Section: .. / 0611-advisories /
| /// File Name: |
MDKSA-2006-219.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-219-1 - GNU tar 1.16 and 1.15.1, and possibly other versions, allows user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3939 | | Related CVE(s): | CVE-2006-6097, CVE-2002-1216 | | Last Modified: | Nov 30 19:43:41 2006 |
| MD5 Checksum: | fc6c7979ea68386eb384cec8b81642e2 |
|
| /// File Name: |
macosx-preauth.txt |
Description:
|
The network kernel extension com.apple.nke.pppoe that works concurrently with the pppd has a critical vulnerability that may lead to arbitrary code execution with system privileges. Affected product and versions include Mac OS X version 10.3.9, Mac OS X Server version 10.3.9, Mac OS X version 10.4.8, and Mac OS X Server version 10.4.8.
| | Author: | Mu Security Research | | Homepage: | http://labs.musecurity.com/ | | File Size: | 2911 | | Last Modified: | Nov 30 19:42:21 2006 |
| MD5 Checksum: | f44848b5ca7af2a87549157a6f34a57f |
|
| /// File Name: |
proftpdmodtls.txt |
Description:
|
A remote buffer overflow vulnerability has been found in mod_tls module of ProFTPD server. The vulnerability could allow a remote un-authenticated attacker to gain root privileges. All versions including 1.3.0a are affected.
| | Author: | Evgeny Legerov | | File Size: | 1708 | | Last Modified: | Nov 30 19:37:59 2006 |
| MD5 Checksum: | ecfc1ef50d87351b49f60628686006c2 |
|
| /// File Name: |
USN-387-1.txt |
Description:
|
Ubuntu Security Notice 387-1 - Dovecot was discovered to have an error when handling its index cache files. This error could be exploited by authenticated POP and IMAP users to cause a crash of the Dovecot server, or possibly to execute arbitrary code. Only servers using the non-default option "mmap_disable=yes" were vulnerable.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 6320 | | Related CVE(s): | CVE-2006-5973 | | Last Modified: | Nov 30 19:14:45 2006 |
| MD5 Checksum: | 62f8dcbd3a3d4b3b0fdcc6f655dedd55 |
|
| /// File Name: |
USN-385-1.txt |
Description:
|
Ubuntu Security Notice 385-1 - Teemu Salmela discovered that tar still handled the deprecated GNUTYPE_NAMES record type. This record type could be used to create symlinks that would be followed while unpacking a tar archive. If a user or an automated system were tricked into unpacking a specially crafted tar file, arbitrary files could be overwritten with user privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4942 | | Related CVE(s): | CVE-2006-6097 | | Last Modified: | Nov 30 19:07:26 2006 |
| MD5 Checksum: | bfde5d7997b7b6a4f79a2a7a7b8c7e9b |
|
| /// File Name: |
gpgtaketwo.txt |
Description:
|
While fixing a bug reported by Hugh Warrington, a buffer overflow has been identified in all released GnuPG versions. The current versions 1.4.5 and 2.0.0 are affected. A small patch is provided.
| | Author: | Werner Koch | | File Size: | 2502 | | Last Modified: | Nov 30 19:03:24 2006 |
| MD5 Checksum: | b61c2ceb35b9de65ad9a82a807753b38 |
|
| /// File Name: |
sa23143.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in KOffice, which can be exploited by malicious people to potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23143/ | | File Size: | 2796 | | Last Modified: | Nov 30 11:12:49 2006 |
| MD5 Checksum: | ced1c7a9dbd2688579e2134497177980 |
|
| /// File Name: |
sa23066.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been discovered in Safari, which can be exploited by malicious people to conduct phishing attacks.
| | Homepage: | http://secunia.com/advisories/23066/ | | File Size: | 2695 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 9a6a07c0796b10f62619f11b3fe640c1 |
|
| /// File Name: |
sa23073.txt |
Description:
|
Secunia Security Advisory - Eugene Teo has reported a vulnerability in the Linux Kernel, which potentially can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23073/ | | File Size: | 2725 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 91cc05ff3a651b1a5690ab3749b5a53e |
|
| /// File Name: |
sa23080.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered two vulnerabilities in MailEnable, which can be exploited by malicious users to cause a DoS (Denial of service) or to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23080/ | | File Size: | 3372 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | ef6a76c3b154cdd628ae42954ec2f93b |
|
| /// File Name: |
sa23110.txt |
Description:
|
Secunia Security Advisory - Ubuntu has isssued an update for gnupg. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23110/ | | File Size: | 8173 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | f18f83bc70fa94b10c6b8b81f7238dd2 |
|
| /// File Name: |
sa23112.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for texinfo. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions with escalated privileges and by malicious people to potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23112/ | | File Size: | 6602 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 6282dd1efe445dbd2330f53e68ec7e38 |
|
| /// File Name: |
sa23124.txt |
Description:
|
Secunia Security Advisory - A vulnerability with unknown impact has been reported in freePBX.
| | Homepage: | http://secunia.com/advisories/23124/ | | File Size: | 2359 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | cb0edb61602af3d8a5317487bbd72461 |
|
| /// File Name: |
sa23126.txt |
Description:
|
Secunia Security Advisory - Fukumori has reported a vulnerability in Blogn, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23126/ | | File Size: | 2527 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 66ea266b041c0521c4ca380de80f595b |
|
| /// File Name: |
sa23138.txt |
Description:
|
Secunia Security Advisory - Some bugs have been discovered in Adobe Reader and Adobe Acrobat, which may cause an included ActiveX control to crash.
| | Homepage: | http://secunia.com/advisories/23138/ | | File Size: | 3425 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 2261c6a5a44a87edf76e4d48b242dc3a |
|
| /// File Name: |
sa23145.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Kronolith, which can be exploited by malicious users to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/23145/ | | File Size: | 2677 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 9aafefdb640c585655162dd596a92c9e |
|
| /// File Name: |
sa23147.txt |
Description:
|
Secunia Security Advisory - Aria-Security Team have reported a vulnerability in fipsShop, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23147/ | | File Size: | 2541 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 25e4dd9a1513ff7fef4c057911fe8cd6 |
|
| /// File Name: |
sa23148.txt |
Description:
|
Secunia Security Advisory - tarkus has discovered some vulnerabilities in b2evolution, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23148/ | | File Size: | 2885 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | 9e85da46ef542a622e46071cf7933cac |
|
| /// File Name: |
sa23149.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Chama Cargo, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23149/ | | File Size: | 2651 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | f0c20a63f8d86fae6b74c4117735c946 |
|
| /// File Name: |
sa23154.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for mono. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions with escalated privileges.
| | Homepage: | http://secunia.com/advisories/23154/ | | File Size: | 2353 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | d14780d739db6789079b1d542608ccf4 |
|
| /// File Name: |
sa23156.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for lha. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23156/ | | File Size: | 2379 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | f4cc81553d5a1839ad1485428e5bdad8 |
|
| /// File Name: |
sa23162.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for koffice. This fixes a vulnerability, which can be exploited by malicious people to potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23162/ | | File Size: | 10808 | | Last Modified: | Nov 30 11:12:25 2006 |
| MD5 Checksum: | fe11a4dd9ae2be72d6a31fabb8159ffd |
|
| /// File Name: |
MHL-2006-004.txt |
Description:
|
Mayhemic Labs Public Advisory MHL-2006-004 - MBoard does not check the Post ID for malicious data when replying, allowing an attacker to create blank files on the system wherever the web server has write access. Versions 1.22 and below are affected.
| | Author: | Mayhemic Labs Security | | Homepage: | http://www.mayhemiclabs.com/ | | File Size: | 1742 | | Last Modified: | Nov 29 11:21:53 2006 |
| MD5 Checksum: | 3e0d5f7e7a78b8175c6157c4ba767472 |
|
| /// File Name: |
dsa-1219-1.txt |
Description:
|
Debian Security Advisory 1219-1 - The GNU texinfo package has been found susceptible to insecure file handling and buffer overflow flaws.
| | Homepage: | http://www.debian.org/security | | File Size: | 7145 | | Related CVE(s): | CVE-2005-3011, CVE-2006-4810 | | Last Modified: | Nov 29 11:17:26 2006 |
| MD5 Checksum: | 4801675a34029726bda216edaa28938c |
|
|
|
|
|