Section: .. / 0612-advisories /
| /// File Name: |
sa23324.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for flash-player. This fixes a vulnerability, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/23324/ | | File Size: | 3543 | | Last Modified: | Dec 14 21:28:17 2006 |
| MD5 Checksum: | 2a6c3610c972004d035136ed19826f2f |
|
| /// File Name: |
sa23448.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23448/ | | File Size: | 3535 | | Last Modified: | Dec 27 23:54:47 2006 |
| MD5 Checksum: | da57cd42a08a464bf9f270d847a85f25 |
|
| /// File Name: |
sa23335.txt |
Description:
|
Secunia Security Advisory - SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23335/ | | File Size: | 3521 | | Last Modified: | Dec 11 16:29:46 2006 |
| MD5 Checksum: | 2db4d037ae15fe9cd17aa8a8267a11cf |
|
| /// File Name: |
USN-396-1.txt |
Description:
|
Ubuntu Security Notice 396-1 - A format string vulnerability was discovered in the gdmchooser component of the GNOME Display Manager. By typing a specially crafted host name, local users could gain gdm user privileges, which could lead to further account information exposure.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 3517 | | Related CVE(s): | CVE-2006-6105 | | Last Modified: | Dec 15 10:59:29 2006 |
| MD5 Checksum: | 0d66d20c3dd9b844343d1d23529e95d7 |
|
| /// File Name: |
sa23232.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Microsoft Word, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23232/ | | File Size: | 3507 | | Last Modified: | Dec 7 07:24:29 2006 |
| MD5 Checksum: | 9d32e26419609e23b405cc008f10a358 |
|
| /// File Name: |
MDKSA-2006-234.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-234 - XSP (the Mono ASP.NET server) is vulnerable to source disclosure attack which allow a malicious user to obtain the source code of the server-side application. This vulnerability grants the attacker deeper knowledge of the Web application logic.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 3507 | | Related CVE(s): | CVE-2006-6104 | | Last Modified: | Dec 22 01:24:36 2006 |
| MD5 Checksum: | 9ea2a571d0eb176321fb5f26077db788 |
|
| /// File Name: |
sa20807.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/20807/ | | File Size: | 3473 | | Last Modified: | Dec 14 10:45:41 2006 |
| MD5 Checksum: | 1d49a2db4cc6652a4a9c043214b152d9 |
|
| /// File Name: |
sa23207.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for proftpd. This fixes some vulnerabilities, which can be exploited by malicious users and malicious people to potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23207/ | | File Size: | 3467 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | f2d48f8e111d06a6a4491eefc301e88e |
|
| /// File Name: |
11.30.06-1.txt |
Description:
|
iDefense Security Advisory 11.30.06 - Remote exploitation of a heap overflow vulnerability in libgsf, as included in various vendors' operating system distributions, could allow an attacker to execute arbitrary code. iDefense has confirmed the existence of this vulnerability in version 1.14.0 of the Gnome Structured File library. Any applications or libraries that utilize this library for OLE should be considered vulnerable.
| | Author: | infamous41md | | Homepage: | http://www.idefense.com/ | | File Size: | 3466 | | Related CVE(s): | CVE-2006-4514 | | Last Modified: | Dec 6 04:42:27 2006 |
| MD5 Checksum: | efebacbf57f8445ba77f81bdc4f0c27e |
|
| /// File Name: |
dsa-1239-1.txt |
Description:
|
Debian Security Advisory 1239-1 - Several remote vulnerabilities have been discovered in SQL Ledger, a web based double-entry accounting program, which may lead to the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 3444 | | Last Modified: | Dec 19 20:30:22 2006 |
| MD5 Checksum: | 80a0997514f1c2f36117f9360c160291 |
|
| /// File Name: |
TSLSA-2006-0072.txt |
Description:
|
Trustix Secure Linux Security Advisory #2006-0072: Hendrik Weimer has reported a vulnerability in ClamAV, which can be exploited by malicious people to cause a DoS (Denial of Service). The vulnerability is caused due to a stack overflow when scanning messages with deeply nested multipart content. This can be exploited to crash the service by sending specially crafted emails to a vulnerable system.
| | Homepage: | http://http.trustix.org/pub/trustix/updates | | File Size: | 3437 | | Last Modified: | Dec 19 20:33:18 2006 |
| MD5 Checksum: | d533f574f0004520604f859f03191087 |
|
| /// File Name: |
11.27.06-1.txt |
Description:
|
iDefense Security Advisory 11.27.06 - Remote exploitation of a design error in Horde's Kronolith could allow an authenticated web mail user to execute arbitrary PHP code under the security context of the running Web server. iDefense has confirmed that versions 2.0.1 through 2.1.3 of Horde Kronolith are vulnerable to this issue. Other versions are also likely to be vulnerable.
| | Homepage: | http://www.idefense.com/ | | File Size: | 3430 | | Last Modified: | Dec 6 03:41:50 2006 |
| MD5 Checksum: | 019813eb7c05e9a2f3c80f4848f5a617 |
|
| /// File Name: |
12.01.06-2.txt |
Description:
|
iDefense Security Advisory 12.01.06 - Remote exploitation of an integer overflow vulnerability in Novell Inc.'s ZENworks Asset Management could potentially allow an attacker to execute arbitrary code with the privileges of the administrator. A heap overflow may occur when processing specially crafted packets sent to the Task Server or Collection Server daemons. This problem specifically exists due to an integer overflow when allocating memory for remotely supplied data. iDefense has confirmed the existence of this vulnerability in version 7.0.0.36 of the CClient.exe and Msg.dll files included with Novell Inc's ZENworks Asset Management 7.0 SP1. Older versions are suspected to be vulnerable as well.
| | Author: | Eric Detoisien | | Homepage: | http://www.idefense.com/ | | File Size: | 3425 | | Last Modified: | Dec 6 05:34:27 2006 |
| MD5 Checksum: | 2dfccfa987262d75eab3c906f69f8a21 |
|
| /// File Name: |
sa23318.txt |
Description:
|
Secunia Security Advisory - Mr_KaLiMaN has discovered several vulnerabilities in AnnonceScriptHP, which can be exploited by malicious people to disclose sensitive data, conduct SQL injection and conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/23318/ | | File Size: | 3408 | | Last Modified: | Dec 12 16:19:53 2006 |
| MD5 Checksum: | c18944d3d7e92b73838329ac727a3513 |
|
| /// File Name: |
smf11-xss.txt |
Description:
|
SMFversions 1.1 Final and below suffer from a cross site scripting vulnerability.
| | Author: | Jessica Hope, rotwang | | File Size: | 3394 | | Last Modified: | Dec 6 06:21:45 2006 |
| MD5 Checksum: | 1ee4428f4274484a483264bef07323b9 |
|
| /// File Name: |
12.01.06-1.txt |
Description:
|
iDefense Security Advisory 12.01.06 - Remote exploitation of an integer overflow vulnerability in Novell Inc.'s ZENworks Asset Management could potentially allow an attacker to execute arbitrary code with SYSTEM privileges on Windows or root on the various supported UNIX based operating systems. A heap overflow may occur when processing specially crafted packets sent to the Collection Client daemon. The root cause of this vulnerability is identical to that of the vulnerability in Msg.dll. For more information please consult the Msg.dll advisory. iDefense has confirmed the existence of this vulnerability in version 7.0.0.36 of the CClient.exe and Msg.dll files included with Novell Inc's ZENworks Asset Management 7.0 SP1. Older versions are suspected to be vulnerable as well.
| | Author: | Eric Detoisien | | Homepage: | http://www.idefense.com/ | | File Size: | 3388 | | Last Modified: | Dec 6 05:33:40 2006 |
| MD5 Checksum: | 91d9d7d9e35835f25ada4534818b2fed |
|
| /// File Name: |
sa23445.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Sun Java JRE (Java Runtime Environment), which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23445/ | | File Size: | 3375 | | Last Modified: | Dec 20 23:30:34 2006 |
| MD5 Checksum: | 70609d1b1ef0403f5fe37da28d42e2eb |
|
| /// File Name: |
sa23368.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Symantec Veritas Netbackup, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23368/ | | File Size: | 3373 | | Last Modified: | Dec 14 21:28:17 2006 |
| MD5 Checksum: | 410e738a06f867a26de13650d941f961 |
|
| /// File Name: |
dsa-1241-1.txt |
Description:
|
Debian Security Advisory 1241-1 - In Squirrelmail, Martijn Brinkers discovered cross site scripting vulnerabilities in the the mailto parameter of webmail.php, the session and delete_draft parameters of compose.php and through a shortcoming in the magicHTML filter. An attacker could abuse these to execute malicious JavaScript in the user's webmail session.
| | Homepage: | http://www.debian.org/security | | File Size: | 3370 | | Related CVE(s): | CVE-2006-6142 | | Last Modified: | Dec 28 01:53:40 2006 |
| MD5 Checksum: | 54dc60aafa95a2610bdcbcc6c0bb83a1 |
|
| /// File Name: |
glsa-200611-26.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200611-26 - Evgeny Legerov discovered a stack-based buffer overflow in the s_replace() function in support.c, as well as a buffer overflow in in the mod_tls module. Additionally, an off-by-two error related to the CommandBufferSize configuration directive was reported. Versions less than 1.3.0a are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3361 | | Last Modified: | Dec 6 04:44:43 2006 |
| MD5 Checksum: | 91b7b167053bcdb0805650ea799e9eb0 |
|
| /// File Name: |
sa23208.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for libpng. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23208/ | | File Size: | 3346 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | 3054a0ddf96050a00e7b87be134b54a6 |
|
| /// File Name: |
MDKSA-2006-220.txt |
Description:
|
Mandriva Linux Security Advisory - "infamous41md" discovered a heap buffer overflow vulnerability in libgsf, a GNOME library for reading and writing structured file formats, which could lead to the execution of arbitrary code.
| | Homepage: | http://www.mandriva.com/security | | File Size: | 3344 | | Last Modified: | Dec 6 04:47:50 2006 |
| MD5 Checksum: | 997efcae3cc68433e965727f3a854752 |
|
| /// File Name: |
sa23144.txt |
Description:
|
Secunia Security Advisory - Vincent Audet Ménard has reported some vulnerabilities in AlternC, which can be exploited by malicious users to disclose sensitive information, to conduct script insertion attacks, or to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/23144/ | | File Size: | 3342 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | 831affec0022faa449301e194c4430c8 |
|
| /// File Name: |
CAID-34846.txt |
Description:
|
CAID 34846 - CA BrightStor ARCserve Backup contains a buffer overflow that allows remote attackers to execute arbitrary code with local SYSTEM privileges on Windows. This issue affects the BrightStor Backup Discovery Service in multiple BrightStor ARCserve Backup application agents and the Base product.
| | Author: | Ken Williams | | Homepage: | http://www3.ca.com/ | | File Size: | 3341 | | Related CVE(s): | CVE-2006-6379 | | Last Modified: | Dec 9 00:08:00 2006 |
| MD5 Checksum: | 8de71a296de6c70c131d297bdf14a0b4 |
|
| /// File Name: |
sa23209.txt |
Description:
|
Secunia Security Advisory - Slackware has issued an update for tar. This fixes a security issue, which can be exploited by malicious people to overwrite arbitrary files.
| | Homepage: | http://secunia.com/advisories/23209/ | | File Size: | 3323 | | Last Modified: | Dec 6 03:07:49 2006 |
| MD5 Checksum: | eb4b8e42d690bdf7ab1b7fbeeca031b7 |
|
|
|
|
|