<?xml version="1.0" encoding="ISO-8859-1" ?>
<rss version="2.0">
	<channel>
	<title>Packet Storm Security Last 20</title>
	<link>http://packetstormsecurity.org/</link>
	<description>20 Most Recent Packet Storm File Additions</description>
	<language>en-us</language>

<item>
	<title>mxsystem-sql.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/mxsystem-sql.txt</link>
	<description>MX-System version 2.7.3 suffers from a remote SQL injection vulnerability in index.php. </description>
</item>
<item>
	<title>CORE-2008-0415.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/CORE-2008-0415.txt</link>
	<description>Core Security Technologies Advisory - The Borland Interbase 2007 database server is vulnerable to an integer overflow when a malformed packet is sent to the default TCP port 3050. The integer overflow can cause a stack overflow, which allows arbitrary code execution with system privileges. Service pack 2 (0.1.0.256) on Solaris and Windows are both vulnerable. </description>
</item>
<item>
	<title>glsa-200805-19.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/glsa-200805-19.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200805-19 - Multiple vulnerabilities in ClamAV may result in the remote execution of arbitrary code. Versions less than 0.93 are affected. </description>
</item>
<item>
	<title>glsa-200805-18.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/glsa-200805-18.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200805-18 - Multiple vulnerabilities have been reported in Mozilla Firefox, Thunderbird, SeaMonkey and XULRunner, some of which may allow user-assisted execution of arbitrary code. Versions less than 2.0.0.14 are affected. </description>
</item>
<item>
	<title>glsa-200805-17.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/glsa-200805-17.txt</link>
	<description>Gentoo Linux Security Advisory GLSA 200805-17 - Tavis Ormandy and Will Drewry of the Google Security Team have reported a double free vulnerability when processing a crafted regular expression containing UTF-8 characters. Versions less than 5.8.8-r5 are affected. </description>
</item>
<item>
	<title>dsa-1583-1.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/dsa-1583-1.txt</link>
	<description>Debian Security Advisory 1583-1 - Several remote vulnerabilities have been discovered in Gnome PeerCast, the Gnome interface to PeerCast, a P2P audio and video streaming server. Luigi Auriemma discovered that PeerCast is vulnerable to a heap overflow in the HTTP server code, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SOURCE request. Nico Golde discovered that PeerCast, a P2P audio and video streaming server, is vulnerable to a buffer overflow in the HTTP Basic Authentication code, allowing a remote attacker to crash PeerCast or execute arbitrary code. </description>
</item>
<item>
	<title>dsa-1582-1.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/dsa-1582-1.txt</link>
	<description>Debian Security Advisory 1582-1 - Nico Golde discovered that PeerCast, a P2P audio and video streaming server, is vulnerable to a buffer overflow in the HTTP Basic Authentication code, allowing a remote attacker to crash PeerCast or execute arbitrary code. </description>
</item>
<item>
	<title>dsa-1581-1.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/dsa-1581-1.txt</link>
	<description>Debian Security Advisory 1581-1 - Several remote vulnerabilities have been discovered in GNUTLS, an implementation of the SSL/TLS protocol suite. A pre-authentication heap overflow involving oversized session resumption data may lead to arbitrary code execution. Repeated client hellos may result in a pre-authentication denial of service condition due to a null pointer dereference. Decoding cipher padding with an invalid record length may cause GNUTLS to read memory beyond the end of the received record, leading to a pre-authentication denial of service condition. </description>
</item>
<item>
	<title>comicshout-sql.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/comicshout-sql.txt</link>
	<description>ComicShout version 2.5 suffers from a remote SQL injection vulnerability in index.php. </description>
</item>
<item>
	<title>mantis-xssxsrf.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/mantis-xssxsrf.txt</link>
	<description>Mantis Bug Tracker version 1.1.1 suffers from remote code execution, cross site scripting, and cross site request forgery vulnerabilities. </description>
</item>
<item>
	<title>FICORA-130447.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/FICORA-130447.txt</link>
	<description>CERT-FI Vulnerability Advisory on GnuTLS - GnuTLS versions prior to 2.2.4 suffer from denial of service and buffer overflow vulnerabilities. </description>
</item>
<item>
	<title>ecms-sql.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/ecms-sql.txt</link>
	<description>eCMS version 0.4.2 suffers from remote SQL injection and bypass vulnerabilities. </description>
</item>
<item>
	<title>starsgames-xss.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/starsgames-xss.txt</link>
	<description>Stargames Control Panel versions 4.6.2 and below suffer from a cross site scripting vulnerability. </description>
</item>
<item>
	<title>appservopen-xss.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/appservopen-xss.txt</link>
	<description>AppServ Open Project versions 2.5.10 and below suffer from a cross site scripting vulnerability. </description>
</item>
<item>
	<title>entertainment-lfi.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/entertainment-lfi.txt</link>
	<description>EntertainmentScript version 1.4.0 local file inclusion exploit that takes advantage of page.php. </description>
</item>
<item>
	<title>entertainment-sql.txt</title>
	<link>http://packetstormsecurity.org/0805-exploits/entertainment-sql.txt</link>
	<description>EntertainmentScript suffers from a remote SQL injection vulnerability in play.php. </description>
</item>
<item>
	<title>SSRT080056-2.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/SSRT080056-2.txt</link>
	<description>HP Security Bulletin - Potential security vulnerabilities have been identified with HP-UX running Apache with PHP. These vulnerabilities could be exploited remotely to create a Denial of Service (DoS) or to gain extended privileges. </description>
</item>
<item>
	<title>SSRT071454.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/SSRT071454.txt</link>
	<description>HP Security Bulletin - A potential security vulnerability has been identified HP-UX running the useradd(1M) command. The vulnerability could be exploited locally to allow unauthorized access to directories or files. </description>
</item>
<item>
	<title>SSRT080071.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/SSRT080071.txt</link>
	<description>HP Security Bulletin - Various potential security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Some of these vulnerabilities may be pertinent to the SMA, please check the table in the Resolution section of this Security Bulletin. </description>
</item>
<item>
	<title>mtr-overflow.txt</title>
	<link>http://packetstormsecurity.org/0805-advisories/mtr-overflow.txt</link>
	<description>Mtr suffers from a local and remote stack overflow vulnerability. </description>
</item></channel>
</rss>
