Section: .. / 0803-advisories /
| /// File Name: |
sa29206.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for audacity. This fixes a security issue, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or to delete arbitrary files and directories.
| | Homepage: | http://secunia.com/advisories/29206/ | | File Size: | 2073 | | Last Modified: | Mar 3 18:09:32 2008 |
| MD5 Checksum: | 27f4532b7b871bb96069d8f09d15e942 |
|
| /// File Name: |
starteamz.txt |
Description:
|
Borland StarTeam server 2008 versions 10.0.0.57 and below suffer from multiple integer overflow vulnerabilities.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | starteamz.zip | | File Size: | 2272 | | Last Modified: | Mar 3 17:55:21 2008 |
| MD5 Checksum: | e43d293d8c4977372175759742a8b4b1 |
|
| /// File Name: |
visibroken.txt |
Description:
|
Borland VisiBroker Smart Agent versions 08.00.00.C1.03 and below suffer from a heap overflow vulnerability.
| | Author: | Luigi Auriemma | | Homepage: | http://aluigi.org/ | | Related Exploit: | visibroken.zip | | File Size: | 2534 | | Last Modified: | Mar 3 17:53:55 2008 |
| MD5 Checksum: | f6588a8d50668be1e359971c741656b3 |
|
| /// File Name: |
sa29205.txt |
Description:
|
Secunia Security Advisory - Gentoo has issued an update for acroread. This fixes a security issue and some vulnerabilities, some of which have unknown impacts while others can be exploited by malicious people to disclose system and sensitive information, cause a DoS (Denial of Service), or compromise a user's system.
| | Homepage: | http://secunia.com/advisories/29205/ | | File Size: | 2244 | | Last Modified: | Mar 3 17:50:28 2008 |
| MD5 Checksum: | c956ce3519c1932bdc130dcf3c06ce95 |
|
| /// File Name: |
sa29126.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in pfSense, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/29126/ | | File Size: | 2202 | | Last Modified: | Mar 3 17:45:20 2008 |
| MD5 Checksum: | e14a3ba0f3e27c118156ad59766e3f9e |
|
| /// File Name: |
sa29202.txt |
Description:
|
Secunia Security Advisory - Fedora has issued an update for viewvc. This fixes some security issues, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/29202/ | | File Size: | 2172 | | Last Modified: | Mar 3 17:45:20 2008 |
| MD5 Checksum: | f05f6ecd2f106fbf69081961eca04f4a |
|
| /// File Name: |
VMSA-2008-0004.txt |
Description:
|
VMware Security Advisory - An updated service console package for e2fsprogs has been released for ESX Server versions 2.5.5 and 2.5.4.
| | Homepage: | http://www.vmware.com/ | | File Size: | 3342 | | Related CVE(s): | CVE-2007-5497 | | Last Modified: | Mar 3 17:45:14 2008 |
| MD5 Checksum: | 8e4aad71756e9ab0a3cd93ac097bc1fb |
|
| /// File Name: |
dsa-1511-1.txt |
Description:
|
Debian Security Advisory 1511-1 - libicu in International Components for Unicode (ICU) 3.8.1 and earlier attempts to process backreferences to the nonexistent capture group zero (aka \0), which might allow context-dependent attackers to read from, or write to, out-of-bounds memory locations, related to corruption of REStackFrames. A heap-based buffer overflow in the doInterval function in regexcmp.cpp in libicu in International Components for Unicode (ICU) 3.8.1 and earlier allows context-dependent attackers to cause a denial of service (memory consumption) and possibly have unspecified other impact via a regular expression that writes a large amount of data to the backtracking stack.
| | Homepage: | http://www.debian.org/security | | File Size: | 6819 | | Related CVE(s): | CVE-2007-4770, CVE-2007-4771 | | Last Modified: | Mar 3 17:41:07 2008 |
| MD5 Checksum: | 7a21892de68e8fbb86fad8249d0d85f3 |
|
| /// File Name: |
07122001-eyefi.txt |
Description:
|
Airscanner Mobile Security Advisory #07122001 - Eye-Fi version 1.1.2 suffers from multiple cross site request forgery vulnerabilities.
| | Author: | Seth Fogie | | Homepage: | http://www.airscanner.com/ | | File Size: | 2759 | | Last Modified: | Mar 3 17:39:48 2008 |
| MD5 Checksum: | 9e9c2a6c781bf9e24320603e61b568d9 |
|
| /// File Name: |
DDIVRT-2008-09.txt |
Description:
|
The PacketTrap PT360 Tool Suite version 1.1.33.1.0 TFTP server component is vulnerable to a denial of service condition.
| | Author: | princeofnigeria | | Homepage: | http://www.digitaldefense.net/ | | File Size: | 1175 | | Last Modified: | Mar 3 17:37:51 2008 |
| MD5 Checksum: | 62d0c7485cdd2e557993698fd84e1921 |
|
| /// File Name: |
DDIVRT-2008-10.txt |
Description:
|
The PacketTrap PT360 Tool Suite version 1.1.33.1.0 TFTP server component is vulnerable to directory traversal attacks.
| | Author: | princeofnigeria | | Homepage: | http://www.digitaldefense.net/ | | File Size: | 1288 | | Last Modified: | Mar 3 17:37:18 2008 |
| MD5 Checksum: | 63a7c1cb6dc3594d286903361f7179b7 |
|
| /// File Name: |
DSECRG-08-017.txt |
Description:
|
Flyspray version 0.9.9.4 suffers from multiple cross site scripting vulnerabilities.
| | Author: | Digital Security Research Group | | Homepage: | http://www.dsec.ru/ | | File Size: | 3629 | | Last Modified: | Mar 3 17:35:23 2008 |
| MD5 Checksum: | ffee5a14cb79520404c26239c52a6845 |
|
| /// File Name: |
glsa-200803-07.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-07 - Dwayne C. Litzenberger reported that the file common.py does not properly use RandomPool when using threads or forked processes. Versions less than 1.7.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2994 | | Related CVE(s): | CVE-2008-0299 | | Last Modified: | Mar 3 16:20:38 2008 |
| MD5 Checksum: | 4a5a6c224a680c4d83aed4a5b825bcde |
|
| /// File Name: |
sa29193.txt |
Description:
|
Secunia Security Advisory - dB has reported a security issue in netOffice Dwins, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/29193/ | | File Size: | 2209 | | Last Modified: | Mar 3 16:14:16 2008 |
| MD5 Checksum: | e620f44be3e7d78c1439b65ab2b1fff2 |
|
| /// File Name: |
sa29215.txt |
Description:
|
Secunia Security Advisory - A vulnerability and a weakness have been reported in Flyspray, which can be exploited by malicious people to conduct cross-site scripting attacks or identify valid user accounts.
| | Homepage: | http://secunia.com/advisories/29215/ | | File Size: | 2764 | | Last Modified: | Mar 3 16:14:16 2008 |
| MD5 Checksum: | 89500e8b70092369247ac39cfbace189 |
|
| /// File Name: |
sa29217.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/29217/ | | File Size: | 2525 | | Last Modified: | Mar 3 16:14:16 2008 |
| MD5 Checksum: | 4a46183e4572cadbc75c6619607a31f7 |
|
| /// File Name: |
glsa-200803-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-06 - Dan Dennison reported that the diatheke.pl script used in SWORD does not properly sanitize shell meta-characters in the range parameter before processing it. Versions less than 1.5.8-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3063 | | Related CVE(s): | CVE-2008-0932 | | Last Modified: | Mar 3 16:13:56 2008 |
| MD5 Checksum: | 6af4daeebe05c22de986923daf879240 |
|
| /// File Name: |
glsa-200803-05.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-05 - Mike Ashton reported that SplitVT does not drop group privileges before executing the xprop utility. Versions less than 1.6.6-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2880 | | Related CVE(s): | CVE-2008-0162 | | Last Modified: | Mar 3 16:13:39 2008 |
| MD5 Checksum: | 7da0818089b962b60001c958af1d47a0 |
|
| /// File Name: |
glsa-200803-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-04 - seiji reported that the filename for the uploaded file in bug_report.php is not properly sanitized before being stored. Versions less than 1.0.8-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3048 | | Related CVE(s): | CVE-2007-6611 | | Last Modified: | Mar 3 16:13:22 2008 |
| MD5 Checksum: | aaf87384be6c3e2fa49a02dba098df76 |
|
| /// File Name: |
glsa-200803-03.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-03 - Viktor Griph reported that the AudacityApp::OnInit() method in file src/AudacityApp.cpp does not handle temporary files properly. Versions less than 1.3.4-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2802 | | Related CVE(s): | CVE-2007-6061 | | Last Modified: | Mar 3 16:13:01 2008 |
| MD5 Checksum: | c61f312d22baf4b9f385c4a603c340a2 |
|
| /// File Name: |
glsa-200803-02.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200803-02 - Firebird does not properly handle certain types of XDR requests, resulting in an integer overflow (CVE-2008-0387). Furthermore, it is vulnerable to a buffer overflow when processing usernames (CVE-2008-0467). Versions less than 2.0.3.12981.0-r5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3042 | | Related CVE(s): | CVE-2008-0387, CVE-2008-0467 | | Last Modified: | Mar 3 16:12:42 2008 |
| MD5 Checksum: | e091b565563607edd66074a21f9593b1 |
|
| /// File Name: |
squidanalysis-overflow.txt |
Description:
|
The Squid Analysis Report Generator versions 2.2.3.1 and below suffer from a buffer overflow vulnerability.
| | Author: | L4teral | | File Size: | 1652 | | Last Modified: | Mar 3 15:58:46 2008 |
| MD5 Checksum: | b8962681d2e28a0e946420554052fe51 |
|
| /// File Name: |
sa27885.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered some vulnerabilities in Symantec Backup Exec for Windows Servers, which can be exploited by malicious people to overwrite arbitrary files or compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/27885/ | | File Size: | 3491 | | Last Modified: | Mar 3 13:30:08 2008 |
| MD5 Checksum: | 9e2b5d9e26e0b79f43d7f15d5563c960 |
|
|
|
|
|