.:[ packet storm ]:.
                             
reconnaissance for both sides
reconnaissance for both sides

 Section:  .. / 0805-advisories  /

Page 1 of 25
<< 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 >> Files 1 - 25 of 615
Currently sorted by: File SizeSort By: File Name, Last Modified

 ///  File Name: MDVSA-2008-104.txt
Description:
Mandriva Linux Security Advisory - Multiple race conditions have been addressed in the Linux 2.6 kernel.
Homepage:http://www.mandriva.com/security/
File Size:126630
Related CVE(s):CVE-2008-1375, CVE-2008-1669
Last Modified:May 22 11:59:05 2008
MD5 Checksum:2db709748d519db195ca203ee58d55bf

 ///  File Name: USN-609-1.txt
Description:
Ubuntu Security Notice 609-1 - It was discovered that arbitrary Java methods were not filtered out when opening databases in OpenOffice.org. If a user were tricked into running a specially crafted query, a remote attacker could execute arbitrary Java with user privileges. Multiple memory overflow flaws were discovered in OpenOffice.org's handling of Quattro Pro, EMF, and OLE files. If a user were tricked into opening a specially crafted document, a remote attacker might be able to execute arbitrary code with user privileges.
Homepage:http://security.ubuntu.com/
File Size:62628
Related CVE(s):CVE-2007-4575, CVE-2007-5745, CVE-2007-5746, CVE-2007-5747, CVE-2008-0320
Last Modified:May 7 13:36:08 2008
MD5 Checksum:a3deee4ad320e4a22639ce04c53c56e9

 ///  File Name: sa30100.txt
Description:
Secunia Security Advisory - Ubuntu has issued an update for openoffice.org. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
Homepage:http://secunia.com/advisories/30100/
File Size:58436
Last Modified:May 7 20:31:38 2008
MD5 Checksum:fdb3d090247e10ea38ab7ba9829ccf28

 ///  File Name: mtr-overflow.txt
Description:
Mtr suffers from a local and remote stack overflow vulnerability.
Author:Adam Zabrocki
File Size:43807
Last Modified:May 20 10:29:30 2008
MD5 Checksum:b18432f838e87911eed48c482bdd6978

 ///  File Name: dsa-1578-1.txt
Description:
Debian Security Advisory 1578-1 - Several vulnerabilities have been discovered in PHP version 4, a server-side, HTML-embedded scripting language. The session_start function allows remote attackers to insert arbitrary attributes into the session cookie via special characters in a cookie that is obtained from various parameters. A denial of service was possible through a malicious script abusing the glob() function. Certain maliciously constructed input to the wordwrap() function could lead to a denial of service attack. Large len values of the stspn() or strcspn() functions could allow an attacker to trigger integer overflows to expose memory or cause denial of service. The escapeshellcmd API function could be attacked via incomplete multibyte chars.
Homepage:http://www.debian.org/security
File Size:41977
Related CVE(s):CVE-2007-3799, CVE-2007-3806, CVE-2007-3998, CVE-2007-4657, CVE-2008-2051
Last Modified:May 19 21:10:44 2008
MD5 Checksum:3205ee8e6939c1ffec9ba34acd35594f

 ///  File Name: dsa-1572-1.txt
Description:
Debian Security Advisory 1572-1 - Several vulnerabilities have been discovered in PHP, a server-side, HTML-embedded scripting language. The glob function allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via an invalid value of the flags parameter. Integer overflow allows context-dependent attackers to cause a denial of service and possibly have other impact via a printf format parameter with a large width specifier. Stack-based buffer overflow in the FastCGI SAPI. The escapeshellcmd API function could be attacked via incomplete multibyte chars.
Homepage:http://www.debian.org/security
File Size:40512
Related CVE(s):CVE-2007-3806, CVE-2008-1384, CVE-2008-2050, CVE-2008-2051
Last Modified:May 12 10:39:51 2008
MD5 Checksum:65c9c530978f313191386160ca68b3a9

 ///  File Name: sa30288.txt
Description:
Secunia Security Advisory - Debian has issued an update for php4. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, and malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.
Homepage:http://secunia.com/advisories/30288/
File Size:38852
Last Modified:May 19 18:15:47 2008
MD5 Checksum:e69b4e4161d6321047db603b9177cbf0

 ///  File Name: sa30158.txt
Description:
Secunia Security Advisory - Debian has issued an update for php5. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, malicious users to bypass certain security restrictions, and malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.
Homepage:http://secunia.com/advisories/30158/
File Size:37324
Last Modified:May 13 11:01:47 2008
MD5 Checksum:06918163035e7adeb93187c96a7492fe

 ///  File Name: dsa-1565-1.txt
Description:
Debian Security Advisory 1565-1 - Several local vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. Cyrill Gorcunov reported a NULL pointer dereference in code specific to the CHRP PowerPC platforms. Local users could exploit this issue to achieve a Denial of Service (DoS). Nick Piggin of SuSE discovered a number of issues in subsystems which register a fault handler for memory mapped areas. This issue can be exploited by local users to achieve a Denial of Service (DoS) and possibly execute arbitrary code. David Peer discovered that users could escape administrator imposed cpu time limitations (RLIMIT_CPU) by setting a limit of 0. Alexander Viro discovered a race condition in the directory notification subsystem that allows local users to cause a Denial of Service (oops) and possibly result in an escalation of privileges.
Homepage:http://www.debian.org/security
File Size:37278
Related CVE(s):CVE-2007-6694, CVE-2008-0007, CVE-2008-1294, CVE-2008-1375
Last Modified:May 1 18:34:19 2008
MD5 Checksum:ae6543607f059d419bb854fa3f84d205

 ///  File Name: dsa-1588-2.txt
Description:
Debian Security Advisory 1588-2 - Johannes Bauer discovered an integer overflow condition in the hrtimer subsystem on 64-bit systems. This can be exploited by local users to trigger a denial of service (DoS) by causing the kernel to execute an infinite loop. Jan Kratochvil reported a local denial of service condition that permits local users on systems running the amd64 flavor kernel to cause a system crash. Paul Harks discovered a memory leak in the Simple Internet Transition (SIT) code used for IPv6 over IPv4 tunnels. This can be exploited by remote users to cause a denial of service condition. David Miller and Jan Lieskovsky discovered issues with the virtual address range checking of mmaped regions on the sparc architecture that may be exploited by local users to cause a denial of service. This updated advisory adds the linux-2.6 build for s390 and the fai-kernels build for powerpc which were not yet available at the time of DSA-1588-1.
Homepage:http://www.debian.org/security
File Size:36679
Related CVE(s):CVE-2007-6712, CVE-2008-1615, CVE-2008-2136, CVE-2008-2137
Last Modified:May 31 15:24:22 2008
MD5 Checksum:7b4eb15aa749c16aa43a55bfee18da49

 ///  File Name: dsa-1575-1.txt
Description:
Debian Security Advisory 1575-1 - A vulnerability has been discovered in the Linux kernel that may lead to a denial of service. Alexander Viro discovered a race condition in the fcntl code that may permit local users on multi-processor systems to execute parallel code paths that are otherwise prohibited and gain re-ordered access to the descriptor table.
Homepage:http://www.debian.org/security
File Size:36131
Related CVE(s):CVE-2008-1669
Last Modified:May 13 11:04:01 2008
MD5 Checksum:a095807a32a3fc4ee13e1e39f557b145

 ///  File Name: sa30018.txt
Description:
Secunia Security Advisory - Debian has issued an update for the kernel. This fixes some vulnerabilities and security issues, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), or to potentially gain escalated privileges.
Homepage:http://secunia.com/advisories/30018/
File Size:34675
Last Modified:May 7 20:31:38 2008
MD5 Checksum:678ba979fe0c07712335b6f6cd6d9399

 ///  File Name: dsa-1588-1.txt
Description:
Debian Security Advisory 1588-1 - Johannes Bauer discovered an integer overflow condition in the hrtimer subsystem on 64-bit systems. This can be exploited by local users to trigger a denial of service (DoS) by causing the kernel to execute an infinite loop. Jan Kratochvil reported a local denial of service condition that permits local users on systems running the amd64 flavor kernel to cause a system crash. Paul Harks discovered a memory leak in the Simple Internet Transition (SIT) code used for IPv6 over IPv4 tunnels. This can be exploited by remote users to cause a denial of service condition. David Miller and Jan Lieskovsky discovered issues with the virtual address range checking of mmaped regions on the sparc architecture that may be exploited by local users to cause a denial of service.
Homepage:http://www.debian.org/security
File Size:34460
Related CVE(s):CVE-2007-6712, CVE-2008-1615, CVE-2008-2136, CVE-2008-2137
Last Modified:May 27 19:33:33 2008
MD5 Checksum:948ffa8231b344838e89445e5372dd29

 ///  File Name: sa30164.txt
Description:
Secunia Security Advisory - Debian has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
Homepage:http://secunia.com/advisories/30164/
File Size:33780
Last Modified:May 15 00:56:37 2008
MD5 Checksum:0b3bb329832ac3cc912bea4c8c5a4b2f

 ///  File Name: sa30368.txt
Description:
Secunia Security Advisory - Debian has issued an update for linux-2.6. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions or cause a DoS (Denial of service), and by malicious people to potentially cause a DoS.
Homepage:http://secunia.com/advisories/30368/
File Size:31705
Last Modified:May 28 17:49:52 2008
MD5 Checksum:2c2790576991f4bd689e7912013b06ab

 ///  File Name: cisco-sa-20080521-ssh.txt
Description:
Cisco Security Advisory - The Secure Shell server (SSH) implementation in Cisco IOS contains multiple vulnerabilities that allow unauthenticated users the ability to generate a spurious memory access error or, in certain cases, reload the device. The IOS SSH server is an optional service that is disabled by default, but its use is highly recommended as a security best practice for management of Cisco IOS devices. SSH can be configured as part of the AutoSecure feature in the initial configuration of IOS devices, AutoSecure run after initial configuration, or manually. Devices that are not configured to accept SSH connections are not affected by these vulnerabilities.
Homepage:http://www.cisco.com/
File Size:25352
Related CVE(s):CVE-2008-1159
Last Modified:May 22 01:27:05 2008
MD5 Checksum:3063102a29fafb554148bce2f727f0f5

 ///  File Name: cisco-sa-20080514-cucmdos.txt
Description:
Cisco Security Advisory - Cisco Unified Communications Manager, formerly Cisco CallManager, contains multiple denial of service (DoS) vulnerabilities that may cause an interruption in voice services, if exploited. These vulnerabilities were discovered internally by Cisco.
Homepage:http://www.cisco.com/
File Size:23251
Related CVE(s):CVE-2008-1742, CVE-2008-1743, CVE-2008-1744, CVE-2008-1745, CVE-2008-1747, CVE-2008-1748, CVE-2008-1746
Last Modified:May 15 04:27:01 2008
MD5 Checksum:f01d649c7340d9b0d53c17cf1ce68606

 ///  File Name: USN-607-1.txt
Description:
Ubuntu Security Notice 607-1 - It was discovered that Emacs did not account for precision when formatting integers. If a user were tricked into opening a specially crafted file, an attacker could cause a denial of service or possibly other unspecified actions. This issue does not affect Ubuntu 8.04. Steve Grubb discovered that the vcdiff script as included in Emacs created temporary files in an insecure way when used with SCCS. Local users could exploit a race condition to create or overwrite files with the privileges of the user invoking the program.
Homepage:http://security.ubuntu.com/
File Size:23245
Related CVE(s):CVE-2008-1694, CVE-2007-6109
Last Modified:May 6 19:10:40 2008
MD5 Checksum:a268f077c248e418988b3225432e51aa

 ///  File Name: dsa-1590-1.txt
Description:
Debian Security Advisory 1590-1 - Alin Rad Pop discovered that Samba contained a buffer overflow condition when processing certain responses received while acting as a client, leading to arbitrary code execution
Homepage:http://www.debian.org/security
File Size:22435
Related CVE(s):CVE-2008-1105
Last Modified:May 31 15:22:39 2008
MD5 Checksum:fe58d0edc57780fbc8bfa5688ffbf607

 ///  File Name: sa30109.txt
Description:
Secunia Security Advisory - Ubuntu has issued an update for emacs. This fixes some security issues, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
Homepage:http://secunia.com/advisories/30109/
File Size:21899
Last Modified:May 7 20:31:38 2008
MD5 Checksum:c50cf55e4fbe2abf2de2b8d6a656a706

 ///  File Name: USN-612-2.txt
Description:
Ubuntu Security Notice 612-2 - A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH. This vulnerability only affects operating systems which (like Ubuntu) are based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. We consider this an extremely serious vulnerability, and urge all users to act immediately to secure their systems.
Homepage:http://security.ubuntu.com/
File Size:19137
Related CVE(s):CVE-2008-0166
Last Modified:May 13 11:11:26 2008
MD5 Checksum:08b7a276f7d12fdf3ce857fbdc45404e

 ///  File Name: USN-605-1.txt
Description:
Ubuntu Security Notice 605-1 - Various flaws were discovered in the JavaScript engine. If a user had JavaScript enabled and were tricked into opening a malicious email, an attacker could escalate privileges within Thunderbird, perform cross-site scripting attacks and/or execute arbitrary code with the user's privileges. Several problems were discovered in Thunderbird which could lead to crashes and memory corruption. If a user had JavaScript enabled and were tricked into opening a malicious email, an attacker may be able to execute arbitrary code with the user's privileges.
Homepage:http://security.ubuntu.com/
File Size:18180
Related CVE(s):CVE-2008-1233, CVE-2008-1234, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237
Last Modified:May 6 19:12:13 2008
MD5 Checksum:0b243038ac4bfd44eec2a7fae256dc22

 ///  File Name: USN-606-1.txt
Description:
Ubuntu Security Notice 606-1 - Thomas Pollet discovered that CUPS did not properly validate the size of PNG images. A local attacker, and a remote attacker if printer sharing is enabled, could send a crafted file and cause a denial of service or possibly execute arbitrary code as the non-root user in Ubuntu 6.06 LTS and 7.04. In Ubuntu 7.10, attackers would be isolated by the AppArmor CUPS profile.
Homepage:http://security.ubuntu.com/
File Size:18105
Related CVE(s):CVE-2008-1722
Last Modified:May 5 14:00:06 2008
MD5 Checksum:7d5d5bc230258dce039aa660f76063ad

 ///  File Name: sa30078.txt
Description:
Secunia Security Advisory - Ubuntu has issued an update for cups. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
Homepage:http://secunia.com/advisories/30078/
File Size:17530
Last Modified:May 6 18:57:38 2008
MD5 Checksum:e62a764ed001c572b3e5df4c293c08ab

 ///  File Name: sa30105.txt
Description:
Secunia Security Advisory - Ubuntu has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to bypass certain security restrictions, conduct cross-site scripting attacks, or potentially compromise a user's system.
Homepage:http://secunia.com/advisories/30105/
File Size:17513
Last Modified:May 7 20:31:38 2008
MD5 Checksum:d2d0972862e6d73880ad922200276c3f