Section: .. / 0701-advisories /
| /// File Name: |
sa23814.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for libgtop2. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges.
| | Homepage: | http://secunia.com/advisories/23814/ | | File Size: | 2906 | | Last Modified: | Jan 19 19:09:28 2007 |
| MD5 Checksum: | 2a7063506b1ae85780f772c66248f98a |
|
| /// File Name: |
sa23740.txt |
Description:
|
Secunia Security Advisory - Coloss has discovered some vulnerabilities in All In One Control Panel (AIOCP), which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23740/ | | File Size: | 2901 | | Last Modified: | Jan 15 20:56:26 2007 |
| MD5 Checksum: | 6c9ca34e998c5089ea1ff82849622294 |
|
| /// File Name: |
sa23931.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for xine-ui. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23931/ | | File Size: | 2895 | | Last Modified: | Jan 29 11:19:09 2007 |
| MD5 Checksum: | 9c5ee46c77f292c1f08208515023cf28 |
|
| /// File Name: |
glsa-200701-25.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200701-25 - Multiple memory corruption vulnerabilities have been found in the ProcDbeGetVisualInfo() and the ProcDbeSwapBuffers() of the DBE extension, and ProcRenderAddGlyphs() in the Render extension. Versions less than 1.1.1-r4 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2893 | | Last Modified: | Jan 29 11:32:22 2007 |
| MD5 Checksum: | 7b32d79997096fb64e0c1d9f92b12c2b |
|
| /// File Name: |
sa23826.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in Django, which can be exploited by malicious users to bypass certain security restrictions or malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23826/ | | File Size: | 2892 | | Last Modified: | Jan 19 19:09:28 2007 |
| MD5 Checksum: | 86ab49880feea92270cfcc4d3f978a18 |
|
| /// File Name: |
MDKSA-2007-023.txt |
Description:
|
Mandriva Linux Security Advisory - Stack-based buffer overflow in the glibtop_get_proc_map_s function in libgtop before 2.14.6 (libgtop2) allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a process with a long filename that is mapped in its address space, which triggers the overflow in gnome-system-monitor.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2876 | | Related CVE(s): | CVE-2007-0235 | | Last Modified: | Jan 19 22:42:29 2007 |
| MD5 Checksum: | 7816059ef8c1c6527a8a2d209fca1199 |
|
| /// File Name: |
glsa-200701-23.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200701-23 - rgod discovered that the Cacti cmd.php and copy_cacti_user.php scripts do not properly control access to the command shell, and are remotely accessible by unauthenticated users. This allows SQL injection via cmd.php and copy_cacti_user.php URLs. Further, the results from the injected SQL query are not properly sanitized before being passed to a command shell. The vulnerabilities require that the register_argc_argv option is enabled, which is the Gentoo default. Also, a number of similar problems in other scripts were reported. Versions less than 0.8.6i-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2872 | | Last Modified: | Jan 26 23:18:24 2007 |
| MD5 Checksum: | 20755595642f5525d446d60a180d6784 |
|
| /// File Name: |
sa23475.txt |
Description:
|
Secunia Security Advisory - Secunia Research has discovered a vulnerability in NCTAudioStudio, NCTAudioEditor, and NCTDialogicVoice, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23475/ | | File Size: | 2863 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | e9b8deecdc4a630af6e125d593d608a6 |
|
| /// File Name: |
ZDI-07-002.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The specific flaw exists in the handling of RPC requests to the Tape Engine service which listens by default on TCP port 6502. Affected include BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1, BrightStor ARCserve Backup r11, BrightStor Enterprise Backup r10.5, and BrightStor ARCserve Backup v9.01.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2837 | | Related CVE(s): | CVE-2007-0168 | | Last Modified: | Jan 13 19:14:27 2007 |
| MD5 Checksum: | 14a1278e12723d0ac985d47f748fbc77 |
|
| /// File Name: |
ZDI-07-004.txt |
Description:
|
A vulnerability allows attackers to execute arbitrary code on vulnerable installations of Computer Associates BrightStor ARCserve Backup. User interaction is not required to exploit this vulnerability. The specific flaw exists in the Tape Engine RPC service which listens by default on TCP port 6503. Affected include BrightStor ARCserve Backup r11.5, BrightStor ARCserve Backup r11.1, BrightStor ARCserve Backup r11, BrightStor Enterprise Backup r10.5, and BrightStor ARCserve Backup v9.01.
| | Homepage: | http://www.zerodayinitiative.com/ | | File Size: | 2837 | | Related CVE(s): | CVE-2007-0169 | | Last Modified: | Jan 13 19:16:26 2007 |
| MD5 Checksum: | 751ec3a215916654c25086a3af2b1ae1 |
|
| /// File Name: |
sa23960.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in Drupal, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23960/ | | File Size: | 2814 | | Last Modified: | Jan 30 22:46:19 2007 |
| MD5 Checksum: | 03b0c53c56b1650f6c16ccdce38c4a7d |
|
| /// File Name: |
MDKSA-2007-013.txt |
Description:
|
Mandriva Linux Security Advisory - An array index error in the URI parser in neon 0.26.0 to 0.26.2 could possibly allow remote malicious servers to cause a crash via a URI with non-ASCII characters. This vulnerability may only exist on 64bit systems.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2799 | | Related CVE(s): | CVE-2007-0157 | | Last Modified: | Jan 13 20:06:09 2007 |
| MD5 Checksum: | 08a754e1e98b6355e11aa33ba8e648ad |
|
| /// File Name: |
01.26.07.txt |
Description:
|
CHM files contain various tables and objects stored in "pages." When parsing a page of objects, CHMlib passes an unsanitized value from the file to the alloca() function. This allows an attacker to shift the stack pointer to point to arbitrary locations in memory. Consequently it is possible to write arbitrary data from the file to arbitrary memory locations. Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the permissions of the user viewing the file. An attacker would have to first convince the user to view the CHM file through some type of social engineering. iDefense has confirmed the existence of this vulnerability in CHMlib version 0.38.
| | Author: | Sean Larsson | | Homepage: | http://www.idefense.com/ | | File Size: | 2790 | | Last Modified: | Jan 26 23:36:20 2007 |
| MD5 Checksum: | eae5775da2f691edeea7b2a245121c02 |
|
| /// File Name: |
glsa-200701-17.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200701-17 - Liu Qishuai discovered that glibtop_get_proc_map_s() in sysdeps/linux/procmap.c does not properly allocate memory for storing a filename, allowing certain filenames to cause the buffer to overflow on the stack. Versions less than 2.14.6 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2783 | | Last Modified: | Jan 24 01:39:25 2007 |
| MD5 Checksum: | f2b7f0baf630c02ca8099d8379093ce8 |
|
| /// File Name: |
sa23555.txt |
Description:
|
Secunia Security Advisory - Mandriva has issued an update for libmodplug. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/23555/ | | File Size: | 2776 | | Last Modified: | Jan 3 18:45:45 2007 |
| MD5 Checksum: | d764759dd8b6fe3d036112f7cd076188 |
|
| /// File Name: |
4tphi-sa-20070111-communityserver.t..> |
Description:
|
The Telligent Community Server versions 2.1 and below suffer from a remote denial of service condition.
| | Author: | Blake Matheny | | File Size: | 2773 | | Last Modified: | Jan 26 21:57:26 2007 |
| MD5 Checksum: | e009707e3d4cbcbed0dfda7184e1eb7a |
|
| /// File Name: |
sa23748.txt |
Description:
|
Secunia Security Advisory - Paisterist has discovered a vulnerability in PHP-Nuke, which can be exploited by malicious people to conduct SQL injection attacks.
| | Homepage: | http://secunia.com/advisories/23748/ | | File Size: | 2771 | | Last Modified: | Jan 18 03:44:32 2007 |
| MD5 Checksum: | 7e3e127bda50d95f979f8387e9fb8481 |
|
| /// File Name: |
MDKSA-2007-001.txt |
Description:
|
Mandriva Linux Security Advisory - Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier allow user-assisted remote attackers to execute arbitrary code via long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp and crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp, as demonstrated by crafted AMF files.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2762 | | Related CVE(s): | CVE-2006-4192 | | Last Modified: | Jan 2 20:52:43 2007 |
| MD5 Checksum: | 51a3a40df8054e9dcf031fcb45413519 |
|
| /// File Name: |
sa23799.txt |
Description:
|
Secunia Security Advisory - A weakness has been reported in KDE and KOffice, which can be exploited by malicious people to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23799/ | | File Size: | 2758 | | Last Modified: | Jan 18 03:44:32 2007 |
| MD5 Checksum: | c044de59c30d6854b9cb62efe8e42d07 |
|
| /// File Name: |
sa23636.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in HP DECnet-Plus for OpenVMS, which can be exploited by malicious people to bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/23636/ | | File Size: | 2756 | | Last Modified: | Jan 5 18:44:16 2007 |
| MD5 Checksum: | 9f464c87407abdf6363a0cd60d214948 |
|
| /// File Name: |
sa23896.txt |
Description:
|
Secunia Security Advisory - Two vulnerabilities have been reported in Symantec Web Security, which can be exploited by malicious people to conduct cross-site scripting attacks or to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/23896/ | | File Size: | 2747 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | dfeb87f748a1137c0ab1d5aa47fa97e7 |
|
| /// File Name: |
sa23913.txt |
Description:
|
Secunia Security Advisory - Some vulnerabilities have been reported in CGI Rescue WebFORM, which can be exploited by malicious people to conduct cross-site scripting and HTTP header injection attacks.
| | Homepage: | http://secunia.com/advisories/23913/ | | File Size: | 2746 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | 8142d3cbf2c1818bac6e17eea7bbbdaf |
|
| /// File Name: |
MDKSA-2007-015.txt |
Description:
|
Mandriva Linux Security Advisory - SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the second or third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 2739 | | Related CVE(s): | CVE-2006-6799 | | Last Modified: | Jan 15 22:40:52 2007 |
| MD5 Checksum: | 2fbdaa43c4d9bbfc31b66278eae91103 |
|
| /// File Name: |
sa23908.txt |
Description:
|
Secunia Security Advisory - A vulnerability has been reported in the Project module for Drupal, which can be exploited by malicious users to conduct script insertion attacks.
| | Homepage: | http://secunia.com/advisories/23908/ | | File Size: | 2737 | | Last Modified: | Jan 26 20:46:45 2007 |
| MD5 Checksum: | 5ce31e4546aefd452aec60f89a67680e |
|
| /// File Name: |
sa23856.txt |
Description:
|
Secunia Security Advisory - porkythepig has reported a vulnerability in Microsoft Visual Studio, which can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/23856/ | | File Size: | 2731 | | Last Modified: | Jan 23 22:46:18 2007 |
| MD5 Checksum: | f2747e22d6eecb4427027a15a296aec4 |
|
|
|
|
|