Section: .. / 0608-advisories /
| /// File Name: |
mptho.txt |
Description:
|
OpenMPT versions 1.17.02.43 and below suffer from various buffer and heap overflows.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org | | Related Exploit: | mptho.zip | | File Size: | 3973 | | Last Modified: | Aug 26 21:05:15 2006 |
| MD5 Checksum: | fec3f50ed2e3e2dea43391fc0504b170 |
|
| /// File Name: |
alsapbof.txt |
Description:
|
AlsaPlayer versions 0.99.76 and below suffer from multiple buffer overflows.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org | | Related Exploit: | alsapbof.zip | | File Size: | 4659 | | Last Modified: | Aug 26 21:00:13 2006 |
| MD5 Checksum: | 3951f0c4008697e8598b567265934fbc |
|
| /// File Name: |
MDKSA-2006-140.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-140 - Tavis Ormandy, of the Google Security Team, discovered that ncompress, when uncompressing data, performed no bounds checking, which could allow a specially crafted datastream to underflow a .bss buffer with attacker controlled data.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 2854 | | Related CVE(s): | CVE-2006-1168 | | Last Modified: | Aug 26 20:56:07 2006 |
| MD5 Checksum: | 7fae5c55618f254e0c79c41da1c45510 |
|
| /// File Name: |
MDKSA-2006-139.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-139 - A flaw was discovered in some bundled Kerberos-aware packages that would fail to check the results of the setuid() call. This call can fail in some circumstances on the Linux 2.6 kernel if certain user limits are reached, which could be abused by a local attacker to get the applications to continue to run as root, possibly leading to an elevation of privilege.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 5893 | | Related CVE(s): | CVE-2006-3083 | | Last Modified: | Aug 26 20:55:29 2006 |
| MD5 Checksum: | 1edfba98eb250c8629d1fb7b0e818e2f |
|
| /// File Name: |
dsa-1147-1.txt |
Description:
|
Debian Security Advisory 1147-1 - Ayman Hourieh discovered that Drupal, a dynamic website platform, performs insufficient input sanitizing in the user module, which might lead to cross-site scripting.
| | Homepage: | http://www.debian.org/security | | File Size: | 2815 | | Related CVE(s): | CVE-2006-4002 | | Last Modified: | Aug 26 20:54:39 2006 |
| MD5 Checksum: | 24a337793321b63e9afafa2dc798ba26 |
|
| /// File Name: |
pocketpc.txt |
Description:
|
MMS composer versions 1.5.5.6 and 2.0.0.13 suffer from multiple buffer overflows in the MMS parsing code allowing for arbitrary code execution and denial of service conditions.
| | Author: | Collin Mulliner, Prof. Giovanni Vigna | | File Size: | 4272 | | Last Modified: | Aug 26 20:53:56 2006 |
| MD5 Checksum: | 01dc07778157ff02b13172b0749cec35 |
|
| /// File Name: |
pandaXSS.txt |
Description:
|
Panda ActiveScan contains a flaw that allows for remote cross site scripting attacks. This flaw exists because the application does not validate the 'email' variable upon submission to the ascan_6.asp script. Version 5.53.00 is affected.
| | Author: | Lostmon | | Homepage: | http://lostmon.blogspot.com/ | | File Size: | 1497 | | Last Modified: | Aug 26 20:45:12 2006 |
| MD5 Checksum: | 6941389ffde83c99c29eea0ce3c5c542 |
|
| /// File Name: |
clamav_upx_heap.txt |
Description:
|
Remote exploitation of a heap overflow vulnerability in ClamAV versions below 0.88.4 could allow execution of arbitrary code or cause a denial of service.
| | Author: | Damian Put | | Homepage: | http://www.overflow.pl/ | | File Size: | 3067 | | Last Modified: | Aug 26 20:39:13 2006 |
| MD5 Checksum: | 39cdda45a4ece3067080a595993d5936 |
|
| /// File Name: |
SUSE-SA-2006-046.txt |
Description:
|
SUSE Security Announcement SUSE-SA:2006:046 - Damian Put discovered a bug in the UPX decoder used for scanning UPX compressed Windows executables. The bug allows for a heap buffer overflow and may potentially be exploitable to execute arbitrary code. ClamAV has been version updated to version 0.88.4 in order to fix this problem.
| | Homepage: | http://www.suse.com | | File Size: | 14352 | | Related CVE(s): | CVE-2006-4018 | | Last Modified: | Aug 26 20:37:26 2006 |
| MD5 Checksum: | 333e2c38996341689e5668e8bcc92934 |
|
| /// File Name: |
sofgb10.txt |
Description:
|
Simple one-file Guestbook versions 1.0 and below suffer from an administrative bypass flaw.
| | Author: | omnipresent | | Homepage: | http://it.security.netsons.org | | File Size: | 1245 | | Last Modified: | Aug 26 20:34:27 2006 |
| MD5 Checksum: | b17ef43371f036598e89517fe136983b |
|
| /// File Name: |
cgiDisclose.txt |
Description:
|
A CGI script source disclosure flaw exists for Apache version 2.2.2 on Windows.
| | Author: | Susam Pal | | Homepage: | http://susampal.blogspot.com/ | | File Size: | 4583 | | Last Modified: | Aug 26 20:32:52 2006 |
| MD5 Checksum: | 145c95696dbc34d7cfc103b8a21ec363 |
|
| /// File Name: |
USN-333-1.txt |
Description:
|
Ubuntu Security Notice USN-333-1 - An integer overflow was found in the handling of the MaxRecordSize field in the WMF header parser. By tricking a user into opening a specially crafted WMF image file with an application that uses this library, an attacker could exploit this to execute arbitrary code with the user's privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 9089 | | Related CVE(s): | CVE-2006-3376 | | Last Modified: | Aug 26 20:25:42 2006 |
| MD5 Checksum: | 66a2abcf02931693756dc6d2efd0c150 |
|
| /// File Name: |
dsa-1146-1.txt |
Description:
|
Debian Security Advisory 1146-1 - In certain application programs packaged in the MIT Kerberos 5 source distribution, calls to setuid() and seteuid() are not always checked for success and which may fail with some PAM configurations. A local user could exploit one of these vulnerabilities to result in privilege escalation. No exploit code is known to exist at this time.
| | Homepage: | http://www.debian.org/security | | File Size: | 22414 | | Related CVE(s): | CVE-2006-3083, CVE-2006-3084 | | Last Modified: | Aug 26 20:23:46 2006 |
| MD5 Checksum: | 6a843f8da829224cf6024f840f325fbd |
|
| /// File Name: |
sscms10.txt |
Description:
|
SmartSiteCMS version 1.0 suffers from an authentication bypass flaw.
| | Author: | Paulino Calderon | | Homepage: | http://nah.suckea.com/ | | File Size: | 952 | | Last Modified: | Aug 26 20:22:49 2006 |
| MD5 Checksum: | 1dfefbaa3af69d1d877fe48a768e0cf1 |
|
| /// File Name: |
MDKSA-2006-138.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-138 - Damian Put discovered a boundary error in the UPX extraction module in ClamAV which is used to unpack PE Windows executables. This could be abused to cause a Denial of Service issue and potentially allow for the execution of arbitrary code with the permissions of the user running clamscan or clamd.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 4796 | | Related CVE(s): | CVE-2006-4018 | | Last Modified: | Aug 26 20:21:44 2006 |
| MD5 Checksum: | 156c6851c34b1f7f89c82f4abadbfb01 |
|
| /// File Name: |
sa21535.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been discovered in Dolphin, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21535/ | | File Size: | 2307 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | 04aa3b748eef13b4cd13b296a96a5fc0 |
|
| /// File Name: |
sa21536.txt |
Description:
|
Secunia Security Advisory - Thomas Pollet has discovered a vulnerability in TikiWiki, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/21536/ | | File Size: | 2254 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | 34b2c8e12e25d6201e7aef5a65ad2811 |
|
| /// File Name: |
sa21542.txt |
Description:
|
Secunia Security Advisory - Hessam-x has discovered a vulnerability in Wikepage, which can be exploited by malicious people to disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/21542/ | | File Size: | 2319 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | e3f3ccc3204e8df0edcc1e0070986278 |
|
| /// File Name: |
sa21543.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in mail f/w system, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/21543/ | | File Size: | 2357 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | fe3119754422fdaa757b64ab9b971d78 |
|
| /// File Name: |
sa21547.txt |
Description:
|
Secunia Security Advisory - h07 has discovered a vulnerability in WFPTD Server/Pro Server, which can be exploited by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21547/ | | File Size: | 2358 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | eb80a125f7e5fd4d17960fe6b82e3f57 |
|
| /// File Name: |
sa21548.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Symantec Enterprise Security Manager (ESM), which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/21548/ | | File Size: | 2620 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | ef1919b47dafbbea536c8bc432932b83 |
|
| /// File Name: |
sa21549.txt |
Description:
|
Secunia Security Advisory - Aliaksandr Hartsuyeu has reported a vulnerability in Doika Guestbook, which can be exploited by malicious people to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/21549/ | | File Size: | 2370 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | 4e816a35dbe81abc257c8204ca9f1f98 |
|
| /// File Name: |
sa21552.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Ichitaro, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/21552/ | | File Size: | 2766 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | d013e3fb04d412748b46f34c4817d7f1 |
|
| /// File Name: |
sa21553.txt |
Description:
|
Secunia Security Advisory - Philipp Niedziela has discovered some vulnerabilities in Sonium Enterprise Adressbook, which can be exploited by malicious users to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/21553/ | | File Size: | 2780 | | Last Modified: | Aug 26 20:18:48 2006 |
| MD5 Checksum: | ab98f414aada7778416966aff8f8271e |
|
|
|
|
|