Section: .. / 0703-advisories /
| /// File Name: |
sa24547.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for the kernel. This fixes some vulnerabilities, where one has unknown impacts and others can be exploited by malicious, local users to gain escalated privileges and cause a DoS (Denial of Service), or by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24547/ | | File Size: | 13001 | | Last Modified: | Mar 17 03:22:27 2007 |
| MD5 Checksum: | 1598125cf49a6f7cedfc22306b2f2e00 |
|
| /// File Name: |
USN-431-1.txt |
Description:
|
Ubuntu Security Notice 431-1 - The SSLv2 protocol support in the NSS library did not sufficiently check the validity of public keys presented with a SSL certificate. A malicious SSL web site using SSLv2 could potentially exploit this to execute arbitrary code with the user's privileges. The SSLv2 protocol support in the NSS library did not sufficiently verify the validity of client master keys presented in an SSL client certificate. A remote attacker could exploit this to execute arbitrary code in a server application that uses the NSS library. Various flaws have been reported that could allow an attacker to execute arbitrary code with user privileges by tricking the user into opening a malicious web page.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 12753 | | Related CVE(s): | CVE-2007-0008, CVE-2007-0009, CVE-2007-0775, CVE-2007-0776, CVE-2007-0777 | | Last Modified: | Mar 9 03:20:08 2007 |
| MD5 Checksum: | fca21518a8373a321d2bb42012f82a91 |
|
| /// File Name: |
dsa-1271-1.txt |
Description:
|
Debian Security Advisory 1271-1 - A design error has been identified in the OpenAFS, a cross-platform distributed filesystem included with Debian.
| | Homepage: | http://www.debian.org/security | | File Size: | 12387 | | Related CVE(s): | CVE-2007-1507 | | Last Modified: | Mar 21 04:10:57 2007 |
| MD5 Checksum: | 53037cf5aa2791065e1690f176ea493e |
|
| /// File Name: |
sa24410.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for thunderbird. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24410/ | | File Size: | 12352 | | Last Modified: | Mar 8 01:54:52 2007 |
| MD5 Checksum: | fc3502fdb91d1c4b133465fc355dbb61 |
|
| /// File Name: |
MDKSA-2007-064.txt |
Description:
|
Mandriva Linux Security Advisory - iDefense reported several overflow bugs in libwpd. An attacker could create a carefully crafted Word Perfect file that could cause an application linked with libwpd, such as OpenOffice, to crash or possibly execute arbitrary code if the file was opened by a victim. OpenOffice.org-2.X contains an embedded copy of libpwd, and as such is susceptible to the same issues.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 11908 | | Related CVE(s): | CVE-2007-0002 | | Last Modified: | Mar 20 16:05:17 2007 |
| MD5 Checksum: | 2eb47e64cc41ab1ac026562e2c94fbf0 |
|
| /// File Name: |
USN-447-1.txt |
Description:
|
Ubuntu Security Notice 447-1 - It was discovered that Konqueror did not correctly handle iframes from JavaScript. If a user were tricked into visiting a malicious website, Konqueror could crash, resulting in a denial of service. A flaw was discovered in how Konqueror handled PASV FTP responses. If a user were tricked into visiting a malicious FTP server, a remote attacker could perform a port-scan of machines within the user's network, leading to private information disclosure.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 11882 | | Related CVE(s): | CVE-2007-1308, CVE-2007-1564 | | Last Modified: | Apr 2 23:03:12 2007 |
| MD5 Checksum: | 24a78c76fde9f65c539db7fd0c570fe4 |
|
| /// File Name: |
SSRT071306.txt |
Description:
|
HP Security Bulletin - Various potential security vulnerabilities have been identified in Microsoft software that is running on the Storage Management Appliance (SMA). Some of these vulnerabilities may be pertinent to the SMA, please check the table in the Resolution section of this Security Bulletin.
| | Homepage: | http://www.hp.com | | File Size: | 11797 | | Last Modified: | Mar 6 01:54:23 2007 |
| MD5 Checksum: | b592ae245b56c47aa08c42b73055a4d5 |
|
| /// File Name: |
sa24593.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for openoffice.org. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or potentially compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24593/ | | File Size: | 11735 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 690ca4c6912bb4d1db72141a7f6e7119 |
|
| /// File Name: |
sa24581.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for libwpd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/24581/ | | File Size: | 11586 | | Last Modified: | Mar 20 16:05:29 2007 |
| MD5 Checksum: | 6f583f884f4def0732897a155eec9451 |
|
| /// File Name: |
sa24676.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for openoffice.org. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/24676/ | | File Size: | 11546 | | Last Modified: | Apr 2 04:42:23 2007 |
| MD5 Checksum: | bbd26eef56797db593ece587af4a8c03 |
|
| /// File Name: |
USN-437-1.txt |
Description:
|
Ubuntu Security Notice 437-1 - Sean Larsson of iDefense Labs discovered that libwpd was vulnerable to integer overflows. If a user were tricked into opening a specially crafted WordPerfect document with an application that used libwpd, an attacker could execute arbitrary code with user privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 11446 | | Related CVE(s): | CVE-2007-0002 | | Last Modified: | Mar 20 17:29:47 2007 |
| MD5 Checksum: | 96d8c5413956cd59d823fe9b8d8a15f8 |
|
| /// File Name: |
sa24628.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for nas. This fixes some vulnerabilities, which potentially can be exploited by malicious, local users to gain escalated privileges or by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/24628/ | | File Size: | 10969 | | Last Modified: | Mar 28 17:52:50 2007 |
| MD5 Checksum: | 72132230d88fa6bd08ee77b6904e7204 |
|
| /// File Name: |
dsa-1273-1.txt |
Description:
|
Debian Security Advisory 1273-1 - Several vulnerabilities have been discovered in nas, the Network Audio System. A stack-based buffer overflow in the accept_att_local function in server/os/connection.c in nas allows remote attackers to execute arbitrary code via a long path slave name in a USL socket connection. Integer overflow in the ProcAuWriteElement function in server/dia/audispatch.c allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large max_samples value. The AddResource function in server/dia/resource.c allows remote attackers to cause a denial of service (server crash) via a nonexistent client ID. Array index error allows remote attackers to cause a denial of service (crash) via (1) large num_action values in the ProcAuSetElements function in server/dia/audispatch.c or (2) a large inputNum parameter to the compileInputs function in server/dia/auutil.c. The ReadRequestFromClient function in server/os/io.c allows remote attackers to cause a denial of service (crash) via multiple simultaneous connections, which triggers a NULL pointer dereference.
| | Homepage: | http://www.debian.org/security | | File Size: | 10832 | | Related CVE(s): | CVE-2007-1543, CVE-2007-1544, CVE-2007-1545, CVE-2007-1546, CVE-2007-1547 | | Last Modified: | Mar 28 17:57:35 2007 |
| MD5 Checksum: | 8cadded62e8d82be3b752f801c87f741 |
|
| /// File Name: |
USN-446-1.txt |
Description:
|
Ubuntu Security Notice 446-1 - Luigi Auriemma discovered multiple flaws in the Network Audio System server. Remote attackers could send specially crafted network requests that could lead to a denial of service or execution of arbitrary code. Note that default Ubuntu installs do not include the NAS server.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 10809 | | Related CVE(s): | CVE-2007-1543, CVE-2007-1544, CVE-2007-1545, CVE-2007-1546, CVE-2007-1547 | | Last Modified: | Mar 29 08:19:46 2007 |
| MD5 Checksum: | a957919d456df89b8db38582d69fa4e7 |
|
| /// File Name: |
mshtmldll.txt |
Description:
|
It appears that Microsoft Internet Explorer 6 suffers from some denial of services vulnerabilities that result in a browser crash.
| | Author: | SaiedHacker | | File Size: | 10751 | | Last Modified: | Mar 21 04:00:23 2007 |
| MD5 Checksum: | 99422e45796e2bcc4c787f37eba9f016 |
|
| /// File Name: |
sa24607.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for openafs. This fixes a vulnerability, which can be exploited by malicious users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/24607/ | | File Size: | 10644 | | Last Modified: | Mar 22 02:31:03 2007 |
| MD5 Checksum: | 9fd43e3d44351830fa9f62b73b54f43b |
|
| /// File Name: |
USN-428-2.txt |
Description:
|
Ubuntu Security Notice 428-2 - USN-428-1 fixed vulnerabilities in Firefox 1.5. However, changes to library paths caused applications depending on libnss3 to fail to start up. This update fixes the problem.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 10457 | | Last Modified: | Mar 6 07:28:58 2007 |
| MD5 Checksum: | ec1197bb4064525a19187ab03b62c30f |
|
| /// File Name: |
sa24572.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for libwpd. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or to compromise an application using the library.
| | Homepage: | http://secunia.com/advisories/24572/ | | File Size: | 10370 | | Last Modified: | Mar 20 03:46:32 2007 |
| MD5 Checksum: | 1ebb29cf8b2fa95f6d6bdd1fb57ecc09 |
|
| /// File Name: |
sa24400.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially gain escalated privileges, and by malicious people to cause a DoS.
| | Homepage: | http://secunia.com/advisories/24400/ | | File Size: | 10316 | | Last Modified: | Mar 6 00:12:53 2007 |
| MD5 Checksum: | 143336e128d4443b2e93f9ea677f7b91 |
|
| /// File Name: |
USN-416-2.txt |
Description:
|
Ubuntu Security Notice 416-2 - USN-416-1 fixed various vulnerabilities in the Linux kernel. Unfortunately that update caused the 'nvidia-glx-config' script to not work any more. The new version fixes the problem.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 10179 | | Last Modified: | Mar 6 06:19:40 2007 |
| MD5 Checksum: | bafe30e5e76365335224708d7e76e81f |
|
| /// File Name: |
sa24604.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for file. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/24604/ | | File Size: | 10082 | | Last Modified: | Mar 22 19:34:38 2007 |
| MD5 Checksum: | b96d09b3b425b46b9299ad18bab4a79b |
|
| /// File Name: |
USN-439-1.txt |
Description:
|
Ubuntu Security Notice 439-1 - Jean-Sebastien Guay-Leroux discovered that "file" did not correctly check the size of allocated heap memory. If a user were tricked into examining a specially crafted file with the "file" utility, a remote attacker could execute arbitrary code with user privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 9921 | | Related CVE(s): | CVE-2007-1536 | | Last Modified: | Mar 24 02:14:14 2007 |
| MD5 Checksum: | 9d9eab70c7121f87b8a613aefa779896 |
|
| /// File Name: |
sa24479.txt |
Description:
|
Secunia Security Advisory - Apple has issued a security update for Mac OS X, which fixes multiple vulnerabilities.
| | Homepage: | http://secunia.com/advisories/24479/ | | File Size: | 9781 | | Last Modified: | Mar 17 03:22:27 2007 |
| MD5 Checksum: | 43fffc8cad4cdb3c98203089ffc70998 |
|
| /// File Name: |
msfilemanagement.txt |
Description:
|
Article discussing file management security issues in Microsoft Windows Vista/2003/XP/2000.
| | Author: | 3APA3A | | Homepage: | http://securityvulns.com/ | | File Size: | 9725 | | Last Modified: | Mar 9 04:23:22 2007 |
| MD5 Checksum: | 60fcecd6b876c994b1fd5658afc80a4f |
|
| /// File Name: |
NETRAGARD-20070316.txt |
Description:
|
Netragard, L.L.C Advisory - An exploitable vulnerability exists in FrontBase that can be used to gain NT AUTHORITY\SYSTEM or root privileges on an affected system. FrontBase versions 4.2.7 and below are affected.
| | Author: | Kevin Finisterre, Adriel T. Desautels | | Homepage: | http://www.netragard.com/html/recent_research.html | | File Size: | 9460 | | Last Modified: | Mar 20 16:07:44 2007 |
| MD5 Checksum: | 0f094283a3727f1618c74cdc736e5348 |
|
|
|
|
|