Section: .. / 0507-advisories /
| /// File Name: |
glsa-200507-29.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-29 - Max Vozeler reported that pstotext calls the GhostScript interpreter on untrusted PostScript files without specifying the -dSAFER option. Versions less than 1.8g-r1 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2580 | | Last Modified: | Aug 5 07:57:25 2005 |
| MD5 Checksum: | 5cc93bfca53ae8b32a433ef8ca3de8e0 |
|
| /// File Name: |
openbook122.txt |
Description:
|
OpenBook version 1.2.2 suffers from a SQL injection vulnerability.
| | Homepage: | http://www.svt.nukleon.us | | File Size: | 1350 | | Last Modified: | Aug 5 07:51:59 2005 |
| MD5 Checksum: | 6194694be717028c76d02ed780f7d2df |
|
| /// File Name: |
glsa-200507-28.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200507-28 - Earlier versions of emul-linux-x86-baselibs contain a vulnerable version of zlib, which may lead to a buffer overflow. Versions less than 2.2 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 3119 | | Related CVE(s): | CAN-2005-1849, CAN-2005-2096 | | Last Modified: | Aug 5 07:50:52 2005 |
| MD5 Checksum: | 3f77347d96c2f73b5e43b01a21f6bf23 |
|
| /// File Name: |
pcexpCMS.txt |
Description:
|
PC-EXPERIENCE/TOPPE CMS suffers from cross site scripting and login bypass flaws.
| | Author: | Morinex | | File Size: | 2748 | | Last Modified: | Aug 5 07:50:18 2005 |
| MD5 Checksum: | 0a53b5c49103f87e5fc1d030e3436c67 |
|
| /// File Name: |
trillianClear.txt |
Description:
|
Trillian Pro 3.1 Build 121 saves a user password in clear text in a temporary file that is world readable when attempting to connect to Yahoo mail.
| | Author: | Suramya Tomar | | Homepage: | http://www.suramya.com | | File Size: | 2237 | | Last Modified: | Aug 5 07:43:49 2005 |
| MD5 Checksum: | 7556ddc77fad7efe9e137628505daece |
|
| /// File Name: |
TA05-210A.txt |
Description:
|
Technical Cyber Security Alert TA05-210A - Cisco IOS IPv6 processing functionality contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service.
| | Homepage: | http://www.cert.org | | File Size: | 4497 | | Last Modified: | Aug 5 07:41:02 2005 |
| MD5 Checksum: | c95a2cc5b0c309abb290bf31b8d70b2d |
|
| /// File Name: |
dsa-770-1.txt |
Description:
|
Debian Security Advisory DSA 770-1 - John Goerzen discovered that gopher, a client for the Gopher Distributed Hypertext protocol, creates temporary files in an insecure fashion.
| | Homepage: | http://security.debian.org/ | | File Size: | 8634 | | Related CVE(s): | CAN-2005-1853 | | Last Modified: | Aug 5 07:33:36 2005 |
| MD5 Checksum: | 161a6ee1f53a5397084bdb43665a8d99 |
|
| /// File Name: |
cisco-sa-20050729-ipv6.txt |
Description:
|
Cisco Security Advisory - Cisco Internetwork Operating System (IOS) Software is vulnerable to a Denial of Service (DoS) and potentially an arbitrary code execution attack from a specifically crafted IPv6 packet. The packet must be sent from a local network segment. Only devices that have been explicitly configured to process IPv6 traffic are affected. Upon successful exploitation, the device may reload or be open to further exploitation.
| | Homepage: | http://www.cisco.com/warp/public/707/cisco-sa-20050729-ipv6.shtml | | File Size: | 30839 | | Last Modified: | Aug 5 07:33:00 2005 |
| MD5 Checksum: | 81aa26610de87bb904cf13a389cf7167 |
|
| /// File Name: |
USN-156-1.txt |
Description:
|
Ubuntu Security Notice USN-156-1 - Wouter Hanegraaff discovered that the TIFF library did not sufficiently validate the YCbCr subsampling value in TIFF image headers. Decoding a malicious image with a zero value resulted in an arithmetic exception, which caused the program that uses the TIFF library to crash. This leads to a Denial of Service in server applications that use libtiff (like the CUPS printing system) and can cause data loss in, for example, the Evolution email client.
| | Homepage: | http://www.ubuntu.com/ | | File Size: | 5243 | | Last Modified: | Aug 5 07:20:35 2005 |
| MD5 Checksum: | ec51f28424e28a2a62ac33df15b97212 |
|
| /// File Name: |
dsa-769-1.txt |
Description:
|
Debian Security Advisory DSA 769-1 - Szymon Zygmunt and Michal Bartoszkiewicz discovered a memory alignment error in libgadu (from ekg, console Gadu Gadu client, an instant messaging program) which is included in gaim, a multi-protocol instant messaging client, as well. This can not be exploited on the x86 architecture but on others, e.g. on Sparc and lead to a bus error, in other words a denial of service.
| | Homepage: | http://security.debian.org/ | | File Size: | 6661 | | Related CVE(s): | CAN-2005-2370 | | Last Modified: | Aug 5 07:14:05 2005 |
| MD5 Checksum: | 3377dfdf3724af69d78fcb1c2966dec5 |
|
| /// File Name: |
SPI-0001-07282005.txt |
Description:
|
SPI Dynamics Security Bulletin SPI-0001-07282005 - There exists a potential WebInspect cross application scripting vulnerability for versions below 5.5.386.
| | Author: | SPI Dynamics | | File Size: | 2707 | | Last Modified: | Aug 5 07:10:44 2005 |
| MD5 Checksum: | d1a9b783ffcaf9a713062d7a5a4a140f |
|
| /// File Name: |
advisory_122005.60.txt |
Description:
|
UseBB versions 0.5.1 and below suffer from multiple SQL injection and cross site scripting vulnerabilities.
| | Author: | Stefan Esser | | Homepage: | http://www.hardened-php.net | | File Size: | 3763 | | Last Modified: | Aug 5 07:09:13 2005 |
| MD5 Checksum: | 87efe74fcdd09005ec610e4a68e249d4 |
|
| /// File Name: |
websiteBaker.txt |
Description:
|
The Website Baker Project is susceptible to path disclosure and cross site scripting vulnerabilities.
| | Author: | tgo | | File Size: | 1281 | | Last Modified: | Aug 5 06:59:12 2005 |
| MD5 Checksum: | 592786bb447195f1b20f943929fd3437 |
|
| /// File Name: |
sa15756.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Opera, which can be exploited by malicious people to conduct cross-site scripting attacks and retrieve a user's files.
| | Homepage: | http://secunia.com/advisories/15756/ | | File Size: | 2318 | | Last Modified: | Jul 28 19:02:32 2005 |
| MD5 Checksum: | 18201c9353e20482da58606556f40385 |
|
| /// File Name: |
NRVA05-03.txt |
Description:
|
HAURI live update suffers from remote file download and execution vulnerabilities.
| | Author: | Park Gyutae | | File Size: | 10030 | | Last Modified: | Jul 28 18:55:46 2005 |
| MD5 Checksum: | b0c582692ccecdb7dab8e7a8d192f5e0 |
|
| /// File Name: |
sa16231.txt |
Description:
|
Secunia Security Advisory - Leandro Meiners has reported a security issue in Lotus Domino, which can be exploited by malicious users to disclose certain sensitive information.
| | Homepage: | http://secunia.com/advisories/16231/ | | File Size: | 2628 | | Last Modified: | Jul 28 17:48:02 2005 |
| MD5 Checksum: | 6bcc12b07594ab31120d2733cac55130 |
|
| /// File Name: |
sa16255.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in MySQL Eventum, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/16255/ | | File Size: | 1944 | | Last Modified: | Jul 28 17:47:03 2005 |
| MD5 Checksum: | e910853acfc99974cbbc1ff41e9eb81f |
|
| /// File Name: |
sa16253.txt |
Description:
|
Secunia Security Advisory - Joxean Koret has reported some vulnerabilities in GForge, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/16253/ | | File Size: | 2327 | | Last Modified: | Jul 28 17:47:03 2005 |
| MD5 Checksum: | 11fc5b445bb61be80800c6d072cfa423 |
|
| /// File Name: |
sa16251.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in FileZilla Server, which can be exploited by malicious people to conduct a DoS (Denial of Service) or potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/16251/ | | File Size: | 1958 | | Last Modified: | Jul 28 17:47:03 2005 |
| MD5 Checksum: | 4a34211c6ee59aa5a140ef7363d8647d |
|
| /// File Name: |
sa16228.txt |
Description:
|
Secunia Security Advisory - Yun Jonglim has reported a vulnerability in UnixWare, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/16228/ | | File Size: | 2385 | | Last Modified: | Jul 28 17:47:03 2005 |
| MD5 Checksum: | b1d39f3d34e342361e918e7428561f70 |
|
| /// File Name: |
sa15870.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Opera, which can be exploited by malicious people to trick users into executing malicious files.
| | Homepage: | http://secunia.com/advisories/15870/ | | File Size: | 2416 | | Last Modified: | Jul 28 17:47:03 2005 |
| MD5 Checksum: | eb878ed27d85a7780314f8af7a80a80a |
|
| /// File Name: |
dsa-768-1.txt |
Description:
|
Debian Security Advisory DSA 768-1 - A cross-site scripting vulnerability has been detected in phpBB2 that allows remote attackers to inject arbitrary web script or HTML via nested tags.
| | Homepage: | http://security.debian.org/ | | File Size: | 3283 | | Related CVE(s): | CAN-2005-2161 | | Last Modified: | Jul 28 09:05:30 2005 |
| MD5 Checksum: | 9f8c2f665ccbdca367d2e2e217193569 |
|
| /// File Name: |
dsa-767-1.txt |
Description:
|
Debian Security Advisory DSA 767-1 - Marcin Slusarz discovered two integer overflow vulnerabilities in libgadu, a library provided and used by ekg, a console Gadu Gadu client, an instant messaging program, that could lead to the execution of arbitrary code.
| | Homepage: | http://security.debian.org/ | | File Size: | 8286 | | Related CVE(s): | CAN-2005-1852 | | Last Modified: | Jul 28 09:04:33 2005 |
| MD5 Checksum: | a96d8c31cfa976bbe9634572bbd95d7f |
|
| /// File Name: |
cleverAccess.txt |
Description:
|
Clever Copy contains a flaw that allows for unauthorized reading and deletion of private message from other users. Versions 2.0 and 2.0a are affected.
| | Author: | Lostmon | | File Size: | 1964 | | Last Modified: | Jul 28 09:03:19 2005 |
| MD5 Checksum: | 4f2de0514d7c6b838f32ce512c04fc50 |
|
|
|
|
|