Section: .. / 0603-advisories /
| /// File Name: |
CVE-2006-0745.txt |
Description:
|
CVE-2006-0745 - Local privilege escalation in X.Org server 1.0.0 and later and X11R6.9.0 and X11R7.0. When parsing arguments, the server takes care to check that only root can pass the options -modulepath, which determines the location to load many modules providing server functionality from, and -logfile, which determines the location of the logfile. Normally, these locations cannot be changed by unprivileged users.
| | Author: | Daniel Stone | | Related Exploit: | xmodulepath.tgz | | File Size: | 2691 | | Last Modified: | Mar 22 00:11:27 2006 |
| MD5 Checksum: | 60642fac47808949f86849e0c0176071 |
|
| /// File Name: |
SCOSA-2006.14.txt |
Description:
|
SCO Security Advisory - SCOSA-2006.14 - Multiple X Window System server applications share code that may contain a flaw in the memory allocation for large pixmaps. The affected products include the X.Org X server applications.
| | Author: | SCO | | Homepage: | http://www.sco.com/support/security/index.html | | File Size: | 3030 | | Last Modified: | Mar 21 23:56:09 2006 |
| MD5 Checksum: | 47938db420a00f40d2a98b550db1a608 |
|
| /// File Name: |
SCOSA-2006.13.txt |
Description:
|
SCO Security Advisory - SCOSA-2006.13 - Vim is susceptible to an arbitrary command execution vulnerability with ModeLines. This issue is due to insufficient sanitization of user-supplied input.
| | Author: | SCO | | Homepage: | http://www.sco.com/support/security/index.html | | File Size: | 2844 | | Last Modified: | Mar 21 23:55:22 2006 |
| MD5 Checksum: | 1296210fb79a5512ef492ca9eb9d3fc7 |
|
| /// File Name: |
phpWebsite.txt |
Description:
|
phpWebsite suffers from SQL injection in friend.php and article.php
| | Author: | DaBDouB-MoSiKaR | | File Size: | 646 | | Last Modified: | Mar 21 23:50:51 2006 |
| MD5 Checksum: | debc3465f149ce717c037d4dc891617e |
|
| /// File Name: |
Contrexx.txt |
Description:
|
Contrexx CMS versions greater than or equal to v1.0.8 are vulnerable to XSS.
| | Author: | Shabgard Security Team | | Homepage: | http://www.shabgard.org | | File Size: | 532 | | Last Modified: | Mar 21 23:46:52 2006 |
| MD5 Checksum: | 06ac712a17a55db96b92dc938647cfe0 |
|
| /// File Name: |
EV0093.txt |
Description:
|
eVuln Advisory EV0093 - NMDeluxe XSS & SQL Injection Vulnerabilities
| | Author: | Aliaksandr Hartsuyeu | | Homepage: | http://evuln.com/ | | File Size: | 1312 | | Last Modified: | Mar 21 23:45:30 2006 |
| MD5 Checksum: | 079b3cb72730a0496c01cbe2fff3d17f |
|
| /// File Name: |
Aironet-1300-DoS.txt |
Description:
|
Cisco Aironet 1300 running IOS 12.3(8)JA with default settings is vulnerable to a DoS condition.
| | Author: | Alex | | File Size: | 1989 | | Last Modified: | Mar 21 23:42:58 2006 |
| MD5 Checksum: | 5d330b947dd34015df8737aa441c97da |
|
| /// File Name: |
ASPPortal-3.1.1.txt |
Description:
|
ASPPortal versions less than or equal to 3.1.1 suffer from multiple remote SQL injection vulnerabilities
| | Author: | nukedx | | Homepage: | http://www.nukedx.com | | File Size: | 2976 | | Last Modified: | Mar 21 23:40:22 2006 |
| MD5 Checksum: | 111f3121c602a426c2648bbb10c369ca |
|
| /// File Name: |
SUSE-SA-2006-015.txt |
Description:
|
SUSE Security Announcement - SUSE-SA:2006:015 - A critical security vulnerability has been identified in the Adobe Macromedia Flash Player that allows an attacker who successfully exploits these vulnerabilities to take control of the application running the flash player.
| | Homepage: | http://www.suse.com | | File Size: | 13587 | | Last Modified: | Mar 21 23:19:07 2006 |
| MD5 Checksum: | 60418e77d7a8b6eb204fee235c10b784 |
|
| /// File Name: |
SSRT051078.txt |
Description:
|
HPSBUX02102 SSRT051078 rev.1 - HP-UX usermod(1M) Local UnaUthorized Access A vulnerability has been identified with certain versions of the HP-UX usermod(1M) command. A certain combination of options can result in recursively changing the ownership of all directories and files under a user's new home directory. This may result in unauthorized access to these directories and files.
| | Homepage: | http://www.itrc.hp.com/service/cki/secBullArchive.do | | File Size: | 7484 | | Last Modified: | Mar 21 23:15:44 2006 |
| MD5 Checksum: | d43349d319bb8ef248504f1781825554 |
|
| /// File Name: |
SYM06-005.txt |
Description:
|
Symantec Security Advisory SYM06-005 Veritas Backup Exec for Windows Servers: Media Server BENGINE Service Job log Format String Overflow
| | Homepage: | http://www.symantec.com/avcenter/ | | File Size: | 1088 | | Last Modified: | Mar 21 23:12:26 2006 |
| MD5 Checksum: | 2710dea9b438c4a72d27d722b24cd0b5 |
|
| /// File Name: |
SSRT051128.txt |
Description:
|
HPSBUX02101 SSRT051128 rev.1 - HP-UX VirtualVault running Apache 1.3.X Remote Unauthorized Access - A security vulnerability has been identified in Apache HTTP server versions prior to Apache 1.3.34 that may allow HTTP Request Splitting/Spoofing attacks, resulting in remote unauthorized access.
| | Homepage: | http://www.itrc.hp.com/service/cki/secBullArchive.do | | File Size: | 7368 | | Last Modified: | Mar 21 23:11:49 2006 |
| MD5 Checksum: | 4bce37ff29a05b4ee84921ce4148926f |
|
| /// File Name: |
SSRT051251-2.txt |
Description:
|
HPSBUX02074 SSRT051251 rev.2 - Apache-based Web Server on HP-UX mod_ssl, proxy_http, Remote Execution of Arbitrary Code, Denial of Service (DoS), and Unauthorized Access.
| | Homepage: | http://www.itrc.hp.com/service/cki/secBullArchive.do | | File Size: | 9297 | | Last Modified: | Mar 21 23:11:07 2006 |
| MD5 Checksum: | 822a5ee0dd0792967d42831bde87917b |
|
| /// File Name: |
SYM06-004.txt |
Description:
|
Symantec Security Advisory - SYM06-004 - Veritas Backup Exec: Application Memory Denial of Service Revision History
| | Homepage: | http://www.symantec.com/avcenter | | File Size: | 1286 | | Last Modified: | Mar 21 23:10:02 2006 |
| MD5 Checksum: | fb6b3694dad14707759a6e2146fbe820 |
|
| /// File Name: |
MDKSA-2006-057.txt |
Description:
|
Mandriva Linux Security Advisory - MDKSA-2006:057 - GNOME Evolution allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to repeatedly crash until the e-mail message is manually removed, possibly due to a buffer overflow, as demonstrated using an XML attachment.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3178 | | Last Modified: | Mar 21 23:06:13 2006 |
| MD5 Checksum: | ad08e1c3c27d7593058d707a8e2a2094 |
|
| /// File Name: |
MDKSA-2006-056.txt |
Description:
|
Mandriva Linux Security Advisory - MDKSA-2006:056 Versions of Xorg 6.9.0 and greater have a bug in xf86Init.c, which allows non-root users to use the -modulepath, -logfile and -configure options. This allows loading of arbitrary modules which will execute as the root user, as well as a local DoS by overwriting system files.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 5550 | | Last Modified: | Mar 21 23:05:39 2006 |
| MD5 Checksum: | aff489e9584155d20d9137feb6117ce5 |
|
| /// File Name: |
FLSA-2006-178606.txt |
Description:
|
Fedora Legacy Update Advisory - The International Domain Name (IDN) support in the Konqueror browser allowed remote attackers to spoof domain names using punycode encoded domain names. Such domain names are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
| | Homepage: | http://fedoralegacy.org | | File Size: | 8776 | | Last Modified: | Mar 21 22:53:52 2006 |
| MD5 Checksum: | 1752e120757cfe6fe7dc42a6ee93cda4 |
|
| /// File Name: |
FLSA-2006-175404.txt |
Description:
|
Fedora Legacy Update Advisory - A flaw was discovered in Xpdf in that an attacker could construct a carefully crafted PDF file that would cause Xpdf to consume all available disk space in /tmp when opened.
| | Homepage: | http://fedoralegacy.org | | File Size: | 8419 | | Last Modified: | Mar 21 22:53:14 2006 |
| MD5 Checksum: | 60e478324f6cbda2c3afe65f749eb4ba |
|
| /// File Name: |
FLSA-2006-174479.txt |
Description:
|
Fedora Legacy Update Advisory - FLSA:174479 - Several bugs in the way libungif decodes GIF images were discovered. An attacker could create a carefully crafted GIF image file in such a way that it could cause an application linked with libungif to crash or execute arbitrary code when the file is opened by a victim.
| | Homepage: | http://fedoralegacy.org | | File Size: | 6656 | | Last Modified: | Mar 21 22:52:38 2006 |
| MD5 Checksum: | b43dba0d8772ca21a8d0627e7366c91b |
|
| /// File Name: |
FLSA-2006-173274.txt |
Description:
|
Fedora Legacy Update Advisory FLSA:173274 - A bug was found in the way gdk-pixbuf processes XPM images. An attacker could create a carefully crafted XPM file in such a way that it could cause an application linked with gdk-pixbuf to execute arbitrary code when the file was opened by a victim. The Common Vulnerabilities and Exposures project has assigned the name CVE-2005-3186 to this issue.
| | Homepage: | http://fedoralegacy.org | | File Size: | 7684 | | Last Modified: | Mar 21 22:52:05 2006 |
| MD5 Checksum: | 5938187a915dace9cfb5e94e0048e73b |
|
| /// File Name: |
FLSA-2006-157459-4.txt |
Description:
|
Fedora Legacy Update Advisory FLSA:157459-4 - Updated kernel packages that fix several security issues are now available
| | Homepage: | http://fedoralegacy.org | | File Size: | 7897 | | Last Modified: | Mar 21 22:51:21 2006 |
| MD5 Checksum: | 47ecad5cf388bf80b7332f2499e01ef1 |
|
| /// File Name: |
glsa-200603-16.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200603-16 - Ulf Harnhammar discovered a buffer overflow in Metamail when processing mime boundraries. Versions less than 2.7.45.3-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2416 | | Last Modified: | Mar 21 22:46:20 2006 |
| MD5 Checksum: | 7b5409819040192993832187d27ccdaf |
|
| /// File Name: |
glsa-200603-15.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200603-15 - Lincoln Stein discovered that Crypt::CBC fails to handle 16 bytes long initializiation vectors correctly when running in the RandomIV mode, resulting in a weaker encryption because the second part of every block will always be encrypted with zeros if the blocksize of the cipher is greater than 8 bytes. Versions less than 2.17 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2687 | | Last Modified: | Mar 21 22:46:14 2006 |
| MD5 Checksum: | fcedd08bcc8639730e6a5289232f5f6e |
|
| /// File Name: |
glsa-200603-14.ttx |
Description:
|
Gentoo Linux Security Advisory GLSA 200603-14 - An unspecified privilege escalation vulnerability in the rshd server of Heimdal has been reported. Versions less than 0.7.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2517 | | Related CVE(s): | CAN-2006-0582 | | Last Modified: | Mar 21 22:46:09 2006 |
| MD5 Checksum: | 6facecb52367f33e35e99460268fcfa0 |
|
|
|
|
|