existence of this vulnerability in Mac OS X 10.4.10, Workstation and Server editions. Previous versions may also be affected.
| | Author: | Sean Larsson | | Homepage: | http://www.idefense.com/ | | File Size: | 4022 | | Related CVE(s): | CVE-2007-4269 | | Last Modified: | Nov 14 21:18:12 2007 |
| MD5 Checksum: | 5bd7873cfc1a981a20a28fff6f9c381f |
|
| /// File Name: |
glsa-200711-20.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200711-20 - Bas Wijnen discovered that the Pioneers server may free sessions objects while they are still in use, resulting in access to invalid memory zones. Versions less than 0.11.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2797 | | Related CVE(s): | CVE-2007-5933 | | Last Modified: | Nov 14 21:13:20 2007 |
| MD5 Checksum: | 5da6825de9348088c32d2d8d06d10924 |
|
| /// File Name: |
glsa-200711-19.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200711-19 - Stefan Esser reported that a previous vulnerability was not properly fixed in TikiWiki 1.9.8.1. The TikiWiki development team also added several checks to avoid file inclusion. Versions less than 1.9.8.3 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 3088 | | Related CVE(s): | CVE-2007-5423, CVE-2007-5682 | | Last Modified: | Nov 14 21:13:11 2007 |
| MD5 Checksum: | 756e25fd4face3714ba508cfca928d4a |
|
| /// File Name: |
glsa-200711-18.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200711-18 - A buffer overflow vulnerability in the safer_name_suffix() function in GNU cpio has been discovered. Versions less than 2.9-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2823 | | Related CVE(s): | CVE-2007-4476 | | Last Modified: | Nov 14 21:12:08 2007 |
| MD5 Checksum: | 8f79f9df7168b3a8e16794ea3234dbbd |
|
| /// File Name: |
glsa-200711-17.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200711-17 - candlerb found that ActiveResource, when processing responses using the Hash.from_xml() function, does not properly sanitize filenames. The session management functionality allowed the session_id to be set in the URL. BCC discovered that the to_json() function does not properly sanitize input before returning it to the user. Versions less than 1.2.5 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 3506 | | Related CVE(s): | CVE-2007-3227, CVE-2007-5379, CVE-2007-5380 | | Last Modified: | Nov 14 21:12:01 2007 |
| MD5 Checksum: | dc5f1796319d91545f0c0f7455838bc9 |
|
| /// File Name: |
sa27656.txt |
Description:
|
Secunia Security Advisory - Red Hat has issued an update for kdegraphics. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27656/ | | File Size: | 2328 | | Last Modified: | Nov 14 21:11:02 2007 |
| MD5 Checksum: | 1a2b09126bc3294b827b21017720eaf7 |
|
| /// File Name: |
sa27604.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for cups. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27604/ | | File Size: | 2170 | | Last Modified: | Nov 14 21:10:34 2007 |
| MD5 Checksum: | b6cccd6ac7b587487ad3c239e65679f0 |
|
| /// File Name: |
sa27613.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for perl. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27613/ | | File Size: | 5348 | | Last Modified: | Nov 14 21:10:34 2007 |
| MD5 Checksum: | 658f1301c6fb3fbfc9042b1fbf6297d9 |
|
| /// File Name: |
sa27624.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for multiple KDE packages. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/27624/ | | File Size: | 28197 | | Last Modified: | Nov 14 21:10:34 2007 |
| MD5 Checksum: | 7e96a7465ce5deded31ed2d5eb67eecb |
|
| /// File Name: |
sa27647.txt |
Description:
|
Secunia Security Advisory - Jan Fry and Adrian Pastor have reported a vulnerability in F5 Firepass 4100 SSL VPN, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/27647/ | | File Size: | 2732 | | Last Modified: | Nov 14 21:10:34 2007 |
| MD5 Checksum: | c4adea6000bbb7d92ec80c3312738b29 |
|
| /// File Name: |
sa27662.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged a vulnerability in various Avaya products, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/27662/ | | File Size: | 3037 | | Last Modified: | Nov 14 21:10:34 2007 |
| MD5 Checksum: | faaa4832bb8c59cf81d15d6c7a74ab54 |
|
|
|
|
|