Section: .. / 0611-advisories /
| /// File Name: |
advisory_122006.137.txt |
Description:
|
Hardened-PHP Project Security Advisory - phpMyAdmin versions 2.9.0.2 and below suffer from a cross site scripting vulnerability in error.php.
| | Author: | Stefan Esser | | Homepage: | http://www.hardened-php.net/ | | File Size: | 2525 | | Last Modified: | Nov 5 23:55:53 2006 |
| MD5 Checksum: | 7debbde23ded5dc07bfc575954cbce7d |
|
| /// File Name: |
SAP-multiple.txt |
Description:
|
The SAP Web Application Server suffers from denial of service, remote file disclosure, and local privilege escalation vulnerabilities.
| | Author: | Nicob | | File Size: | 1904 | | Last Modified: | Nov 5 23:52:43 2006 |
| MD5 Checksum: | fb3d3058c79e768dd0f000090523bd13 |
|
| /// File Name: |
ZDI-06-036.txt |
Description:
|
ZDI-06-036: Novell Netmail User Authentication Buffer Overflow Vulnerability - The specific flaw exists within the user authentication component of Novell Netmail. The routine responsible for authenticating Netmail users lacks adequate bounds checking when processing a username containing one or more period (.) characters. The affected code is reused by several Netmail services including SMTP, POP, IMAP, HTTP and the proprietary NMAP. Each of these services is vulnerable to an exploitable stack-based buffer overflow.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2992 | | Last Modified: | Nov 3 18:06:15 2006 |
| MD5 Checksum: | 82e9c8131cd176119f057ca5ffaa3941 |
|
| /// File Name: |
dsa-1205-1.txt |
Description:
|
Debian Security Advisory 1205-1: Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might lead to a denial of service through a symlink attack.
| | Homepage: | http://www.debian.org/security | | File Size: | 7138 | | Last Modified: | Nov 3 18:04:53 2006 |
| MD5 Checksum: | 3d170dd83d52348a9de5a1ebf06ee65d |
|
| /// File Name: |
glsa-200611-01.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200611-01 - cstone and Richard Felker discovered a flaw in Screen's UTF-8 combining character handling. Versions less than 4.0.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3662 | | Last Modified: | Nov 3 18:04:42 2006 |
| MD5 Checksum: | 458197d688275073032e419c428941f9 |
|
| /// File Name: |
MDKSA-2006-195.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-195: Vulnerabilities in the HTTP, LDAP, XOT, WBXML, and MIME Multipart dissectors were discovered in versions of wireshark less than 0.99.4, as well as various other bugs.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 5410 | | Last Modified: | Nov 3 18:04:35 2006 |
| MD5 Checksum: | f8121899a7b32febaf6feffa93d3299a |
|
| /// File Name: |
MDKSA-2006-196.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-196: The Hardened-PHP Project discovered buffer overflows in htmlentities/htmlspecialchars internal routines to the PHP Project. Of course the whole purpose of these functions is to be filled with user input. (The overflow can only be when UTF-8 is used)
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 8280 | | Last Modified: | Nov 3 18:02:46 2006 |
| MD5 Checksum: | f9729a71047aec99b0736602d9135186 |
|
| /// File Name: |
dsa-1204-1.txt |
Description:
|
Debian Security Advisory 1204-1: It was discovered that the Ingo email filter rules manager performs insufficient escaping of user-provided data in created procmail rules files, which allows the execution of arbitrary shell commands.
| | Homepage: | http://www.debian.org/security | | File Size: | 3063 | | Last Modified: | Nov 3 17:29:51 2006 |
| MD5 Checksum: | d7f92e70dfd583defd9d1766db2a7c6c |
|
| /// File Name: |
USN-375-1.txt |
Description:
|
Ubuntu Security Notice 375-1: \Stefan Esser discovered two buffer overflows in the htmlentities() and htmlspecialchars() functions. By supplying specially crafted input to PHP applications which process that input with these functions, a remote attacker could potentially exploit this to execute arbitrary code with the privileges of the application.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 38421 | | Last Modified: | Nov 3 17:29:11 2006 |
| MD5 Checksum: | a8e5654b52cccc7014be8d414e380b5a |
|
| /// File Name: |
SSRT061238-1.txt |
Description:
|
HPSBMA02159 SSRT061238 rev.1 - HP System Management Homepage (SMH), Remote Bypassing of Security Features or Cross Site Scripting or Denial of Service (DoS)
| | Homepage: | http://www.hp.com | | File Size: | 5931 | | Last Modified: | Nov 3 17:29:05 2006 |
| MD5 Checksum: | 5246b29cf0bdb98dcff2bfbf09d70c8a |
|
| /// File Name: |
dsa-1203-1.txt |
Description:
|
Debian Security Advisory 1203-1: Steve Rigler discovered that the PAM module for authentication against LDAP servers processes PasswordPolicyReponse control messages incorrectly, which might lead to an attacker being able to login into a suspended system account.
| | Homepage: | http://www.debian.org/security | | File Size: | 5066 | | Last Modified: | Nov 3 17:27:49 2006 |
| MD5 Checksum: | f08f02aa45cdfb41ca5dc772176ff0bd |
|
| /// File Name: |
sa22655.txt |
Description:
|
Secunia Security Advisory - MLH has reported a vulnerability in Fedora Core, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22655/ | | File Size: | 2605 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 81437542717172f2bc863ccb819b28a6 |
|
| /// File Name: |
sa22656.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for ingo1. This fixes a vulnerability, which can be exploited by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22656/ | | File Size: | 3082 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | f0cf16b550d7d3311c0bd36c274cff0f |
|
| /// File Name: |
sa22664.txt |
Description:
|
Secunia Security Advisory - Spiked and anonymous have discovered some vulnerabilities in FreeWebshop.org Script, which can be exploited by malicious people to disclose sensitive information or conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/22664/ | | File Size: | 3035 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 32d984bd02d8cd0742b368dd028b9dc5 |
|
| /// File Name: |
sa22667.txt |
Description:
|
Secunia Security Advisory - Tal Argoni has reported a vulnerability in B-FOCuS Wireless router, which can be exploited by malicious people to disclose certain sensitive information.
| | Homepage: | http://secunia.com/advisories/22667/ | | File Size: | 2438 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | ce75a4db21b1d024914623a638210d11 |
|
| /// File Name: |
sa22674.txt |
Description:
|
Secunia Security Advisory - poplix has discovered a vulnerability in iodine's client, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/22674/ | | File Size: | 2606 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | f996b8a78f1ff97681a681deeaaee997 |
|
| /// File Name: |
sa22676.txt |
Description:
|
Secunia Security Advisory - Sun has acknowledged a vulnerability in Sun Solaris, which can be exploited by malicious, local users to gain escalated privileges and potentially by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/22676/ | | File Size: | 2820 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 1f05448a5bc66aacc2fe4cf18d44f1f5 |
|
| /// File Name: |
sa22682.txt |
Description:
|
Secunia Security Advisory - Steve Rigler has reported a security issue in pam_ldap, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/22682/ | | File Size: | 2512 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 48bb00d85fe6bdf015654826bfda76f3 |
|
| /// File Name: |
sa22688.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for PHP. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22688/ | | File Size: | 36224 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 2cdca15bc491d9c63ce481a5fb13c78d |
|
| /// File Name: |
sa22690.txt |
Description:
|
Secunia Security Advisory - Two security issues have been reported in Yazd Discussion Forum Software, which potentially can be exploited by malicious users to gain sensitive information and bypass security functionality.
| | Homepage: | http://secunia.com/advisories/22690/ | | File Size: | 2775 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 84ae8ab499a99e75a9e94a70a14d994c |
|
| /// File Name: |
sa22691.txt |
Description:
|
Secunia Security Advisory - HP has acknowledged some vulnerabilities in HP System Management Homepage, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22691/ | | File Size: | 3051 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 646332c3a5fe0db7e9e54f13e3d65fd9 |
|
| /// File Name: |
sa22692.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for wireshark. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/22692/ | | File Size: | 4224 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 31cd49442b980b20a0f3e306b7f7c9fe |
|
| /// File Name: |
sa22693.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for php. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/22693/ | | File Size: | 4548 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 50b56c4efbe4d3a3d54d992c04673e12 |
|
| /// File Name: |
sa22694.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for pam_ldap. This fixes a security issue, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/22694/ | | File Size: | 4933 | | Last Modified: | Nov 3 17:27:13 2006 |
| MD5 Checksum: | 2f64ba4694a515f5e8de0e61dd0a9a8a |
|
|
|
|
|