Section: .. / 0601-advisories /
| /// File Name: |
2006090173928420.txt |
Description:
|
Due to an insecure usage of the Apache logging function (ap_log_rerror) in auth_ldap_log_reason of auth_ldap, it is possible to run arbitrary code on the server running the module. Versions 1.6.0 and below are affected.
| | Author: | Seregorn | | Homepage: | http://www.digitalarmaments.com/ | | File Size: | 2380 | | Last Modified: | Jan 10 06:03:19 2006 |
| MD5 Checksum: | 58f97d666df92f02647a28d8cad405bf |
|
| /// File Name: |
EV0020.txt |
Description:
|
Foxrum BBCode version 4.0.4f is susceptible to cross site scripting attacks.
| | Author: | Aliaksandr Hartsuyeu | | File Size: | 972 | | Last Modified: | Jan 10 05:56:44 2006 |
| MD5 Checksum: | a8f56cc2e26a7bc50b628635e580c8d6 |
|
| /// File Name: |
NetBSD-SA2006-002.txt |
Description:
|
NetBSD Security Advisory 2006-002 - The prohibition against setting the system time backwards at securelevel > 1 can be circumvented.
| | Homepage: | http://www.NetBSD.org/Security/ | | File Size: | 3207 | | Last Modified: | Jan 10 05:54:08 2006 |
| MD5 Checksum: | 2fdff858ac9159d97935dc26b5530ca3 |
|
| /// File Name: |
NetBSD-SA2006-001.txt |
Description:
|
NetBSD Security Advisory 2006-001 - The kernfs filesystem does not validate file offsets properly and a userlevel non-privileged process can read arbitrary kernel memory locations.
| | Homepage: | http://www.NetBSD.org/Security/ | | File Size: | 2929 | | Last Modified: | Jan 10 05:53:04 2006 |
| MD5 Checksum: | 7c3395740681de7aea30a35cf4e00e2b |
|
| /// File Name: |
rt-sa-2005-16.txt |
Description:
|
The implementations of securelevels on NetBSD and Linux contain an integer overflow, allowing the protection of system time to be completely circumvented.
| | Homepage: | http://www.redteam-pentesting.de/ | | File Size: | 3929 | | Related CVE(s): | CVE-2005-4352 | | Last Modified: | Jan 10 05:51:10 2006 |
| MD5 Checksum: | 849401f20aafd7ad6d40b6543eec82e3 |
|
| /// File Name: |
dsa-930-1.txt |
Description:
|
Debian Security Advisory DSA 930-1 - Ulf Harnhammar from the Debian Security Audit project discovered a format string attack in the logging code of smstools, which may be exploited to execute arbitrary code with root privileges.
| | Author: | Steve Kemp | | Homepage: | http://www.debian.org/security/ | | File Size: | 4230 | | Related CVE(s): | CVE-2006-0083 | | Last Modified: | Jan 10 05:41:57 2006 |
| MD5 Checksum: | e41cb8151709bcee68295233a15fbef9 |
|
| /// File Name: |
dsa-929-1.txt |
Description:
|
Debian Security Advisory DSA 929-1 - Steve Kemp from the Debian Security Audit project discovered a buffer overflow in petris, a clone of the Tetris game, which may be exploited to execute arbitrary code with group games privileges.
| | Author: | Steve Kemp | | Homepage: | http://www.debian.org/security/ | | File Size: | 4183 | | Related CVE(s): | CVE-2005-3540 | | Last Modified: | Jan 10 05:40:56 2006 |
| MD5 Checksum: | 69b6ace45aaec6bd6cfde7e0cd729e2f |
|
| /// File Name: |
USN-235-2.txt |
Description:
|
Ubuntu Security Notice USN-235-2 - USN-235-1 fixed a vulnerability in sudo's handling of environment variables. Tavis Ormandy noticed that sudo did not filter out the PYTHONINSPECT environment variable, so that users with the limited privilege of calling a python script with sudo could still escalate their privileges.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4908 | | Related CVE(s): | CVE-2005-4158 | | Last Modified: | Jan 10 05:39:13 2006 |
| MD5 Checksum: | 8958705501f5ee195c029d9e31e371d8 |
|
| /// File Name: |
mswGRE.txt |
Description:
|
Microsoft Windows GRE is susceptible to multiple overrun vulnerabilities when rendering WMF files.
| | Author: | cocoruder | | Homepage: | http://ruder.cdut.net/ | | File Size: | 7537 | | Last Modified: | Jan 10 05:37:54 2006 |
| MD5 Checksum: | cebfd36187a4aed9d6a6944ea95b5819 |
|
| /// File Name: |
USN-239-1.txt |
Description:
|
Ubuntu Security Notice USN-239-1 - Several format string vulnerabilities were discovered in the error logging handling of libapache2-mod-auth-pgsql. By sending specially crafted user names, an unauthenticated remote attacker could exploit this to crash the Apache server or possibly even execute arbitrary code with the privileges of Apache.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 5127 | | Related CVE(s): | CVE-2005-3656 | | Last Modified: | Jan 10 05:19:58 2006 |
| MD5 Checksum: | c63bb4290dbb2697a9432ab2f2070308 |
|
| /// File Name: |
sa18363.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for sudo. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/18363/ | | File Size: | 4541 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | 03ab5138bc88c149309a21e0cb897159 |
|
| /// File Name: |
sa18358.txt |
Description:
|
Secunia Security Advisory - Tavis Ormandy has reported a vulnerability in Sudo, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/18358/ | | File Size: | 1897 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | 78357b4fc02dc3973765d62952f549b8 |
|
| /// File Name: |
sa18357.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for smstools. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/18357/ | | File Size: | 3593 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | a2cd41555b08152d477381548a40b245 |
|
| /// File Name: |
sa18343.txt |
Description:
|
Secunia Security Advisory - Ulf Harnhammar has reported a vulnerability in SMS Server Tools, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and potentially to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/18343/ | | File Size: | 2000 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | 81138a0cb11fa9ecca044ca37d553ec4 |
|
| /// File Name: |
sa18276.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a security issue in Cacti, which can be exploited by malicious people to execute arbitrary SQL code and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/18276/ | | File Size: | 1677 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | 0101afe07d592d2ab3d529771c9a43b5 |
|
| /// File Name: |
sa18267.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered two security issues in Moodle, which can be exploited by malicious people to disclose system information, execute arbitrary SQL code, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/18267/ | | File Size: | 1728 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | 0043305ce3c93e1032146bddb49fefa9 |
|
| /// File Name: |
sa18260.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a security issue in PostNuke, which can be exploited by malicious people to execute arbitrary SQL code and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/18260/ | | File Size: | 1901 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | 85cfcaa2df12247a9cf8d3836a4f5987 |
|
| /// File Name: |
sa18254.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered two security issues in Mantis, which can be exploited by malicious people to disclose system information, execute arbitrary SQL code, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/18254/ | | File Size: | 1798 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | 8567b3e9456de37bb381635ce6d741f0 |
|
| /// File Name: |
sa17418.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered two security issues in ADOdb, which can be exploited by malicious people to disclose system information, execute arbitrary SQL code, and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/17418/ | | File Size: | 2697 | | Last Modified: | Jan 10 04:51:06 2006 |
| MD5 Checksum: | e059cc6fd802c8e0f83e15031be89f83 |
|
| /// File Name: |
sa18364.txt |
Description:
|
Secunia Security Advisory - Avaya has acknowledged a vulnerability in various products, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/18364/ | | File Size: | 2016 | | Last Modified: | Jan 9 19:23:14 2006 |
| MD5 Checksum: | 41da8e6d71ac5434684a73a759271601 |
|
| /// File Name: |
sa18361.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Joomla!, which can be exploited by malicious people to conduct cross-site scripting attacks and disclose sensitive information.
| | Homepage: | http://secunia.com/advisories/18361/ | | File Size: | 2394 | | Last Modified: | Jan 9 19:23:14 2006 |
| MD5 Checksum: | 8b5825d663634ffbb3a6763b78278301 |
|
| /// File Name: |
sa18360.txt |
Description:
|
Secunia Security Advisory - Preddy has reported a vulnerability in phpChamber, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/18360/ | | File Size: | 1706 | | Last Modified: | Jan 9 19:23:14 2006 |
| MD5 Checksum: | c8d7a6cda2263ea4ca1b1ed35108409c |
|
| /// File Name: |
sa18359.txt |
Description:
|
Secunia Security Advisory - Preddy has discovered a vulnerability in Andromeda, which can be exploited by malicious people to conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/18359/ | | File Size: | 1796 | | Last Modified: | Jan 9 19:23:14 2006 |
| MD5 Checksum: | 93814ce81e9af96581198a161f0941c1 |
|
| /// File Name: |
sa18356.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Eudora Internet Mail Server (EIMS), which potentially can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/18356/ | | File Size: | 2296 | | Last Modified: | Jan 9 19:23:14 2006 |
| MD5 Checksum: | 3c808ec026f8845c61f9becfd73f8820 |
|
|
|
|
|